ZiPIDA archive

Projects & research /

Research on a next-generation malware information collection architecture for cybercrime investigation

Architecture design research that applies MALGUARD (a next-generation dynamic malware analysis system) to cyber investigation

This is theoretical architecture research. Building and validating an actual system was proposed as follow-up work.

Written by N@D4, a researcher at ZiPIDA.

This write-up covers architecture design research that applies MALGUARD (a next-generation dynamic malware analysis system) to cyber investigation.

Overview

Cybercrime has recently become more sophisticated through a variety of new techniques, such as virtualization technology and evading tracking of distribution sites, making it increasingly difficult to track and detect.

Companies in Korea and abroad are suffering heavy damage, but existing, traditional analysis methods such as static analysis are limited when it comes to analyzing such malware and tracking its distributors.

Moreover, in the field of cyber investigation, analyzing the malware itself is important, but tracking its distributors is an even more important issue.

This research describes a malware information collection architecture that combines traditional methods, such as static analysis, with the latest information collection methods, such as threat intelligence and OSINT, to track malware distributors efficiently.

Malware analysis method #1

Intelligence

Threat intelligence can be defined as a platform that shares data collected from security incidents and threat information as meaningful information.

Threat intelligence list

VirusTotal
KISA C-TAS
MISP

OSINT

OSINT can be defined as a platform that collects publicly available data from a variety of information sources.

Its sources include mass media, public data, and professional and academic materials.

OSINT list

Identifying activity resources in Korea and abroad
Identifying relationship-based information

Malware analysis method #2

Machine learning

Machine learning is a method that uses algorithms to learn from input data.

  • Machine learning

    • Supervised learning

      • Classification

      • Regression

    • Unsupervised learning

      • Clustering

Machine learning concept diagram
Supervised learning
Unsupervised learning
Correlation analysis heatmap

To analyze malware with machine learning:

  1. Each feature of the files to be analyzed must be extracted.
  2. The extracted features are preprocessed, and feature selection is performed to raise the malware detection rate.
  3. Correlation analysis is then used to select the features that are meaningful for detecting malware.
  4. Training is performed with machine learning algorithms and the detection rate and accuracy are checked; repeating the steps above can resolve problems that lower accuracy, such as overfitting.

Malware analysis method #3

Dynamic analysis

Dynamic analysis is intended to overcome the limitations of static malware analysis.

In particular, when analyzing malware that uses techniques to evade detection by antivirus software, dynamic analysis can counter the obfuscation techniques that static analysis runs into.

An emulator or a virtual machine (VM) is mainly used to see how malware actually affects the system when it runs.

Cuckoo Sandbox

Application

For cyber investigation, it is not enough simply to analyze malware as discussed above: it must be possible to identify distributors through link analysis of the malware’s features and the characteristics of its malicious behavior.

The table below shows the stage-by-stage malware analysis architecture based on cyber investigation:

  • Stage 1: Malware analysis information is collected through the analysis engine.
  • Stage 2: Smart filtering keeps only the information needed for cyber investigation, and the characteristics of the analyzed malware are extracted and normalized.
  • Stage 3: Information linked to open-source intelligence and to big data is collected through OSINT and threat intelligence. The earlier analysis results for the malware itself are then combined with the OSINT and threat intelligence information through link analysis, so that the essential feature information needed for cyber investigation is collected and derived.
  • Stage 4: Link analysis of the information from stages 1–3 extracts meaning relevant to cyber investigation, giving cyber investigators a basis for using information about the malware itself to track its distributors.
Stage 1 analysis engineStage 2 smart filteringStage 3 OSINT and IntelligenceStage 4 link analysis
Concept
  • collecting malicious behavior logs using a comprehensive malware analysis platform
  • an advanced automated malware execution environment
  • specialized filters based on cyber investigation work
  • selecting and filtering meaningful data from the collected malicious behavior information
  • collecting information linked to open-source intelligence
  • collecting information linked to threat big data
  • link analysis of stages 1–3
  • deriving the essential meaningful information needed for cyber investigation
Details
  • static analysis
  • dynamic analysis
  • artifact analysis
  • virtual C&C integration and analysis
  • automatic injection of user interaction
  • defining information based on cyber investigation work
  • structuring information and making it lightweight
  • extracting information based on investigation work
  • analyzing information linked to location and service providers
  • analyzing information linked to domain service and registration information
  • malware reputation analysis
  • portal sites for domains, IPs, and more

Analysis results

  • IP
  • domain
  • country
  • second-level domain
  • IP class
  • domain owner
  • malware hash
  • malware detection name
  • malware strings
  • open port
  • Received
  • Mail From
  • Mail To
  • URLs in Body
  • C&C information
  • signature
Software and algorithms
  • analysis platforms such as (Customized)Cuckoo, Norman, and Joe Sandbox

Tools

  • String
  • YARA
  • Static Analyzer
  • API Analyzer
  • Process Analyzer
  • tcpdump
  • Volatility
  • M2Crypto
  • Suricata
  • Snort
  • hosts
  • Pre-filter
  • FakeNet-NG
  • INetSim
  • HIEH

Filter

  • Host
  • IP
  • DNS address
  • HTTP URL
  • mail address
  • copyright
  • author
  • account
  • MAC
  • timestamp
  • signature
  • GeoIP

OSINT

  • IP2Location
  • MaxMind
  • GeoBytes
  • NetAcuity
  • Akamai
  • Quova
  • WHOIS
  • C-Class
  • ISP
  • VirusTotal
  • DomainTools
  • Bing
  • Google

Intelligence

  • VirusTotal
  • C-TAS
  • CTI
  • Mandiant Threat Intelligence
Structure of the stage-by-stage malware analysis architecture based on cyber investigation

Conclusion

Most cybercrime today is carried out with malware, but existing methods are limited in their ability to rapidly analyze increasingly sophisticated malware and track its distributors.

We therefore researched a next-generation analysis platform architecture capable of linked analysis through threat intelligence and OSINT, in order to track the distributors of sophisticated malware.

However, because the scope of the research and analysis was vast and experiments through implementation were limited, we limited the work to a theoretical study.

In the future, we plan to address the shortcomings by building an actual system and to validate its value as a next-generation cyber investigation platform.

References

CONTACT ZIPIDA

For your next idea, let’s kindle the fire of technology together.

Location
3F #301, Donghee Bldg., 16 Nonhyeon-ro 157-gil Gangnam-gu, Seoul 06032, Republic of Korea
Talk to us about a project