SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsIt is known that HYDAN changes the statistical distribution of Sub and Add calls in the assembly code to embed the 'hidden data'. Before this paper, there were no publicly released tools or methods available to detect HYDAN. The methods previously used to detect HYDAN have been inefficient and involved extensive manual processes that could not be easily automated. This paper presents a method to take the assembly code (using a disassembler) and to feed this into a statistical language, in order to detect if the file has been altered steganographically.