The Experts below are selected from a list of 726 Experts worldwide ranked by ideXlab platform

Yuhao Luo - One of the best experts on this subject based on the ideXlab platform.

  • Android Malware Forensics: Reconstruction of Malicious Events
    2014
    Co-Authors: Yuhao Luo
    Abstract:

    Abstract—Smart mobile devices have been widely used and the contained sensitive information is endangered by Malwares. The malicious events caused by Malwares are crucial evidences for digital forensic analysis, and the main task of mobile forensic analysis is to reconstruct these events. However, the reconstruction heavily relies on the code analysis of the Malware. The difficulties and challenges include how to quickly identify the suspicious programs, how to defeat the anti-Forensics tricks of malicious code, and how to deduce the malicious behaviors according to the code. To address this issue, we propose sys-tematic procedures of analyzing typical Malware behaviors on the popular mobile operating system Android. Based on the procedures we discuss the deduction of Android malicious events. We also give a real Malware forensic case as a reference. Index Terms—forensic analysis, Android, Malware, reverse engineering

  • android Malware Forensics reconstruction of malicious events
    International Conference on Distributed Computing Systems Workshops, 2012
    Co-Authors: Yuhao Luo
    Abstract:

    Smart mobile devices have been widely used and the contained sensitive information is endangered by Malwares. The malicious events caused by Malwares are crucial evidences for digital forensic analysis, and the main task of mobile forensic analysis is to reconstruct these events. However, the reconstruction heavily relies on the code analysis of the Malware. The difficulties and challenges include how to quickly identify the suspicious programs, how to defeat the anti-Forensics tricks of malicious code, and how to deduce the malicious behaviors according to the code. To address this issue, we propose systematic procedures of analyzing typical Malware behaviors on the popular mobile operating system Android. Based on the procedures we discuss the deduction of Android malicious events. We also give a real Malware forensic case as a reference.

James M Aquilina - One of the best experts on this subject based on the ideXlab platform.

  • linux Malware incident response a practitioner s guide to forensic collection and examination of volatile data an excerpt from Malware forensic field guide for linux systems
    2013
    Co-Authors: Cameron H Malin, Eoghan Casey, James M Aquilina
    Abstract:

    Linux Malware Incident Response is a "first look" at the Malware Forensics Field Guide for Linux Systems, exhibiting the first steps in investigating Linux-based incidents. The Syngress Digital Forensics Field Guides series includes companions for any digital and computer forensic investigator and analyst. Each book is a "toolkit" with checklists for specific tasks, case studies of difficult situations, and expert analyst tips. This compendium of tools for computer Forensics analysts and investigators is presented in a succinct outline format with cross-references to supplemental appendices. It is designed to provide the digital investigator clear and concise guidance in an easily accessible format for responding to an incident or conducting analysis in a lab.Presented in a succinct outline format with cross-references to included supplemental components and appendicesCovers volatile data collection methodology as well as non-volatile data collection from a live Linux systemAddresses Malware artifact discovery and extraction from a live Linux system

  • Malware Forensics investigating and analyzing malicious code
    2008
    Co-Authors: Cameron H Malin, Eoghan Casey, James M Aquilina
    Abstract:

    Malware Forensics: Investigating and Analyzing Malicious Code covers the emerging and evolving field of "live Forensics," where investigators examine a computer system to collect and preserve critical live data that may be lost if the system is shut down. Unlike other forensic texts that discuss "live Forensics" on a particular operating system, or in a generic context, this book emphasizes a live Forensics and evidence collection methodology on both Windows and Linux operating systems in the context of identifying and capturing malicious code and evidence of its effect on the compromised system. Malware Forensics: Investigating and Analyzing Malicious Code also devotes extensive coverage of the burgeoning forensic field of physical and process memory analysis on both Windows and Linux platforms. This book provides clear and concise guidance as to how to forensically capture and examine physical and process memory as a key investigative step in malicious code Forensics. Prior to this book, competing texts have described malicious code, accounted for its evolutionary history, and in some instances, dedicated a mere chapter or two to analyzing malicious code. Conversely, Malware Forensics: Investigating and Analyzing Malicious Code emphasizes the practical "how-to" aspect of malicious code investigation, giving deep coverage on the tools and techniques of conducting runtime behavioral Malware analysis (such as file, registry, network and port monitoring) and static code analysis (such as file identification and profiling, strings discovery, armoring/packing detection, disassembling, debugging), and more. * Winner of Best Book Bejtlich read in 2008!* http://taosecurity.blogspot.com/2008/12/best-book-bejtlich-read-in-2008.html* Authors have investigated and prosecuted federal Malware cases, which allows them to provide unparalleled insight to the reader.* First book to detail how to perform "live forensic" techniques on malicous code.* In addition to the technical topics discussed, this book also offers critical legal considerations addressing the legal ramifications and requirements governing the subject matter

Casey Eoghan - One of the best experts on this subject based on the ideXlab platform.

