Papers & Presentations

Papers and presentations from the FortiGuard Labs Research Team

Guns and Smoke to Defeat Mobile Malware

You've already reversed Android applications with baksmali and apktool? That's great! But how about learning a few new tricks with those tools and others? This talk will discuss some advanced featu...

Posted: 05 November 2012

Reducing the Window of Opportunity for Android Malware

This paper is all about finding new Android malware in the wild (crawling Google Play but also spotting suspicious applications among loads of genuine apps using a heuristic engine). Was presented ...

Posted: 10 May 2012

An Attacker's Day into Human Virology

Computer virology bares such a strong resemblance with Human virology that both worlds have often been compared humorously. In this presentation, we wish to push the comparison further down into th...

Posted: 10 May 2012

Android Reverse Engineering Tools

Android Reverse Engineering Tools, from an anti-virus analyst's perspective. Presents known reversing tools: apktool, baksmali, dex2jar, androguard, ded, dedexer... Tutorial on reversing of Android...

Posted: 05 March 2012

Defeating mTANs for profit

Malware on mobile phones has existed for several years, but until recently it had not been used for organized crime involving large amounts of money. This changed in September 2010 when the infamou...

Posted: 27 October 2011

Cryptography for mobile malware obfuscation

Malware for mobile phones are perhaps less known than Windows viruses, but they are nevertheless a fact now, confirmed by the recent trojans on Android (Geinimi, DrdDream). In this session, we addr...

Posted: 24 October 2011

An OpenBTS GSM Replication Jail for Mobile Malware

There is one golden rule in the Anti-Virus industry all AV analysts are very cautious about: making sure they do not spread samples which are under study. On PCs, vendors commonly use replication h...

Posted: 24 October 2011

Understanding and Exploiting Flash ActionScript Vulnerabilities

Understanding and Exploiting Flash ActionScript Vulnerabilities

Adobe's Flash Player has become the most popular rich internet application (RIA) today. Recent years we have seen many Fl...

Posted: 01 March 2011

Mobile Malware..In Practice

Recent examples of malware for mobile phones, what they do, how they do it and frequent symptoms

Posted: 01 March 2011

Defeating mTANs for profit

Nowadays, many banks try to secure their online transactions by sending an additional one-time password by SMS (mTAN) to the end-user. Unfortunately, in September 2010, the infamous ZeuS gang has w...

Posted: 04 January 2011

Rearing its Seven Ugly Heads: The DLL-Preload Attack



Posted: 01 August 2010

The Four Horsemen: Malware on Mobile Phones in 2009-2010

This talk selects four malware targeting mobile phone platforms, currently among the most prevalent. A technical description is provided for each: how it infects the phone, its malicious payload ...

Posted: 01 May 2010

Symbian Worm Yxes: Towards Mobile Botnets?

In 2009, a new Symbian malware named SymbOS/Yxes was detected and quickly hit the headlines as one of the first malware for Symbian OS 9 and above all as the foretaste of a mobile botnet. Yet, the ...

Posted: 01 May 2010

Four Malware and a Funeral

This paper selects four malware targeting mobile phone platforms, namely Eeki, Yxes, Redoc and GameSat. They are currently among the most relevant malware in terms of prevalence, or because they a...

Posted: 01 May 2010

Adobe Reader's Custom Memory Management: a Heap of Trouble

This is a PDF-specific exploitation research focusing on the custom heap management on Adobe Reader. When Adobe Reader is processing a PDF file, in most allocation cases, it does not directly use t...

Posted: 01 April 2010

'I am not a numero!': assessing global security threat levels

Late last year Gartner analyst Greg Young wrote a blog post about the varying worldwide security threat levels as indicated in vendor online threat centres. He pointed out that, since global vendor...

Posted: 01 September 2009

Fighting cybercrime: technical, juridical, and ethical challenges

Since the massive rise of cybercrime in 2005, which now steadily drains several billion dollars (if not hundreds of billions) per year, a variety of challenges in efficiently fighting cybercriminal...

Posted: 01 September 2009

Botnet-powered SQL injection attacks: a deeper look within

Looking back, the past year has seen botnet-powered SQL injection attacks reaching a rampant level, sparing no category of websites in their malicious code injection campaigns. With several million...

Posted: 01 September 2009

Vital Threat Management for Enterprise Carrier



Posted: 01 June 2009

Corporate Threats



Posted: 01 June 2009

Accelerating Unified Threat Management with Specialized Hardware



Posted: 01 June 2008

Network Security Consolidation



Posted: 01 April 2008

Find out the "Bad guys" on the Symbian

After the emergence of Cabir mobile virus, the mobile virus has become a new trend. To date, there are more than 400 types of mobile viruses discovered. As we know, most of them are executing on th...

Posted: 01 November 2007

Unifying Your Threat Management Practice



Posted: 01 October 2007

Securing IPv6 Networks



Posted: 01 September 2007

Menace 2 The Wires: Advances in the Business Models of Cyber Criminals

Today, the profits generated by cybercrime worldwide are somewhere between $50 billion and $100 billion per annum, flirting with the revenues yielded by the 'historic' business of trading illegal d...

Posted: 01 September 2007

A deeper look at malware - the whole story

Despite researcher curiosities about how each and every type of malware works, the cyber world still suffers a deluge of more than thousands of malware per day. Malware packers and encoders are bui...

Posted: 01 September 2007

Beyond UTM - The Value of a Purpose-Built Network Security Platform



Posted: 01 August 2007

Real Time Network Protection for Educational Institutions



Posted: 01 July 2007

The Importance of FortiGuard Web Filtering as part of a Multi-Threat Security System



Posted: 01 January 2007