The Experts below are selected from a list of 12 Experts worldwide ranked by ideXlab platform
James M. Aquilina - One of the best experts on this subject based on the ideXlab platform.
-
Analysis of a Malware Specimen
Malware Forensics Field Guide for Windows Systems, 2012Co-Authors: Cameron H. Malin, Eoghan Casey, James M. AquilinaAbstract:Through the file profiling method, tools, and techniques discussed in Chapter 5, forensic investigators can gain important insight into the dependencies, strings, antivirus signatures, and metadata associated with a suspect file and use this knowledge to learn more about the file. Building on that information, this chapter further explores the nature, purpose, and functionality of a suspect program by conducting a dynamic and static analysis of the binary. The chapter demonstrates the importance of using dynamic and static analysis to gain a better understanding of a Malicious Code Specimen. It explains what an investigator should consider while analyzing a suspect program, including the nature and purpose of the program, how it accomplishes its purpose, how it interacts with the host system and network, how the attacker interacts with the program, and more. The chapter also covers how phylogenetic relationships between Specimens can provide insight into their origin, composition, and development.
-
Malware Forensics - Analysis of a Suspect Program
Malware Forensics, 2008Co-Authors: James M. AquilinaAbstract:This chapter endeavors to establish a general guideline of the tools and techniques that can be used to examine Malicious executable binaries in a Windows environment. There are a variety of Malware laboratory configuration options. In many instances, a Specimen can dictate the parameters of the lab environment, particularly if the Code requires numerous servers to fully function, or more nefariously, employs antivirtualization Code to stymie the digital investigator's efforts to observe the Code in a VMWare or other virtualized host system. Use of virtualization is helpful during the behavioral analysis of a Malicious Code Specimen, as the analysis requires frequent stops and starts of the Malicious program to observe the nuances of the program's behavior.
-
Analysis of a Suspect Program: Windows
Malware Forensics, 2008Co-Authors: James M. AquilinaAbstract:This chapter endeavors to establish a general guideline of the tools and techniques that can be used to examine Malicious executable binaries in a Windows environment. There are a variety of Malware laboratory configuration options. In many instances, a Specimen can dictate the parameters of the lab environment, particularly if the Code requires numerous servers to fully function, or more nefariously, employs antivirtualization Code to stymie the digital investigator's efforts to observe the Code in a VMWare or other virtualized host system. Use of virtualization is helpful during the behavioral analysis of a Malicious Code Specimen, as the analysis requires frequent stops and starts of the Malicious program to observe the nuances of the program's behavior.
-
Analysis of a Suspect Program: Linux
Malware Forensics, 2008Co-Authors: James M. AquilinaAbstract:Publisher Summary This chapter provides a general guideline to clearer sense of tools and techniques that can be used to examine a Malicious executable binary in the Linux environment. With the seemingly endless number of Malicious Code Specimens being generated by attackers—often with varying functions and purposes—flexibility and adjustment of the methodology to meet the needs of each individual case is required. A valuable way a Malicious Code Specimen interacts with a victim system, and in turn, to determine the risk that the Malware poses to the system is to monitor certain aspects of the system during the runtime of the Specimen. In particular, tools that monitor the host system with network activity is deployed prior to the execution of a subject Specimen and during the course of the Specimen's runtime; in this way, the tools will capture the activity of the Specimen from the moment it is executed. On a Linux system, there are five main aspects relating to the infected system: the files system, system calls, running processes, the /proc directory, and network activity (to include IDS).
Cameron H. Malin - One of the best experts on this subject based on the ideXlab platform.
-
Analysis of a Malware Specimen
Malware Forensics Field Guide for Windows Systems, 2012Co-Authors: Cameron H. Malin, Eoghan Casey, James M. AquilinaAbstract:Through the file profiling method, tools, and techniques discussed in Chapter 5, forensic investigators can gain important insight into the dependencies, strings, antivirus signatures, and metadata associated with a suspect file and use this knowledge to learn more about the file. Building on that information, this chapter further explores the nature, purpose, and functionality of a suspect program by conducting a dynamic and static analysis of the binary. The chapter demonstrates the importance of using dynamic and static analysis to gain a better understanding of a Malicious Code Specimen. It explains what an investigator should consider while analyzing a suspect program, including the nature and purpose of the program, how it accomplishes its purpose, how it interacts with the host system and network, how the attacker interacts with the program, and more. The chapter also covers how phylogenetic relationships between Specimens can provide insight into their origin, composition, and development.
Eoghan Casey - One of the best experts on this subject based on the ideXlab platform.
-
Analysis of a Malware Specimen
Malware Forensics Field Guide for Windows Systems, 2012Co-Authors: Cameron H. Malin, Eoghan Casey, James M. AquilinaAbstract:Through the file profiling method, tools, and techniques discussed in Chapter 5, forensic investigators can gain important insight into the dependencies, strings, antivirus signatures, and metadata associated with a suspect file and use this knowledge to learn more about the file. Building on that information, this chapter further explores the nature, purpose, and functionality of a suspect program by conducting a dynamic and static analysis of the binary. The chapter demonstrates the importance of using dynamic and static analysis to gain a better understanding of a Malicious Code Specimen. It explains what an investigator should consider while analyzing a suspect program, including the nature and purpose of the program, how it accomplishes its purpose, how it interacts with the host system and network, how the attacker interacts with the program, and more. The chapter also covers how phylogenetic relationships between Specimens can provide insight into their origin, composition, and development.