Soroush Meghdadi Zanjani

dblp:248/8301 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2026
0000-0002-8478-2470ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2026 TRM: An Efficient Hypervisor-Based Framework For Malware Analysis and Memory Reconstruction
abstract
Modern rootkits leverage kernel privileges to hide from analysis tools, while obfuscation techniques render them resistant to static analysis. Reverse engineering malware requires observing memory usage and reconstructing data structures. Existing tools rely on instrumentation or emulation, which introduce high overhead, leave detectable artifacts, and cannot reliably analyze kernel-level malware. We present The Reversing Machine (TRM), a hypervisor-based framework for high-performance introspection of evasive malware. It is the first system to support selective memory tracing and structure reconstruction in the hypervisor. TRM repurposes hardware virtualization to efficiently detect user-kernel mode transitions and obtain memory traces independently of a potentially compromised guest kernel. TRM introduces new insights into leveraging hardware virtualization for runtime memory reconstruction and analysis of data structures while remaining invisible to malware. We demonstrate automatic reconstruction of function signatures and data structures, reduce system call latency overhead from 142% to 57% compared to prior work, and accelerate manual reverse engineering by 43% on average, even for complex kernel objects. TRM shows that hypervisor-level memory tracing makes data structure reconstruction practical in hostile environments, bridging the gap between prior feasibility studies and real-world malware analysis.
Mohammad Sina Karvandi, Soroush Meghdadi Zanjani, Sima Arasteh, Saleh Khalaj Monfared, Mohammad K. Fallah, Saeid Gorgin 0001, Jeong-A Lee, Asia Slowinska, Erik van der Kouwe
AsiaCCS2
2022 HyperDbg: Reinventing Hardware-Assisted Debugging
abstract
Software analysis, debugging, and reverse engineering have a crucial impact in today's software industry. Efficient and stealthy debuggers are especially relevant for malware analysis. However, existing debugging platforms fail to address a transparent, effective, and high-performance low-level debugger due to their detectable fingerprints, complexity, and implementation restrictions.
Mohammad Sina Karvandi, MohammadHosein Gholamrezaei, Saleh Khalaj Monfared, Soroush Meghdadi Zanjani, Behrooz Abbassi, Reza Mortazavi, Saeid Gorgin 0001, Dara Rahmati, Michael Schwarz 0001
CCS4