The Convergence of eBPF, Buildroot, and QEMU for Automated Linux Malware Analysis
Offered By: nullcon via YouTube
Course Description
Overview
Explore the convergence of eBPF, Buildroot, and QEMU for automated Linux malware analysis in this informative conference talk. Delve into the rising threat of Linux-based malware and learn about open-source technologies that can be leveraged for in-depth analysis. Discover the principles of extended Berkeley Packet Filter (eBPF) and its role in tracing and observability for behavioral analysis. Examine the use of Buildroot in developing effective Linux sandboxes for various architectures and QEMU for emulation. Gain insights into the ELFEN sandbox, an automated analysis system, and witness demonstrations of popular Linux malware families like Mirai and AvosLocker. Understand the current landscape of Linux malware analysis and explore potential future developments in this critical area of cybersecurity.
Syllabus
Speaker and Talk Introduction
Talk Agenda
extended Berkeley Packet Filter eBPF
ELFEN Sandbox
Demo Analysis with ELFEN
Future Work
Taught by
nullcon
Related Courses
Linux System Programming and Introduction to BuildrootUniversity of Colorado Boulder via Coursera Introduction to Embedded Linux Part 1 - Buildroot - Digi-Key Electronics
Digi-Key via YouTube Linux Embedded System Topics and Projects
University of Colorado Boulder via Coursera MIPS-X - The Next IoT Frontier
Hack In The Box Security Conference via YouTube Advanced Embedded Linux Development
University of Colorado Boulder via Coursera