An interesting talk by Nikhil Hegde, covers the below-mentioned topics:
00:00 Speaker and Talk Introduction
01:26 Talk Agenda
01:54 extended Berkeley Packet Filter (eBPF)
12:04 ELFEN Sandbox
14:19 Demo Analysis with ELFEN
22:18 Future Work
Click here to download the slides: https://goa2023.nullcon.net/goa-2023/...
Abstract:
----------
In recent years, malware targeting Linux-based systems has been on the rise. Malware strains range from pervasive DDoS botnets to devastating ransomware. The analysis of such malware has historically been a pain point. Much is attributed to the fact that they target diverse architectures, thereby increasing the costs of developing and maintaining comprehensive automated analysis systems. This talk will go over open-source technologies that can be leveraged to conduct an in-depth analysis of Linux-based malware such as Mirai, AvosLocker, and more. We will cover the principles of the extended Berkeley Packet Filter (eBPF) and how it enables tracing and observability, specifically in the context of behavioral analysis. We will look at leveraging Buildroot to develop effective Linux sandboxes for various architectures and QEMU for emulating them. Lastly, we will look at the ELFEN sandbox which was developed as an automated analysis system, and showcase the analysis of popular Linux malware families.
#linuxmalware #ebpf #buildroot #Mirai #AvosLocker #QEMU #ELFENsandbox
--------
Follow Nullcon on Facebook: / nullcon
Twitter: / nullcon
LinkedIn: / posts
Website: https://nullcon.net/