官术网_书友最值得收藏!

Basic analysis lab setup

A typical setup would require a system that can run malware without it being compromised externally. However, there are instances that may require external information from the internet. For starters, we're going to mimic an environment of a home user. Our setup will, as much as possible, use free and open source tools. The following diagram shows an ideal analysis environment setup:

The sandbox environment here is where we do analysis of a file. MITM, mentioned on the right of the diagram, means the man in the middle environment, which is where we monitor incoming and outgoing network activities. The sandbox should be restored to its original state. This means that after every use, we should be able to revert or restore its unmodified state. The easiest way to set this up is to use virtualization technology, since it will then be easy to revert to cloned images. There are many virtualization programs to choose from, including VMware, VirtualBox, Virtual PC, and Bochs. 

It should also be noted that there is software that can detect that it is being run, and doesn't like to be run in a virtualized environment. A physical machine setup may be needed for this case. Disk management software that can store images or re-image disks would be the best solution for us here. These programs include Fog, Clonezilla, DeepFreeze, and HDClone.

主站蜘蛛池模板: 鹰潭市| 巨野县| 日喀则市| 霍山县| 洪洞县| 墨竹工卡县| 清原| 旺苍县| 湖州市| 华蓥市| 尉犁县| 秭归县| 阿荣旗| 湖南省| 汶川县| 抚松县| 平远县| 额济纳旗| 沅江市| 拉萨市| 多伦县| 祁门县| 广水市| 宁明县| 礼泉县| 佛冈县| 林芝县| 三原县| 兴海县| 锡林浩特市| 凤山县| 监利县| 灵川县| 扬中市| 胶南市| 平南县| 江川县| 武山县| 无锡市| 永福县| 嘉定区|