{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:49:43Z","timestamp":1780634983561,"version":"3.54.1"},"reference-count":67,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2022,7,9]],"date-time":"2022-07-09T00:00:00Z","timestamp":1657324800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"European Research Council"},{"name":"European Unions Horizon 2020","award":["771844 (BitCrumbs), 786669 (ReAct)"],"award-info":[{"award-number":["771844 (BitCrumbs), 786669 (ReAct)"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2022,11,30]]},"abstract":"<jats:p>The first step required to perform any analysis of a physical memory image is the reconstruction of the virtual address spaces, which allows translating virtual addresses to their corresponding physical offsets. However, this phase is often overlooked, and the challenges related to it are rarely discussed in the literature. Practical tools solve the problem by using a set of custom heuristics tailored on a very small number of well-known operating systems (OSs) running on few architectures.<\/jats:p>\n          <jats:p>In this article, we look for the first time at all the different ways the virtual to physical translation can be operated in 10 different CPU architectures. In each case, we study the inviolable constraints imposed by the memory management unit that can be used to build signatures to recover the required data structures from memory without any knowledge about the running OS. We build a proof-of-concept tool to experiment with the extraction of virtual address spaces showing the challenges of performing an OS-agnostic virtual to physical address translation in real-world scenarios. We conduct experiments on a large set of 26 different OSs and a use case on a real hardware device. Finally, we show a possible usage of our technique to retrieve information about user space processes running on an unknown OS without any knowledge of its internals.<\/jats:p>","DOI":"10.1145\/3528102","type":"journal-article","created":{"date-parts":[[2022,3,30]],"date-time":"2022-03-30T11:35:48Z","timestamp":1648640148000},"page":"1-32","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["In the Land of MMUs: Multiarchitecture OS-Agnostic Virtual Memory Forensics"],"prefix":"10.1145","volume":"25","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7820-1927","authenticated-orcid":false,"given":"Andrea","family":"Oliveri","sequence":"first","affiliation":[{"name":"Eurecom, Sophia-Antipolis, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5957-6213","authenticated-orcid":false,"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[{"name":"Eurecom, Sophia-Antipolis, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,7,9]]},"reference":[{"key":"e_1_3_5_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2007.06.010"},{"key":"e_1_3_5_3_2","unstructured":"Cellbrite. https:\/\/cellebrite.com\/en\/home\/."},{"key":"e_1_3_5_4_2","volume-title":"Home Page","author":"Association Buildroot","year":"2022","unstructured":"Buildroot Association. 2022. Home Page. Retrieved April 2, 2022 from https:\/\/buildroot.org\/."},{"key":"e_1_3_5_5_2","volume-title":"Darwin OS","author":"Inc Apple","year":"2022","unstructured":"Apple Inc. 2022. Darwin OS. Retrieved April 2, 2022 from https:\/\/github.com\/apple\/darwin-xnu."},{"key":"e_1_3_5_6_2","unstructured":"Embox Developers Embox OS. https:\/\/github.com\/embox\/embox."},{"key":"e_1_3_5_7_2","unstructured":"Genode Labs. 2022. Home Page. Retrieved April 2 2022 from https:\/\/genode.org\/."},{"key":"e_1_3_5_8_2","volume-title":"Home Page","author":"Inc Haiku","year":"2022","unstructured":"Haiku Inc. 2022. Home Page. Retrieved April 2, 2022 from https:\/\/www.haiku-os.org\/."},{"key":"e_1_3_5_9_2","volume-title":"Home Page","author":"Community HelenOS","year":"2022","unstructured":"HelenOS Community. 2022. Home Page. Retrieved April 2, 2022 from http:\/\/www.helenos.org\/."},{"key":"e_1_3_5_10_2","volume-title":"MINIX3 OS","author":"University VU","year":"2022","unstructured":"VU University. 2022. MINIX3 OS. Retrieved April 2, 2022 from https:\/\/www.minix3.org\/."},{"key":"e_1_3_5_11_2","volume-title":"Home Page","author":"Team MorphOS Development","year":"2022","unstructured":"MorphOS Development Team. 2022. Home Page. Retrieved April 2, 2022 from https:\/\/www.morphos-team.net\/."