Advanced malware analysis

A one-of-a-kind guide to setting up a malware research lab, using cutting-edge analysis tools, and reporting the findings Advanced Malware Analysis is a critical resource for every information security professional's anti-malware arsenal. The proven troubleshooting techniques will give an edge...

Full description

Bibliographic Details
Main Author: Elisan, Christopher C.
Format: eBook
Language:English
Published: New York McGraw-Hill Education 2015
Edition:Version 1.0
Subjects:
Online Access:
Collection: O'Reilly - Collection details see MPG.ReNa
LEADER 05189nmm a2200397 u 4500
001 EB001907705
003 EBX01000000000000001070607
005 00000000000000.0
007 cr|||||||||||||||||||||
008 210123 ||| eng
020 |a 9780071819756 
050 4 |a QA76.76.C68 
100 1 |a Elisan, Christopher C. 
245 0 0 |a Advanced malware analysis  |c Christopher C. Elisan 
250 |a Version 1.0 
260 |a New York  |b McGraw-Hill Education  |c 2015 
300 |a 1 volume  |b illustrations 
505 0 |a Cover -- Title Page -- Copyright Page -- Dedication -- Contents at a Glance -- Contents -- Foreword -- Acknowledgments -- Introduction -- Part I Malware Blueprint -- Chapter 1 Malware Analysis 101 -- Malware Analysis -- Malware Analysis and Reverse Engineering -- Types of Malware Analysis -- Purpose of Malware Analysis -- Limitations of Malware Analysis -- The Malware Analysis Process -- The Effective Malware Analyst -- Familiarization with Malware -- Familiarization with Analysis Tools -- Patience -- Recap -- Chapter 2 Malware Taxonomy -- Malware Classes -- Infectors -- Network Worms 
505 0 |a Trojan Horse -- Backdoors -- Remote-Access Trojan -- Information Stealers -- Ransomware -- Scareware -- Fakeware -- Greyware -- Recap -- Chapter 3 Malware Deployment -- Malware Infection Vectors -- Speed -- Stealth -- Coverage -- Shelf Life -- Types of Malware Infection Vectors -- Physical Media -- E-mails -- Instant Messaging and Chat -- Social Networking -- URL Links -- File Shares -- Software Vulnerabilities -- Potential Infection Vectors -- Recap -- Chapter 4 Protective Mechanisms -- The Two States of Malware -- Static Malware -- Dynamic Malware -- Protective Mechanisms 
505 0 |a Includes bibliographical references and index 
505 0 |a Malware Blacklist -- Malwarebytes Forum -- Malekal's Forum -- Open Malware -- Tuts4You -- VirusShare.com -- VX Heaven -- Malware Trackers -- Research Mailing Lists -- Sample Exchange -- Commercial Sources -- Honeypots -- Dionaea -- Recap -- Tools -- Chapter 7 Static Analysis Lab -- The Static Analysis Lab -- Host File Inspection Tools -- Mitigate Possible Infection -- Mitigate Becoming a Malware Staging Point -- Anonymous Communication -- Setting Up the Lab -- Choose the Hardware -- Install the Operating System -- Harden the Lab -- Anonymize the Lab -- Isolate the Lab 
505 0 |a Static Malware Protective Mechanisms -- Dynamic Malware Protective Mechanisms -- Recap -- Chapter 5 Malware Dependencies -- Dependency Types -- Environment Dependencies -- Program Dependencies -- Timing Dependencies -- Event Dependencies -- User Dependencies -- File Dependencies -- Recap -- Part II Malware Research Lab -- Chapter 6 Malware Collection -- Your Own Backyard -- Scan for Malicious Files -- Look for Active Rootkits -- Inspect Startup Programs -- Inspect Running Processes -- Extract Suspicious Files -- Free Sources -- Contagio -- KernelMode.info -- MalShare.com -- Malware.lu 
505 0 |a The Virtualized Static Analysis Lab -- Backing Up and Restoring -- Recap -- Tools -- Chapter 8 Dynamic Analysis Lab -- Setting Up the Lab -- Choose the Hardware -- Install the Operating System -- Make the Lab Malware Friendly -- Anonymize the Lab -- Isolate the Lab -- Restoring to a Clean State -- Virtualized Environment Clean State Restoration -- Bare-Metal Environment Clean State Restoration -- Backing Up and Restoring -- The Golden Image -- Host OS -- Other Systems Supporting the Lab -- Recap -- Tools -- Part III Malware Inspection -- Chapter 9 The Portable Executable File 
653 |a Computer security 
653 |a Sécurité informatique 
653 |a Logiciels malveillants 
653 |a Malware (Computer software) / http://id.loc.gov/authorities/subjects/sh2009005103 
653 |a Malware (Computer software) / fast 
653 |a Computer security / fast 
653 |a Computer Security 
041 0 7 |a eng  |2 ISO 639-2 
989 |b OREILLY  |a O'Reilly 
776 |z 9780071819749 
856 4 0 |u https://learning.oreilly.com/library/view/~/9780071819756/?ar  |x Verlag  |3 Volltext 
082 0 |a 005.8/4 
520 |a A one-of-a-kind guide to setting up a malware research lab, using cutting-edge analysis tools, and reporting the findings Advanced Malware Analysis is a critical resource for every information security professional's anti-malware arsenal. The proven troubleshooting techniques will give an edge to information security professionals whose job involves detecting, decoding, and reporting on malware. After explaining malware architecture and how it operates, the book describes how to create and configure a state-of-the-art malware research lab and gather samples for analysis. Then, you'll learn how to use dozens of malware analysis tools, organize data, and create metrics-rich reports. A crucial tool for combatting malware--which currently hits each second globally Filled with undocumented methods for customizing dozens of analysis software tools for very specific uses Leads you through a malware blueprint first, then lab setup, and finally analysis and reporting activities Every tool explained in this book is available in every country around the world