Detecting Threats, Not Sandboxes
Blake Anderson (blake.anderson@cisco.com), David McGrew (mcgrew@cisco.com) FloCon 2017 January, 2017
(C (Characterizin ing Ne Network Environments to
- Im
Improve Mal alware Clas lassification)
Detecting Threats, Not Sandboxes (C (Characterizin ing Ne Network - - PowerPoint PPT Presentation
Detecting Threats, Not Sandboxes (C (Characterizin ing Ne Network Environments to o Im Improve Mal alware Clas lassification) Blake Anderson (blake.anderson@cisco.com), David McGrew (mcgrew@cisco.com) FloCon 2017 January, 2017 Data
Blake Anderson (blake.anderson@cisco.com), David McGrew (mcgrew@cisco.com) FloCon 2017 January, 2017
(C (Characterizin ing Ne Network Environments to
Improve Mal alware Clas lassification)
Training/Storage
Benign Records Malware Records
Classifier/Rules
...
Malware Sandbox
...
Malware Sandbox
Classifier/Rules
...
Enterprise A
...
Enterprise N
…
environments
always possible
different
Client Server
ClientHello ServerHello / Certificate ClientKeyExchange / ChangeCipherSpec Application Data ChangeCipherSpec
Record Headers
ClientHello
Random Nonce [Session ID] Cipher suites Compression Methods Extensions
Indicative of TLS Client 0.9.8 1.0.0 1.0.1 1.0.2
OpenSSL Versions
TLS clients)
different environments
artifacts