Skip to main content

An Early Malware Detection, Correlation, and Incident Response System with Case Studies

Software and systems complexity can have a profound impact on information security. Such complexity is not only imposed by the imperative technical challenges of monitored heterogeneous and dynamic (IP and VLAN assignments) network infrastructures, but also through the advances in exploits and malware distribution mechanisms driven by the underground economics. In addition, operational business constraints (disruptions and consequences, manpower, and end-user satisfaction), increase the complexity of the problem domain that security analysts must adequately operate within. This is particularly evident when implementing effective response measures to malware infections in a timely manner, minimizing the risk to business. A simple question becomes particularly valid under such complex environments; what appropriate response actions must be met to appropriately eradicate malware infections while maintaining high operational and low risk profile? This need stems from the absence of predefined and pre-correlated knowledge of the environment and malware behaviors. Without such knowledge, isolating, analyzing, and responding to incidents at the very same time of the infection become increasingly difficult. Specially, when the incident involves aggressive malware specimens exhibiting behaviors such as network propagation, acting as a spambot, or seeking data exfiltration. In this case, it is critical to respond to the incident before serious consequences to the business occur.The faster the compromise is detected and responded to, the more it will be controlled and the less impact it will have. For this purpose, a methodological framework to respond to malware incidents is proposed. At its core, the framework focuses on minimizing the Detection-To-Response (DTR) process and time frames. The foundations upon which the framework is built consist of pre-correlated contextual knowledge about the monitored network, and a pre-built malware analysis knowledgebase. This allows the framework to systematically and dynamically automate network actions to isolate infected hosts as early as detection. At the same time, the collected multidimensional knowledge is presented to the analyst to aid during the investigation and response phases. Ultimately, the early automation of response actions, and reduced response time frames preserve the continuity of operations, as well as end-users relationship fidelity. To demonstrate the efficacy of such framework, two case studies are presented to help evaluate the proposed framework in responding to malware incidents.

34485 (PDF, 5.11MB)

20 Jan 2014
ByYaser Mansour
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

Malware Function-based encryption technique

Research Paper

Recent malware often uses techniques to evade detection by cybersecurity products. One of the...

  • 22 Jun 2022
  • Hirokazu Murakami

Detecting Unauthorized Behavior From Legitimate Accounts

Research Paper

Incident Responders face an almost insurmountable amount of log events, and the move to the Cloud...

  • 22 Jun 2022
  • Rodney Caudle

Recover an RSA Private Key from a TLS v1.2 session

Research Paper

Cyberattacks happen every day.Most organizations have administrative and technical controls...

  • 22 Jun 2022
  • Johan Loos

Cyber Guardian Exercise: A Case Study in Brazil to Address Challenges in Cybersecurity and Protect Critical Infrastructure

Research Paper

Discussions of cybersecurity, in particular those associated with critical infrastructure (CI),...

  • 22 Feb 2022
  • Maxli Barroso Campos

Recommendations for small/medium-sized businesses enabling incident response

Research Paper

Security incidents are inevitable. While large businesses can afford security teams to prepare and...

  • 17 Jan 2022
  • Luke Pearson

Black-Box Fuzzing for Android Native Libraries

Research Paper

Many Android application developers are adopting C\C++ native language development in their Android...

  • 12 Jan 2022
  • Nawaf Alkeraithe

Machine Learning Techniques for Intrusion Detection

Research Paper

This paper aims to equip intrusion analysts with the basic techniques needed to apply machine...

  • 9 Jun 2021
  • Yih Han Tan

Detecting DLL Search Order Hijacking: How using a purple team approach can help create better defensive techniques and a more tactical SIEM

Research Paper

Many SIEM analysts will recognize the feeling of being overwhelmed with security logs and alerts,...

  • 4 May 2020
  • Lasse Hauballe Jensen

Corporate Information Governance with Business Wisdom

Research Paper

Whether a secret ingredient used for a lemonade stand across the street or the business strategies...

  • 4 May 2020
  • David Alexander Cruz Urena

Automated Detection and Disinfection of Ransomware Attacks using Roadblock Software

Research Paper

We often hear about ransomware locking data and demanding the ransom. Ransomware is a kind of...

  • 18 Mar 2020
  • Hemant Kumar

Assisted Security Investigations Using Cognitive Computing

Research Paper

The purpose of this research is to illustrate the application of cognitive computing and machine...

  • 3 Dec 2019
  • Lori Stroud

Leveraging the PE Rich Header for Static Malware Detection and Linking

Research Paper

An ever-increasing number of malware samples are identified and assessed daily. Malware researchers...

  • 1 Jul 2019
  • Maksim Dubyk

Analysis of a Multi-Architecture SSH Linux Backdoor

Research Paper

A key aspect in any intrusion is to attempt to gain persistence on the compromised system. Threat...

  • 17 Jun 2019
  • Angel Alonso-Parrizas

Unpacking and Decrypting FlawedAmmyy

Research Paper

Malware authors commonly utilize packers (Roccia, 2017) as a method of concealing functionality and...

  • 22 Apr 2019
  • Mike Downey

Continuous Security Monitoring in non-Active Directory Environments

Research Paper

Active Directory-centric monitoring techniques, tools, and methodologies have dominated information...

  • 20 Feb 2019
  • Blair Gillam

Intrusion Prevention System Signature Management Theory

Research Paper

The intrusion prevention system (IPS) serves as one of the critical components for a...

  • 5 Feb 2019
  • Joshua Levine

SDN Southbound Threats

Research Paper

SDN (Software-Defined Networks) technologies are based on three pillars: decoupling control and...

  • 20 Nov 2018
  • Mohamed Mahdy

Processing experimental protocols against IDS

Research Paper

Experimental protocols such as TCP Fastopen, QUIC, and Multipath TCP are not uncommon on...

  • 10 Aug 2018
  • Tommy Adams

Extracting Timely Sign-in Data from Office 365 Logs

Research Paper

Office 365 is quickly becoming a repository of valuable organizational information, including data...

  • 22 May 2018
  • Mark Lucas

Automated Detection and Analysis using Mathematical Calculations

Research Paper

A compromised system usually shows some form of anomalous behaviour. Examples include new processes,...

  • 17 May 2018
  • Lionel Teo

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.