Star 0

Abstract

Thursday 25 September 09:00 - 09:30, Green room.Jonathan Burns Federal Bureau of InvestigationDaniel Raygoza Federal Bureau of Investigation  download slides (PDF) The FBI's Operational Technology Division is responsible for research and reverse engineering of malware. The Division also develops analytic tools, including an automated malware analysis system that is now used by the bureau enterprise wide. This tool is known as the Binary Analysis Characterization and Storage System (BACSS) and it provides the FBI's investigators and net defenders with technical information about malware functionality as well as correlation so that investigators and incident responders can 'connect dots'. BACSS has been highly successful and won the 2012 ODNI Science and Technology award as well as the FBI's highest honour - the Director's Award for Technical Innovation. Based on the success of BACSS, the FBI approved the development of a second unclassified malware analysis system that would be available to other government agencies, law enforcement, researchers and private sector partners. This system, known as Malware Investigator, will be in production by mid-2014. In this presentation we will introduce Malware Investigator, discussing its analytic architecture, how it operates, what kind of information it produces, and how participants can gain access to the free tool. We will also discuss current research intended to enhance Malware Investigator's ability to characterize malware and uncover relationships between samples. The FBI's intent is to raise awareness and share the fruits of our research and development with others in the field, hopefully bringing the community closer together. Click here for more details about the conference.

Slides