Chrome Extension
WeChat Mini Program
Use on ChatGLM

The evidence beyond the wall: Memory forensics in SGX environments

Flavio Toffalini, Andrea Oliveri, Mariano Graziano, Jianying Zhou, Davide Balzarotti

Forensic Science International: Digital Investigation(2021)

Cited 2|Views3
No score
Abstract
Software Guard eXtensions (SGX) is a hardware-based technology that introduces unobservable portions of memory, called enclaves, that physically screens software components from system tampering. Enclaves can be used to run arbitrary programs (including malicious code), but their actual impact on digital forensics and incident response remains unknown. In our work, we propose a methodical study of what information can be retrieved from an SGX machine and how to use this information to infer the enclaves interfaces and structure layout. We tested our techniques over a dataset of 45 SGX applications and we showed the practicality of our techniques in a real-product use-case and on two malware-enclaves. (c) 2021 Elsevier Ltd. All rights reserved.
More
Translated text
Key words
SGX,TEE,Memory forensics
AI Read Science
Must-Reading Tree
Example
Generate MRT to find the research sequence of this paper
Chat Paper
Summary is being generated by the instructions you defined