Reverse Engineering and Automated Defense Strategies for Detecting and Preventing Rat Malware

dc.contributor.authorLinda Bsharat
dc.contributor.authorLara Shahrori
dc.contributor.authorLana Khdair
dc.date.accessioned2025-02-04T06:38:13Z
dc.date.available2025-02-04T06:38:13Z
dc.date.issued2025-02-03
dc.description.abstractThis research presents a multi-faceted approach to detecting and preventing Remote Access Trojan (RAT) malware using reverse engineering and automated defense mechanisms. The study employs static and dynamic analysis techniques to deconstruct RAT malware, revealing its structure, persistence mechanisms, and command-and-control (C2) communication. Advanced cybersecurity tools such as Wireshark, Process Monitor, and Regshot are utilized to analyze system modifications and network traffic. To enhance real-time detection, automated analysis through APIs like VirusTotal is integrated, enabling the extraction of malicious indicators. Custom Snort intrusion detection system (IDS) rules are generated and deployed dynamically within a pfSense firewall, ensuring active blocking of RAT-related network traffic. This approach demonstrates the effectiveness of combining manual expertise with automation in fortifying network security. The study's methodology provides a scalable defense strategy against evolving malware threats, with potential applications in broader cybersecurity frameworks.
dc.identifier.urihttps://hdl.handle.net/20.500.11888/19877
dc.language.isoen
dc.supervisorAhmed Awad
dc.titleReverse Engineering and Automated Defense Strategies for Detecting and Preventing Rat Malware
dc.typeGraduation Project
Files
Original bundle
Now showing 1 - 2 of 2
Loading...
Thumbnail Image
Name:
abstract.docx
Size:
12.65 KB
Format:
Microsoft Word XML
Description:
Loading...
Thumbnail Image
Name:
Reverse Engineering.pptx
Size:
8.96 MB
Format:
Microsoft Powerpoint XML
Description:
License bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: