Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 25 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Featuresarrow Book Reviewsarrow Book Review: Virus Research & Defense
Ethical Hacker Community Forums
December 02, 2008, 12:10:08 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Book Review: Virus Research & Defense  (Read 7621 times)
0 Members and 1 Guest are viewing this topic.
oleDB
Full Member
***
Offline Offline

Posts: 231



View Profile WWW
« on: April 16, 2008, 11:53:07 AM »

I recently finished reading The Art of Computer Virus Research and Defense and believe me that was no small task. Its easily one of the more technical books you will read. Thats a tribute to the author, Peter Szor, who in my opinion is one of the founding fathers of malware analysis. His knowledge on this subject is immense. To get the most out of the book though, you would be advised to have at least a basic understanding of C++ code, IA32 Assembly, and Windows API's. It would be even better if you had some debugging and malware profiling experience. The books aim is to provide a thorough understanding of viruses by type, infection strategy and payload strategy, while explaining antivirus techniques and mitigation options.

    Before I delve into the content too much, I would like to touch on some of the shortfalls of the book. First off, its not written in a traditional manner that could be easily used as a reference. It very much reads like a wiki or personal notes, which it is in effect, however that doesn't make for easy reading. I also felt the first 3 chapters took up way too much space, which could have been used for more productive topics. I particularly hated Chapter 3, where every virus type and dependecy is simply listed out in no cohesive manner. My only other complaint would have to have been to limit the discussion of older, non-relevant viruses to a concept only and focus more on a deeper undertanding of more current threats. I would like to have seen several in depth case studies in the appendix(CodeRed, Sasser, Blaster, Bagel, Slammer, etc). I also wish it came in hard cover, because my paperback binding is already in shambles from frequent page turning and rereading Smile

    On to the good stuff. Chapter 4's discussion of Win32 viruses and coverage of the PE format was great. It helped me understand things quite a bit better, and had lots of code and memory visuals to look at. Its probaby the best section in the first half of the book. His coverage of in-memory strategies was also excellent and shows how malware can be read from memory after being injected in a process thread. I always wondered how heavily encrypted viruses were broken and now I know. They simply step through the code with a debugger until its decrypted in memory and then they dump it. That lead to another great section on malware defense techniques. Sophisticated malware will actually put in timers into the code so that it will know if someone is running it through a debugger line by line. The book also touches on poly and metamorphic shellcode and the type of heuristics that can be used to detect them. There is also a dedicated chapter to worms that is okay, and a really great chapter on exploits, vulnerabilities, and buffer overflows that is filled with all kinds of knowledge. The book also made me aware of a type of buffer overflow I hadn't known before. The "return-to-LIBC attack", where an overflow of the stack is done, but merely to pass malicious option to legitimate API calls, which is really hard to detect because there is no stack or heap execution. The second half of the book, Chapters 11-15, were just awesome. There were many strategies listed for dealing with worms via network controls. I particularly enjoyed Chapter 15, where he covered malicous code analysis using a defined methodology and mostly freely available tools. I also liked his advice on creating a sandbox with a honeyd and dns server to virtualize network interaction. There is also much more coverage of heuristic functions, which can aid in profiling malware, as well as a great section on memory scanning and disinfection. It exposed to me alot of the built in API commands that you can used to identify and remove viruses from memory.

    There are almost too many great things to mention in the second half of the book, as mine is heavily highlighted, so you will definitely need to read for yourself. I think this book, even being 3 years old now, still fills a niche in the market that no other book does. If you deal with malware on a weekly basis, I would recommend you adding it to your library.
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #1 on: April 16, 2008, 02:10:20 PM »

good review
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #2 on: April 16, 2008, 02:50:37 PM »

Great addition to the forums.

Thanks,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
Kev
Sr. Member
****
Offline Offline

Posts: 348


View Profile
« Reply #3 on: April 16, 2008, 07:14:09 PM »

Nice!
Logged
RoleReversal
Sr. Member
****
Offline Offline

Posts: 469


View Profile WWW
« Reply #4 on: April 17, 2008, 03:33:05 AM »

Thanks oleDB,

another book to add to my wish-list.
Logged

A little bit of sanity:
http://www.infosanity.co.uk
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.046 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.