99級-楊昆鑫-以DNS Query Time 為基礎偵測Fast-Flux Service Networks(FFSN)
[ 摘要 ]
隨著網際網路被運用在商業的頻率越來越高,網路攻擊所造成的利益損害已經逐漸擴大。駭客運用著網際網路從事非法的活動,像是木馬、病毒散播、分散式阻斷服務攻擊、垃圾郵件與釣魚網站的威脅等,為了獲取龐大的利益,犯罪者對於非法活動的需求日漸成長,而為了讓這些詐欺行為具有高度的隱蔽性,犯罪者開始使用一種稱為Fast-Flux Service Networks的攻擊手法,FFSN是由一群被用來當作代理轉向服務的傀儡網路(botnet)所組成,利用這些受感染的傀儡主機便可以將使用者重新導向至犯罪者所架設的惡意內容。
本研究實作建置一系統,以本研究所探討之偵測特徵搭配既有特徵為偵測基準,針對Malware Domain List及ATLAS資料來源偵測FFSN惡意網域,探討當前網路犯罪中FFSN被犯罪者應用的實際情形、並分析偵測效益並挑選出最佳方案作為日後之偵測基準。
[ 英文摘要 ]
With the Internet being used more frequently in the business, network attack have caused damage to the interests gradually expanded. Hackers use the Internet for illegal activities, such as Trojan, viruses, DDoS attacks, spam and phishing, etc. In order to obtain huge benefits, the offender’s demand for illegal activities growth, and to make such fraud a high degree of concealment, the offender began to use the attack tactics called Fast-Flux Service Network (FFSN). FFSN is composed by who is used by a group of agents to service as a proxy of the botnet. Use these infected host can redirect the user to the malicious content that offender set.
In this thesis we implemented a system, we use the detection feature discuss in this thesis and the features that is already discussed in other study to detect whether the data which are from Malware Domain List and ATLAS are belong to FFSN or not. Also, we investigate the utilization of FFSN by miscreants on the Internet, and analyze the detection performance and select the best case as the baseline of detection in the future.
99級-林庭弘-以逆向工程偵測惡意代碼行為
99級-林庭弘-以逆向工程偵測惡意代碼行為
[ 摘要 ]
過去幾年來惡意程式的數量和破壞能力已成倍數成長,惡意程式開始使用代碼混淆技術、加密和加殼技術來躲避防毒軟體的特徵碼偵測。目前很多惡意作者都是使用加殼技術加密惡意程式,以躲避防毒軟體的檢測,所以惡意程式加殼已成為現今防毒公司最具挑戰性的問題。
如何去偵測惡意加殼程式,本研究提出使用Entropy和其他的輔助特徵來檢測加殼程式,並使用靜態特徵與動態特徵來偵測惡意加殼程式。實驗結果,本研究能即時偵測出代碼混淆技術、加殼和加殼技術,並能有效區分善意加殼程式和惡意加殼程式的差別。
[ 英文摘要 ]
In the past few years, the amount of the malicious program and the capability of destruction have become more and more. Malicious programs and their writers are also staring to use the packed technology of encryption and code obfuscation to avoid the detection from anti-virus software. Therefore, the packed technology has become a challenging problem to the anti-virus company.
How to detect the malicious packed program is also the important issue of researches of the information security. This study uses the encryption and the other assistant feature to help the detection to malicious packed program. Furthermore, there has use the combination of the static and dynamic feature to detect the malicious packed program. The result of this study shows that the packed technology of encryption and code obfuscation could be detected more efficiency and the different between the friendly packed program and the malicious packed program can also be identified more operative.
[ 摘要 ]
過去幾年來惡意程式的數量和破壞能力已成倍數成長,惡意程式開始使用代碼混淆技術、加密和加殼技術來躲避防毒軟體的特徵碼偵測。目前很多惡意作者都是使用加殼技術加密惡意程式,以躲避防毒軟體的檢測,所以惡意程式加殼已成為現今防毒公司最具挑戰性的問題。
如何去偵測惡意加殼程式,本研究提出使用Entropy和其他的輔助特徵來檢測加殼程式,並使用靜態特徵與動態特徵來偵測惡意加殼程式。實驗結果,本研究能即時偵測出代碼混淆技術、加殼和加殼技術,並能有效區分善意加殼程式和惡意加殼程式的差別。
[ 英文摘要 ]
In the past few years, the amount of the malicious program and the capability of destruction have become more and more. Malicious programs and their writers are also staring to use the packed technology of encryption and code obfuscation to avoid the detection from anti-virus software. Therefore, the packed technology has become a challenging problem to the anti-virus company.
How to detect the malicious packed program is also the important issue of researches of the information security. This study uses the encryption and the other assistant feature to help the detection to malicious packed program. Furthermore, there has use the combination of the static and dynamic feature to detect the malicious packed program. The result of this study shows that the packed technology of encryption and code obfuscation could be detected more efficiency and the different between the friendly packed program and the malicious packed program can also be identified more operative.
訂閱:
文章 (Atom)
RSS Feed
Twitter