• Home
  • Search
  • Automated Extraction of Network Activity From Memory Resident Code
  • https://doi.org/10.31390/gradschool_theses.5076Copy DOI Icon

Automated Extraction of Network Activity From Memory Resident Code

  • Mar 9, 2020
  • Austin Sellers
Show More
  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

Advancements in malware development, including the use of file-less and memory-only payloads, have led to a significant interest in the use of volatile memory analysis by digital forensics practitioners. Memory analysis can uncover a wealth of information not available via traditional analysis, such as the discovery of injected code, hooked APIs, and more. Unfortunately, the process of analyzing such malicious code is largely left to analysts who must manually reverse engineer the code to discover its intent. This task is not only slow and error-prone, but is also generally left only to senior-level analysts to perform, given that significant reverse engineering skills are required. This work focuses on the use of code emulation to automatically complete one of the most common tasks of malware analysis -discovering a malware sample’s network activity. Our tool automatically discovers the locations where malware uses networking APIs, emulates the network operations, and records the parameters passed to those functions. Through the monitoring of such parameters, this work enables the automatic discovery of the IP addresses, domain names, and network ports utilized by malware to connect to remote command-and-control (C2) servers as well as accept incoming connections. This novel use of emulation applied to in-memory code provides significant benefits compared to traditional whole-system emulation, which requires a full executable to run and does not match the environment that malware executed during a live incident. In contrast, our approach can emulate any code in memory, including inside of shellcode buffers and memory-only libraries. The novel network API monitoring capabilities developed for this research project were written as an extension to HookTracer, which is an plugin for the Volatility memory analysis framework. HookTracer provides emulation of API hooks in memory, but does not target any specific network activity. The contribution of this work is the incorporation of network API monitoring into HookTracer, development of a test suite that ensures the parameter monitoring is correct, and the evaluation of the techniques we have developed against real-world malware.

Similar Papers
  • Research Article

DGA Clustering and Analysis: Mastering Modern, Evolving Threats, DGALab

  • May 12, 2016
  • SHILAP Revista de lepidopterología
  • Alexander Chailytko +1
  • Research Article
  • Citations7

Toward Optimal LSTM Neural Networks for Detecting Algorithmically Generated Domain Names

  • Jan 01, 2021
  • IEEE Access
  • Jose Selvi +2
  • Research Article
  • Citations3

Malware Instrumentation Application to Regin Analysis

  • Dec 21, 2015
  • SHILAP Revista de lepidopterología
  • Matthieu Kaczmarek
  • Book Chapter
  • Citations14

Introduction to Malware Analysis

  • Oct 31, 2021
  • Nitul Dutta +4
  • Research Article
  • Citations2

Study on Live analysis of Windows Physical Memory

  • Jan 01, 2013
  • IOSR Journal of Computer Engineering
  • Divyang Rahevar
  • Research Article

Data Mining of Social Media Specific Strings for Rapid Forensic Investigation

  • Nov 15, 2015
  • Indian Journal of Science and Technology
  • A Vinu +1
  • Research Article

An Intelligent Analysis Model for Multisource Volatile Memory

  • Oct 16, 2013
  • Journal of Networks
  • Xiaolu Zhang +5
  • Research Article
  • Citations21

Design and implementation of a novel enterprise network defense system bymaneuveringmulti-dimensional network properties

  • Feb 01, 2019
  • Frontiers of Information Technology & Electronic Engineering
  • Yang Chen +2
  • Book Chapter
  • Citations19

Using Dalvik Opcodes for Malware Detection on Android

  • Jan 01, 2015
  • José Gaviria De La Puerta +3
  • Research Article
  • Citations4

EmuID: Detecting presence of emulation through microarchitectural characteristic on ARM

  • Dec 02, 2021
  • Computers & Security
  • Yeseul Choi +4
  • Research Article

Trisentry-MD- A unified and high performance deep ensemble model for android malware detection

  • Dec 31, 2025
  • International Journal of Software Engineering and Knowledge Engineering
  • Veeresh K M +1
  • Book Chapter
  • Citations6

Leopard: Understanding the Threat of Blockchain Domain Name Based Malware

  • Jan 01, 2020
  • Zhangrong Huang +2
  • Book Chapter
  • Citations40

Chapter 1 - Intrusion Detection Systems

  • Jan 01, 2004
  • Snort 2.1 Intrusion Detection, Second Edition
  • Andrew R Baker +10
  • Research Article
  • Citations10

ARCADIS: Asynchronous Remote Control-Flow Attestation of Distributed IoT Services

  • Jan 01, 2021
  • IEEE Access
  • Ragnar Mikael Halldorsson +2
  • Conference Article
  • Citations1

Machine Learning Model of an Intelligent Decision Support System in the Information Security Sphere

  • Sep 01, 2020
  • Fyodor O Fedin +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.