Learning Malware Analysis

Monnappa K A

  • 出版商: Packt Publishing
  • 出版日期: 2018-06-29
  • 售價: $1,925
  • 貴賓價: 9.5$1,829
  • 語言: 英文
  • 頁數: 510
  • 裝訂: Paperback
  • ISBN: 1788392507
  • ISBN-13: 9781788392501
  • 相關分類: 資訊安全
  • 立即出貨 (庫存=1)

  • Learning Malware Analysis-preview-1
  • Learning Malware Analysis-preview-2
  • Learning Malware Analysis-preview-3
  • Learning Malware Analysis-preview-4
  • Learning Malware Analysis-preview-5
  • Learning Malware Analysis-preview-6
  • Learning Malware Analysis-preview-7
  • Learning Malware Analysis-preview-8
Learning Malware Analysis-preview-1

買這商品的人也買了...

商品描述

Key Features

  • Gets you up and running with the key concepts of malware analysis
  • Learn the art of detecting, analyzing and investigating malware threats
  • Practical use of malware analysis using different tools and techniques.
  • Learn the concepts using real world examples

Book Description

Malware analysis and memory forensics are powerful analysis and investigation techniques used in reverse engineering, digital forensics and incident response. With adversaries becoming sophisticated and carrying out advanced malware attacks on critical infrastructures, Data centers, private and public organizations; detecting, responding and investigating such intrusions are critical to information security professionals. Malware analysis and memory forensics have become a must have skill for fighting advanced malware, targeted attacks and security breaches.

This book teaches concepts, techniques, and tools to understand the behavior and characteristics of malware by using malware analysis and it also teaches the techniques to investigate and hunt malwares using memory forensics.

This book will introduce readers to the basics of malware analysis, Windows internals and it then gradually progresses deep into more advanced concepts of code analysis & memory forensics. This book uses real world malware samples and infected memory images to help readers gain a better understanding of the subject so that the readers will be equipped with skills required to analyze, investigate and respond to malware related incidents.

What you will learn

  • Create a safe and isolated lab environment for malware analysis
  • Tools, concepts & techniques to perform malware analysis using static, dynamic, code and memory analysis/forensics
  • Extracting the metadata associated with malware
  • Determining malware interaction with system
  • Reverse engineering and debugging using code analysis tools like IDA pro and x64dbg
  • Reverse engineering various malware functionalities
  • Reverse engineering & decoding the common encoding/encryption algorithms.
  • Techniques to investigate & hunt malware using memory forensics.
  • Build a custom sandbox to automate malware analysis

商品描述(中文翻譯)

主要特點


  • 讓您快速掌握惡意軟體分析的關鍵概念

  • 學習檢測、分析和調查惡意軟體威脅的技巧

  • 實際運用不同工具和技術進行惡意軟體分析

  • 通過實際案例學習相關概念

書籍描述

惡意軟體分析和記憶體取證是逆向工程、數位取證和事件回應中使用的強大分析和調查技術。隨著對手變得複雜並對關鍵基礎設施、資料中心、私人和公共組織進行先進的惡意軟體攻擊,檢測、回應和調查此類入侵對於資訊安全專業人員至關重要。惡意軟體分析和記憶體取證已成為對抗先進惡意軟體、針對性攻擊和安全漏洞的必備技能。

本書教授使用惡意軟體分析來理解惡意軟體的行為和特徵的概念、技術和工具,並教授使用記憶體取證來調查和追蹤惡意軟體的技巧。

本書將向讀者介紹惡意軟體分析、Windows 內部結構的基礎知識,並逐漸深入更高級的代碼分析和記憶體取證概念。本書使用真實的惡意軟體樣本和受感染的記憶體映像,幫助讀者更好地理解主題,以便讀者具備分析、調查和回應與惡意軟體相關的事件所需的技能。

你將學到什麼


  • 建立一個安全且隔離的實驗環境進行惡意軟體分析

  • 使用靜態、動態、代碼和記憶體分析/取證的工具、概念和技術進行惡意軟體分析

  • 提取與惡意軟體相關的元數據

  • 確定惡意軟體與系統的互動

  • 使用 IDA Pro 和 x64dbg 等代碼分析工具進行逆向工程和調試

  • 逆向工程各種惡意軟體功能

  • 逆向工程和解碼常見的編碼/加密算法

  • 使用記憶體取證技術調查和追蹤惡意軟體

  • 構建自定義沙盒以自動化惡意軟體分析