Correlating processes for automatic memory evidence analysis

Xiao Fu, Xiaojiang Du, Bin Luo, Jin Shi, Zhitao Guan, Yuhua Wang

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Nowadays in order to process and store many kinds of multimedia data, the storage capability of memory has grown greatly. Moreover the widespread use of mobile devices and cloud computing has made criminal investigators often face a lot of memory dumps. They have to deal with a large quantity of memory data and complex OS data structures which they have little knowledge of. How to analyze memory evidence automatically in order to find hidden criminal behavior and reconstruct the criminal scenario in an understandable way has become an important problem. Current memory analysis methods usually aim at recovering certain data structures. The illegal behavior identification and the event reconstruction are still completed manually by investigators. This paper presents a novel method to correlate processes for automatic memory evidence analysis. Through analyzing key OS data structures and utilizing a clustering algorithm, it can discover the relationships among processes. And by describing these relationships as correlation graphs, our method can display evidence in a high semantic level. Some experiments have proved that these correlation graphs can help investigators find hidden criminal behavior and reconstruct the criminal scenarios.

Original languageEnglish
Title of host publication2015 IEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2015
Pages115-120
Number of pages6
ISBN (Electronic)9781467371315
DOIs
StatePublished - 4 Aug 2015
EventIEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2015 - Hong Kong, Hong Kong
Duration: 26 Apr 20151 May 2015

Publication series

NameProceedings - IEEE INFOCOM
Volume2015-August
ISSN (Print)0743-166X

Conference

ConferenceIEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2015
Country/TerritoryHong Kong
CityHong Kong
Period26/04/151/05/15

Keywords

  • clustering
  • event reconstruction
  • memory evidence analysis
  • memory forensics
  • processes correlation

Fingerprint

Dive into the research topics of 'Correlating processes for automatic memory evidence analysis'. Together they form a unique fingerprint.

Cite this