RATScope: Recording and Reconstructing Missing RAT Semantic Behaviors for Forensic Analysis on Windows

Runqing Yang,Xutong Chen,Haitao Xu,Yueqiang Cheng,Chunlin Xiong,Linqi Ruan,Mohammad Kavousi,Zhenyuan Li,Liheng Xu,Yan Chen
DOI: https://doi.org/10.1109/TDSC.2020.3032570
2022-01-01
IEEE Transactions on Dependable and Secure Computing
Abstract:Remote Access Trojan (RAT) attacks have become an extensively prevailing and serious threat to enterprise security. A forensic system targeting RAT attacks is needed to record and reconstruct fine-grained semantic behaviors of RATs. However, existing forensic systems suffer from various issues such as intrusive instrumentation, nontrivial recording overhead, and RAT behavior blindness. In this art...
What problem does this paper attempt to address?