基本信息来源于合作网站,原文需代理用户跳转至来源网站获取       
摘要:
Memory forensics is a young but fast-growing area of research and a promising one for the field of computer forensics. The learned model is proposed to reside in an isolated core with strict communication restrictions to achieve incorruptibility as well as efficiency, therefore providing a probabilistic memory-level view of the system that is consistent with the user-level view. The lower level memory blocks are constructed using primary block sequences of varying sizes that are fed as input into Long-Short Term Memory (LSTM) models. Four configurations of the LSTM model are explored by adding bi- directionality as well as attention. Assembly level data from 50 Windows portable executable (PE) files are extracted, and basic blocks are constructed using the IDA Disassembler toolkit. The results show that longer primary block sequences result in richer LSTM hidden layer representations. The hidden states are fed as features into Max pooling layers or Attention layers, depending on the configuration being tested, and the final classification is performed using Logistic Regression with a single hidden layer. The bidirectional LSTM with Attention proved to be the best model, used on basic block sequences of size 29. The differences between the model’s ROC curves indicate a strong reliance on the lower level, instructional features, as opposed to metadata or string features.
推荐文章
基于recurrent neural networks的网约车供需预测方法
长短时记忆循环神经网络
网约车数据
交通优化调度
TensorFlow
深度学习
Determination of brominated diphenyl ethers in atmospheric particulate matter using selective pressu
Brominated diphenyl ethers
Atmospheric particulate matters
Selective pressurised liquid extraction
Gas chromatography-mass spectrometry
基于recurrent neural networks的网约车供需预测方法
长短时记忆循环神经网络
网约车数据
交通优化调度
TensorFlow
深度学习
内容分析
关键词云
关键词热度
相关文献总数  
(/次)
(/年)
文献信息
篇名 Malware Detection for Forensic Memory Using Deep Recurrent Neural Networks
来源期刊 信息安全(英文) 学科 工学
关键词 BiLSTM DEEP LEARNING Forensic MEMORY LSTM RNN
年,卷(期) 2020,(2) 所属期刊栏目
研究方向 页码范围 103-120
页数 18页 分类号 TP3
字数 语种
DOI
五维指标
传播情况
(/次)
(/年)
引文网络
引文网络
二级参考文献  (0)
共引文献  (0)
参考文献  (0)
节点文献
引证文献  (0)
同被引文献  (0)
二级引证文献  (0)
2020(0)
  • 参考文献(0)
  • 二级参考文献(0)
  • 引证文献(0)
  • 二级引证文献(0)
研究主题发展历程
节点文献
BiLSTM
DEEP
LEARNING
Forensic
MEMORY
LSTM
RNN
研究起点
研究来源
研究分支
研究去脉
引文网络交叉学科
相关学者/机构
期刊影响力
信息安全(英文)
季刊
2153-1234
武汉市江夏区汤逊湖北路38号光谷总部空间
出版文献量(篇)
230
总下载数(次)
0
总被引数(次)
0
论文1v1指导