97, 1/4 회원가입  로그인  
   멍멍
   http://www.hackerschool.org
   파트1 분량입니다.

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=79 [복사]


uh..I'm ryan russeil again
또 다시 저 ryan russeil의 발표입니다.

and this time I brought nichlas brulez, am I pronounciating your name correctly?
이번엔 nichlas brulez와 함께 나왔습니다. 이름을 이렇게 발음하는거 맞나요?

ye, ok
맞아요.

and we gonna show you how to do some malicaous code analysis
이번 발표에선 악성코드 분석을 어떻게 하는지 보여드리겠습니다.

uh.. just me  time constraints..
근데 시간이 좀 빡빡하네요

we dont have enough time to present fully today
오늘의 전체 발표 시간이 부족할 것 같습니다.

we actually talking about when you are looking at the a malicious code
악성 코드를 분석할 때의 과정에 대해 설명해 드릴 겁니다.

so, uh.. quick quick poll to help attract talk my a little bit
간단한 설문조사를 하나 하겠습니다.

how many ida pro users in this room?
IDA PRO 사용자이신 분들?

ok
예

uh.. analysis .. ok. thank you
감사합니다.

um.. I'm trying to go through the slides a little bit quickly
조금 빠르게 진행을 하겠습니다.

'someone' gave us permission to go ahead make you guys late for lunch
점심 시간은 좀 늦어져도 괜찮다고 하네요.

no pressure there
그러니 걱정하지 마시구요.

and the at same time I'm gonna trying keep my english speaking speed to a low level
그리고 이번엔 제 말 속도를 늦추도록 노력하겠습니다.

so that the, as nikolas was reminding me
nikolas가 요청한대로요.

um.. there are several major analysis methods you might use when you looking at piece of malicious code
악성코드를 분석할 때 사용할 수 있는 다양한 방법들이 존재합니다.

and our case today, we are focusing on windows
오늘 우리는 윈도우 환경에 집중할 것입니다.

pretty much because if you see malicious code thats where vast majority of your samples are gonna be functioning
샘플에서 채집한 악성코드가 작동하도록 할 때,

so major analysis methods are using sacrificial lamb
보통 가상 환경(제물로 바쳐진 양)을 사용하게 됩니다.

and by that I mean something in particular a box you are willing to infect
즉, 악성코드를 감염시킬 특정 대상이 필요하단 말입니다.

uh often times, vmware, or virtual pc
그것은 vmware 혹은 virtual pc가 될 수 있습니다.

if you work actual real any virus company
만약 여러분이 실제 백신 업체에 다니고 있다면..

they are very very strict about the boxes that they use for research
바이러스 연구를 위한 환경이 매우 엄격할 것입니다.

they are disconnected network in different room
특히 네트워크가 고립된 환경을 사용하게 됩니다.

supposedly some of them are in a, you know, ..., fun stuff
아마 그들중 일부는..

I dont think any of them have poisonous ....
분명 누군가는 이미 감염이 되었을 겁니다.

nice thing about sacrificial lamb, is that could be a big time saver
가상 환경을 이용하면 분석 시간을 크게 줄일 수 있습니다.

later on we'll talk about things like unpackers, and ways to find out where malicous code talks to network
다음으로 우리는 unpacker 같은 것들이나 악성코드가 네트워크 통신하는 부분을 찾는 방법에 대해 설명할 겁니다.

if you have a box that you are willing to infect .. ... that could sometimes give you very quick answer
만약 감염시킬 가상 PC가 있다면, 답은 명확할 겁니다.

it's like well maybe i'm not gonna .. figuring how file dumper works,
파일 덤퍼가 어떻게 작동하는지는 설명하지 않겠습니다.

i'm just gonna infect the virus, and grab the files off the disk when it's done
바이러스를 감염시키고, 그게 끝나면 파일들을 디스크에서 grab off할 것입니다.

i don't necessarily wanna disassemble the network ..,
네트워크 통신하는 부분을 disasseble하지는 않을 겁니다

i'm just gonna sniff it out after I infect the box and let it talk on the network
단지 감염 후에 통신하는 내용을 패킷 스니핑 할 겁니다.

you are gonna see myself and nikolas do little bit of risky behaviors in terms of how we are analyzing this stuff,
여러분은 저와 nikolas이 분석을 하면서 약간 위험한 행동을 하는 것들을 보게 될 겁니다.

