MemTri: A Memory Forensics Triage Tool Using Bayesian Network and Volatility

Antonis Michalas, Rohan Murray

Research output: Chapter in Book/Report/Conference proceedingConference contributionScientificpeer-review

5 Citations (Scopus)

Abstract

This work explores the development of MemTri. A memory forensics triage tool that can assess the likelihood of criminal activity in a memory image, based on evidence data artefacts generated by several applications. Fictitious illegal suspect activity scenarios were performed on virtual machines to generate 60 test memory images for input into MemTri. Four categories of applications (i.e. Internet Browsers, Instant Messengers, FTP Client and Document Processors) are examined for data artefacts located through the use of regular expressions. These identified data artefacts are then analysed using a Bayesian Network, to assess the likelihood that a seized memory image contained evidence of illegal firearms trading activity. MemTri's normal mode of operation achieved a high artefact identification accuracy performance of 95.7% when the applications' processes were running. However, this fell significantly to 60% as applications processes' were terminated. To explore improving MemTri's accuracy performance, a second mode was developed, which achieved more stable results of around 80% accuracy, even after applications processes' were terminated.
Original languageEnglish
Title of host publicationProceedings of the 2017 International Workshop on Managing Insider Security Threats
Place of PublicationNew York, NY, USA
PublisherACM
Pages57-66
Number of pages10
ISBN (Print)978-1-4503-5177-5
DOIs
Publication statusPublished - 2017
Externally publishedYes
Publication typeA4 Article in conference proceedings

Publication series

NameMIST '17
PublisherACM

Keywords

  • cyber crime, digital evidence, digital forensics, random access memory, triage

Fingerprint

Dive into the research topics of 'MemTri: A Memory Forensics Triage Tool Using Bayesian Network and Volatility'. Together they form a unique fingerprint.

Cite this