RUVIDEO
Поделитесь видео 🙏

SHAREM shellcode analysis framework with emulation, a disassembler, and timeless debugging VERONA L

Presented at the VB2022 conference in Prague, 28 - 30 September, 2022.
↓ Slides: https://www.virusbulletin.com/uploads/pdf/conference/vb2022/slides/VB2022-SHAREM-shellcode-analysis-framework-with-emulation-disassembler-and-timeless-debugging.pdf
↓ Paper: https://www.virusbulletin.com/uploads/pdf/conference/vb2022/papers/VB2022-SHAREM-shellcode-analysis-framework-with-emulation-disassembler-and-timeless-debugging.pdf
→ Details: https://www.virusbulletin.com/conference/vb2022/abstracts/sharem-shellcode-analysis-framework-emulation-disassember-and-timeless-debugging/

✪ PRESENTED BY ✪

• Bramwell Brizendine (University of Alabama in Huntsville)
• Sascha Walker (VERONA Lab)
• Shelby VandenHoek (VERONA Lab)

✪ ABSTRACT ✪

SHAREM is a new shellcode analysis framework, funded by an NSA grant. SHAREM provides many capabilities to malware analysts, as the framework possesses a powerful emulator, a dedicated shellcode disassembler, timeless debugging, and abilities to deobfuscate shellcode through brute-force deobfuscation or via emulation.

SHAREM not only provides support for 16,000 WinAPI functions to be emulated and logged, but it is also the first project to support emulation of Windows syscalls, and 98% of all user-mode syscalls are supported, identifying the syscall and its parameters. In testing, we have emulated and logged over 300 APIs in a single large, complex shellcode.

Existing disassemblers are relatively poor at providing accurate disassembly of modern Windows shellcode. SHAREM’s dedicated disassembler uses static analysis to create disassembly of shellcode that is significantly more accurate. Additionally, SHAREM can use emulation to enhance the disassembly, and it also implements a complete code coverage algorithm, ensuring every instruction in the shellcode is executed. In so doing, we can enumerate all WinAPIs and their parameters, even those that would not normally be reached, and the disassembly obtained can be nearly flawless.

With SHAREM, a heavily encoded shellcode can be deobfuscated via emulation, and the disassembler will display not the encoded shellcode, but instead the decoded shellcode, with all WinAPI calls labelled, with vivid colours. Users can toggle between decoded and encoded shellcode. API tables are also discovered and identified in the disassembly, and many unique instructions associated with shellcode are identified. For users who prefer minimalist interactions, the config file may be set with numerous customizable options, generating a detailed text report and JSON output. While SHAREM may be used by individual malware analysts, it can also be deployed as part of a web service, allowing shellcode to be analysed comprehensively with results displayed online.

Что делает видео по-настоящему запоминающимся? Наверное, та самая атмосфера, которая заставляет забыть о времени. Когда вы заходите на RUVIDEO, чтобы посмотреть онлайн «SHAREM shellcode analysis framework with emulation, a disassembler, and timeless debugging VERONA L», вы рассчитываете на нечто большее, чем просто загрузку плеера. И мы это понимаем. Контент такого уровня заслуживает того, чтобы его смотрели в HD 1080, без дрожания картинки и бесконечного буферизации.

Честно говоря, Rutube сегодня — это кладезь уникальных находок, которые часто теряются в общем шуме. Мы же вытаскиваем на поверхность самое интересное. Будь то динамичный экшн, глубокий разбор темы от любимого автора или просто уютное видео для настроения — всё это доступно здесь бесплатно и без лишних формальностей. Никаких «заполните анкету, чтобы продолжить». Только вы, ваш экран и качественный поток.

Если вас зацепило это видео, не забудьте взглянуть на похожие материалы в блоке справа. Мы откалибровали наши алгоритмы так, чтобы они подбирали контент не просто «по тегам», а по настроению и смыслу. Ведь в конечном итоге, онлайн-кинотеатр — это не склад файлов, а место, где каждый вечер можно найти свою историю. Приятного вам отдыха на RUVIDEO!

Видео взято из открытых источников Rutube. Если вы правообладатель, обратитесь к первоисточнику.