Ir al contenido (pulsa Retorno)

Universitat Politècnica de Catalunya

    • Català
    • Castellano
    • English
    • LoginRegisterLog in (no UPC users)
  • mailContact Us
  • world English 
    • Català
    • Castellano
    • English
  • userLogin   
      LoginRegisterLog in (no UPC users)

UPCommons. Global access to UPC knowledge

Banner header
64.109 UPC academic works
You are here:
View Item 
  •   DSpace Home
  • Treballs acadèmics
  • Màsters oficials
  • Màster universitari en Ciberseguretat (Pla 2020)
  • View Item
  •   DSpace Home
  • Treballs acadèmics
  • Màsters oficials
  • Màster universitari en Ciberseguretat (Pla 2020)
  • View Item
JavaScript is disabled for your browser. Some features of this site may not work without it.

Understanding malware behaviour through traffic analysis

Thumbnail
View/Open
TFM MARTA GALINDO.pdf (3,012Mb)
Share:
 
  View Usage Statistics
Cita com:
hdl:2117/367984

Show full item record
Galindo Quintana, Marta
Tutor / directorBarlet Ros, PereMés informacióMés informacióMés informació; Pedersen, Jens Myrup
CovenanteeAalborg universitet
Document typeMaster thesis
Date2022-02-02
Rights accessOpen Access
All rights reserved. This work is protected by the corresponding intellectual and industrial property rights. Without prejudice to any existing legal exemptions, reproduction, distribution, public communication or transformation of this work are prohibited without permission of the copyright holder
Abstract
This project was developed as the final Thesis for the Master's degree in Cybersecurity at Universitat Politècnica de Catalunya (and in collaboration with Aalborg University Copenhagen). The task for the project was to perform an analysis on the banking trojan TrickBot and understand its traffic behaviour. In order to achieve this, an adequate closed sandbox environment had to be designed and implemented. As such, a system was made consisting of Cuckoo Sandbox and VirtualBox, where multiple TrickBot binaries were submitted and analyzed dynamically. Not enough samples behaved as it was expected from them, so another environment was deployed in order to simulate the attack of a banking trojan. With this second system, the task of understanding the credential stealing process was accomplished, and the project was therefore successful as it would serve as a guide to future malware analyses.
 
Este proyecto fue desarrollado como Trabajo Final del Máster de Ciberseguridad de la Universitat Politècnica de Catalunya (y en colaboración con Aalborg University Copenhagen). El objetivo del proyecto era realizar un análisis sobre el troyano bancario TrickBot y entender el comportamiento de su tráfico. Para conseguir esto, un entorno de pruebas adecuado debía ser diseñado e implementado. Por ello, se creó un sistema formado por Cuckoo Sandbox y VirtualBox, en el que múltiples muestras de TrickBot fueron analizadas de forma dinámica. No hubo suficientes muestras que se comportasen como se esperaba, por lo que se creó otro entorno en el que desarrollar una simulación de un ataque por parte de un troyano bancario. Con este segundo sistema, se cumplió el objetivo de comprender el proceso de robo de credenciales, y el proyecto fue, por tanto, un éxito, ya que podrá servir de guía para futuros análisis de malware.
SubjectsComputer viruses, Malware (Computer software), Virus informàtics
DegreeMÀSTER UNIVERSITARI EN CIBERSEGURETAT (Pla 2020)
URIhttp://hdl.handle.net/2117/367984
Collections
  • Màsters oficials - Màster universitari en Ciberseguretat (Pla 2020) [37]
Share:
 
  View Usage Statistics

Show full item record

FilesDescriptionSizeFormatView
TFM MARTA GALINDO.pdf3,012MbPDFView/Open

Browse

This CollectionBy Issue DateAuthorsOther contributionsTitlesSubjectsThis repositoryCommunities & CollectionsBy Issue DateAuthorsOther contributionsTitlesSubjects

© UPC Obrir en finestra nova . Servei de Biblioteques, Publicacions i Arxius

info.biblioteques@upc.edu

  • About This Repository
  • Contact Us
  • Send Feedback
  • Privacy Settings
  • Inici de la pàgina