4. Malware Countermeasures Flashcards

1
Q

What are the malware countermeasures

A

-Prevention
- Raise awareness
- Prevent Vulnurabilities
- Define Policies
-Detection
- Host-based
- Network-based
- Honeypots
-Mitigation
- Threat mitigation
- Teardown
-** Malware Analysis**
- Static Analysis
- Dynamic Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the requirements for effective countermeasures?

A
  • General – able to handle a wide variety of attacks
  • Timely – respond quickly to limit number of infected programs/systems
  • Resilient – resistant to evasion techniques
  • Causing minimal denial-of-service cost – minimal reduction in capacity or service, minimal disruption of normal operation
  • Transparent – countermeasure software and devices should not require modification to existing legacy operating systems, application software and hardware
  • Global and local coverage – deal with attack sources from the outside as well as inside the enterprise network
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How to detect infections with known malware

A
  • Host based
  • Scan for known malware signatures
  • ** Network based**
  • Scan for known traffic patterns or C&C server traffic
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What types of honeypots exist?

A

Honeypots
- Server or Client-side
- Low or high interaction
- Physical or virtual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly