Interactive Assistance in Malware Dissemination Detection and Analysis
Raul Zaharia, Dragoş Teodor Gavriluţ, Gheorghiţă Mutu, Dorel Lucanu · 2024
Analysis of a complex cyber-security attack often involves a variety of tools, for each specific payload used in the attack. The information supplied by these tools must be soundly correlated to obtain a correct verdict. We propose a tool, GView, that is designed to investigate cyber-attacks by providing guided analysis for various file types using automatic artifact identification, extraction, coherent correlation & inference, and meaningful & intuitive views at different levels of granularity w.r.t. revealed information. The concept behind GView simplifies navigation through all payloads in a complex attack, streamlining the process for security researchers, and increasing the quality of analysis. Our evaluation shows that GView improves the analysis time of an attack by up to 90% compared to conventional tools used in forensics. We show a scenario where GView is used to analyze a misleading email.