Coseinc Automated Malware Analysis Lab (Camal)

No ratings

Presented at SyScan 2010 by

Thousands of malware are being detected each day and the sheer volume made it impossible to perform manual analysis on each of them.This talk will introduce CAMAL (COSEINC Automated Malware Analysis Lab) an automated malware analysis framework that can produce both static and network analysis snapshots of a malware.The main objective of such a framework is to speed up a malware analyst's job by automatically profiling the malware's binary characteristics, its interaction with the operating system, its access to the file system and its communication through the network.During the talk, we will be first discuss the general framework, followed by technical details on how the whole process can be automated seamlessly. We will also touch on the potential usage of such a framework and how it can help to provide an accurate malware characterization within a shorter timeframe.u6bcfu5929u90fdu6709u4e0au5343u500bu60e1u610fu8edfu9ad4u88abu5075u67e5u5230uff0cu55aeu7d14u5c31u5b83u7684u91cfu4f86u770buff0cu5c31u77e5u9053u8981u89aau624bu5206u6790u6bcfu4e00u500bu662fu4e0du53efu80fdu7684u4efbu52d9u3002u9019u6b21u7684u8a0eu8ad6u6703u4ecbu7d39CAMAL (COSEINC Automated Malware Analysis Lab)uff0c u5b83u662fu4e00u500bu7528u65bcu81eau52d5u5206u6790u60e1u610fu8edfu9ad4u7684u67b6u69cbuff0cu53efu4ee5u63d0u4f9bu60e1u610fu8edfu9ad4u7684u975cu614bu548cu7db2u8defu5206u6790u65b9u9762u7684u7c21u8981u4e86u89e3u3002u9019u6a23u7684u4e00u500bu67b6u69cbu7684u4e3bu8981u76eeu7684uff0cu662fu8981u900fu904eu81eau52d5u4f9du60e1u610fu8edfu9ad4u7684u7279u6027u3001u5b83u548cu4f5cu696du7cfbu7d71u4e4bu9593u7684u4e92u52d5u3001u5b83 u53d6u5f97u7cfbu7d71u548cu6a94u6848u7684u65b9u6cd5u4ee5u53cau5b83u900fu904eu7db2u8defu7684u8a0au606fu50b3u905euff0cu5c07u60e1u610fu8edfu9ad4u5206u985euff0cu597du8b93u60e1u610fu8edfu9ad4u7814u7a76u8005u7684u5de5u4f5cu53efu4ee5u52a0u901fu9032u884cu3002u8a0eu8ad6u7684u904eu7a0bu4e2duff0cu6211u5011u6703u5148u8a0eu8ad6u57fau672cu67b6u69cbuff0cu518du4f86u662fu6280u8853u4e0au7684u7d30u7bc0uff0cu4ee5u53cau9019u6574u500bu904eu7a0bu662fu600eu9ebcu6a23u80fdu7121u7e2bu9699u7684u81eau52d5u4f5cu696du3002u6211 u5011u4e5fu6703u7a0du5faeu8a0eu8ad6u9019u500bu67b6u69cbu5728u904bu7528u4e0au7684u53efu80fdu6027uff0cu4ee5u53cau5b83u5982u4f55u53efu4ee5u5728u8f03u77edu7684u6642u9593u5167u505au5230u6b63u78bau7684u60e1u610fu8edfu9ad4u5206u985eu3002