
Advanced Malware Analysis
Description
Alles über E-Books | Antworten auf Fragen rund um E-Books, Kopierschutz und Dateiformate finden Sie in unserem Info- & Hilfebereich.
More details
Other editions
Additional editions

Content
- Cover
- Title Page
- Copyright Page
- Dedication
- Contents at a Glance
- Contents
- Foreword
- Acknowledgments
- Introduction
- Part I Malware Blueprint
- Chapter 1 Malware Analysis 101
- Malware Analysis
- Malware Analysis and Reverse Engineering
- Types of Malware Analysis
- Purpose of Malware Analysis
- Limitations of Malware Analysis
- The Malware Analysis Process
- The Effective Malware Analyst
- Familiarization with Malware
- Familiarization with Analysis Tools
- Patience
- Recap
- Chapter 2 Malware Taxonomy
- Malware Classes
- Infectors
- Network Worms
- Trojan Horse
- Backdoors
- Remote-Access Trojan
- Information Stealers
- Ransomware
- Scareware
- Fakeware
- Greyware
- Recap
- Chapter 3 Malware Deployment
- Malware Infection Vectors
- Speed
- Stealth
- Coverage
- Shelf Life
- Types of Malware Infection Vectors
- Physical Media
- E-mails
- Instant Messaging and Chat
- Social Networking
- URL Links
- File Shares
- Software Vulnerabilities
- Potential Infection Vectors
- Recap
- Chapter 4 Protective Mechanisms
- The Two States of Malware
- Static Malware
- Dynamic Malware
- Protective Mechanisms
- Static Malware Protective Mechanisms
- Dynamic Malware Protective Mechanisms
- Recap
- Chapter 5 Malware Dependencies
- Dependency Types
- Environment Dependencies
- Program Dependencies
- Timing Dependencies
- Event Dependencies
- User Dependencies
- File Dependencies
- Recap
- Part II Malware Research Lab
- Chapter 6 Malware Collection
- Your Own Backyard
- Scan for Malicious Files
- Look for Active Rootkits
- Inspect Startup Programs
- Inspect Running Processes
- Extract Suspicious Files
- Free Sources
- Contagio
- KernelMode.info
- MalShare.com
- Malware.lu
- Malware Blacklist
- Malwarebytes Forum
- Malekal's Forum
- Open Malware
- Tuts4You
- VirusShare.com
- VX Heaven
- Malware Trackers
- Research Mailing Lists
- Sample Exchange
- Commercial Sources
- Honeypots
- Dionaea
- Recap
- Tools
- Chapter 7 Static Analysis Lab
- The Static Analysis Lab
- Host File Inspection Tools
- Mitigate Possible Infection
- Mitigate Becoming a Malware Staging Point
- Anonymous Communication
- Setting Up the Lab
- Choose the Hardware
- Install the Operating System
- Harden the Lab
- Anonymize the Lab
- Isolate the Lab
- The Virtualized Static Analysis Lab
- Backing Up and Restoring
- Recap
- Tools
- Chapter 8 Dynamic Analysis Lab
- Setting Up the Lab
- Choose the Hardware
- Install the Operating System
- Make the Lab Malware Friendly
- Anonymize the Lab
- Isolate the Lab
- Restoring to a Clean State
- Virtualized Environment Clean State Restoration
- Bare-Metal Environment Clean State Restoration
- Backing Up and Restoring
- The Golden Image
- Host OS
- Other Systems Supporting the Lab
- Recap
- Tools
- Part III Malware Inspection
- Chapter 9 The Portable Executable File
- The Windows Portable Executable File
- The PE File Format
- Relative Virtual Address
- PE Import Functions
- PE Export Functions
- 64-Bit PE File Format
- Recap
- Tools
- Chapter 10 The Proper Way to Handle Files
- File's Analysis Life Cycle
- Transfer
- Analysis
- Storage
- Recap
- Tools
- Chapter 11 Inspecting Static Malware
- Static Analysis Techniques
- ID Assignment
- File Type Identification
- Antivirus Detection
- Protective Mechanisms Identification
- PE Structure Verification
- Strings Analysis
- Recap
- Tools
- Chapter 12 Inspecting Dynamic Malware
- Virtual vs. Bare Metal
- Dynamic Analysis
- Analyzing Host Behavior
- Analyzing Network Behavior
- Dynamic Analysis Limitations
- Recap
- Tools
- Chapter 13 Tools of the Trade
- Malware Analysis Use Cases
- Malware Analyst Toolbox
- Tools of the Trade
- Sysinternals Suite
- Yara
- Cygwin
- Debuggers
- Disassemblers
- Memory Dumpers
- PE Viewers
- PE Reconstructors
- Malcode Analyst Pack
- Rootkit Tools
- Network Capturing Tools
- Automated Sandboxes
- Free Online Automated Sandbox Services
- Recap
- Tools
- Part IV Appendixes
- Appendix A Tools List
- Appendix B List of Laboratories
- Appendix C Volatility Framework Basic Plug-ins
- Index
System requirements
File format: ePUB
Copy protection: Adobe-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Install the free reader Adobe Digital Editions prior to download (see eBook Help).
- Tablet/smartphone (Android; iOS): Install the free app Adobe Digital Editions or the app PocketBook before downloading (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (not Kindle).
The file format ePub works well for novels and non-fiction books – i.e., „flowing” text without complex layout. On an e-reader or smartphone, line and page breaks automatically adjust to fit the small displays.
This eBook uses Adobe-DRM, a „hard” copy protection. If the necessary requirements are not met, unfortunately you will not be able to open the eBook. You will therefore need to prepare your reading hardware before downloading.
Please note: We strongly recommend that you authorise using your personal Adobe ID after installation of any reading software.
For more information, see our ebook Help page.
File format: PDF
Copy-Protection: Adobe-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Install the free reader Adobe Digital Editions prior to download (see eBook Help).
- Tablet/smartphone (Android; iOS): Install the free app Adobe Digital Editions or the app PocketBook before downloading (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (only limited: Kindle).
The file format PDF always displays a book page identically on any hardware. This makes PDF suitable for complex layouts such as those used in textbooks and reference books (images, tables, columns, footnotes). Unfortunately, on the small screens of e-readers or smartphones, PDFs are rather annoying, requiring too much scrolling.
This eBook uses Adobe-DRM, a „hard” copy protection. If the necessary requirements are not met, unfortunately you will not be able to open the eBook. You will therefore need to prepare your reading hardware before downloading.
Please note: We strongly recommend that you authorise using your personal Adobe ID after installation of any reading software.
For more information, see our eBook Help page.