首页
社区
课程
招聘
[原创]由沙箱说去——2013的总结
发表于: 2013-12-31 20:34 4391

[原创]由沙箱说去——2013的总结

2013-12-31 20:34
4391

走着走着,就踩到了13的尾巴,听见了14的召唤。
也来总结一下,拂去过往的尘埃,2014一切清零,脚踏实地的推进。
与大伙共勉。

------------------------------------------------------------------------------------
之前的文档,稍加修改,涵盖内容较多,但都比较空,再多的文字也显得苍白无力。。。。。。

Make SandBox Be Part of Security Solution

One Target:
                        To Know More about Applications

Two Things:
                        Monitor its behavior
                        Verify its Suspicious Action

-------------------------------目录-----------------------------------------------------
0. 调研        2
0.1由SandBoxie+BSA切入        3
0.2 SandBox as Part of Security Solution        3
0.3 Malware Analysi        3
0.4 案例——Toward Automated Dynamic Malware Behaviors Using CWSandbox        3
1. 概述        4
2. 整体框架        4
2.1现有框架        4
2.2框架改进        5
2.3 案例参考——CWSandbox        7
3. 基础模块        7
3.1 DLL Implementation        7
3.2 Inject        9
3.3 Hook        11
3.4 API        13
3.5 Log Module——规范、统一        13
3.6 通信机制        14
3.7 PE        20
4. 可疑行为检测        23
4.1分割——功能专注        24
4.2 配置文件——灵活加载        24
4.3 可疑行为收集——原材料        24
4.4可疑行为分析        27
5. SandBox样本检测        27
6. 技术兴奋点        28
6.1 Inject,Hook——永恒的主题        28
6.2 Windows——Forensic Research        28
6.3 Secure Programming        29
6.4 Windows Data Type        29
6.5规范、设计——软实力        29
6.6环境、工具        29
6.7 来源        30
7.调研        31
7.1由SandBoxie+BSA切入        31
7.2 SandBox as Part of Security Solution        31
7.3 Malware Analysis        35
7.4 案例——Toward Automated Dynamic Malware Analysis Using CWSandbox        37

-----------------------------摘选------------------------------------------------------
7.2 SandBox as Part of Security Solution
上面更多是以单软件、服务、产品的形式出现的,这里我们来关注一下SandBox 与安全厂商的关系。

7.2.1 Trend Micro
Trend Micro Debuts Malware SandBox For Security Managers
http://www.informationweek.com/security/management/trend-micro-debuts-malware-sandbox-for-s/230600126

“Antivirus vendors have long used sandboxes—benign computing environments—as a way to study captured malware and write signatures, which they push out to their customers’ antivirus scanning engines, to arrest further copies of the malware. But with their own malware sandbox, security managers could craft bespoke virtual patches to block emerging malware without waiting for a signature update.”

变集中式的Signature Producing, Update 为分布式的,可定制的,不依赖Signatue及时反应的机制。

“To make a sandbox available in an enterprise usable form is a great improvement over existing offerings.”

“Using sandboxes enables security-conscious organizations to more rapidly address outbreaks.”

“watching not just for incoming malware, but also outbreaks, is essential because no antivirus software reliably detects all malware.:

7.2.2 Paloalto WildFire
Keywords:   
WildFire  Site:paloaltonetworks.com

WildFire: Protection from Targeted and Unknown Malware
http://www.paloaltonetworks.com/solutions/wildfire.html

Controlling Modern Malware
Introducing WildFire: the Next-Generation of Malware Defense
http://media.paloaltonetworks.com/documents/WildFire_WP.pdf

Fully Integrated Threat Prevention
It only represents part of the threat prevention puzzle. The control of unknown malware must be integrated into an overall security strategy that incorporates application controls, known exploits and malware dangerous URLs and websites, and even dangerous file types or restricted content.

Integrated Threat Prevention
http://media.paloaltonetworks.com/documents/Threat_Prevention_ds.pdf

-----------------------------------------------------------------------------------
直接上附件吧


[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)

上传的附件:
收藏
免费 5
支持
分享
最新回复 (5)
雪    币: 31
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
学习收藏
2013-12-31 21:09
0
雪    币: 31
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
3
总觉得纯RING3容易漏沙
2013-12-31 21:12
0
雪    币: 31
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
说是沙箱,看了半天其实是行为检测,我最近都在搞这块,不过是驱动加注入DLL一起搞,感觉比纯DLL可靠些,还能检测驱动的行为。
2013-12-31 21:18
0
雪    币: 118
活跃值: (72)
能力值: ( LV4,RANK:50 )
在线值:
发帖
回帖
粉丝
5
我是来挺楼主的哟!
2013-12-31 22:45
0
雪    币: 130
活跃值: (59)
能力值: ( LV7,RANK:100 )
在线值:
发帖
回帖
粉丝
6
所言即是,共同学习
2014-1-1 23:32
0
游客
登录 | 注册 方可回帖
返回
//