Dementia bluffs live memory analysis

Forensics fooled.

View larger image
The 29th Chaos Communication Congress (CCC) was themed 'not my department'. Credit: Markus Hametner
View larger image
The CCC rocket outside of the Congress Centrum Hamburg. Notice the dodgy C in the upper right ...
View larger image
The main auditorium seated 4000. Credit: Jan-Niklas Meier
See all pictures here »

A security researcher has released a tool that hides a computer's memory to defeat live digital forensics efforts.

Dementia is a proof of concept tool for hiding various OS artifacts from the memory or crash dumps acquired by the memory acquisition software.

Creator Luka Milković told SC ahead of the Chaos Communication Congress last month the method used was an extension of existing research into disk anti-forensics. 

 

"It's intention is to raise awareness for (or to remind) the forensic professionals that memory forensics, any other live forensic process and forensic applications have potential pitfalls and problems." 
It could hide operating system objects like processes and threads from a host of forensic analysis applications including Volatility and Memoryze.

The Infigo security consultant said two fundamental problems with acquisition tools are that they are usually run on machines not controlled by the handler, meaning attackers can have a kernel-level visibility and control over the system. A further complication was that tools must dump their data either on a local or external disk, or on a networked machine.

"Although these issues are well known, many incident handlers and forensic experts are still using those methods because the alternatives are rare, difficult to use in practice or expensive," Milković said.

By combining these two issues and controlling the process of dump writing, attackers can defeat most live memory acquisition methods used by forensics experts and incident handlers.

Previous recent research into memory anti-forensic techniques and methods made it difficult to impossible to hide operating system objects like network connections and processes.

The research included methods that completely blocked the acquisition process and were therefore easy to detect, thwarted the acquisition and analysis processes by tricking the memory manager and modifying the kernel structures.

Copyright © SC Magazine, Australia

Dementia bluffs live memory analysis
Technology

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read