官术网_书友最值得收藏!

Basic analysis lab setup

A typical setup would require a system that can run malware without it being compromised externally. However, there are instances that may require external information from the internet. For starters, we're going to mimic an environment of a home user. Our setup will, as much as possible, use free and open source tools. The following diagram shows an ideal analysis environment setup:

The sandbox environment here is where we do analysis of a file. MITM, mentioned on the right of the diagram, means the man in the middle environment, which is where we monitor incoming and outgoing network activities. The sandbox should be restored to its original state. This means that after every use, we should be able to revert or restore its unmodified state. The easiest way to set this up is to use virtualization technology, since it will then be easy to revert to cloned images. There are many virtualization programs to choose from, including VMware, VirtualBox, Virtual PC, and Bochs. 

It should also be noted that there is software that can detect that it is being run, and doesn't like to be run in a virtualized environment. A physical machine setup may be needed for this case. Disk management software that can store images or re-image disks would be the best solution for us here. These programs include Fog, Clonezilla, DeepFreeze, and HDClone.

主站蜘蛛池模板: 如皋市| 汨罗市| 咸丰县| 天门市| 淅川县| 彝良县| 金堂县| 开封县| 通河县| 临西县| 肥乡县| 南丰县| 泽库县| 福安市| 定襄县| 揭西县| 乐平市| 梁平县| 禄劝| 广安市| 秦安县| 新巴尔虎左旗| 南木林县| 湟源县| 姚安县| 白河县| 石渠县| 封丘县| 会昌县| 天镇县| 山阳县| 霍邱县| 鄂托克前旗| 沅陵县| 靖西县| 南投市| 洪雅县| 宁化县| 邮箱| 兴仁县| 双辽市|