Scollr summary
What this paper is about
Frankenstein is presented, a simulation-based framework that synthesizes a memory dump from a time series of atomic, hypervisor-level ground-truth snapshots under a configurable traversal strategy and bandwidth model and proposes novel page-category priority orderings that cut semantic inconsistencies and Hamming distance respectively.
Full abstract
Read the full abstract
Memory forensics relies on acquiring a faithful copy of RAM, yet software-based acquisition is inherently non-atomic: the operating system keeps modifying memory while pages are read, producing inconsistencies known as page smear. Prior work formalized quality criteria and measured such inconsistencies, but how the acquisition strategy , i.e., page order and transfer rate, affects image quality remains unexplored, and no public framework decouples strategy from the acquisition channel. We present Frankenstein , a simulation-based framework that synthesizes a memory dump from a time series of atomic, hypervisor-level ground-truth snapshots under a configurable traversal strategy and bandwidth model. We implement seven strategy–bandwidth combinations and evaluate them across three workloads via Hamming distance and semantic analysis. We find the acquisition strategy considerably affects quality, but, interestingly, no traversal minimizes byte-level distance and structural-semantic inconsistencies at the same time, since pages dominating byte-level change (user mappings, page cache) compete with pointer-rich kernel objects (slab, kernel pages) for the most timely acquisition. We therefore propose novel page-category priority orderings—a structural focus (slab and kernel pages first) and a volatile focus (user and page-cache pages first)—cutting semantic inconsistencies and Hamming distance respectively.
Direct answer
What can I do from this paper page?
Use this page to scan "Frankenstein’s RAM: A Simulation Framework for Evaluating Memory Forensic Acquisition Strategies" quickly: start with the summary and abstract, then check the authors, source, topics, and related papers. From here, open Scollr to follow Digital and Cyber Forensics research, save the paper, or map adjacent work.
Research areas
Follow related topics
Citation
BibTeX
@article{Rzepka2026Frankenstein,
title = {Frankenstein’s RAM: A Simulation Framework for Evaluating Memory Forensic Acquisition Strategies},
author = {Lisa Rzepka and Jan Gruber and Felix Freiling and Harald Baier},
journal = {Digital Threats Research and Practice},
year = {2026},
doi = {10.1145/3839565},
url = {https://doi.org/10.1145/3839565}
}
FAQ
Using this paper in a discovery workflow
How do I find related work for this paper?
Use the related papers and topic links on this page as starting points. In Scollr, you can also open the paper and build a literature map around its references, citing papers, and related work.
How can I keep up with new Digital and Cyber Forensics research papers?
Follow Digital and Cyber Forensics research in Scollr. New papers from the topic flow into a personalized feed, and you can save useful studies to revisit later.
Can I cite this paper from this page?
This page includes a static BibTeX block for Frankenstein’s RAM: A Simulation Framework for Evaluating Memory Forensic Acquisition Strategies. Always verify the DOI, source, and publication details against the publisher record before submitting a manuscript.
Follow this research in Scollr
Follow the topics and authors behind this paper, save useful studies, and build a literature map when you are ready to go deeper.
Get the app