Iskra: Dinamik zararlı yazılım platformu
2020
0 görüntülenme
0 i̇ndirme
Danışman: Prof. Dr. Erkay Savaş
Özet (EN)
With the proliferation of ''cyber-crime as a service'' economy, besides gaining new victims, providing permanence on them has been one of the key points of profit for attackers. Thus, hiding malicious presence while operating is now more important for malware than being fully undetectable when it is first distributed. Due to the increasing number of malware attacks and prohibitively long hours required for manual inspection, analysts often use dynamic analysis platforms to investigate malware samples. However, these platforms have been repeatedly shown to fail to combat evasion methods that are constantly updated by attackers. Even if malware is correctly classified by the existing dynamic analysis platforms, which are widely deployed in the cyber security industry, it has been frequently observed that the malware detects the analysis environment and behaves differently to evade inspection; consequently the malicious code targeted by the attacker does not execute. In this case, the inspection, which will make the malicious code run and be examined, has to be done by the analyst manually. In this study, we present the bare metal hypervisor-based framework for dynamic analysis, ISKRA, which facilitates system calls to be collected and analyzed without being detected by malware. ISKRA is a portable and easily modifiable framework and not only allows any system to be easily transformed into an analysis environment, regardless of the virtual machine or bare metal; but also allows for forensics to be run without being detected in live systems. This way, incident response specialists can quickly transform the system under inspection into an analysis environment and can collect evidence, examine and remedy the system without being detected by the attacker. We designed, implemented and experimented with the framework, which employs machine learning algorithms to learn from new attack campaigns. Our work shows that the framework leads to negligibly low overhead and provides a high detection rate for the most current malware campaigns that evade dynamic inspection by other frameworks.
Yazar
Dr. Yusuf Arslan Polat
Kurum
Bu Yayına Nasıl Atıf Yapılır
Yusuf Arslan Polat (Master Thesis). Iskra: Dinamik zararlı yazılım platformu, 2020, Sabanci University.
Anahtar Kelimeler
Lisans
Tüm Hakları Saklıdır
Bu eser belirtilen lisans koşulları altında paylaşılmaktadır.
Sabanci University tezlerinden daha fazlası
- Popülizm, bozulmalar ve kriz algısı(2019)
- Görme biçimleri: Nevizâde Atai'nin Alemnüma'sı ve 17. yüzyılın başlarında Osmanlı toplumunun görsel algısında değişimler(2020)
- Kim Var Orada? çağdaş Türkiye tiyatrosu'nda sessizleştirilmiş geçmişleri sahnelemek: Kim Var Orada? Muhsin Bey'in Son Hamleti(2020)
- İstanbul'da bulunan fahişelerin Geç Osmanlı Dönemi'ndeki yaşamlarının Ahmed Midhat Efendi ve Hüseyin Rahmi Gürpınar romanları üzerinden bir değerlendirmesi(2019)
- Sınırların yeniden çizilmesi: Üniversite öğrencilerinin sözlü tarihi(2020)
- Normal ve genelleştirilmiş bir gamma popülasyonundaki m'inci (merkezi) moment için maksimum olabilirlik ve örnek momenti tahmin edicisi üzerine(2020)
