Binary Analysis Cookbook: Actionable Recipes for Disassembling and Analyzing Binaries for Security Risks
Book information
Description
Explore open-source Linux tools and advanced binary analysis techniques to analyze malware, identify vulnerabilities in code, and mitigate information security risks Key Features Adopt a methodological approach to binary ELF analysis on Linux Learn how to disassemble binaries and understand disassembled code Discover how and when to patch a malicious binary during analysis Book Description Binary analysis is the process of examining a binary program to determine information security actions. It is a complex, constantly evolving, and challenging topic that crosses over into several domains of information technology and security. This binary analysis book is designed to help you get started with the basics, before gradually advancing to challenging topics. Using a recipe-based approach, this book guides you through building a lab of virtual machines and installing tools to analyze binaries effectively. You'll begin by learning about the IA32 and ELF32 as well as IA64 and ELF64 specifications. The book will then guide you in developing a methodology and exploring a variety of tools for Linux binary analysis. As you advance, you'll learn how to analyze malicious 32-bit and 64-bit binaries and identify vulnerabilities. You'll even examine obfuscation and anti-analysis techniques, analyze polymorphed malicious binaries, and get a high-level overview of dynamic taint analysis and binary instrumentation concepts. By the end of the book, you'll have gained comprehensive insights into binary analysis concepts and have developed the foundational skills to confidently delve into the realm of binary analysis. What you will learn Traverse the IA32, IA64, and ELF specifications Explore Linux tools to disassemble ELF binaries Identify vulnerabilities in 32-bit and 64-bit binaries Discover actionable solutions to overcome the limitations in analyzing ELF binaries Interpret the output of Linux tools to identify security risks in binaries Understand how dynamic taint analysis works Who this book is for This book is for anyone looking to learn how to dissect ELF binaries using open-source tools available in Linux. If you're a Linux system administrator or information security professional, you'll find this guide useful. Basic knowledge of Linux, familiarity with virtualization technologies and the working of network sockets, and experience in basic Python or Bash scripting will assist you with understanding the concepts in this book Cover Title Page Copyright and Credits Dedication About Packt Contributors Table of Contents Preface Chapter 1: Setting Up the Lab Installing VirtualBox on Windows Getting ready How to do it... How it works... There's more... See also Installing VirtualBox on Mac Getting ready How to do it... How it works... There's more... See also Installing VirtualBox on Ubuntu Getting ready How to do it... How it works... There's more... See also Installing a 32-bit Ubuntu 16.04 LTS Desktop virtual machine Getting ready How to do it... How it works... There's more... See alsoInstalling a 64-bit Ubuntu 16.04 LTS Desktop virtual machine Getting ready How to do it... How it works... There's more... See also Installing the dependencies and the tools Getting ready How to do it... How it works... There's more... See also Installing the code examples Getting ready How to do it... How it works... There's more... See also Installing the EDB Debugger Getting ready How to do it... How it works... There's more... See also Taking a snapshot of the virtual machines Getting ready How to do it... How it works... There's more... See also Chapter 2: 32-bit Assembly on Linux and the ELF SpecificationTechnical requirements Differences between Intel and AT&T syntax Getting ready How to do it... How it works... There's more... See also Introduction to the IA-32 registers Getting ready How to do it... How it works... There's more... See also Introducing common IA-32 instructions Getting ready How to do it... How it works... There's more... See also Making IA-32 system calls on Linux Getting ready How to do it... How it works... There's more... See also Introducing the ELF 32-bit specification Getting ready How to do it...How it works... There's more... See also Chapter 3: 64-bit Assembly on Linux and the ELF Specification Technical requirements Introducing the IA64 registers Getting ready How to do it... How it works... There's more... See also Introducing common IA64 instructions Getting ready How to do it... How it works... There's more... See also Making IA64 system calls on Linux Getting ready How to do it... How it works... There's more... See also Introducing the ELF 64-bit specification Getting ready How to do it... How it works... There's more... See also Chapter 4: Creating a Binary Analysis MethodologyTechnical requirements Performing binary discovery Getting ready How to do it... How it works... There's more... See also Information gathering Getting ready How to do it... How it works... There's more... See also Static analysis Getting ready How to do it... How it works... There's more... See also Dynamic analysis Getting ready How to do it... How it works... There's more... See also Iterating each step Getting ready How to do it... How it works... There's more... See also Automating methodology tasks
Similar books
Europäisches Kollisionsrecht des Effektengiros: Intermediatisierte Wertpapiere im Schnittfeld von Internationalem Sachen-, Schuld- und Insolvenzrecht
2014 · PDF
Recommendations for Adopting a Cloud-Native Key Management Service
2021 · PDF
Binary Analysis Cookbook: Actionable recipes for disassembling and analyzing binaries for security risks
2019 · PDF
EXCEL 2023 CRASH COURSE: Master Excel 2023 With This Complete Crash Course In 7 Days
2022 · EPUB
The arraignment and tryall with a declaration of the Ranters also, several sentences proceedings at the sessions in the Old-Baily, and Councel of War: their protestations and the hanging of one up by the thumbs; with divers penalties to be inflicted upon others. The dancing and revelling of Dr. Buckeridge and his wife, and other gent. dancing all in white, in Berkshire, and their Christmas carol. A dispute between a Ranter in Bridewel, and one that came to see him; with his creed and pater noster: and the names of the false gods they worship. As also, a list of many of the Ranters, from whence they are derived: and of many hundreds of them in England
2019 · EPUB
The discoverer; vvherein is set forth (to undeceive the nation) the reall plots and stratagems of Lievt. Col. John Lilburn, Mr. William Walwyn, Mr. Thomas Prince, Mr. Richard Overton, and that partie ... Namely, under the pretence and colour of libertie ... a most dangerous and destructive designe is carried on to deprive the nation of their religion, rights, liberties, proprieties, lawes, government, &c. and to bring a totall and universall ruine upon the land. And so much is here clearely proved. The first part
2019 · EPUB
An act to impower Sir John Molesworth: Baronet, and Joseph Moyle, Esquire, Two of the surviving Trustees, in an Indenture, dated the Twenty-Fifth Day of December One thousand Seven hundred and Forty-Three, to raise the several Sums in the said Indenture mentioned, or such of them as are still unsatisfied, and pay the same, as well as the rest of the personal Estate of Hugh Gregor, deceased, to such Person as Jane Gregor, an Infant, shall marry during her Infancy, with the Consent of the surviving Trustees, and of her Guardians
EPUB
Case Histories
2008 · EPUB