Diplomová práce

Design and evaluation of a network malware laboratory with virtual honeypots

Bc. Michal Mečíř, učo 173301
Anotace

Diplomová práca sa zaoberá témou návrhu a otestovania sieťového laboratória na výskum škodlivého softvéru s dôrazom na sieťový prvok činnosti tohto softvéru. V laboratóriu sa použijú virtuálne počítače. Kladie sa dôraz na bezpečnosť. Skúma sa možnosť simulácie užívateľa a experimentuje sa s dlžkou trvania experimentu. V závere sa predložia skúsenosti z použivánia a návrhy pre zlepšienie na základe zistení.

Abstract

This thesis deals with the design and evaluation of a network malware laboratory. The design will consists of building and virtual environment, make it secure and provide necessary tools for malware research. The laboratory will contain tools for simulating human interaction. The laboratory will be tested on several real world malware samples. The conclusion will provide information about experiences from usage and lessons learned.

Zadání práce
The aim of the thesis is to design and evaluate a malware laboratory suited for an automatic analysis of network malware behavior. Data obtained from the analyzes should be used to create network signatures for one of the intrusion detection systems.
The laboratory will be based on virtual environment which will ensure required configurability and scalability. Several common services, such as SMTP, HTTP, IRC, and SMB should be emulated on the network.
Moreover, the laboratory will contain a honeypot - a workstation, that will be regularly infected by a malware. The laboratory will collect network communication data and provide tools for emulation of user activity, monitoring of malware behavior and provide further data analysis. The laboratory should fulfill desired security requirements in order to mitigate spreading malware and to provide anonymous communication of malware.
In the thesis, it will be proposed a methodology for realizing an experiment in order to evaluate design and set-up of the laboratory. Moreover, the data obtained from the experiment will be analyzed and interpreted according to observations from literature.

References:

[1] Jason Ross. Malware Analysis for the Enterprise. Black Hat 2010. http://www.blackhat.com/presentations/bh-dc-10/Ross_Jason/Blackhat-DC-2010-Ross-Malware-Analysis-for-the-Enterprise-slides.pdf

[2] Christian Rossow, et al. Sandnet: Network Traffic Analysis of Malicious Software. Proceedings of BADGERS 2011, 2011

[3] Michael Ligh et al. Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code. Wiley, 2010
Práce zkontrolována:
10. 1. 2013 11:00, RNDr. Marián Novotný, Ph.D.
Jazyk práce
angličtina angličtina
Termín obhajoby
14. 2. 2013
Práce byla úspěšně obhájena

Vedoucí

RNDr. Marián Novotný, Ph.D.

Oponent

doc. RNDr. Petr Švenda, Ph.D., učo 4085
KPSK FI MU

Masarykova univerzita Fakulta informatiky
Studijní program
Informatika
  • Přidání souboru

    Soubor nebo složku lze nahrát pomocí tlačítka Přidat.
  • Další operace se soubory

    Podrobnosti lze zjistit označením příslušného řádku.
  • Pohled pro experty

    Pro častou práci je možné zvolit režim Více možností.
  • Vyhledávání souborů

    Vyhledávaný výraz můžete zadat přímo do adresního řádku.
  • Rychlý přístup k souborům

    Pomocí funkce Nedávné je možné se rychle vrátit k právě prohlíženým souborům. Oblíbené soubory je také možné označit Hvězdičkou.