CRAISep 20, 2021

A proactive malicious software identification approach for digital forensic examiners

arXiv:2109.09567v115 citations
Originality Synthesis-oriented
AI Analysis

This addresses the issue for digital forensic examiners by providing a proactive approach to malware identification, though it appears incremental as it builds on existing forensic methods.

The paper tackled the problem of digital forensic examiners wasting time on cases where malware is initially overlooked, by investigating malware behavior across Windows OS versions to correlate it with OS artifacts, enabling more efficient identification of new malware.

Digital investigators often get involved with cases, which seemingly point the responsibility to the person to which the computer belongs, but after a thorough examination malware is proven to be the cause, causing loss of precious time. Whilst Anti-Virus (AV) software can assist the investigator in identifying the presence of malware, with the increase in zero-day attacks and errors that exist in AV tools, this is something that cannot be relied upon. The aim of this paper is to investigate the behaviour of malware upon various Windows operating system versions in order to determine and correlate the relationship between malicious software and OS artifacts. This will enable an investigator to be more efficient in identifying the presence of new malware and provide a starting point for further investigation.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes