Protocol Parser Development to Inspect Malware Command and Control Traffic by Kevin McMahon

Опубликовано: 06 Октябрь 2024
на канале: Zeek
808
11

Originally recorded September 13, 2017

This presentation describes work that MITRE is performing to dissect malware command-and-control (C2) network protocols, which is currently a blind-spot for many cybersecurity defenders, using the Bro Network Security Monitor parser-generator framework. Many cybersecurity teams across industry, academia, and the U.S. Government are involved in the development of parsers for this type of network traffic. Currently, this type of work is implemented with hand-crafted programs/scripts written in general-purpose high-level languages, which are generally not extensible or re-useable. This research seeks to show that the publicly available Spicy/BinPAC framework for generating protocol parsers can be used to more effectively develop parsers for malware C2 protocols for use in Bro, Wireshark, and other cybersecurity applications. It is expected that using this tool will: (1) significantly reduce the time to develop these parsers; (2) provide greater scalability for processing this type of network traffic from large volumes of data; (3) provide greater flexibility in updating parsers as new information is acquired about particular protocols or as they evolve; and (4) allow for greater sharing of these parsers across the communities of interest.

Kevin McMahon is a cybersecurity engineer at the MITRE Corporation. He has been using Bro for network traffic analysis for the last four years.

Slides: https://www.bro.org/brocon2017/slides...