Developing an automated malware detection, analysis and reporting tool for MS-Windows

dc.contributor.authorMutyethau, David Matingi
dc.date.accessioned2020-01-23T15:53:56Z
dc.date.available2020-01-23T15:53:56Z
dc.date.issued2019
dc.descriptionA thesis submitted in partial fulfilment of the requirements for the Degree of Master of Science in Information Systems Security (MSc.ISS) at Strathmore Universityen_US
dc.description.abstractMemory and computer forensics is a field that has witnessed a lot of advancements in the recent past. Memory forensics enables investigators acquire and investigate the content of a computer’s RAM while computer forensics enable the investigator to acquire information from the hard drive. While valuable artifacts can be extracted from computers, the use of this technique presents several challenges, such as, data acquisition, searching for artifacts and data analysis of extracted information. The variants of malware families share typical behavioral patterns reflecting their origin and purpose. The behavioral patterns obtained either statically or dynamically can be exploited to detect and classify unknown malwares into their known families using machine learning techniques. This dissertation aims to create a malware detection, analysis and reporting tool that shall be open source, user friendly, intuitive and automated for MS Windows. The tool shall assist forensic investigators in discovering crucial information in the suspect computer such as malware present. The tool shall analyse content stored in the computer’s hard drive and captured memory images. This shall include analysis of single files, folders, hard disk partitions and the entire hard disk. For live memory, the tool shall aim to determine processes and files that were open or present at time of live analysis.en_US
dc.identifier.urihttp://hdl.handle.net/11071/6782
dc.language.isoenen_US
dc.publisherStrathmore Universityen_US
dc.subjectDigital Forensicsen_US
dc.subjectInformation Securityen_US
dc.subjectData visualisationen_US
dc.subjectInformation analysisen_US
dc.subjectRandom Access Memoryen_US
dc.subjectGraphical User Interfaceen_US
dc.subjectCommand Line Interfaceen_US
dc.subjectMalware analysisen_US
dc.titleDeveloping an automated malware detection, analysis and reporting tool for MS-Windowsen_US
dc.typeThesisen_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Developing an automated malware detection, analysis and reporting tool for MS-Windows.pdf
Size:
3.1 MB
Format:
Adobe Portable Document Format
Description:
Full-text thesis
License bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: