Exploiting Non-Uniform Program Execution Time to Evade Record/Replay Forensic Analysis

Computers & Security(2020)

引用 0|浏览22
暂无评分
摘要
Record/replay system is an essential and widely used module in forensic analysis, as it can help forensic analysts to reconstruct programs’ behaviors. However, the security implication of record/replay systems (i.e., whether record/replay systems can faithfully reproduce all behaviors of a program) has not been thoroughly studied. This paper is the first work which investigates and explores the security limitations of record/replay systems from the perspective of software forensics. In particular, we reveal a type of vulnerability in record/replay systems caused by non-uniform program execution time. A program can exploit this vulnerability to prevent its malicious behavior from being replayed. We conduct a series of experiments on three platforms (i.e., web browser, mobile operating system and virtualized sandbox) to illustrate the wide footprints of the vulnerability. Finally, we discuss possible methods to mitigate the vulnerability. The goal of this work is to study the inherent security limitations of record/replay systems, discover the vulnerability and explore potential mitigation methods, from which forensic analysts can be informed and cautious when applying record/replay systems to software forensics.
更多
查看译文
关键词
Forensic analysis,Record/replay system,Anti-forensics,Vulnerability exploitation,Malware analysis
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要