Memory Carving in Embedded Devices: Separate the Wheat from the Chaff - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

Memory Carving in Embedded Devices: Separate the Wheat from the Chaff

Résumé

Embedded devices usually gather and store personal data about the behaviours of their holders. For example, a public transportation card may record the last trips of the passenger, or a car ignition key may store the fuel consumption and the average engine speed of the vehicle. Being able to interpret these raw data without the knowledge of the specifications can be useful to establish digital evidence, for example in connection with criminal investigations. This paper investigates memory carving techniques for embedded devices. Given that cryptographic material in memory dumps makes carving techniques inefficient, we introduce a methodology to distinguish meaningful information from cryptographic material in small-sized memory dumps. The proposed methodology uses an adaptive boosting technique with statistical tests. Experimented on EMV cards, the methodology reaches a successful recognition rate greater than 99.8%.
Fichier principal
Vignette du fichier
ACNS_Final.pdf (355.88 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-01338109 , version 1 (27-06-2016)
hal-01338109 , version 2 (01-07-2016)

Identifiants

Citer

Thomas Gougeon, Morgan Barbier, Patrick Lacharme, Gildas Avoine, Christophe Rosenberger. Memory Carving in Embedded Devices: Separate the Wheat from the Chaff. International Conference on Applied Cryptography (ACNS), Jun 2016, Guilford, United Kingdom. ⟨10.1007/978-3-319-39555-5_32⟩. ⟨hal-01338109v1⟩
478 Consultations
447 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More