Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software (Paperback)
暫譯: 實用惡意軟體分析:解剖惡意軟體的實作指南 (平裝本)

Michael Sikorski, Andrew Honig

買這商品的人也買了...

相關主題

商品描述

Malware analysis is big business, and attacks can cost a company dearly. When malware breaches your defenses, you need to act quickly to cure current infections and prevent future ones from occurring.

For those who want to stay ahead of the latest malware, Practical Malware Analysis will teach you the tools and techniques used by professional analysts. With this book as your guide, you'll be able to safely analyze, debug, and disassemble any malicious software that comes your way.

You'll learn how to:

  • Set up a safe virtual environment to analyze malware
  • Quickly extract network signatures and host-based indicators
  • Use key analysis tools like IDA Pro, OllyDbg, and WinDbg
  • Overcome malware tricks like obfuscation, anti-disassembly, anti-debugging, and anti-virtual machine techniques
  • Use your newfound knowledge of Windows internals for malware analysis
  • Develop a methodology for unpacking malware and get practical experience with five of the most popular packers
  • Analyze special cases of malware with shellcode, C++, and 64-bit code

Hands-on labs throughout the book challenge you to practice and synthesize your skills as you dissect real malware samples, and pages of detailed dissections offer an over-the-shoulder look at how the pros do it. You'll learn how to crack open malware to see how it really works, determine what damage it has done, thoroughly clean your network, and ensure that the malware never comes back.

Malware analysis is a cat-and-mouse game with rules that are constantly changing, so make sure you have the fundamentals. Whether you're tasked with securing one network or a thousand networks, or you're making a living as a malware analyst, you'll find what you need to succeed in Practical Malware Analysis.

商品描述(中文翻譯)

惡意軟體分析是一個龐大的行業,攻擊可能會讓公司付出高昂的代價。當惡意軟體突破你的防禦時,你需要迅速行動,以治療當前的感染並防止未來的發生。

對於那些想要領先於最新惡意軟體的人來說,《實用惡意軟體分析》將教你專業分析師使用的工具和技術。以這本書作為指導,你將能夠安全地分析、除錯和反組譯任何出現的惡意軟體。

你將學會如何:

- 設置安全的虛擬環境來分析惡意軟體
- 快速提取網路簽名和基於主機的指標
- 使用關鍵分析工具,如 IDA Pro、OllyDbg 和 WinDbg
- 克服惡意軟體的各種技巧,如混淆、反反組譯、反除錯和反虛擬機技術
- 利用你新獲得的 Windows 內部知識進行惡意軟體分析
- 開發解包惡意軟體的方法論,並獲得五種最受歡迎的打包工具的實踐經驗
- 分析特殊情況的惡意軟體,包括 shellcode、C++ 和 64 位代碼

書中的實作實驗室挑戰你在解剖真實惡意軟體樣本時練習和綜合你的技能,詳細的解剖頁面提供了專業人士如何操作的直觀視角。你將學會如何破解惡意軟體以了解其實際運作方式,確定其造成的損害,徹底清理你的網路,並確保惡意軟體不會再回來。

惡意軟體分析是一場貓捉老鼠的遊戲,規則不斷變化,因此確保你掌握基本知識。無論你是負責保護一個網路還是一千個網路,或是以惡意軟體分析師為生,你都會在《實用惡意軟體分析》中找到成功所需的資源。