A collaborative distributed virtual platform for forensic analysis of malicious code

Leonard Shand, Theo Tryfonas · Bristol Research (University of Bristol) · 2008

Malicious software is prevalent in many forms with the potential for many types of malware to be downloaded while browsing the Internet using an unprotected system. The potential impact can be irreparable harm to a computer file system or even place a person in a situation where they could be charged for a criminal act, if the perpetrator assumes control of their system. Understanding contemporary forms of malware is crucial in order to prepare better defences against it as well as investigate related incidents and claims. Therefore forensic analysis of specific malware, requires specialised tools and techniques and is of significant importance for information security professionals. In an effort to facilitate the process of forensic analysis of malicious and hostile code we intend to develop a system whereby specific malware can be identified, classified and the malware and detailed forensic analysis stored in a searchable database. The research results would assist computer forensics expert witnesses and infosecurity specialists, to determine the potential role, and impact on a case of certain malware types found to be present on a computer under examination. To this end, we first research on different types of malware and obtain a selection of malware samples as a specimen to investigate. We create an environment containing suitable investigative tools with which to analyse malware and devise a virtual testing utility platform (containing networking settings, software etc.) to conduct examinations. Experts can use the virtual infrastructure provided to analyse malware and then log their analysis results, notes and experiences in a bespoke on-line collaborative web accessed database. In there experts can log their findings and further produce analytical aids including the behavioural profile of the malware inspected, and potentially be others analysing the same types of malicious code.

Read the paper · More papers on PaperTik