{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/88107"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/88107","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Exploring application memory","abstract":"Increasingly complex malware continues to evade detection, stealing information, taking systems offline, and disrupting functionality of many computer systems. Traditional techniques have not adequately protected systems from attackers, and the most commonly used detection techniques overlook the contents of memory. Modern systems contain a wealth of information in the contents of memory, but making use of that information is anything but trivial. There are a number of challenges related to both the acquisition and analysis of a system's memory. Many forensic situations could involve machines in hostile environments, and many acquisition techniques result in artifacts, which reduce the fidelity of the image and hinder the analysis phase. Although the kernel memory space has come a long way in being mapped, the state of application memory has largely been unexplored. We have created a toolset that extracts the application's context from the structure of pointers in a sample of that application's memory. This context allows us to perform statistical analysis, visualize the structure of memory, and provides a new way to train classifiers.","abstract_html":"Increasingly complex malware continues to evade detection, stealing information, taking systems offline, and disrupting functionality of many computer systems. Traditional techniques have not adequately protected systems from attackers, and the most commonly used detection techniques overlook the contents of memory. Modern systems contain a wealth of information in the contents of memory, but making use of that information is anything but trivial. There are a number of challenges related to both the acquisition and analysis of a system&#x27;s memory. Many forensic situations could involve machines in hostile environments, and many acquisition techniques result in artifacts, which reduce the fidelity of the image and hinder the analysis phase. Although the kernel memory space has come a long way in being mapped, the state of application memory has largely been unexplored. We have created a toolset that extracts the application&#x27;s context from the structure of pointers in a sample of that application&#x27;s memory. This context allows us to perform statistical analysis, visualize the structure of memory, and provides a new way to train classifiers.","abstract_has_math":false,"creators":["Larson, Kevin Andrew"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Campbell, Roy H."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2015,"date_issued":"2015-09-29T20:38:50Z","date_published":"2015-09-29T20:38:50Z","updated_at":"2026-07-22T22:26:31Z","subjects":["Forensics","Memory","Visualization"],"languages":["en"],"rights":["Copyright 2015 Kevin Larson"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/88107","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Campbell, Roy H."]},{"key":"dc:creator","label":"Author","values":["Larson, Kevin Andrew"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2015-09-29T20:38:50Z","2015-08","2015-07-22","2015-8"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Forensics","Memory","Visualization"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2015 Kevin Larson"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/88107"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Increasingly complex malware continues to evade detection, stealing information, taking systems offline, and disrupting functionality of many computer systems. Traditional techniques have not adequately protected systems from attackers, and the most commonly used detection techniques overlook the contents of memory. Modern systems contain a wealth of information in the contents of memory, but making use of that information is anything but trivial. There are a number of challenges related to both the acquisition and analysis of a system's memory. Many forensic situations could involve machines in hostile environments, and many acquisition techniques result in artifacts, which reduce the fidelity of the image and hinder the analysis phase. Although the kernel memory space has come a long way in being mapped, the state of application memory has largely been unexplored. We have created a toolset that extracts the application's context from the structure of pointers in a sample of that application's memory. This context allows us to perform statistical analysis, visualize the structure of memory, and provides a new way to train classifiers.","Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2015-09-29 without embargo terms","The student, Kevin Larson, accepted the attached license on 2015-07-21 at 22:06.","The student, Kevin Larson, submitted this Thesis for approval on 2015-07-22 at 08:12.","This Thesis was approved for publication on 2015-07-22 at 09:29.","DSpace SAF Submission Ingestion Package generated from Vireo submission #8598 on 2015-09-29 at 13:23:32","Made available in DSpace on 2015-09-29T20:38:50Z (GMT). No. of bitstreams: 2 LARSON-THESIS-2015.pdf: 3745828 bytes, checksum: a592077d91ebdce0d6b09cf4d26734d0 (MD5) LICENSE.txt: 4209 bytes, checksum: 4c30b26926dbf2dbcb549a846b03cd59 (MD5) Previous issue date: 2015-07-22"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Exploring application memory"]}]}],"canonical_facts":{"dc:contributor":["Campbell, Roy H."],"dc:creator":["Larson, Kevin Andrew"],"dc:date":["2015-09-29T20:38:50Z","2015-08","2015-07-22","2015-8"],"dc:description":["Increasingly complex malware continues to evade detection, stealing information, taking systems offline, and disrupting functionality of many computer systems. Traditional techniques have not adequately protected systems from attackers, and the most commonly used detection techniques overlook the contents of memory. Modern systems contain a wealth of information in the contents of memory, but making use of that information is anything but trivial. There are a number of challenges related to both the acquisition and analysis of a system's memory. Many forensic situations could involve machines in hostile environments, and many acquisition techniques result in artifacts, which reduce the fidelity of the image and hinder the analysis phase. Although the kernel memory space has come a long way in being mapped, the state of application memory has largely been unexplored. We have created a toolset that extracts the application's context from the structure of pointers in a sample of that application's memory. This context allows us to perform statistical analysis, visualize the structure of memory, and provides a new way to train classifiers.","Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2015-09-29 without embargo terms","The student, Kevin Larson, accepted the attached license on 2015-07-21 at 22:06.","The student, Kevin Larson, submitted this Thesis for approval on 2015-07-22 at 08:12.","This Thesis was approved for publication on 2015-07-22 at 09:29.","DSpace SAF Submission Ingestion Package generated from Vireo submission #8598 on 2015-09-29 at 13:23:32","Made available in DSpace on 2015-09-29T20:38:50Z (GMT). No. of bitstreams: 2 LARSON-THESIS-2015.pdf: 3745828 bytes, checksum: a592077d91ebdce0d6b09cf4d26734d0 (MD5) LICENSE.txt: 4209 bytes, checksum: 4c30b26926dbf2dbcb549a846b03cd59 (MD5) Previous issue date: 2015-07-22"],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/88107"],"dc:language":["en"],"dc:rights":["Copyright 2015 Kevin Larson"],"dc:subject":["Forensics","Memory","Visualization"],"dc:title":["Exploring application memory"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:26:31Z"}