Skip to content
itai00 edited this page Jun 10, 2018 · 30 revisions

In this diary we will document our meetings and planning for the future.


Meetings

Date: 27.9.17
Hour: 10:00
Location: Vicarius office

In this meeting we met for the first time with Vicarius founders and where explain about the company and what they do. We also discussed about some options that they have to offer for a project:

  1. Dynamic program analysis - mapping and learning a process activity.
  2. integration with patch engine - setting and connecting data base to Vicarius system.
  3. developing remote control system - running automated commends to Vicarius agents.
  4. developing analytic system - building a database for system events in a long time period. We chose to work on option number 1 because we found it to be the most challenging.

Date: 26.10.17
Hour: 10:00
Location: Vicarius office

We met with Yossi and Roiy which is the CTO of Vicarius. They explained us about how
they want the project to look like which programs can assist us and where to focus in the
beginning.
Roiy showed us the progress they have made so far and which tools they have already developed.


Date: 6.11.17
Hour: 13:30
Location: Azrieli Collage

We introduced the project to Shimrit and explained her what exactly our plan for the beginning.
Shimrit gave us some comments and focused us on the important part of the project.
We understood the scale of this project and that we have to minimise the part that maps
system calls for each process and focus on one to five process in order for us to complete the project on time.


Date: 12.11.17
Hour: 9:30
Location: Azrieli Collage

In the last meeting with Yossi and Roiy they Showed us A tool called frida which is an open source tool for Dynamic instrumentation, reverse-engineers, and security researchers for developers. We started exploring frida to see what it can do.
We started by installing frida cli and play with some commands. We saw that it can attach it self in to a given process and with a given regex for a function name it can trace when this function is called. So we started looking at the javascript api for program implementation of frida and found a tool called interceptor which with a given module name and function within the module return a pointer to the location of this function and you can also provide it with a callback function which has a state of onEnter which is called when a the function we trace is called. This is exactly what we need.


Date: 16.11.17
Hour: 10:00
Location: Azrieli Collage

In the meeting with Yossi and Roiy they told us that they want our project to work on Linux so we needed to write the project in c or c++ language for it to work on Linux OS. Luckily for us frida has it code written in a lot of languages and one of them is c.
We downloaded the frida core c api and ran the example that was built in the frida c project. We than studied each section of the program to see what it does. We found out that in order for us to inject a javascript code to a given process and intercept its functions we need a couple of things:

  1. The process id
  2. what modules is this process use
  3. what functions hides inside a given module

    We understood that we have to speak with Vicarius team again to see where we go from here.

Date: 19.11.17
Hour: 12:00
Location: Azrieli Collage

We spoke with Yossi on the phone and explained him where we have got so far. Yossi told us that what we ned is IAT-Hooking which is a well documented technique for intercepting calls to imported functions. We found an open source project online which implements this technique. We started exploring the code to see how we modify it to our needs. However we found out that it only work for 32bit process and we want to support 64bit process as well. We called Yossi again to tell him what we found out, Yossi told us that he also wrote a filter driver that does the exact thing and he want us to meat him to explain how it works.


Date: 22.11.17
Hour: 13:00
Location: Vicarius office

We met with Yossi, he sowed us how the filter driver works what each section in the code does what are the outputs and what we need to change in order for it to work for our purposes.


Date: 29.11.17
Hour: 10:00
Location: Azrieli Collage

We started by downloading Vicarius filter driver and making it worked on our systems. Yossi gave us a code that is written in c# and one that is written in c++. The c# code was more baked which means that that he already wrote the part that was in charge of communicating between the different threads and the pipe and it was well tested. while the c code didn't also the c code did not install and uninstall the filter driver correctly. We tried fixing the c code and making it work for our needs but we soon understood we don't have enough time to make it work so we started focusing on the c# code.


Date: 6.12.17
Hour: 10:00
Location: Azrieli Collage

We needed a data base that will hold for us which process uses which dll and will be easy to search in. We started thinking about sqlite library but we soon understood that we cannot expand coulombs dynamically. We then choose to work with xml files but soon realised that to search within an xml file will take more time. We than choose to go back to sql and write a table for each process that we intercept. inside the table we we hold the module that it is using.


