Learning Malware Analysis
暫譯: 學習惡意程式分析

Monnappa K A

  • 出版商: Packt Publishing
  • 出版日期: 2018-06-29
  • 售價: $1,925
  • 貴賓價: 9.5$1,829
  • 語言: 英文
  • 頁數: 510
  • 裝訂: Paperback
  • ISBN: 1788392507
  • ISBN-13: 9781788392501
  • 相關分類: 資訊安全
  • 立即出貨 (庫存=1)

  • Learning Malware Analysis-preview-1
  • Learning Malware Analysis-preview-2
  • Learning Malware Analysis-preview-3
  • Learning Malware Analysis-preview-4
  • Learning Malware Analysis-preview-5
  • Learning Malware Analysis-preview-6
  • Learning Malware Analysis-preview-7
  • Learning Malware Analysis-preview-8
Learning Malware Analysis-preview-1

買這商品的人也買了...

商品描述

Key Features

  • Gets you up and running with the key concepts of malware analysis
  • Learn the art of detecting, analyzing and investigating malware threats
  • Practical use of malware analysis using different tools and techniques.
  • Learn the concepts using real world examples

Book Description

Malware analysis and memory forensics are powerful analysis and investigation techniques used in reverse engineering, digital forensics and incident response. With adversaries becoming sophisticated and carrying out advanced malware attacks on critical infrastructures, Data centers, private and public organizations; detecting, responding and investigating such intrusions are critical to information security professionals. Malware analysis and memory forensics have become a must have skill for fighting advanced malware, targeted attacks and security breaches.

This book teaches concepts, techniques, and tools to understand the behavior and characteristics of malware by using malware analysis and it also teaches the techniques to investigate and hunt malwares using memory forensics.

This book will introduce readers to the basics of malware analysis, Windows internals and it then gradually progresses deep into more advanced concepts of code analysis & memory forensics. This book uses real world malware samples and infected memory images to help readers gain a better understanding of the subject so that the readers will be equipped with skills required to analyze, investigate and respond to malware related incidents.

What you will learn

  • Create a safe and isolated lab environment for malware analysis
  • Tools, concepts & techniques to perform malware analysis using static, dynamic, code and memory analysis/forensics
  • Extracting the metadata associated with malware
  • Determining malware interaction with system
  • Reverse engineering and debugging using code analysis tools like IDA pro and x64dbg
  • Reverse engineering various malware functionalities
  • Reverse engineering & decoding the common encoding/encryption algorithms.
  • Techniques to investigate & hunt malware using memory forensics.
  • Build a custom sandbox to automate malware analysis

商品描述(中文翻譯)

**主要特點**

- 讓您快速掌握惡意程式分析的關鍵概念
- 學習檢測、分析和調查惡意程式威脅的技巧
- 實際使用不同工具和技術進行惡意程式分析
- 通過真實世界的例子學習這些概念

**書籍描述**

惡意程式分析和記憶體取證是用於逆向工程、數位取證和事件響應的強大分析和調查技術。隨著對手變得越來越複雜,並對關鍵基礎設施、數據中心、私營和公共組織發動先進的惡意程式攻擊;檢測、響應和調查這些入侵對於資訊安全專業人員至關重要。惡意程式分析和記憶體取證已成為對抗先進惡意程式、針對性攻擊和安全漏洞的必備技能。

本書教授使用惡意程式分析來理解惡意程式的行為和特徵的概念、技術和工具,並教授使用記憶體取證調查和追蹤惡意程式的技術。

本書將向讀者介紹惡意程式分析、Windows 內部結構的基本知識,然後逐步深入更高級的代碼分析和記憶體取證概念。本書使用真實的惡意程式樣本和感染的記憶體映像,幫助讀者更好地理解主題,使讀者具備分析、調查和響應與惡意程式相關事件所需的技能。

**您將學到的內容**

- 創建一個安全且隔離的實驗室環境以進行惡意程式分析
- 使用靜態、動態、代碼和記憶體分析/取證進行惡意程式分析的工具、概念和技術
- 提取與惡意程式相關的元數據
- 確定惡意程式與系統的互動
- 使用 IDA Pro 和 x64dbg 等代碼分析工具進行逆向工程和調試
- 逆向工程各種惡意程式功能
- 逆向工程和解碼常見的編碼/加密算法
- 使用記憶體取證調查和追蹤惡意程式的技術
- 建立自定義沙盒以自動化惡意程式分析