Cuckoo Malware Analysis
暫譯: Cuckoo 惡意程式分析
Digit Oktavianto, Iqbal Muhardianto
- 出版商: Packt Publishing
- 出版日期: 2013-09-20
- 售價: $1,760
- 貴賓價: 9.5 折 $1,672
- 語言: 英文
- 頁數: 142
- 裝訂: Paperback
- ISBN: 1782169237
- ISBN-13: 9781782169239
-
相關分類:
資訊安全
海外代購書籍(需單獨結帳)
相關主題
商品描述
Analyze malware using Cuckoo Sandbox
Overview
- Learn how to analyze malware in a straightforward way with minimum technical skills
- Understand the risk of the rise of document-based malware
- Enhance your malware analysis concepts through illustrations, tips and tricks, step-by-step instructions, and practical real-world scenarios
In Detail
Cuckoo Sandbox is a leading open source automated malware analysis system. This means that you can throw any suspicious file at it and, in a matter of seconds, Cuckoo will provide you with some detailed results outlining what said file did when executed inside an isolated environment.
Cuckoo Malware Analysis is a hands-on guide that will provide you with everything you need to know to use Cuckoo Sandbox with added tools like Volatility, Yara, Cuckooforcanari, Cuckoomx, Radare, and Bokken, which will help you to learn malware analysis in an easier and more efficient way.
Cuckoo Malware Analysis will cover basic theories in sandboxing, automating malware analysis, and how to prepare a safe environment lab for malware analysis. You will get acquainted with Cuckoo Sandbox architecture and learn how to install Cuckoo Sandbox, troubleshoot the problems after installation, submit malware samples, and also analyze PDF files, URLs, and binary files. This book also covers memory forensics – using the memory dump feature, additional memory forensics using Volatility, viewing result analyses using the Cuckoo analysis package, and analyzing APT attacks using Cuckoo Sandbox, Volatility, and Yara.
Finally, you will also learn how to screen Cuckoo Sandbox against VM detection and how to automate the scanning of e-mail attachments with Cuckoo.
What you will learn from this book
- Get started with automated malware analysis using Cuckoo Sandbox
- Use Cuckoo Sandbox to analyze sample malware
- Analyze output from Cuckoo Sandbox
- Report results with Cuckoo Sandbox in standard form
- Learn tips and tricks to get the most out of your malware analysis results
Approach
This book is a step-by-step, practical tutorial for analyzing and detecting malware and performing digital investigations. This book features clear and concise guidance in an easily accessible format.
Who this book is written for
Cuckoo Malware Analysis is great for anyone who wants to analyze malware through programming, networking, disassembling, forensics, and virtualization. Whether you are new to malware analysis or have some experience, this book will help you get started with Cuckoo Sandbox so you can start analysing malware effectively and efficiently.
商品描述(中文翻譯)
分析惡意軟體使用 Cuckoo Sandbox
概述
- 學習如何以簡單的方式分析惡意軟體,並且所需的技術技能最低
- 了解基於文件的惡意軟體上升所帶來的風險
- 透過插圖、技巧與竅門、逐步指導和實際案例增強你的惡意軟體分析概念
詳細內容
Cuckoo Sandbox 是一個領先的開源自動化惡意軟體分析系統。這意味著你可以將任何可疑的文件丟給它,幾秒鐘內,Cuckoo 將提供一些詳細的結果,概述該文件在隔離環境中執行時的行為。
Cuckoo Malware Analysis 是一本實用指南,將提供你使用 Cuckoo Sandbox 所需的所有知識,並附加工具如 Volatility、Yara、Cuckooforcanari、Cuckoomx、Radare 和 Bokken,這些工具將幫助你以更簡單和更有效的方式學習惡意軟體分析。
Cuckoo Malware Analysis 將涵蓋沙箱技術的基本理論、自動化惡意軟體分析以及如何準備一個安全的實驗室環境進行惡意軟體分析。你將熟悉 Cuckoo Sandbox 的架構,學習如何安裝 Cuckoo Sandbox、安裝後的故障排除、提交惡意軟體樣本,以及分析 PDF 文件、URL 和二進位文件。本書還涵蓋記憶體取證——使用記憶體轉儲功能、使用 Volatility 進行額外的記憶體取證、使用 Cuckoo 分析包查看結果分析,以及使用 Cuckoo Sandbox、Volatility 和 Yara 分析 APT 攻擊。
最後,你還將學習如何防範 Cuckoo Sandbox 被虛擬機檢測,以及如何自動化掃描電子郵件附件。
你將從本書學到的內容
- 開始使用 Cuckoo Sandbox 進行自動化惡意軟體分析
- 使用 Cuckoo Sandbox 分析樣本惡意軟體
- 分析來自 Cuckoo Sandbox 的輸出
- 以標準格式報告 Cuckoo Sandbox 的結果
- 學習技巧與竅門,以充分利用你的惡意軟體分析結果
方法
本書是一本逐步的實用教程,旨在分析和檢測惡意軟體以及進行數位調查。本書提供清晰且簡明的指導,以易於訪問的格式呈現。
本書的讀者對象
Cuckoo Malware Analysis 非常適合任何希望通過程式設計、網路、反組譯、取證和虛擬化來分析惡意軟體的人。無論你是惡意軟體分析的新手還是有一些經驗,本書將幫助你開始使用 Cuckoo Sandbox,讓你能夠有效且高效地開始分析惡意軟體。