Nullcon Goa 2023 | The Convergence Of EBPF, Buildroot, And QEMU For Automated Linux Malware Analysis

23:16 · 23 Sep 2023 – 24 Sep 2023 · YouTube

About this talk

In this talk, Nikhil Hegde discusses the increasing prevalence of malware targeting Linux-based systems, including major threats like DDoS botnets and ransomware. He explores how open-source technologies can aid in the analysis of Linux malware such as Mirai and AvosLocker. The session delves into the principles of the extended Berkeley Packet Filter (eBPF) for tracing and observability in behavioral analysis, as well as the use of Buildroot and QEMU for creating effective Linux sandboxes. Additionally, Hegde presents the ELFEN sandbox, developed as an automated analysis system, and demonstrates its capabilities in analyzing popular Linux malware families.

From event

Nullcon Goa 2023

23 Sep 2023 – 24 Sep 2023

All event videos
Back to Watch