Evaluating Tool Based Automated Malware Analysis Through Persistence Mechanism Detection

Evaluating Tool Based Automated Malware Analysis Through Persistence Mechanism Detection
Author :
Publisher :
Total Pages :
Release :
ISBN-10 : OCLC:1046984480
ISBN-13 :
Rating : 4/5 ( Downloads)

Book Synopsis Evaluating Tool Based Automated Malware Analysis Through Persistence Mechanism Detection by : Matthew S. Webb

Download or read book Evaluating Tool Based Automated Malware Analysis Through Persistence Mechanism Detection written by Matthew S. Webb and published by . This book was released on 2018 with total page pages. Available in PDF, EPUB and Kindle. Book excerpt: Since 2014 there have been over 120 million new malicious programs registered every year. Due to the amount of new malware appearing every year, analysts have automated large sections of the malware reverse engineering process. Many automated analysis systems are created by re-implementing analysis techniques rather than automating existing tools that utilize the same techniques. New implementations take longer to create and do not have the same proven quality as a tool that evolved alongside malware for many years. The goal of this study is to assess the efficiency and effectiveness of using existing tools for the application of automated malware analysis. This study focuses on the problem of discovering how malware persists on an infected system. Six tools are chosen based on their usefulness in manual analysis for revealing different persistence techniques employed by malware. The functions of these tools are automated in a fashion that emulates how they can be manually utilized, resulting in information about a tested sample. These six tools are tested against a collection of actual malware samples, pulled from malware families that are known for employing various persistence techniques. The findings are then scanned for indicators of persistence. The results of these tests are used to determine the smallest tool subset that discovers the largest range of persistence mechanisms. For each tool, implementation difficulty is compared to the number of indicators discovered to reveal the effectiveness of similar tools for future analysis applications. The conclusion is that while the tools covered a wide range of persistence mechanisms, the standalone tools that were designed with scripting in mind were more effective than those with multiple system requirements or those with only a graphical interface. It was also discovered that the automation process limits functionality of some tools, as they are designed for analyst interaction. Regaining the tools' functionality lost from automation to use them for other reverse engineering applications could be cumbersome and could require necessary implementation overhauls. Finally, the more successful tools were able to detect a broader range of techniques, while some less successful tools could only detect a portion of the same techniques. This study concludes that while an analysis system can be created by automating existing tools, the characteristics of the tools chosen impact the workload required to automate them. A well-documented tool that is controllable through a command line interface that offers many configuration options will require less work for an analyst to automate than a tool with little documentation that can only be controlled through a graphical interface.


Evaluating Tool Based Automated Malware Analysis Through Persistence Mechanism Detection Related Books

Evaluating Tool Based Automated Malware Analysis Through Persistence Mechanism Detection
Language: en
Pages:
Authors: Matthew S. Webb
Categories:
Type: BOOK - Published: 2018 - Publisher:

DOWNLOAD EBOOK

Since 2014 there have been over 120 million new malicious programs registered every year. Due to the amount of new malware appearing every year, analysts have a
Malware Science
Language: en
Pages: 230
Authors: Shane Molinari
Categories: Computers
Type: BOOK - Published: 2023-12-15 - Publisher: Packt Publishing Ltd

DOWNLOAD EBOOK

Unlock the secrets of malware data science with cutting-edge techniques, AI-driven analysis, and international compliance standards to stay ahead of the ever-ev
Automatic Malware Analysis
Language: en
Pages: 83
Authors: Heng Yin
Categories: Computers
Type: BOOK - Published: 2012-09-14 - Publisher: Springer Science & Business Media

DOWNLOAD EBOOK

Malicious software (i.e., malware) has become a severe threat to interconnected computer systems for decades and has caused billions of dollars damages each yea
Malware Detection
Language: en
Pages: 307
Authors: Mihai Christodorescu
Categories: Computers
Type: BOOK - Published: 2007-03-06 - Publisher: Springer Science & Business Media

DOWNLOAD EBOOK

This book captures the state of the art research in the area of malicious code detection, prevention and mitigation. It contains cutting-edge behavior-based tec
Malware Analysis Techniques
Language: en
Pages: 282
Authors: Dylan Barker
Categories: Computers
Type: BOOK - Published: 2021-06-18 - Publisher: Packt Publishing Ltd

DOWNLOAD EBOOK

Analyze malicious samples, write reports, and use industry-standard methodologies to confidently triage and analyze adversarial software and malware Key Feature