this is my don't try this at work warning
****

because there are, we are doing a debugging of piece of malicious code,
왜냐하면 악성코드 디버깅을 하는 것이기 때문입니다.

and there is also chance of infection so
그래서 감염될 가능성도 있습니다.

other ways, determining what piece of malicious code does began
반면, 악성코드의 어떤 부분이 실행될지를 결정합니다.

this is when you are running on the box you don't necessarily care about,
이걸 가상 pc에서 실행하면 그런 걱정을 할 필요가 없습니다.

you could restore back to original state if you running it on sacrificial lamb
단지 이전 설정으로 복원하기만하면 되기 때문입니다.

use might use some tools, filemon, regmon, from this sysinternals suites
몇몇 툴을 쓸 예정입니다. sysinternals에서 만든 filemon, regmon 등입니다.

those are tools that will tell you every registry access every file access that particilar prcocess is doing
이 툴들은 특정 프로세스의 모든 파일 접근 및 레지스트리 접근 정보를 보여주게 됩니다.

same thing with ethereal, monitor network
네트워크 모니터링에 이더리얼을 쓰는 것과 같습니다.

um.. the one we are gonna be actually demonstrating today is disassembly with some light debugging
오늘 우리가 데모로 보여드릴 것은 light debugging을 이용한 디스어셈블리입니다.

oftentimes we are gonna use a debugger, in conjunction with disassembler, in order to get through some of difficult pieces of code
약간 어려운 부분을 분석할 때엔 디버거와 디스어셈블러를 함께 사용할 겁니다.

and .. finally  nikolas reminded me
그리고 마지막으로 nikolas가...

the.. halvar's bindiff uh.. programs commecial tool
halvar가 만든 상용툴인 bindiff도 사용하게 됩니다.

has feature I didn't realize he added in there..
이 설명이 추가됐는지 모르겠네요.

which is .. um.. you can actually, not only it will tell you differences of two binaries
bindiff는 두 바이너리 상의 차이점을 보여줍니다.

for example .A version of worm .B version of worm
예를 들어 웜 바이러스의 A버젼과 B버젼의 차이점을 보여줍니다.

.. which are gonna be slightly different.. then we'll give you a dump of what the differences are beetween the two
이 둘은 약간 다를 겁니다. 그 다음엔 이 둘이 어떻게 다른지 덤프해서 보여드리겠습니다.

but also, it actually let you take all of the imports of .A version all the names the ... manually
그리고 bindiff는 A 버젼의 모든 import와 함수 이름들을 보여줍니다.

automatically port those over to match the functions to .B version
그리고 B 버젼과 자동으로 비교해 줍니다.

which is something I didn't realize that could be a huge time saver if you are following a family of virus worm
만약 여러분이 하나의 웜으로부터 변형된 여러 파일들을 이 방법으로 분석한다면 분석 시간을 크게 줄일 수 있습니다.

so we are gonna focus on disassembly specifically today
우리는 오늘 특히 디스어셈블링에 초점을 맞춰 진행하겠습니다.

reasons for that it gives you most complete picture
왜냐하면 가장 정확한 정보를 얻을 수 있기 때문입니다.

you can go ahead run a piece of malicious code on sacrificial lamb..
악성 코드를 가상 pc에서 실행 할 수 있으며,

and observe its external behavors
그것의 행위를 분석할 수 있습니다.

of course you are not gonna see everything,
물론 모든 것을 완벽하게 분석할 수는 없습니다.

you'll find out some sites.. that it tries to talk to are down or don't exist yet,
예를 들어 악성코드가 어떤 사이트에 접속을 하는데, 다운되었거나 더이상 존재하지 않을 수도 있습니다.

you'll find that they do things different days and months
혹은 날짜에 따라 다른 작동을 하는 악성코드일 수도 있습니다.

programmer would code, did things depending on what day and month it was
악성코드 개발자가 날짜를 체크해서 다른 행동을 하도록 짜놨을 수도 있기 때문입니다.

sometimes it would spread, sometimes it would DoS some site, sometimes it will stay idle
어떤 땐 퍼져 나가기도 하고, 어떤 땐 사이트에 DoS 공격을 하기도하며, 아무것도 하지 않고 대기할 때도 있습니다.



영어신 "종크"님께서 대부분을 도와주셨습니다.

  Hit : 2489     Date : 2011/08/02 11:27