YoVDO

File Disinfection Framework - Striking Back at Polymorphic Viruses

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Malware Analysis Courses Static Analysis Courses

Course Description

Overview

Explore an innovative approach to combating polymorphic viruses in this Black Hat USA 2012 conference talk. Delve into the File Disinfection Framework (FDF), an open-source project built on TitanEngine, designed to address the challenges of file disinfection and remediation. Learn about the framework's advanced features, including static analysis functionality, PE32/PE32+ file validation and repair, integrated hash database, and a unique x86 emulator. Discover how FDF combines static analysis and emulation to provide analysts with unprecedented control over the emulated environment. Gain insights into the framework's capabilities for decryption, decompression, and disinfection of complex malware. Understand how FDF tackles issues with PE file formats and offers solutions for reverting function name hashes. Explore the emulator's support for multiple processes, Windows structures, and API integration. Learn about the framework's specific functionality for disinfecting files infected with polymorphic viruses like Virut and Sality. Discover tools designed to aid in writing disinfection routines and automatic binary profiling. Gain exclusive access to the latest developments in this DARPA-supported project, presented for the first time at Black Hat USA 2012.

Syllabus

Black Hat USA 2012 - File Disinfection Framework: Striking Back at Polymorphic Viruses


Taught by

Black Hat

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network