Leveraging Next-Generation Virtualization Technologies for Advanced Malware Analysis in the Classroom

Dale C. Rowe, Laura K. Wilkinson · 2014

Malicious software (malware) represents an ever-increasing threat to our technological lives. In the last decade, the proliferation of malware on traditional computing devices has expanded to include mobile platforms and embedded technologies. The development and use of malware is no longer limited to computer scientists and hackers but is now becoming an integral operational capability of militaries and governments worldwide. Recalling that in 2003, a primitive MS-SQL worm resulted in the shutdown of a nuclear plant, the threats faced today and in the near future are alarming. In 2013, it was estimated that the business cost of malware exceeded $114 billion. Technology, computing, and engineering students of multiple disciplines can be better prepared to deal with malware risks by a comprehensive study of malware. Traditional pedagogical methods typically involve isolating computers and/or networks to enable students to learn without posing a risk to connected networks. While this method does provide a relatively safe environment, modern malware is frequently dependent on a complete network connection, and isolation is no longer representative of current best practices in malware analysis. In the last year, we have been developing a new course in malware analysis that uses innovative methods of infrastructure-as-a-service (IaaS) and network-as-a-service (NaaS) technologies to enhance student learning in an instructor controllable and inherently safe environment. We show how these approaches are leveraged to allow a variety of dynamic and static analysis techniques and how we have optimized this approach for a typical classroom schedule. We also demonstrate in detail how this solution can be implemented on a limited budget using low-cost surplus hardware. In conclusion, we contrast our implementation with traditional approaches and discuss its benefits and limitations.

Read the paper · More papers on PaperTik