Analysis on Malware's Hidden Information Detection based onVM's vmem File
He Xiang · Information Security and Communications Privacy · 2012
For detection of malware's hidden information with Rootkit,a new scheme based on VM Cross-view comparison is proposed. In this scheme,malwares are analyzed in a virtual machine and the information of the virtual machine is acquired from virtual machine itself and the vmem file in the host machine. By comparing the information, the process information hidden in the malware could thus be found.