The Catcher in the YARA — predicting black swans
#1
Bug 
Quote:
[Image: cybersecurity-expert-training-featured.png]

Kaspersky introduces an online cybersecurity expert training series that starts with an extensive course on YARA.

It’s been a long, long time since humanity has had a year like this one. I don’t think I’ve ever known a year with such a high concentration of black swans of various types and forms. And I don’t mean the kind with feathers. I’m talking about unexpected events with far-reaching consequences, as per the theory of Nassim Nicholas Taleb, published in 2007 in his book The Black Swan: The Impact of the Highly Improbable. One of the main tenets of the theory is that, with hindsight, surprising events that have already occurred seem obvious and predictable; however, before they occur, no one predicts them.

Example: this ghastly virus that’s had the world in lockdown since March. It turns out there’s a whole extended family of coronaviridae — several dozen of them — and new ones are found regularly. Cats, dogs, birds, and bats all get them. Humans get them. Some cause common colds. Others manifest … differently. So, surely, we need to develop vaccines for them as we have for other deadly viruses such as smallpox, polio, and others. Sure, but having a vaccine doesn’t always help a great deal. Look at the flu — still no vaccine that inoculates folks after how many centuries? And anyway, even to start developing a vaccine you need to know what you’re looking for, and that is apparently more art than science.

So, why am I telling you this? What’s the connection to … well, it’s inevitably gonna be either cybersecurity or exotic travel, right?! Today, it’s the former.

Now, one of the most dangerous cyberthreats in existence is zero-days — rare, unknown (to cybersecurity folks et al.) vulnerabilities in software that can do oh-my-grotesque large-scale awfulness and damage — but they tend to remain undiscovered up until (or sometimes after) the moment they’re exploited.

However, cybersecurity experts have ways of dealing with ambiguity and predicting black swans. In this post I want to talk about one such means: YARA.

Briefly, YARA aids malware research and detection by identifying files that meet certain conditions and providing a rules-based approach to creating descriptions of malware families based on textual or binary patterns. (Ooh, that sounds complicated. Read on for clarification.) Thus, it’s used to search for similar malware by identifying patterns. The aim is to be able to say that certain malicious programs look like they were made by the same folks, with similar objectives.

OK, let’s turn to another metaphor — like a black swan, another water-based one: the sea.

Let’s say your network is the ocean, which is full of thousands of kinds of fish, and you’re an industrial fisherman out on the ocean in your ship casting off huge drift nets to catch the fish — but only certain breeds of fish (malware created by particular hacker groups) are interesting to you. Now, the drift net is special. It has special compartments, and only fish of a particular breed (malware characteristics) get caught in each compartment.

Then, at the end of the shift, what you have is a lot of fish, all compartmentalized, some of which are relatively new, never-before-seen fish (new malware samples) about which you know practically nothing. But if they’re in a certain compartment — say, “Looks like Breed [hacker group] X” or “Looks like Breed [hacker group] Y.”

Here’s a case that illustrates the fish/fishing metaphor. In 2015, our YARA guru and head of GReAT, Costin Raiu, went full-on cyber-Sherlock to find an exploit in Microsoft’s Silverlight software. You really should read that article, but, briefly, what Raiu did was carefully examine certain hacker-leaked e-mail correspondence to assemble a YARA rule from practically nothing, but that went on to help find the exploit and thus protect the world from mega-trouble. (The correspondence was from an Italian firm called Hacking Team — hackers hacking hackers!)

So, about these YARA rules…

We’ve been teaching the art of creating YARA rules for years. The cyberthreats that YARA helps uncover are rather complex, that’s why we always ran the courses in person — offline — and for only a narrow group of top cybersecurity researchers. Of course, since March, offline training has been tricky because of lockdown; however, the need for education has hardly gone away, and indeed we’ve seen no dip in interest in our courses.

That’s only natural: Cyber-baddies continue to think up ever-more-sophisticated attacks — even more so under lockdown. Accordingly, keeping our specialized know-how about YARA to ourselves during lockdown would have been just plain wrong. Therefore, we’ve (1) transferred our training format from offline to online, and (2) made it accessible to everyone. It’s not free, but for such a course at such a level (the very highest), the price is very competitive and market-level.
...
Continue Reading
Reply


Messages In This Thread
The Catcher in the YARA — predicting black swans - by harlan4096 - 01 September 20, 11:57

Forum Jump:


Users browsing this thread: 2 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes 19.1.6
24.12.4 The wel...Kool — 12:56
INTEL Arc Graphics 32.0.101.6325/6253 dr...
Highlights Fix...harlan4096 — 11:06
GFYI [Official] Revo Uninstaller Pro v5...
"Share feedback...damien76 — 09:01
GFYI [Official] SpyShelter PRO v15 Chri...
Merry Christmas and ...damien76 — 08:56
GFYI [Official] IObit Christmas 2024 Bl...
Merry Christmas and ...damien76 — 08:54

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>