Cybersecurity: Malware Analysis

Unit Outline (Higher Education)

   
?   Display Outline Guidelines      


Effective Term: 2024/20
Institute / School :Institute of Innovation, Science & Sustainability
Unit Title: Cybersecurity: Malware Analysis
Unit ID: HENAG1101
Credit Points: 15.00
Prerequisite(s): Nil
Co-requisite(s): Nil
Exclusion(s): Nil
ASCED: 029901
Other Change:  
Brief description of the Unit

This project aims to prepare Engineering students and other aspiring cybersecurity professionals on malware analysis and detection. Working within the environment of a cybersecurity department, the teams will perform static and dynamic analysis of an identified malware and will gain an understanding of the process for the reverse engineering of malware.

Experience of these processes will help learners gain skills in the most critical challenge faced by organisations in the fast-evolving digital era. The team will produce reports on their work and make their colleagues aware of potential vulnerabilities.

Grade Scheme: Ungraded (S, UN)
Work Experience Indicator:
No work experience
Placement Component:
Supplementary Assessment:No
Supplementary assessment is not available to students who gain a fail in this Unit.
Course Level:
Level of Unit in CourseAQF Level(s) of Course
5678910
Introductory                                        
Intermediate                                                
Advanced                                                
Learning Outcomes:
Knowledge:
K1.

Understand the reason for system malfunction

K2.

Understand impacts of Malware

K3.

Understand how to analyse the network behaviour of unknown malwares

K4.

Understand how to set up a baseline analysis environment and determine a starting point for triaging

Skills:
S1.

Use hash value to research the details of malware

S2.

Use tools to explore DLLs and functions imported by malware

S3.

Use utilities to help manage, troubleshoot and diagnose Windows systems and applications

S4.

Work effectively in a team

Application of knowledge and skills:
A1.

Perform static analysis of malware

A2.

Perform dynamic analysis of malware

A3.

Simulate Malware to identify the impact on network

A4.

Create a response plan to detect and protect - plan and execute reverse engineering

Other outcomes:
Unit Content:

•Sprint 1 (2 Weeks) Gain a complete understanding of the problem scenario. Complete installation of requisite tools/software needed for static and dynamic analysis. Prepare the required lab environment needed for analysis and debugging.
•Sprint 2 (2 Weeks) Define a project plan, standard operating procedures and reporting templates to document all findings, roles and responsibilities and recommendations.
•Sprint 3 (2 Weeks) Confirm details affecting system changes on endpoints. Understand how processes executed by machine effect system behavioural change.
•Sprint 4 (2 Weeks) Identify existing processes running on a system and learn how to sniff the packets through the machine. Implement software suite for simulating common internet services in a lab environment.
•Sprint 5 (2 Weeks) Undertake complete static and dynamic analysis flow for malware by setting up a baseline analysis environment and triaging to determine a starting point. Perform static analysis to get a sense of where everything is before debugging. Perform dynamic analysis to determine behaviours that cannot be understood by static analysis.
•Sprint 6 (2 Weeks) Perform manual debugging by stepping through the program to navigate until the malware is identified. Perform reverse engineering to find hard-coded passwords and create a response plan.

Graduate Attributes:
 Learning Outcomes AssessedAssessment TasksAssessment TypeWeightingProfessional Standards
1.

K1-2 S1-2, S4 A1

Documenting findings about the type of malware file, compiler used, the encrypting tool, the packer and protector used. Documenting findings about when the executable was compiled, the timeframe of attack and corresponding deductions.

Team report and presentation

N/A

2.

K1-2 S1-2, S4 A1

Documenting findings about information gathered on malicious DLLs, processes using those DLLs (if any), determining whether DLL is loaded into a process after load time, comparison of DLL list in Process Explorer vs imports shown in Dependency Walker.

Team report and presentation

N/A

3.

K2-4 S2-4 A2

Documenting findings about impact on system and process

Team report and presentation

N/A

4.

K2-4 S2-4 A2

Documenting findings on performance impact Documenting findings on network impact

Team report and presentation

N/A

5.

K3-4 S2-4 A1-4

Documenting the steps followed and observations during: 1. Completing the process of static analysis 2. Completing the process of dynamic analysis

Team report and presentation

N/A

6.

K3-4 S2-4 A1-4

Documenting the steps followed and observations during: 1. Completing the process of anti-debugging 2. Documenting the recommendations to protect the system from malware

Team report and presentation

N/A

Adopted Reference Style:
APA  ()

Professional Standards / Competencies:
 Standard / Competency