Papers

shellcode emulation

Advanced Computer Networks Polymorphic Shellcode (Detection)

Analyzing Network Traffic To Detect Self-Decrypting Exploit Code

http://discovery.csc.ncsu.edu/pubs/ASIACCS07a.pdf

Permission to make digital or hard copies of all or part of this work for
personal or classroom use is granted without fee provided that copies are
not made or distributed for profit or commercial advantage and that copies
bear this notice and the full citation on the first page. To copy otherwise, to    
republish, to post on servers or to redistribute to lists, requires prior specific 
permission and/or a fee.
                                                                                  
ASIACCS’07, March 20-22, 2007, Singapore.
                                                                                  
Copyright 2007 ACM 1-59593-574-6/07/0003 ...$5.00

by Qinghua Zhang, Douglas S. Reeves, Peng Ning, S. Purushothaman Iyer

Defending against Polymorphic Attacks: Recent Results and Open Questions

Detecting Network-based Obfuscated Code Injection Attacks Using Sandboxing

Hybrid Engine for Polymorphic Shellcode Detection

Network-Level Polymorphic Shellcode Detection Using Emulation

papers_and_news:network_level_polymorphic_shellcode_detection_terena_2006_polychronakis.pdf
by Michalis Polychronakis , Kostas G. Anagnostakis , and Evangelos P. Markatos

generic

Operation Cyberslam

They re just a bunch of script kiddies

Life, Love, and War in the Underground
Rob Thomas 5 November 2003
http://www.cert.pl/PDF/secure2003/thomas1.pdf

The Case for Beneficial Computer Viruses and Worms

Understanding shellcodes

Analyzing Worms using Compression

Analyzing Worms and Network Traffic using Compression

From: Stephanie Wehner
http://arxiv.org/abs/cs.CR/0504045

Entropy Based Worm and Anomaly Detection in Fast IP Networks

New Fields of Applications for honeynets

Bagle

Reverse Code Engineering: An In-Depth Analysis of the Bagle Virus

Dabber

LURHQ Dabber Worm Analysis

Mydoom & Doomjuice

Attack Analysis: Observation of the Novarg/MyDoom Worm

MyDoom.B Worm Analysis

MyDoom.C Analysis (Doomjuice)

A Brief Analysis of Bofra/MyDoom.AG/AH

Netsky

NETSKY.D MUSICAL PAYLOAD: SOUNDS FROM OUTER SPACE

Sasser

LURHQ Sasser Worm Analysis

Sobig

Who wrote Sobig

SQL Slammer

The spread of the Sapphire/Slammer Worm

Poxdar

This Worm is mainly unknown, no real analysis yet, but as we receive that many samples from doxpar, here are some links to av vendors ‘analysis’ reports.
If you want a sample to write a better analysis, contact us.
The sample has the md5sum 17028f1eda9d3a3f7423f47bd2f525f6 , current nepenthes is able to catch the virus in no time.

AV Vendors

Witty Worm

Outwitting the Witty Worm

Exploiting Underlying Structure for Detailed Reconstruction of an Internet Scale Event
http://www.cc.gatech.edu/~akumar/witty.html
http://www.cc.gatech.edu/~akumar/witty-draft.pdf



The Spread of the Witty Worm

News

heise.de

theregister.com

 
papers_and_news.txt · Last modified: 2007/04/01 14:39
 
Recent changes RSS feed Creative Commons License Donate Powered by PHP Valid XHTML 1.0 Valid CSS Driven by DokuWiki