NetwIOC: a framework for the automated generation of network-based IOCS for malware information sharing and defence

dc.contributor.advisorIrwin, Barry Vivian William
dc.contributor.authorRudman, Lauren Lynne
dc.date.accessioned2026-03-09T07:19:07Z
dc.date.issued2018
dc.description.abstractWith the substantial number of new malware variants found each day, it is useful to have an efficient way to retrieve Indicators of Compromise (IOCs) from the malware in a format suitable for sharing and detection. In the past, these indicators were manually created after inspection of binary samples and network traffic. The Cuckoo Sandbox, is an existing dynamic malware analysis system which meets the requirements for the proposed framework and was extended by adding a few custom modules. This research explored a way to automate the generation of detailed network-based IOCs in a popular format which can be used for sharing. This was done through careful filtering and analysis of the PCAP hie generated by the sandbox, and placing these values into the correct type of STIX objects using Python, Through several evaluations, analysis of what type of network traffic can be expected for the creation of IOCs was conducted, including a brief ease study that examined the effect of analysis time on the number of IOCs created. Using the automatically generated IOCs to create defence and detection mechanisms for the network was evaluated and proved successful, A proof of concept sharing platform developed for the STIX IOCs is showcased at the end of the research.
dc.description.degreeMaster's thesis
dc.description.degreeMSc
dc.format.extent162 pages
dc.format.mimetypeapplication/pdf
dc.identifier.otherhttp://hdl.handle.net/10962/60639
dc.identifier.urihttps://researchrepository.ru.ac.za/handle/123456789/9305
dc.languageEnglish
dc.publisherRhodes University, Faculty of Science, Department of Computer Science
dc.rightsRudman, Lauren Lynne
dc.subjectMalware (Computer software)
dc.subjectComputer networks -- Security measures
dc.subjectComputer security
dc.subjectPython (Computer program language)
dc.titleNetwIOC: a framework for the automated generation of network-based IOCS for malware information sharing and defence
dc.typeAcademic thesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
vital_27809+SOURCE1+SOURCE1.2.pdf
Size:
3.12 MB
Format:
Adobe Portable Document Format