VB2016 paper: Debugging and monitoring malware network activities with Haka

Posted by   Martijn Grooten on   Apr 24, 2017

Anyone who has ever analysed malware through its network communications will knows that this often involves ad-hoc scripts in languages like Python or Perl to decode the traffic. After all, for somewhat understandable reasons, there is no standard C&C protocol for malware.

If you regularly find yourself in this situation, you may want to have a look at Haka, an open-source language for monitoring, debugging and controlling malicious network traffic. At VB2016 in Denver, Stormshield researchers Benoît Ancel and Mehdi Talbi, who wrote Haka, presented the paper 'Debugging and Monitoring Malware Network Activities with Haka', in which they introduced Haka and explained how it can be used.

Ancel-Talbi1.jpg

We have now published the paper in both HTML and PDF format. We have also uploaded the video recording of their presentation to our YouTube channel.

For 26 years, the Virus Bulletin Conference has been the place where security researchers share their tools, tricks and ideas to further the fight against online malicious activity. VB2017, which will take place in Madrid, 4-6 October this year, will be no exception – check out the programme and make sure you grab your ticket before 30 June for the early bird discount!

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

WannaCry shows we need to understand why organizations don't patch

Perhaps the question we should be asking about WannaCry is not "why do so many organizations allow unpatched machines to exist on their networks?" but "why doesn't patching work reasonably well most of the time?"

Modern security software is not necessarily powerless against threats like WannaCry

The WannaCry ransomware has affected many organisations around the world, making it probably the worst and most damaging of its kind. But modern security is not necessarily powerless against such threats.

Throwback Thursday: CARO: A personal view

This week sees the 11th International CARO Workshop taking place in Krakow, Poland – a prestigious annual meeting of anti-malware and security experts. As a founding member of CARO, Fridrik Skulason was well placed, in August 1994, to shed some light…

VB2016 paper: Uncovering the secrets of malvertising

Malicious advertising, a.k.a. malvertising, has evolved tremendously over the past few years to take a central place in some of today’s largest web-based attacks. It is by far the tool of choice for attackers to reach the masses but also to target…

Throwback Thursday: Tools of the DDoS Trade

As DDoS attacks become costlier to fix and continue to increase in both number and diversity, we turn back the clock to 2000, when Aleksander Czarnowski took a look at the DDoS tools of the day.