Mohammad Sina Karvandi

dblp:265/6072 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
4since 2021 · last 2026
0009-0007-5810-4549ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 TRM: An Efficient Hypervisor-Based Framework For Malware Analysis and Memory Reconstruction
abstract
Modern rootkits leverage kernel privileges to hide from analysis tools, while obfuscation techniques render them resistant to static analysis. Reverse engineering malware requires observing memory usage and reconstructing data structures. Existing tools rely on instrumentation or emulation, which introduce high overhead, leave detectable artifacts, and cannot reliably analyze kernel-level malware. We present The Reversing Machine (TRM), a hypervisor-based framework for high-performance introspection of evasive malware. It is the first system to support selective memory tracing and structure reconstruction in the hypervisor. TRM repurposes hardware virtualization to efficiently detect user-kernel mode transitions and obtain memory traces independently of a potentially compromised guest kernel. TRM introduces new insights into leveraging hardware virtualization for runtime memory reconstruction and analysis of data structures while remaining invisible to malware. We demonstrate automatic reconstruction of function signatures and data structures, reduce system call latency overhead from 142% to 57% compared to prior work, and accelerate manual reverse engineering by 43% on average, even for complex kernel objects. TRM shows that hypervisor-level memory tracing makes data structure reconstruction practical in hostile environments, bridging the gap between prior feasibility studies and real-world malware analysis.
Mohammad Sina Karvandi, Soroush Meghdadi Zanjani, Sima Arasteh, Saleh Khalaj Monfared, Mohammad K. Fallah, Saeid Gorgin 0001, Jeong-A Lee, Asia Slowinska, Erik van der Kouwe
AsiaCCS1
2026 Digital Hole: Bypassing Commercial Audio DRM Solutions with DReaMcatcher
abstract
Digital Rights Management (DRM) technologies underpin the protection of modern digital content, including music, films, software, games, and e-books, and support multibillion-dollar industries that rely on its effectiveness. In this paper, we question whether this trust in DRM is warranted. In the absence of malicious content-capturing hardware, it rests on the assumption that DRM forces content pirates to resort to the "Analog Hole", where the conversion from digital to analog and back leads to significant degradation in quality. We show that this assumption is false and that even the most sophisticated designs and hardware-level protection of high-quality audio is fundamentally vulnerable to what we term the software-based "Digital Hole". In particular, our hypervisor-based solution intercepts digital communication between kernel space and hardware-based audio peripherals—well beyond the reach of audio DRM technology. As an example, we investigate HD Audio-compatible devices and demonstrate that it is possible to dump DRM-protected songs and convert them to lossless audio files across major commercially available streaming services (Netflix, Spotify, etc.), along with a proof-of-concept for effectively extracting and storing protected content. We analyze the technical roots of this weakness, discuss potential countermeasures, and highlight the broader implications for designing more resilient audio DRM systems. Our work underscores that audio DRM, in its current form, cannot fully achieve its intended goals, motivating the community to radically redesign approaches to digital content protection.
Björn Ruytenberg, Mohammad Sina Karvandi, Herbert Bos, Erik van der Kouwe, Asia Slowinska
EuroSys2
2022 HyperDbg: Reinventing Hardware-Assisted Debugging
abstract
Software analysis, debugging, and reverse engineering have a crucial impact in today's software industry. Efficient and stealthy debuggers are especially relevant for malware analysis. However, existing debugging platforms fail to address a transparent, effective, and high-performance low-level debugger due to their detectable fingerprints, complexity, and implementation restrictions.
Mohammad Sina Karvandi, MohammadHosein Gholamrezaei, Saleh Khalaj Monfared, Soroush Meghdadi Zanjani, Behrooz Abbassi, Reza Mortazavi, Saeid Gorgin 0001, Dara Rahmati, Michael Schwarz 0001
CCS1
2021 A TSX-Based KASLR Break: Bypassing UMIP and Descriptor-Table Exiting
Mohammad Sina Karvandi, Saleh Khalaj Monfared, Sina Kiarostami, Dara Rahmati, Saeid Gorgin 0001
CRiSIS1