首页> 外文会议>International Conference on Information Security for South Africa >Dridex: Analysis of the traffic and automatic generation of IOCs
【24h】

Dridex: Analysis of the traffic and automatic generation of IOCs

机译:DRIDEX:IOC的交通和自动生成分析

获取原文

摘要

In this paper we present a framework that generates network Indicators of Compromise (IOC) automatically from a malware sample after dynamic runtime analysis. The framework addresses the limitations of manual Indicator of Compromise generation and utilises sandbox environment to perform the malware analysis in. We focus on the generation of network based IOCs from captured traffic files (PCAPs) generated by the dynamic malware analysis. The Cuckoo Sandbox environment is used for the analysis and the setup is described in detail. Accordingly, we discuss the concept of IOCs and the popular formats used as there is currently no standard. As an example of how the proof-of-concept framework can be used, we chose 100 Dridex malware samples and evaluated the traffic and showed what can be used for the generation of network-based IOCs. Results of our system confirm that we can create IOCs from dynamic malware analysis and avoid the legitimate background traffic originating from the sandbox system. We also briefly discuss the sharing of, and application of the generated IOCs and the number of systems that can be used to share them. Lastly we discuss how they can be useful in combating cyber threats.
机译:在本文中,我们介绍了一个框架,它在动态运行时分析后自动从恶意软件样本自动生成妥协(IOC)的网络指示符。该框架解决了妥协生成的手动指示器的限制,并利用沙箱环境执行恶意软件分析。我们专注于从动态恶意软件分析生成的捕获的业务文件(PCAP)的基于网络的IOC。 Cuckoo Sandbox环境用于分析,并详细描述设置。因此,我们讨论了IOC的概念和当前没有标准的流行格式。作为如何使用概念验证框架的示例,我们选择了100个Riddex恶意软件样本并评估流量并显示了什么可以用于生成基于网络的IOC。我们的系统结果证实我们可以从动态恶意软件分析中创建IOC,并避免源自沙箱系统的合法背景流量。我们还简要介绍生成的IOC的共享和应用程序的应用程序和可用于共享它们的系统数。最后,我们讨论它们在打击网络威胁方面是有用的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号