Enhanced Malware Detection Method Using Baseline Comparison in Memory Forensics
Akash Thakar, Rakesh Singh Kunwar, Hemang A. Thakar, Kapil Kumar, Chintan Patel · 2023
The existing malware detection techniques are futile owing to the enormous quantity of malicious samples we have encountered in recent years. Consequently, new methods for malware analysis are required in order to analyze contemporary rootkits and file less malware. Since traces of such malware cannot be found after the machine has been shut down, memory forensics is the only means for doing so. In this study, a novel technique termed memory image mapping is put forth to enhance the widely utilized memory analysis method. It can take a while to locate the rogue process among the several others that are currently operating on the system when using the conventional investigative approach. By associating processes with a known standard memory image of the same operating system and version, a researcher can detect rogue processes more quickly. The method was also applied in a test environment, and researchers found excellent outcomes.