Building stack traces from memory dump of Windows x64. (March 2018)
- Record Type:
- Journal Article
- Title:
- Building stack traces from memory dump of Windows x64. (March 2018)
- Main Title:
- Building stack traces from memory dump of Windows x64
- Authors:
- Otsuki, Yuto
Kawakoya, Yuhei
Iwamura, Makoto
Miyoshi, Jun
Ohkubo, Kazuhiko - Abstract:
- Abstract: Stack traces play an important role in memory forensics as well as program debugging. This is because stack traces provide a history of executed code in a malware-infected host and this history could become a clue for forensic analysts to uncover the cause of an incident, i.e., what malware have actually done on the host. Nevertheless, existing research and tools for building stack traces for memory forensics are not well designed for the x64 environments, even though they have already become the most popular environment. In this paper, we introduce the design and implementation of our method for building stack traces from a memory dump of the Windows x64 environment. To build a stack trace, we retrieve a user context of the target thread from a memory dump for determining the start point of a stack trace, and then emulate stack unwinding referencing the metadata for exceptional handling for building the call stack of the thread. Even if the metadata are unavailable, which often occurs in a case of malicious software, we manage to produce the equivalent data by scanning the stack with a flow-based verification method. In this paper, we discuss the evaluation of our method through comparing the stack traces built with it with those built with WinDbg to show the accuracy of our method. We also explain some case studies using real malware to show the practicability of our method.
- Is Part Of:
- Digital investigation. Volume 24(2018)
- Journal:
- Digital investigation
- Issue:
- Volume 24(2018)
- Issue Display:
- Volume 24, Issue 2018 (2018)
- Year:
- 2018
- Volume:
- 24
- Issue:
- 2018
- Issue Sort Value:
- 2018-0024-2018-0000
- Page Start:
- S101
- Page End:
- S110
- Publication Date:
- 2018-03
- Subjects:
- Memory forensics -- Stack trace -- Windows x64 -- Thread context
Forensic sciences -- Data processing -- Periodicals
Criminal investigation -- Data processing -- Periodicals
363.250285 - Journal URLs:
- http://www.sciencedirect.com/science/journal/17422876 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.diin.2018.01.013 ↗
- Languages:
- English
- ISSNs:
- 1742-2876
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3588.396620
British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 6450.xml