volGPT: Evaluation on triaging ransomware process in memory forensics with Large Language Model

被引:1
|
作者
Oh, Dong Bin [1 ]
Kim, Donghyun [2 ,3 ]
Kim, Dong Hyun [2 ,3 ]
Kim, Huy Kang [1 ]
机构
[1] Korea Univ, Sch Cybersecur, Anam Ro 145, Seoul 02841, South Korea
[2] Ajou Univ, Dept Cyber Secur, World Cup Ro 206, Suwon 16499, South Korea
[3] Korea Mil Acad, Dept Comp Sci, Hwarang Ro 574, Seoul 01805, South Korea
来源
FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION | 2024年 / 49卷
关键词
digital forensics; Memory forensics; Ransomware; Volatility; ChatGPT; Large language model (LLM);
D O I
10.1016/j.fsidi.2024.301756
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the face of the harm that ransomware can inflict upon users' computers, the imperative to efficiently and accurately triage its processes within memory forensics becomes increasingly crucial. However, ransomware perpetrators employ sophisticated techniques, such as process masquerading, to evade detection and analysis. In response to these challenges, we propose a novel ransomware triage method leveraging a Large Language Model (LLM) in conjunction with the Volatility framework, the de-facto standard in memory forensics. We conducted experiments on memory dumps infected by five different ransomware families, utilizing LLM-based approaches. Through extensive experiments, our method named volGPT demonstrated high accuracy in identifying ransomware-related processes within memory dumps. Additionally, our approach exhibited greater efficiency and provided more comprehensive explanations during ransomware triage than other state-of-the-art methods.
引用
收藏
页数:10
相关论文
共 18 条
  • [1] Process based volatile memory forensics for ransomware detection
    Arfeen, Asad
    Khan, Muhammad Asim
    Zafar, Obad
    Ahsan, Usama
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2022, 34 (04)
  • [2] ForensicLLM: A local large language model for digital forensics
    Sharma, Binaya
    Ghawaly, James
    Mccleary, Kyle
    Webb, Andrew M.
    Baggili, Ibrahim
    FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2025, 52
  • [3] Large language model triaging of simulated nephrology patient inbox messages
    Pham, Justin H.
    Thongprayoon, Charat
    Miao, Jing
    Suppadungsuk, Supawadee
    Koirala, Priscilla
    Craici, Iasmina M.
    Cheungpasitporn, Wisit
    FRONTIERS IN ARTIFICIAL INTELLIGENCE, 2024, 7
  • [4] Evaluation of a Large Language Model's Ability to Assist in an Orthopedic Hand Clinic
    Kotzur, Travis
    Singh, Aaron
    Parker, John
    Peterson, Blaire
    Sager, Brian
    Rose, Ryan
    Corley, Fred
    Brady, Christina
    HAND-AMERICAN ASSOCIATION FOR HAND SURGERY, 2024,
  • [5] A Comparative Evaluation of Large Language Model Utility in Neuroimaging Clinical Decision Support
    Miller, Luke
    Kamel, Peter
    Patel, Jigar
    Agrawal, Jay
    Zhan, Min
    Bumbarger, Nathan
    Wang, Kenneth
    JOURNAL OF IMAGING INFORMATICS IN MEDICINE, 2024,
  • [6] Evaluation of responses to cardiac imaging questions by the artificial intelligence large language model ChatGPT
    Monroe, Cynthia L.
    Abdelhafez, Yasser G.
    Atsina, Kwame
    Aman, Edris
    Nardo, Lorenzo
    Madani, Mohammad H.
    CLINICAL IMAGING, 2024, 112
  • [7] Evaluation of prompt engineering strategies for pharmacokinetic data analysis with the ChatGPT large language model
    Euibeom Shin
    Murali Ramanathan
    Journal of Pharmacokinetics and Pharmacodynamics, 2024, 51 : 101 - 108
  • [8] Evaluation of prompt engineering strategies for pharmacokinetic data analysis with the ChatGPT large language model
    Shin, Euibeom
    Ramanathan, Murali
    JOURNAL OF PHARMACOKINETICS AND PHARMACODYNAMICS, 2024, 51 (02) : 101 - 108
  • [9] Evaluation of the safety, accuracy, and helpfulness of the GPT-4.0 Large Language Model in neurosurgery
    Huang, Kevin T.
    Mehta, Neel H.
    Gupta, Saksham
    See, Alfred P.
    Arnaout, Omar
    JOURNAL OF CLINICAL NEUROSCIENCE, 2024, 123 : 151 - 156
  • [10] Investigating the Accuracy and Completeness of an Artificial Intelligence Large Language Model About Uveitis: An Evaluation of ChatGPT
    Marshall, Rayna F.
    Mallem, Krishna
    Xu, Hannah
    Thorne, Jennifer
    Burkholder, Bryn
    Chaon, Benjamin
    Liberman, Paulina
    Berkenstock, Meghan
    OCULAR IMMUNOLOGY AND INFLAMMATION, 2024, 32 (09) : 2052 - 2055