2 papers
cs.CR2019
Discovering Encrypted Bot and Ransomware Payloads Through Memory Inspection Without A Priori Knowledge
Peter McLaren, William J Buchanan, Gordon Russell +1
Malware writers frequently try to hide the activities of their agents within tunnelled traffic. Within the Kill Chain model the infection time is often measured in seconds, and if…
cs.CR2019
Deriving ChaCha20 Key Streams From Targeted Memory Analysis
Peter McLaren, William J Buchanan, Gordon Russell +1
There can be performance and vulnerability concerns with block ciphers, thus stream ciphers can used as an alternative. Although many symmetric key stream ciphers are fairly resist…