21
Malware Analysis as a Hobby - the short story Michael Boman - Security Consultant/Researcher, Father of 5

Malware analysis as a hobby - the short story (lightning talk)

Embed Size (px)

Citation preview

Page 1: Malware analysis as a hobby - the short story (lightning talk)

Malware Analysis as a Hobby - the short story

Michael Boman - Security Consultant/Researcher, Father of 5

Page 2: Malware analysis as a hobby - the short story (lightning talk)

The manual way

Page 3: Malware analysis as a hobby - the short story (lightning talk)

DrawbacksTime consuming

Boring in the long run (not all malware are created equal)

Page 4: Malware analysis as a hobby - the short story (lightning talk)

Choose any two….Cheap

FastGood

Page 5: Malware analysis as a hobby - the short story (lightning talk)

Choose any two? Why not all of them?

I can do it cheaply (hardware and license cost-wise). Human time not included.

I can do it quickly (I spend up to 3 hours a day doing this, at average even less).

I get pretty good results (quality). Where the system lacks I can compensate for its shortcomings.

Cheap

FastGood

Page 6: Malware analysis as a hobby - the short story (lightning talk)

AutomateEngineer yourself out of the workflow

Automate everything!

Page 7: Malware analysis as a hobby - the short story (lightning talk)

Birth of theMART ProjectMalware Analyst Research Toolkit

Page 8: Malware analysis as a hobby - the short story (lightning talk)

Components

Page 9: Malware analysis as a hobby - the short story (lightning talk)
Page 10: Malware analysis as a hobby - the short story (lightning talk)

Sample Acquisition• Public & Private Collections• Exchange with other malware analysts• Finding and collecting malware

yourself

Page 11: Malware analysis as a hobby - the short story (lightning talk)

Sample Analysis• Cuckoo Sandbox• VirusTotal

Page 12: Malware analysis as a hobby - the short story (lightning talk)

DEMO: Submit sample for analysis

Page 13: Malware analysis as a hobby - the short story (lightning talk)
Page 14: Malware analysis as a hobby - the short story (lightning talk)

Sample Reporting• Results are stored in MongoDB (optional)

• Accessed using a analyst GUI

Page 15: Malware analysis as a hobby - the short story (lightning talk)
Page 16: Malware analysis as a hobby - the short story (lightning talk)
Page 17: Malware analysis as a hobby - the short story (lightning talk)
Page 18: Malware analysis as a hobby - the short story (lightning talk)
Page 19: Malware analysis as a hobby - the short story (lightning talk)

Budget Computer: €520

MSDN License: €800 (€590 renewal)

Year 1: €1320

Year N: €590

Money saved from stopped smoking (yearly): €2040

Page 20: Malware analysis as a hobby - the short story (lightning talk)

Next steps• Barebone on-the-iron malware

analysis• Android platform support• OSX platform support• iOS patform support

Page 21: Malware analysis as a hobby - the short story (lightning talk)

Questions?