  • Malware Forensics Field Guide for Linux Systems
    2013
    Co-Authors: Malin Cameron, Casey Eoghan, Aquilina James
    Abstract:

    Malware Forensics Field Guide for Linux Systems is a handy reference that shows students the essential tools needed to do computer Forensics analysis at the crime scene. It is part of Syngress Digital Forensics Field Guides, a series of companions for any digital and computer forensic student, investigator or analyst. Each Guide is a toolkit, with checklists for specific tasks, case studies of difficult situations, and expert analyst tips that will aid in recovering data from digital media that will be used in criminal prosecution. This book collects data from all methods of electronic data storage and transfer devices, including computers, laptops, PDAs and the images, spreadsheets and other types of files stored on these devices. It is specific for Linux-based systems, where new Malware is developed every day. The authors are world-renowned leaders in investigating and analyzing malicious code. Chapters cover Malware incident response - volatile data collection and examination on a live Linux system; analysis of physical and process memory dumps for Malware artifacts; post-mortem Forensics - discovering and extracting Malware and associated artifacts from Linux systems; legal considerations; file identification and profiling initial analysis of a suspect file on a Linux system; and analysis of a suspect program

  • Linux Malware incident response: an excerpt from Malware forensic field guide for Linux systems
    Elsevier Science, 2013
    Co-Authors: Malin, Cameron H, Casey Eoghan, Aquilina, James M
    Abstract:

    Linux Malware Incident Response is a ""first look"" at the Malware Forensics Field Guide for Linux Systems, exhibiting the first steps in investigating Linux-based incidents. The Syngress Digital Forensics Field Guides series includes companions for any digital and computer forensic investigator and analyst. Each book is a ""toolkit"" with checklists for specific tasks, case studies of difficult situations, and expert analyst tips. This compendium of tools for computer Forensics analysts and investigators is presented in a succinct outline format with cross-references to supplem

  • Malware Forensics Field Guide for Windows Systems
    2012
    Co-Authors: Malin Cameron, Casey Eoghan, Aquilina James
    Abstract:

    Malware Forensics Field Guide for Windows Systems is a handy reference that shows students the essential tools needed to do computer Forensics analysis at the crime scene. It is part of Syngress Digital Forensics Field Guides, a series of companions for any digital and computer forensic student, investigator or analyst. Each Guide is a toolkit, with checklists for specific tasks, case studies of difficult situations, and expert analyst tips that will aid in recovering data from digital media that will be used in criminal prosecution. This book collects data from all methods of electronic data storage and transfer devices, including computers, laptops, PDAs and the images, spreadsheets and other types of files stored on these devices. It is specific for Windows-based systems, the largest running OS in the world. The authors are world-renowned leaders in investigating and analyzing malicious code. Chapters cover Malware incident response - volatile data collection and examination on a live Windows system; analysis of physical and process memory dumps for Malware artifacts; post-mortem Forensics - discovering and extracting Malware and associated artifacts from Windows systems; legal considerations; file identification and profiling initial analysis of a suspect file on a Windows system; and analysis of a suspect program

Aquilina, James M - One of the best experts on this subject based on the ideXlab platform.

  • Linux Malware incident response: an excerpt from Malware forensic field guide for Linux systems
    Elsevier Science, 2013
    Co-Authors: Malin, Cameron H, Casey Eoghan, Aquilina, James M
    Abstract:

    Linux Malware Incident Response is a ""first look"" at the Malware Forensics Field Guide for Linux Systems, exhibiting the first steps in investigating Linux-based incidents. The Syngress Digital Forensics Field Guides series includes companions for any digital and computer forensic investigator and analyst. Each book is a ""toolkit"" with checklists for specific tasks, case studies of difficult situations, and expert analyst tips. This compendium of tools for computer Forensics analysts and investigators is presented in a succinct outline format with cross-references to supplem

Aquilina James - One of the best experts on this subject based on the ideXlab platform.

  • Malware Forensics Field Guide for Linux Systems
    2013
    Co-Authors: Malin Cameron, Casey Eoghan, Aquilina James
    Abstract:

    Malware Forensics Field Guide for Linux Systems is a handy reference that shows students the essential tools needed to do computer Forensics analysis at the crime scene. It is part of Syngress Digital Forensics Field Guides, a series of companions for any digital and computer forensic student, investigator or analyst. Each Guide is a toolkit, with checklists for specific tasks, case studies of difficult situations, and expert analyst tips that will aid in recovering data from digital media that will be used in criminal prosecution. This book collects data from all methods of electronic data storage and transfer devices, including computers, laptops, PDAs and the images, spreadsheets and other types of files stored on these devices. It is specific for Linux-based systems, where new Malware is developed every day. The authors are world-renowned leaders in investigating and analyzing malicious code. Chapters cover Malware incident response - volatile data collection and examination on a live Linux system; analysis of physical and process memory dumps for Malware artifacts; post-mortem Forensics - discovering and extracting Malware and associated artifacts from Linux systems; legal considerations; file identification and profiling initial analysis of a suspect file on a Linux system; and analysis of a suspect program

  • Malware Forensics Field Guide for Windows Systems
    2012
    Co-Authors: Malin Cameron, Casey Eoghan, Aquilina James
    Abstract:

    Malware Forensics Field Guide for Windows Systems is a handy reference that shows students the essential tools needed to do computer Forensics analysis at the crime scene. It is part of Syngress Digital Forensics Field Guides, a series of companions for any digital and computer forensic student, investigator or analyst. Each Guide is a toolkit, with checklists for specific tasks, case studies of difficult situations, and expert analyst tips that will aid in recovering data from digital media that will be used in criminal prosecution. This book collects data from all methods of electronic data storage and transfer devices, including computers, laptops, PDAs and the images, spreadsheets and other types of files stored on these devices. It is specific for Windows-based systems, the largest running OS in the world. The authors are world-renowned leaders in investigating and analyzing malicious code. Chapters cover Malware incident response - volatile data collection and examination on a live Windows system; analysis of physical and process memory dumps for Malware artifacts; post-mortem Forensics - discovering and extracting Malware and associated artifacts from Windows systems; legal considerations; file identification and profiling initial analysis of a suspect file on a Windows system; and analysis of a suspect program