Geir Olav Dyrkolbotn

dblp:91/5317 · DBLP profile ↗
← Back
9ranked-venue papers
2as first author
3since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1Computer networks · 1Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2024 Exploring a Low-Cost Hardware Reverse Engineering Approach: A Use Case Experiment
André Jung Waltoft-Olsen, Phillip Johnson, Lasse Øverlier, Geir Olav Dyrkolbotn
SEC4
2021 Leveraging USB Power Delivery Implementations for Digital Forensic Acquisition
Gunnar Alendal, Stefan Axelsson, Geir Olav Dyrkolbotn
IFIP Int. Conf. Digital Forensics3
2021 Digital Forensic Acquisition Kill Chain - Analysis and Demonstration
Gunnar Alendal, Geir Olav Dyrkolbotn, Stefan Axelsson
IFIP Int. Conf. Digital Forensics2
2020 Detection of Previously Unseen Malware using Memory Access Patterns Recorded Before the Entry Point
abstract
Recently it has been shown, that it is possible to detect malware based on the memory access patterns produced before executions reaches its Entry Point. In this paper, we investigate the usefulness of memory access patterns over time, i.e to what extent can machine learning algorithm trained on “old” data, detect new malware samples, that was not part of the training set and how does this performance change over time. During our experiments, we found that machine learning models trained on memory access patterns of older samples can provide both high accuracy and a high true positive rate for the period from several months to almost a year from the update of the model. We also perform a substantial analysis of our findings that may aid researchers who work with malware and Big Data.
Sergii Banin, Geir Olav Dyrkolbotn
IEEE BigData2
2020 Disk Cluster Allocation Behavior in Windows and NTFS
abstract
Abstract The allocation algorithm of a file system has a huge impact on almost all aspects of digital forensics, because it determines where data is placed on storage media. Yet there is only basic information available on the allocation algorithm of the currently most widely spread file system; NTFS. We have therefore studied the NTFS allocation algorithm and its behavior empirically. To do that we used two virtual machines running Windows 7 and 10 on NTFS formatted fixed size virtual hard disks, the first being 64 GiB and the latter 1 TiB in size. Files of different sizes were written to disk using two writing strategies and the $Bitmap files were manipulated to emulate file system fragmentation. Our results show that files written as one large block are allocated areas of decreasing size when the files are fragmented. The decrease in size is seen not only within files, but also between them. Hence a file having smaller fragments than another file is written after the file having larger fragments. We also found that a file written as a stream gets the opposite allocation behavior, i. e. its fragments are increasing in size as the file is written. The first allocated unit of a stream written file is always very small and hence easy to identify. The results of the experiment are of importance to the digital forensics field and will help improve the efficiency of for example file carving and timestamp verification.
Martin Karresand, Stefan Axelsson, Geir Olav Dyrkolbotn
Mob. Networks Appl.3
2019 Exploiting Vendor-Defined Messages in the USB Power Delivery Protocol
Gunnar Alendal, Stefan Axelsson, Geir Olav Dyrkolbotn
IFIP Int. Conf. Digital Forensics3
2019 Creating a Map of User Data in NTFS to Improve File Carving
Martin Karresand, Asalena Warnqvist, David Lindahl, Stefan Axelsson, Geir Olav Dyrkolbotn
IFIP Int. Conf. Digital Forensics5
2010 Security Implications of Crosstalk in Switching CMOS Gates
Geir Olav Dyrkolbotn, Knut Wold, Einar Snekkenes
ISC1
2006 A Wireless Covert Channel on Smart Cards (Short Paper)
Geir Olav Dyrkolbotn, Einar Snekkenes
ICICS1