yasin.dehfouli
Back to publications
PAPERjournal

/publications/memory-analysis-malware-detection-oscar-survey

Memory Analysis for Malware Detection: A Comprehensive Survey Using the OSCAR Methodology

A structured survey of memory acquisition, forensic methods, datasets, and malware-detection approaches using an OSCAR-guided methodology.

Citation

Yasin Dehfouli and Arash Habibi Lashkari. “Memory Analysis for Malware Detection: A Comprehensive Survey Using the OSCAR Methodology.” ACM Computing Surveys, Volume 58, Issue 4, Article 86. 2025. doi:10.1145/3764580.
SUMMARYmethod · findings · limitations

Citation

Yasin Dehfouli and Arash Habibi Lashkari. “Memory Analysis for Malware Detection: A Comprehensive Survey Using the OSCAR Methodology.” ACM Computing Surveys, Volume 58, Issue 4, Article 86, October 2025. https://doi.org/10.1145/3764580

Why this survey

Memory analysis spans acquisition hardware, operating-system internals, forensic plugins, malware datasets, and detection models. Earlier surveys often covered only one part of that landscape or reflected tools and datasets that had become outdated. This work connects the full workflow and makes the comparison criteria explicit.

OSCAR-guided methodology

The survey adapts OSCAR—Obtain, Strategize, Collect, Analyze, Report—into a domain-specific structure for acquisition, forensics, datasets, approaches, and results. Research questions are mapped to each stage before literature collection and comparison.

Acquisition and forensic analysis

The taxonomy covers software and hardware acquisition across user, kernel, hypervisor, and device levels. It then compares forensic methods and tools for processes, injected code, networking, credentials, persistence, and other volatile artifacts, including practical limitations caused by operating-system and symbol changes.

Datasets and scoring

The survey catalogs public memory-dump datasets and proposes a comparison score spanning sample count, malware diversity, feature coverage, release date, dump size, and accessibility. The score is a decision aid rather than a universal ranking: a specialized dataset can still be the right choice for a focused research question.

Detection approaches

Both machine-learning and non-machine-learning methods are organized by their inputs, feature strategies, model families, results, and forensic applicability. The comparison highlights the trade-off between predictive performance, explainability, reproducibility, and the cost of acquiring and processing volatile memory.

Research gaps and practical implications

The study identifies continuing needs for standardized acquisition, current and accessible datasets, reproducible evaluation, cross-environment validation, and explanations that lead analysts back to evidence. It also documents aging tools and the difficulty of comparing results across incompatible datasets and experimental protocols.

Source

Read the canonical DOI record

Original publicationOpen DOI record