MemCatcher: An In-Depth Analysis Approach to Detect In-Memory Malware

Citations

WEB OF SCIENCE

1
Citations

SCOPUS

2

초록

Recent advancements in cyber threats have led to increasingly sophisticated attack methods that evade traditional malware detection systems. In-memory malware, a particularly challenging variant, operates by modifying volatile memory, leaving minimal traces on secondary storage. This paper presents an in-depth analysis of in-memory malware characteristics, behavior, and evasion strategies. We propose "MemCatcher", a novel detection algorithm that integrates real-time system activity monitoring and memory analysis to effectively identify these threats from the Windows 10 system. Experimental validation using real-world and synthetic in-memory malware samples demonstrates the effectiveness of our approach. Additionally, we analyze evasion tactics using "Volatility3" and "PEview", providing insights into countermeasures. Future work will focus on enhancing in-memory malware detection using "Processor-in-Memory (PIM) hardware".

키워드

malware detectionmalware analysisin-memory malwaremalicious serviceswindows securityFORENSICS
제목
MemCatcher: An In-Depth Analysis Approach to Detect In-Memory Malware
저자
Rai, AndriIm, Eul Gyu
DOI
10.3390/app152111800
발행일
2025-11
유형
Article
저널명
APPLIED SCIENCES-BASEL
15
21
페이지
1 ~ 24