Efficient Threat Hunting Methodology for Analyzing Malicious Binaries in Windows Platform

被引:0
作者
Elmisery, Ahmed M. [1 ]
Sertovic, Mirela [2 ]
Qasem, Mamoun [1 ]
机构
[1] Univ South Wales, Fac Comp Engn & Sci, Pontypridd, M Glam, Wales
[2] Concept Tech Int Ltd, Threat Def Unit, Belfast, Antrim, North Ireland
来源
SERVICE-ORIENTED COMPUTING, ICSOC 2020 | 2021年 / 12632卷
关键词
Malicious binaries; Malware; Threat hunting; Digital investigations;
D O I
10.1007/978-3-030-76352-7_54
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The rising cyber threat puts organizations and ordinary users at risk of data breaches. In many cases, Early detection can hinder the occurrence of these incidents or even prevent a full compromise of all internal systems. The existing security controls such as firewalls and intrusion prevention systems are constantly blocking numerous intrusions attempts that happen on a daily basis. However, new situations may arise where these security controls are not sufficient to provide full protection. There is a necessity to establish a threat hunting methodology that can assist investigators and members of the incident response team to analyse malicious binaries quickly and efficiently. The methodology proposed in this research is able to distinguish malicious binaries from benign binaries using a quick and efficient way. The proposed methodology consists of static and dynamic hunting techniques. Using these hunting techniques, the proposed methodology is not only capable of identifying a range of signature-based anomalies but also to pinpoint behavioural anomalies that arise in the operating system when malicious binaries are triggered. Static hunting can describe any extracted artifacts as malicious depending on a set of pre-defined patterns of malicious software. Dynamic hunting can assist investigators in finding behavioural anomalies. This work focuses on applying the proposed threat hunting methodology on samples of malicious binaries, which can be found in common malware repositories and presenting the results.
引用
收藏
页码:627 / 641
页数:15
相关论文
共 24 条
  • [21] Miller B.A., 2011, 2011 Proceedings of the 14th International Conference on Information Fusion (FUSION), P1
  • [22] Scarabeo N, 2015, PEERJ COMPUT SCI, DOI 10.7717/peerj-cs.25
  • [23] INDUSTRIAL PERSPECTIVE ON STATIC ANALYSIS
    WICHMANN, BA
    CANNING, AA
    CLUTTERBUCK, DL
    WINSBORROW, LA
    WARD, NJ
    MARSH, DWR
    [J]. SOFTWARE ENGINEERING JOURNAL, 1995, 10 (02): : 69 - 75
  • [24] Wojner C., 2015, PROCDOT NEW WAY VISU