Please enable JavaScript.
Coggle requires JavaScript to display documents.
Defense from Polymorphic & Metamorphic Malware (Disciplines Needed…
Defense from
Polymorphic &
Metamorphic
Malware
Means to Identify
File / Process Signature (Changes)
Heuristics
File behaviors
Process
Behaviors
API Calls
API Call Sequence
Network Behaviors
Registry changes
Prediction of FQDN
Feature Matching
Static
Manual Analysis
Software Tools
Dynamic
Software Tools
PCAP Signature
Means to Isolate/
Defend / Protect
Quarantine
Block
Ignore
Gateway
Network-based
Host-based
Methods of Polymorphism /
Metamorphism
Slightly modify (Change hash)
Recompile / Restructure
Different tactic (Small or Large)
Change the order of execution
Change the instruction set
Disciplines
Needed
Security System
Operation
Malware Analysis
Signature Developer
Threat Intelligence
Analytic Development
Software Development
Forensics Analyst
Solution
Characteristics
Effectiveness
Resources
Speed
Instance vs. En Masse