Memory Forensics 2.0

Balzarotti, Davide
SSTIC 2023, Symposium sur la sécurité des technologies de l'information et des communications, 7-9 June 2023, Rennes, France

The risk of security breaches is higher than ever and attackers are routinely breaking into corporate networks, government services, and critical infrastructures. As a result, it is not a matter of `if' a system will be compromised, but only a matter of `when' -- thus making the way we handle computer incidents and investigations of paramount importance.

Unfortunately, the forensics field still relies on a collection of best practices and a multitude of dedicated tools, without a proper scientific and theoretical foundation. In this talk I will discuss some of the limitation of the current approaches for Memory forensics. I will then present some of the recent contributions of my group in this area and use them to introduce my view on the future of memory forensics.


Type:
Talk
City:
Rennes
Date:
2023-06-09
Department:
Sécurité numérique
Eurecom Ref:
7328
Copyright:
© EURECOM. Personal use of this material is permitted. The definitive version of this paper was published in SSTIC 2023, Symposium sur la sécurité des technologies de l'information et des communications, 7-9 June 2023, Rennes, France and is available at :
See also:

PERMALINK : https://www.eurecom.fr/publication/7328