ENGLISH

The Art of Computer Virus Research and Defense

Book information

Publisher
Addison-Wesley Professional
Year
2005
ISBN
0321623983, 9780321623980
Language
english
Format
PDF
Filesize
9 MB (9349040 bytes)
Pages
745\745
Time added
2020-04-21 10:41:33

Description

Symantec's chief antivirus researcher has written the definitive guide to contemporary virus threats, defense techniques, and analysis tools. Unlike most books on computer viruses, The Art of Computer Virus Research and Defense is a reference written strictly for white hats: IT and security professionals responsible for protecting their organizations against malware. Peter Szor systematically covers everything you need to know, including virus behavior and classification, protection strategies, antivirus and worm-blocking techniques, and much more. Szor presents the state-of-the-art in both malware and protection, providing the full technical detail that professionals need to handle increasingly complex attacks. Along the way, he provides extensive information on code metamorphism and other emerging techniques, so you can anticipate and prepare for future threats. Szor also offers the most thorough and practical primer on virus analysis ever published--addressing everything from creating your own personal laboratory to automating the analysis process. This book's coverage includes Discovering how malicious code attacks on a variety of platforms Classifying malware strategies for infection, in-memory operation, self-protection, payload delivery, exploitation, and more Identifying and responding to code obfuscation threats: encrypted, polymorphic, and metamorphic Mastering empirical methods for analyzing malicious code--and what to do with what you learn Reverse-engineering malicious code with disassemblers, debuggers, emulators, and virtual machines Implementing technical defenses: scanning, code emulation, disinfection, inoculation, integrity checking, sandboxing, honeypots, behavior blocking, and much more Using worm blocking, host-based intrusion prevention, and network-level defense strategies TABLE OF CONTENTS ABOUT THE AUTHOR PREFACE ACKNOWLEDGMENTS PART I: Strategies of the Attacker 1 INTRODUCTION TO THE GAMES OF NATURE 1.1 Early Models of Self-Replicating Structures 1.2 Genesis of Computer Viruses 1.3 Automated Replicating Code: The Theory and Definition of Computer Viruses References 2 THE FASCINATION OF MALICIOUS CODE ANALYSIS 2.1 Common Patterns of Virus Research 2.2 Antivirus Defense Development 2.3 Terminology of Malicious Programs 2.4 Other Categories 2.5 Computer Malware Naming Scheme 2.6 Annotated List of Officially Recognized Platform Names References 3 MALICIOUS CODE ENVIRONMENTS 3.1 Computer Architecture Dependency 3.2 CPU Dependency 3.3 Operating System Dependency 3.4 Operating System Version Dependency 3.5 File System Dependency 3.6 File Format Dependency 3.7 Interpreted Environment Dependency 3.8 Vulnerability Dependency 3.9 Date and Time Dependency 3.10 JIT Dependency: Microsoft .NET Viruses 3.11 Archive Format Dependency 3.12 File Format Dependency Based on Extension 3.13 Network Protocol Dependency 3.14 Source Code Dependency 3.15 Resource Dependency on Mac and Palm Platforms 3.16 Host Size Dependency 3.17 Debugger Dependency 3.18 Compiler and Linker Dependency 3.19 Device Translator Layer Dependency 3.20 Embedded Object Insertion Dependency 3.21 Self-Contained Environment Dependency 3.22 Multipartite Viruses 3.23 Conclusion References 4 CLASSIFICATION OF INFECTION STRATEGIES 4.1 Boot Viruses 4.2 File Infection