Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

8/10/2011
05:47 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

New Free Tool Helps Gather Attackers' 'Footprints'

Researchers simplify the process of physical memory analysis in forensics investigations

Researchers have devised a new more efficient way to glean attacker information from a machine’s physical memory, which often contains valuable bits of information that can help get to the bottom of a breach investigation case.

Click here for more of Dark Reading's Black Hat articles.

Jamie Butler and Justin Murdock, both researchers from Mandiant, presented their new technique for memory analysis last week at Black Hat USA in Las Vegas. Their approach solves an age-old problem in forensics -- being able to rapidly assess an infected machine or group of machines within the victim organization.

"Memory analysis is critical when trying to triage an infected host. Instead of looking for the attacker in 250 GB of hard drive space, an incident responder can focus on the 4 GB of RAM where the intruder is executing," said Butler, who is director of research and development for Mandiant.

"We do a pretty good job at getting that data now. But we have done research and submitted techniques to get more of that data in memory," he said.

There still are hundreds of processes and thousands of DLLs and executables to analyze, he said.

"If you're trying to pull processes out of memory to disassemble and send to the malware team, you can do that a lot better with this system so that more of the binary comes out of memory, and when you lot it into the disassembler, you get a lot better data and results ... You can find interesting things for Microsoft Word files [there]," he says. "So it makes the malware analyst's job more productive."

So the researchers use what they coined as "MemD5" hashing, as well as whitelisting, to consolidate and pare down the list of malicious items to a more manageable number.

"By using MemD5 and whitelisting, we can reduce the number of things that could be malicious from thousands to tens. This goes a long way toward the goal of quickly triaging a host in an enterprise full of over 100,000 hosts -- any of which could be compromised. In order to eradicate the invader, quick identification is key," he said.

The problem, of course, is that it isn't just one machine that's infected, but many. And attackers can leave their malware dormant on some machines while exfiltrating from another, for instance. "With the size of disk drives increasing, it is difficult to triage the 50,000 to 150,000 hosts found in many enterprises, but memory forensics can be used initially to reduce a typical 250-GB drive on a host down to the 4 GB of RAM it contains," Butler says.

The new physical memory forensics feature is now part of Mandiant's free Memoryze tool.

Previous forensics techniques attempted to reduce the number of binaries using so-called pattern-matching. The Mandiant researchers used hashing instead to shrink a large amount of data into known good and known bad chunks -- legitimate Windows processes and third-party apps would fall in the "good" category, for example.

Butler and Murdock demonstrated how to generate a hash of a binary from memory that matches the hash on disk. "Using this technique of comparing hashes and eliminating the things we already know about, we can greatly reduce the dataset of things that need to be investigated further," Butler says.

The bottom line: Attackers leave a bigger memory footprint than they realize.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
I 'Hacked' My Accounts Using My Mobile Number: Here's What I Learned
Nicole Sette, Director in the Cyber Risk practice of Kroll, a division of Duff & Phelps,  11/19/2019
TPM-Fail: What It Means & What to Do About It
Ari Singer, CTO at TrustPhi,  11/19/2019
Ransomware Surge & Living-Off-the-Land Tactics Remain Big Threats
Jai Vijayan, Contributing Writer,  11/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19013
PUBLISHED: 2019-11-22
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
CVE-2019-3427
PUBLISHED: 2019-11-22
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users� information leakage.
CVE-2019-3428
PUBLISHED: 2019-11-22
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker could directly access the management portal in HTTP, resulting in users� information leakage.
CVE-2019-4214
PUBLISHED: 2019-11-22
IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 159185.
CVE-2019-4215
PUBLISHED: 2019-11-22
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks ag...