官术网_书友最值得收藏!

Basic analysis lab setup

A typical setup would require a system that can run malware without it being compromised externally. However, there are instances that may require external information from the internet. For starters, we're going to mimic an environment of a home user. Our setup will, as much as possible, use free and open source tools. The following diagram shows an ideal analysis environment setup:

The sandbox environment here is where we do analysis of a file. MITM, mentioned on the right of the diagram, means the man in the middle environment, which is where we monitor incoming and outgoing network activities. The sandbox should be restored to its original state. This means that after every use, we should be able to revert or restore its unmodified state. The easiest way to set this up is to use virtualization technology, since it will then be easy to revert to cloned images. There are many virtualization programs to choose from, including VMware, VirtualBox, Virtual PC, and Bochs. 

It should also be noted that there is software that can detect that it is being run, and doesn't like to be run in a virtualized environment. A physical machine setup may be needed for this case. Disk management software that can store images or re-image disks would be the best solution for us here. These programs include Fog, Clonezilla, DeepFreeze, and HDClone.

主站蜘蛛池模板: 宿松县| 延安市| 丰台区| 高淳县| 长葛市| 定边县| 平罗县| 固阳县| 双柏县| 武宣县| 山西省| 西峡县| 巫山县| 陆川县| 霞浦县| 同德县| 佛山市| 华阴市| 五原县| 平顺县| 砀山县| 鞍山市| 博湖县| 和静县| 营山县| 朔州市| 崇州市| 墨脱县| 鹿泉市| 桦川县| 闽清县| 章丘市| 蕲春县| 庐江县| 永康市| 图们市| 上栗县| 司法| 当涂县| 米脂县| 苏尼特左旗|