securing the neighbourhood

28
Malware detection – past, present and future Michael Shalyt SECURING THE NEIGHBORHOOD

Upload: shalyt

Post on 07-Aug-2015

240 views

Category:

Software


2 download

TRANSCRIPT

Page 1: Securing The Neighbourhood

Malware detection – past, present and future

Michael Shalyt

SECURING THE NEIGHBORHOOD

Page 2: Securing The Neighbourhood

� http://cyberparse.co.uk/

BUZZWORD EXPLOSION

Page 3: Securing The Neighbourhood

PAST

Page 4: Securing The Neighbourhood
Page 5: Securing The Neighbourhood
Page 6: Securing The Neighbourhood

MUGSHOT DATABASE

Page 7: Securing The Neighbourhood

MUGSHOT DATABASE

Page 8: Securing The Neighbourhood

BINARY SIGNATURES

Page 9: Securing The Neighbourhood

BINARY SIGNATURES

Page 10: Securing The Neighbourhood

BINARY SIGNATURES

Page 11: Securing The Neighbourhood

POLIMORPHISM

Page 12: Securing The Neighbourhood

POLIMORPHISM

Page 13: Securing The Neighbourhood

PRESENT

Page 14: Securing The Neighbourhood

INDICATORS OF COMPROMISE

Page 15: Securing The Neighbourhood

IOC DETECTION DOWNSIDES

Page 16: Securing The Neighbourhood

IOC DETECTION DOWNSIDES

• Which areas do we watch?

Page 17: Securing The Neighbourhood

IOC DETECTION DOWNSIDES

• Which areas do we watch?

• Some suspicious mechanisms are used by innocent software as well.

Page 18: Securing The Neighbourhood

IOC DETECTION DOWNSIDES

• Which areas do we watch?

• Some suspicious mechanisms are used by innocent software as well.

• Attackers can see and sometimes circumvent alarms.

Page 19: Securing The Neighbourhood

INDICATORS OF INTEREST

Page 20: Securing The Neighbourhood

INDICATORS OF INTEREST

Page 21: Securing The Neighbourhood

INDICATORS OF INTEREST

Page 22: Securing The Neighbourhood

INDICATORS OF INTEREST

Page 23: Securing The Neighbourhood

EMULATION

Page 24: Securing The Neighbourhood

FUTURE

Page 25: Securing The Neighbourhood

ANOMALY DETECTION

Page 26: Securing The Neighbourhood

HONEYNET

Page 27: Securing The Neighbourhood

MALWARE RESEARCH

Page 28: Securing The Neighbourhood

MALWARE RESEARCH