Nullcon Goa 2023 | The Convergence Of EBPF, Buildroot, And QEMU For Automated Linux Malware Analysis
About this talk
In this talk, Nikhil Hegde discusses the increasing prevalence of malware targeting Linux-based systems, including major threats like DDoS botnets and ransomware. He explores how open-source technologies can aid in the analysis of Linux malware such as Mirai and AvosLocker. The session delves into the principles of the extended Berkeley Packet Filter (eBPF) for tracing and observability in behavioral analysis, as well as the use of Buildroot and QEMU for creating effective Linux sandboxes. Additionally, Hegde presents the ELFEN sandbox, developed as an automated analysis system, and demonstrates its capabilities in analyzing popular Linux malware families.
More from this event
See all 25 talks →
Nullcon Goa 2023 | Aftermovie
2:10
Nullcon Goa 2023 | Keynote: Multiplying Threat Intelligence by John Lambert
33:51
Nullcon Goa 2023 | Smashing The State Machine: The True Potential Of Web Race Conditions by James
43:52
Nullcon Goa 2023 | How I Hacked Your Bank Account: A Detailed Look At UPI Security by Nemo
21:08