Content area

Abstract

The Internet Information Services (IIS) is a Microsoft-developed web server designed with a modular architecture to foster extensibility. Its worker process loads all IIS modules when the server receives a request, and native modules operate with the same level of access as the worker process. The built-in persistence and resource access make malicious modules powerful tools post-compromise. This thesis focuses on identifying all native modules in the system by analyzing volatile memory. Through binary analysis of the worker process, we identify critical data structures containing information about system modules. We developed two Volatility plugins to assist in detecting these modules and extracting critical information, offering valuable tools for memory forensics of IIS web servers.

Details

1010268
Business indexing term
Title
IIScan: Detection and Analysis of IIS Native Modules in Volatile Memory
Number of pages
43
Publication year
2025
Degree date
2025
School code
0107
Source
MAI 87/5(E), Masters Abstracts International
ISBN
9798265413277
University/institution
Louisiana State University and Agricultural & Mechanical College
University location
United States -- Louisiana
Degree
M.S.
Source type
Dissertation or Thesis
Language
English
Document type
Dissertation/Thesis
Dissertation/thesis number
32306901
ProQuest document ID
3275477681
Document URL
https://www.proquest.com/dissertations-theses/iiscan-detection-analysis-iis-native-modules/docview/3275477681/se-2?accountid=208611
Copyright
Database copyright ProQuest LLC; ProQuest does not claim copyright in the individual underlying works.
Database
ProQuest One Academic