Date: 10.12.17
Hour: 10:00
Location: Azrieli Collage

We started writing an sql class that will support inserting values and searching values. We also needed a table for each module that we want to inspect, to hold the functions name and how many times it was called. We decided to write 2 sql classes one for the exe and one for the dlls.


Date: 14.12.17
Hour: 10:00
Location: Azrieli Collage

We start working on extracting functions name from a dll. in the meeting with Yossi he told us that there is a tool for visual studio that does the exact thing and it called dumpbin the only problem was that it is a visual studio tool and will not work on other OS then windows. After Hours searching online we came to a conclusion that it is the only working option. we than started searching on line to see how we use this tool programatically.


Date: 19.12.17
Hour: 10:00
Location: Azrieli Collage

We started working on the dumbing command fix the code to look more allegiant. We also found a command that takes the dumpbin output and cuts the relevant function name part and also added a part that finds the process id for later use.


Date: 24.12.17
Hour: 10:00
Location: Azrieli Collage

We made some test for the data base we wrote.


Date: 28.12.17
Hour: 10:00
Location: Azrieli Collage

We started working on the frida part. We exported the c code to a dll and and called it for our own c# code. we than started sending commands from the c# code to the frida function to execute. We than discovered that frida can't attach it self to every function in a module and that it searches the module table to see if it has been loaded and if not it returns null. After speaking with yossi we came to a conclusion that we cannot support attachment failings in frida.


Date: 3.1.18
Hour: 10:00
Location: Azrieli Collage

We now have everting working but we needed to find a way to make fired communicate with our database. We found out that frida team also included an sqlite support in their javascript api, so we implemented it in out code.


Date: 8.1.18
Hour: 10:00
Location: Tel Aviv, Gal House

We started working on the test program and code modification. We also made some tests to see if everything work as it should.


Date: 21.1.18
Hour: 10:00
Location: Azrieli Collage

We presented to Shimrit the project until the alpha stage. We've received suggestions for improvement. We talked about the continuation of the project.


Date: 28.1.18
Hour: 9:00
Location: Tel Aviv, Gal House

We met to close the final tasks of the alpha stage and prepare the video for submission.


Date: 20.2.18
Hour: 12:00
Location: Vicarius office

We met with Yossi to present him what we have accomplish so far he was pleases and recommended us to write a small GUI for the project to make it easer for us to test everything and for future progress. we started speaking about the second stage of the project and how we should implement the learning machine and which programs can simulate hacks


Date: 15.4.18
Hour: 16:00
Location: Azrieli Collage

We met with Assaf Spanier to discuss the implementation of the machine learning phase. He started the conversation by telling us that we must first tag our data if we don't have a tagged data than we can't build a learning machine.


Date: 15.4.18
Hour: 16:00
Location: Azrieli Collage

We met with Assaf Spanier to discuss the implementation of the machine learning phase. He started the conversation by telling us that we must first tag our data if we don't have a tagged data than we can't build a learning machine.


Date: 13.5.18
Hour: 13:00
Location: Azrieli Collage

We met with Shimrit to see how continue from here, can we tag the data, or we should change directions. In the end we came to a conclusion that this is not the right way to go. instead we will try to look for patterns with heavy hitters algorithm and build a dictionary of words. The letters will be the functions names and the words will be all the possible patterns. once we have the dictionary we can build a state machine with aho-corasick.


Date: 20.5.18
Hour: 12:00
Location: Vicarius office

We met again with Yossi and this time Roiy we show them the GUI that we made and told them what we have discussed with Shimrit. They showed us what we can search for exploits and what functions are suspicious.


Date: 25.5.18
Hour: 9:00
Location: Azrieli Collage

We started researching for heavy hitters algorithm and found that its not really suits us we than started looking for different patterns searching algorithm and found one that met our demands.


Date: 1.6.18
Hour: 9:00
Location: Azrieli Collage

We searched for exploits and found a small guid that explain how to make a program call a functions of your desire we started building a small program for it


Date: 5.6.18
Hour: 9:00
Location: Azrieli Collage

We searched for exploits and found a small guid that explain how to make a program call a functions of your desire we started building a small program for it and chose notepad for the presentation.


Date: 10.6.18
Hour: 9:00
Location: Azrieli Collage

start implementing the aho-corasick algorithm and running tests

Clone this wiki locally