4. Malware Countermeasures Flashcards
1
Q
What are the malware countermeasures
A
-Prevention
- Raise awareness
- Prevent Vulnurabilities
- Define Policies
-Detection
- Host-based
- Network-based
- Honeypots
-Mitigation
- Threat mitigation
- Teardown
-** Malware Analysis**
- Static Analysis
- Dynamic Analysis
2
Q
What are the requirements for effective countermeasures?
A
- General – able to handle a wide variety of attacks
- Timely – respond quickly to limit number of infected programs/systems
- Resilient – resistant to evasion techniques
- Causing minimal denial-of-service cost – minimal reduction in capacity or service, minimal disruption of normal operation
- Transparent – countermeasure software and devices should not require modification to existing legacy operating systems, application software and hardware
- Global and local coverage – deal with attack sources from the outside as well as inside the enterprise network
3
Q
How to detect infections with known malware
A
- Host based
- Scan for known malware signatures
- ** Network based**
- Scan for known traffic patterns or C&C server traffic
4
Q
What types of honeypots exist?
A
Honeypots
- Server or Client-side
- Low or high interaction
- Physical or virtual
5
Q
A