首页> 外文会议>International Symposium on Digital Forensic and Security >A tool to compute approximation matching between windows processes
【24h】

A tool to compute approximation matching between windows processes

机译:计算Windows进程之间的近似匹配的工具

获取原文

摘要

Finding identical digital objects (or artifacts) during a forensic analysis is commonly achieved by means of cryptographic hashing functions, such as MD5, SHA1, or SHA-256, to name a few. However, these functions suffer from the avalanche effect property, which guarantees that if an input is changed slightly the output changes significantly. Hence, these functions are unsuitable for typical digital forensics scenarios where a forensics memory image from a likely compromised machine shall be analyzed. This memory image file contains a snapshot of processes (instances of executable files) which were up on execution when the dumping process was done. However, processes are relocated at memory and contain dynamic data that depend on the current execution and environmental conditions. Therefore, the comparison of cryptographic hash values of different processes from the same executable file will be negative. Bytewise approximation matching algorithms may help in these scenarios, since they provide a similarity measurement in the range [0,1] between similar inputs instead of a yeso answer (in the range {0,1}). In this paper, we introduce ProcessFuzzyHash, a Volatility plugin that enables us to compute approximation hash values of processes contained in a Windows memory dump.
机译:在取证分析期间找到相同的数字对象(或伪像)通常是通过加密哈希函数(例如MD5,SHA1或SHA-256等)来实现的。但是,这些函数具有雪崩效应属性,该属性可确保如果输入稍有变化,则输出会发生显着变化。因此,这些功能不适用于典型的数字取证场景,在这种情况下,应分析来自可能受损计算机的取证存储映像。此内存映像文件包含进程(执行文件实例)的快照,这些快照在完成转储过程时即已执行。但是,进程将重定位在内存中,并且包含取决于当前执行和环境条件的动态数据。因此,来自同一可执行文件的不同进程的加密哈希值的比较将为负。在这些情况下,按字节近似匹配算法可能会有所帮助,因为它们在相似输入之间的范围[0,1]中提供相似性度量,而不是是/否答案(范围为{0,1})。在本文中,我们介绍了ProcessFuzzyHash,这是一个Volatility插件,使我们能够计算Windows内存转储中包含的进程的近似哈希值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号