Techniques 4.3 An In-Depth Look at Win32 Viruses 4.4 Conclusion References 5 CLASSIFICATION OF IN-MEMORY STRATEGIES 5.1 Direct-Action Viruses 5.2 Memory-Resident Viruses 5.3 Temporary Memory-Resident Viruses 5.4 Swapping Viruses 5.5 Viruses in Processes (in User Mode) 5.6 Viruses in Kernel Mode (Windows 9x/Me) 5.7 Viruses in Kernel Mode (Windows NT/2000/XP) 5.8 In-Memory Injectors over Networks References 6 BASIC SELF-PROTECTION STRATEGIES 6.1 Tunneling Viruses 6.2 Armored Viruses 6.3 Aggressive Retroviruses References 7 ADVANCED CODE EVOLUTION TECHNIQUES AND COMPUTER VIRUS GENERATOR KITS 7.1 Introduction 7.2 Evolution of Code 7.3 Encrypted Viruses 7.4 Oligomorphic Viruses 7.5 Polymorphic Viruses 7.6 Metamorphic Viruses 7.7 Virus Construction Kits References 8 CLASSIFICATION ACCORDING TO PAYLOAD 8.1 No-Payload 8.2 Accidentally Destructive Payload 8.3 Nondestructive Payload 8.4 Somewhat Destructive Payload 8.5 Highly Destructive Payload 8.6 DoS (Denial of Service) Attacks 8.7 Data Stealers: Making Money with Viruses 8.8 Conclusion References 9 STRATEGIES OF COMPUTER WORMS 9.1 Introduction 9.2 The Generic Structure of Computer Worms 9.3 Target Locator 9.4 Infection Propagators 9.5 Common Worm Code Transfer and Execution Techniques 9.6 Update Strategies of Computer Worms 9.7 Remote Control via Signaling 9.8 Intentional and Accidental Interactions 9.9 Wireless Mobile Worms References 10 EXPLOITS, VULNERABILITIES, AND BUFFER OVERFLOW ATTACKS 10.1 Introduction 10.2 Background 10.3 Types of Vulnerabilities 10.4 Current and Previous Threats 10.5 Summary References Part II: STRATEGIES OF THE DEFENDER 11 ANTIVIRUS DEFENSE TECHNIQUES 11.1 First-Generation Scanners 11.2 Second-Generation Scanners 11.3 Algorithmic Scanning Methods 11.4 Code Emulation 11.5 Metamorphic Virus Detection Examples 11.6 Heuristic Analysis of 32-Bit Windows Viruses 11.7 Heuristic Analysis Using Neural Networks 11.8 Regular and Generic Disinfection Methods 11.9 Inoculation 11.10 Access Control Systems 11.11 Integrity Checking 11.12 Behavior Blocking 11.13 Sand-Boxing 11.14 Conclusion References 12 MEMORY SCANNING AND DISINFECTION 12.1 Introduction 12.2 The Windows NT Virtual Memory System 12.3 Virtual Address Spaces 12.4 Memory Scanning in User Mode 12.5 Memory Scanning and Paging 12.6 Memory Disinfection 12.7 Memory Scanning in Kernel Mode 12.8 Possible Attacks Against Memory Scanning 12.9 Conclusion and Future Work References 13 WORM-BLOCKING TECHNIQUES AND HOST-BASED INTRUSION PREVENTION 13.1 Introduction 13.2 Techniques to Block Buffer Overflow Attacks 13.3 Worm-Blocking Techniques 13.4 Possible Future Worm Attacks 13.5 Conclusion References 14 NETWORK-LEVEL DEFENSE STRATEGIES 14.1 Introduction 14.2 Using Router Access Lists 14.3 Firewall Protection 14.4 Network-Intrusion Detection Systems 14.5 Honeypot Systems 14.6 Counterattacks 14.7 Early Warning Systems 14.8 Worm Behavior Patterns on the Network 14.9 Conclusion References 15 MALICIOUS CODE ANALYSIS TECHNIQUES 15.1 Your Personal Virus Analysis Laboratory 15.2 Information, Information, Information 15.3 Dedicated Virus Analysis on VMWARE 15.4 The Process of Computer Virus Analysis 15.5 Maintaining a Malicious Code Collection 15.6 Automated Analysis: The Digital Immune System References 16 CONCLUSION Further Reading INDEX A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Similar books

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

2010 · PDF

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

1858 · PDF

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

2022 · PDF