Principal Investigator: James Goldman
To date, malware and analysis and reverse engineering has been largely performed in an ad hoc manner leading to difficulties in repeatability and process optimization. A standardized analysis methodology and associated tool kit has been created in order to allow malware analysis to be performed more quickly and efficiently. The architecture runs over a Vmware environment and is a turn key operation, being delivered on 2 CDs. Tutotials have been developed. MARQUES is currently being field tested by law enforcement. Elements of the overall architecture that have been developed at this point include: honeypot, automated analsysis, storage of results in intelligence database, malicious executable and pdf analysis, innoculation development environment.
Students: Cory Nguyen Anthony Smith
Keywords: malicious documents, Malware