},{"key":"e_1_3_5_12_2","volume-title":"Blackberry QNX","author":"Ltd BlackBerry","year":"2022","unstructured":"BlackBerry Ltd. 2022. Blackberry QNX. Retrieved April 2, 2022 from https:\/\/www.qnx.com."},{"key":"e_1_3_5_13_2","volume-title":"Home Page","author":"Foundation RaspberryPI","year":"2022","unstructured":"RaspberryPI Foundation. 2022. Home Page. Retrieved April 2, 2022 from https:\/\/www.raspberrypi.org\/."},{"key":"e_1_3_5_14_2","volume-title":"rCore","author":"Developers rCore","year":"2022","unstructured":"rCore Developers. 2022. rCore. Retrieved April 2, 2022 from https:\/\/github.com\/rcore-os\/rCore."},{"key":"e_1_3_5_15_2","volume-title":"Home Page","author":"Contributors ReactOS Team and","year":"2022","unstructured":"ReactOS Team and Contributors. 2022. Home Page. Retrieved April 2, 2022 from https:\/\/reactos.org\/."},{"key":"e_1_3_5_16_2","volume-title":"Home Page","author":"Developers Redox","year":"2022","unstructured":"Redox Developers. 2022. Home Page. Retrieved April 2, 2022 from https:\/\/www.redox-os.org\/."},{"key":"e_1_3_5_17_2","volume-title":"Home Page","author":"Ltd RISC OS Open","year":"2022","unstructured":"RISC OS Open Ltd. 2022. Home Page. Retrieved April 2, 2022 from https:\/\/www.riscosopen.org."},{"key":"e_1_3_5_18_2","volume-title":"The Barrelfish Operating System","author":"Zurich ETH","year":"2022","unstructured":"ETH Zurich. 2022. The Barrelfish Operating System. Retrieved April 2, 2022 from http:\/\/www.barrelfish.org\/."},{"key":"e_1_3_5_19_2","volume-title":"TLSH\u2014Trend Micro Locality Sensitive Hash","author":"Micro Trend","year":"2022","unstructured":"Trend Micro. 2022. TLSH\u2014Trend Micro Locality Sensitive Hash. Retrieved April 2, 2022 from https:\/\/github.com\/trendmicro\/tlsh."},{"key":"e_1_3_5_20_2","volume-title":"VxWorks","author":"Systems Wind River","year":"2022","unstructured":"Wind River Systems. 2022. VxWorks. Retrieved April 2, 2022 from https:\/\/www.windriver.com\/products\/vxworks\/."},{"key":"e_1_3_5_21_2","volume-title":"XV6","author":"Technology Massachusetts Institute of","year":"2022","unstructured":"Massachusetts Institute of Technology. 2022. XV6. Retrieved April 2, 2022 from https:\/\/github.com\/mit-pdos\/xv6-riscv."},{"key":"e_1_3_5_22_2","volume-title":"Alibaba on the bleeding edge of RISC-V with XT910","author":"Burt Jeffrey","year":"2020","unstructured":"Jeffrey Burt. 2020. Alibaba on the bleeding edge of RISC-V with XT910. The Next Platform. Retrieved April 2, 2022 from https:\/\/www.nextplatform.com\/2020\/08\/21\/alibaba-on-the-bleeding-edge-of-risc-v-with-xt910\/."},{"key":"e_1_3_5_23_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.fsidi.2020.301004"},{"key":"e_1_3_5_24_2","unstructured":"Michael Cohen. 2014. Rekall Memory Forensic Framework. Retrieved April 2 2022 from http:\/\/www.rekall-forensic.com\/."},{"key":"e_1_3_5_25_2","volume-title":"9Front OS","author":"Community 9Front","year":"2022","unstructured":"9Front Community. 2022. 9Front OS. Retrieved April 2, 2022 from http:\/\/9front.org\/."},{"key":"e_1_3_5_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00054"},{"key":"e_1_3_5_27_2","doi-asserted-by":"publisher","DOI":"10.5555\/1855741.1855759"},{"key":"e_1_3_5_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.11"},{"key":"e_1_3_5_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653730"},{"key":"e_1_3_5_30_2","volume-title":"Home Page","author":"Edition OmniOS Community","year":"2022","unstructured":"OmniOS Community Edition. 2022. Home Page. Retrieved April 2, 2022 from https:\/\/omniosce.org\/."},{"key":"e_1_3_5_31_2","volume-title":"Home Page","year":"2022","unstructured":"QEMU.2022. Home Page. Retrieved April 2, 2022 from https:\/\/www.qemu.org\/."},{"key":"e_1_3_5_32_2","volume-title":"Miasm","author":"Desclaux. Fabrice","year":"2022","unstructured":"Fabrice Desclaux.2022. Miasm. Retrieved April 2, 2022 from https:\/\/github.com\/cea-sec\/miasm."},{"key":"e_1_3_5_33_2","volume-title":"Home Page","author":"Community. Radare2","year":"2022","unstructured":"Radare2 Community.2022. Home Page. Retrieved April 2, 2022 from https:\/\/rada.re\/n\/."},{"key":"e_1_3_5_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664248"},{"key":"e_1_3_5_35_2","volume-title":"Programming Environments Manual for 32-Bit Implementations of the PowerPC Architecture","year":"2005","unstructured":"FreeScale. 2005. Programming Environments Manual for 32-Bit Implementations of the PowerPC Architecture. FreeScale."},{"key":"e_1_3_5_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.40"},{"key":"e_1_3_5_37_2","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1007\/978-3-642-41284-4_2","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"Graziano Mariano","year":"2013","unstructured":"Mariano Graziano, Andrea Lanzi, and Davide Balzarotti. 2013. Hypervisor memory forensics. In Research in Attacks, Intrusions, and Defenses, Salvatore J. Stolfo, Angelos Stavrou, and Charles V. Wright (Eds.). Springer, Berlin, Germany, 21\u201340."},{"key":"e_1_3_5_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCC.2014.2338305"},{"key":"e_1_3_5_39_2","volume-title":"ReFirmLabs\/Binwalk","author":"Heffner Craig","year":"2022","unstructured":"Craig Heffner. 2022. ReFirmLabs\/Binwalk. Retrieved April 2, 2022 from https:\/\/github.com\/ReFirmLabs\/binwalk."},{"key":"e_1_3_5_40_2","volume-title":"ARM Architecture Reference Manual, ARMv7-A and ARMv7-R edition","author":"Holdings ARM","year":"2018","unstructured":"ARM Holdings. 2018. ARM Architecture Reference Manual, ARMv7-A and ARMv7-R edition. ARM Holdings."},{"key":"e_1_3_5_41_2","volume-title":"ARM Architecture Reference Manual, ARMv8, for ARMv8-A Architecture Profile","author":"Holdings ARM","year":"2020","unstructured":"ARM Holdings. 2020. ARM Architecture Reference Manual, ARMv8, for ARMv8-A Architecture Profile. ARM Holdings."},{"key":"e_1_3_5_42_2","volume-title":"Power ISA. Version 3.0B","year":"2017","unstructured":"IBM. 2017. Power ISA. Version 3.0B. IBM."},{"key":"e_1_3_5_43_2","volume-title":"Intel 64 and IA-32 Architectures\u2014Software Developer\u2019s Manual\u2014Volume 3 (3A, 3B, 3C & 3D): System Programming Guide","year":"2020","unstructured":"Intel. 2020. Intel 64 and IA-32 Architectures\u2014Software Developer\u2019s Manual\u2014Volume 3 (3A, 3B, 3C & 3D): System Programming Guide. Intel Corporation."},{"key":"e_1_3_5_44_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2006.12.002"},{"key":"e_1_3_5_45_2","volume-title":"Western Digital gives a billion unit boost to open source RISC-V CPU","author":"Krewell Kevin","year":"2017","unstructured":"Kevin Krewell. 2017. Western Digital gives a billion unit boost to open source RISC-V CPU. Forbes. Retrieved April 2, 2022 from https:\/\/www.forbes.com\/sites\/tiriasresearch\/2017\/12\/06\/western-digital-gives-a-billion-unit-boost-to-open-source-risc-v-cpu\/."},{"key":"e_1_3_5_46_2","volume-title":"Using PROT_NONE on Linux","author":"Levy Jamie","year":"2015","unstructured":"Jamie Levy. 2015. Using PROT_NONE on Linux. Volatility Labs. Retrieved April 2, 2022 from https:\/\/volatility-labs.blogspot.com\/2015\/05\/using-mprotect-protnone-on-linux.html."},{"key":"e_1_3_5_47_2","volume-title":"Proceedings of the 19th Network and Distributed System Security Symposium (NDSS\u201912)","author":"Lin Zhiqiang","year":"2012","unstructured":"Zhiqiang Lin, Junghwan Rhee, Chao Wu, Xiangyu Zhang, and Dongyan Xu. 2012. Discovering semantic data of interest from un-mappable with confidence. In Proceedings of the 19th Network and Distributed System Security Symposium (NDSS\u201912)."},{"key":"e_1_3_5_48_2","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS\u201911)","author":"Lin Zhiqiang","year":"2011","unstructured":"Zhiqiang Lin, Junghwan Rhee, Xiangyu Zhang, Dongyan Xu, and Xuxian Jiang. 2011. SigGraph: Brute force scanning of kernel data structure instances using graph-based signatures. In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201911). https:\/\/www.ndss-symposium.org\/ndss2011\/siggraph-brute-force-scanning-of-kernel-data-structure-instances-using-graph-based-signatures."},{"key":"e_1_3_5_49_2","doi-asserted-by":"publisher","DOI":"10.5555\/2788959.2788964"},{"key":"e_1_3_5_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2017.7884661"},{"key":"e_1_3_5_51_2","volume-title":"MIPS Architecture for Programmers Vol. III: MIPS32\/microMIPS32 Privileged Resource Architecture","year":"2015","unstructured":"MIPS. 2015. MIPS Architecture for Programmers Vol. III: MIPS32\/microMIPS32 Privileged Resource Architecture. Imagination Technologies."