Analysis on Malware's Hidden Information Detection based onVM's vmem File

He Xiang · Information Security and Communications Privacy · 2012

For detection of malware's hidden information with Rootkit,a new scheme based on VM Cross-view comparison is proposed. In this scheme,malwares are analyzed in a virtual machine and the information of the virtual machine is acquired from virtual machine itself and the vmem file in the host machine. By comparing the information, the process information hidden in the malware could thus be found.

Read the paper · More papers on PaperTik