NORMA eResearch @NCI Library

Cross-Platform Unified Memory Forensics Framework: Extending Semantic Techniques for Modern Operating Systems

Santhoju, Manoj (2025) Cross-Platform Unified Memory Forensics Framework: Extending Semantic Techniques for Modern Operating Systems. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (1MB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (824kB) | Preview

Abstract

Memory forensics is an integral part of modern incident response, but a fragmented tool ecosystem on different operating systems makes it difficult for analysts to use the same investigation procedures for each system type. As a result, analysts must use different workflows to perform an investigation on each of the three different operating systems (Windows, Linux, and macOS); therefore, response times will take longer and be less efficient due to this issue.

This paper presents a new system called the ”Unified Memory Forensics Framework,” a single framework for all three major operating systems. The Unified Memory Forensics Framework takes advantage of established forensic engines, such as Volatility, without forcing the analyst to understand how those forensic engines work. The Developers of the Unified Memory Forensics Framework have developed an automated OS detection module and an advanced semantic analysis engine to detect malicious behaviour across all three major platforms.

To evaluate the Unified Memory Forensics Framework, memory dumps containing simulated malware were created, and a set of controlled tests was performed. The tests included using Windows 11, Debian Linux, and macOS 13; the Unified Memory Forensics Framework produced a detection of 100% in detecting the type of operating system, and a high precision (0.92) for detecting malware indicators (e.g. code injection and hidden processes). Additionally, by having the Unified Memory Forensics Framework standardise how a memory investigation is performed and what outputs are generated, it reduces the amount of cognitive effort required on the part of the analyst and greatly decreases the amount of time required to conduct a triage.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Hafeez, Khadija
UNSPECIFIED
Uncontrolled Keywords: Memory Forensics; Cross-Platform; Volatility 3; Malware Detection; Automated Triage
Subjects: Q Science > QA Mathematics > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 04 Sep 2026 09:48
Last Modified: 04 Sep 2026 09:48
URI: https://norma.ncirl.ie/id/eprint/9825

Actions (login required)

View Item View Item