Explore advanced techniques for evading anti-Advanced Persistent Threat (APT) technologies in this 16-minute conference talk by Roman Vasilenko at Kaspersky Lab's Security Analyst Summit #TheSAS2015. Delve into traditional sandbox analysis methods and their weaknesses, including API and system calls, timing attacks, and predictable environments. Examine the limitations of limited context and custom images in endpoint security. Investigate the challenges of time constraints in dynamic analysis and gain insights into potential solutions for improving APT detection and prevention.
Overview
Syllabus
Intro
TPT solutions
Traditional sandbox analysis
Sandbox weaknesses
API and system calls
Timing attack
Predictable environment
Limited context
Custom images
Endpoint
Time problem
Dynamic analysis
Conclusion
Taught by
Kaspersky