},{"key":"e_1_3_5_52_2","volume-title":"Eurecom-s3\/MMUShell","author":"Oliveri Andrea","year":"2022","unstructured":"Andrea Oliveri. 2022. Eurecom-s3\/MMUShell. Retrieved April 2, 2022 from https:\/\/github.com\/eurecom-s3\/mmushell."},{"key":"e_1_3_5_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/3176258.3176306"},{"key":"e_1_3_5_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3310355"},{"key":"e_1_3_5_55_2","first-page":"S3\u2013S12","article-title":"In lieu of swap: Analyzing compressed RAM in Mac OS X and Linux","volume":"11","author":"III Golden G. Richard","year":"2014","unstructured":"Golden G. Richard III and Andrew Case. 2014. In lieu of swap: Analyzing compressed RAM in Mac OS X and Linux. Digital Investigation 11 (2014), S3\u2013S12.","journal-title":"Digital Investigation"},{"key":"e_1_3_5_56_2","volume-title":"White Paper: Finding Evil in Windows 10 Compressed Memory","author":"Sardar O.","year":"2019","unstructured":"O. Sardar and D. Andonov. 2019. White Paper: Finding Evil in Windows 10 Compressed Memory. Technical Report. FireEye. https:\/\/www.fireeye.com\/content\/dam\/fireeye-www\/blog\/pdfs\/finding-evil-in-windows-10-compressed-mem-ory-wp.pdf."},{"key":"e_1_3_5_57_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2010.08.002"},{"key":"e_1_3_5_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/1851276.1851280"},{"key":"e_1_3_5_59_2","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS\u201911)","author":"Slowinska Asia","year":"2011","unstructured":"Asia Slowinska, Traian Stancescu, and Herbert Bos. 2011. Howard: A dynamic excavator for reverse engineering data structures. In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201911)."},{"key":"e_1_3_5_60_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243813"},{"key":"e_1_3_5_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM.2010.24"},{"key":"e_1_3_5_62_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11212-1_14"},{"key":"e_1_3_5_63_2","volume-title":"Rekall support for Windows 10 memory compression","author":"Vogl Sebastian","year":"2019","unstructured":"Sebastian Vogl and Blaine Stancill. 2019. Rekall support for Windows 10 memory compression. FireEye. Retrieved April 2, 2022 from https:\/\/github.com\/mandiant\/win10_rekall\/blob\/win10_compressed_memory\/rekall-core\/rekall\/plugins\/windows\/win10_memcompression.py."},{"key":"e_1_3_5_64_2","unstructured":"Volexity. 2022. Home Page. Retrieved April 2 2022 from https:\/\/www.volexity.com\/."},{"key":"e_1_3_5_65_2","unstructured":"Aaron Walker. 2017. Volatility framework: Volatile memory artifact extraction utility framework. https:\/\/www.volatilityfoundation.org\/."},{"key":"e_1_3_5_66_2","volume-title":"The RISC-V Instruction Set Manual, Volume II: Privileged Architecture, Document Version 20190608-Priv-MSU-Ratified","author":"A. Asanovic K. Waterman","year":"2019","unstructured":"Asanovic K. Waterman A. (Ed.). 2019. The RISC-V Instruction Set Manual, Volume II: Privileged Architecture, Document Version 20190608-Priv-MSU-Ratified. RISC-V Foundation."},{"key":"e_1_3_5_67_2","volume-title":"Ada and RISC-V secure Nvidia\u2019s future","author":"Wong William G.","year":"2020","unstructured":"William G. Wong. 2020. Ada and RISC-V secure Nvidia\u2019s future. Endeavour Business Media. https:\/\/www.electronicdesign.com\/markets\/automotive\/article\/21121197\/ada-and-riscv-secure-nvidias-future."},{"key":"e_1_3_5_68_2","doi-asserted-by":"publisher","DOI":"10.1109\/CIT.2012.119"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3528102","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3528102","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:02:25Z","timestamp":1750186945000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3528102"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,9]]},"references-count":67,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2022,11,30]]}},"alternative-id":["10.1145\/3528102"],"URL":"https:\/\/doi.org\/10.1145\/3528102","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,7,9]]},"assertion":[{"value":"2021-08-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-03-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-07-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}