Angad: A Malware Detection Framework using Multi-Dimensional Visualization

By Ankur Tyagi on 06 Sep 2018 @ Grrcon
πŸ“Š Presentation πŸ“„ Whitepaper πŸ’» Source Code πŸ“Ή Video πŸ”— Link
#blueteam #security-assessment #forensics
Focus Areas: πŸ›‘οΈ Security Operations & Defense , 🚨 Incident Response , 🎯 Penetration Testing , πŸ” Vulnerability Management
This talk covers following tools where the speaker has contributed or authored
ANGAD

Presentation Material

Abstract

Angad is a framework to automate classification of an unlabelled malware dataset using multi-dimensional modelling. The input dataset is analyzed to collect various attributes which are then arranged in a number of feature vectors. These vectors are then individually visualized, indexed and then queried for each new input file. Matching vectors are labelled as per their AV detection categories for now but this could be changed to a heuristics approach if needed. If dynamic behavior or network traffic details are available, vectors are also converted into activity graphs that depict evolution of activity with a predefined time scale. This results into an animation of malware/malware category’s behavior traits and is also useful in identifying activity overlaps across the input dataset.