GoldenEye: Efficiently and Effectively Unveiling Malware's Targeted Environment

GoldenEye: Efficiently and Effectively Unveiling Malware's Targeted Environment
复制标题

DOI:
10.1007/978-3-319-11379-1_2
复制
发表时间:
2014-09
期刊:
--
影响因子:
--
通讯作者:
Zhaoyan Xu;Jialong Zhang;G. Gu;Zhiqiang Lin
Zhaoyan Xu;Jialong Zhang;G. Gu;Zhiqiang Lin
中科院分区:
其他
文献类型:
--
作者:
Zhaoyan Xu;Jialong Zhang;G. Gu;Zhiqiang Lin

文献摘要

被引文献

相似文献

在对抗恶意软件威胁时,一个关键的挑战是如何有效地识别目标受害者的环境,给定未知的恶意软件样本。不幸的是,现有的恶意软件分析技术要么使用有限的、固定的分析环境集(不有效),要么使用昂贵、耗时的多路径探索(不有效),这使得它们不适合解决这一挑战。因此,本文提出了一种新的动态分析方案,通过在新的背景下应用推测执行的概念来处理这一问题。具体来说,通过提供多个动态创建的、并行的和虚拟的环境空间,我们可以推测地执行恶意软件样本,并在分析期间自适应地切换到正确的环境。有趣的是,虽然我们的方法似乎是以空间换取速度,但我们表明,它实际上可以使用更少的内存空间,并获得比现有方案高得多的速度。我们已经实现了一个原型系统GoldenEye,并使用大型真实恶意软件数据集对其进行了评估。实验结果表明,该方法优于现有的解决方案,能够有效、高效地暴露恶意软件的目标环境,从而加快了对新出现的针对性恶意软件威胁的关键分析。
A critical challenge when combating malware threat ishow to efficiently and effectively identify the targeted victim’s environment, given an unknown malware sample. Unfortunately, existing malware analysis techniques either use a limited, fixed set of analysis environments (not effective) or employ expensive, time-consuming multi-path exploration (not efficient), making them not well-suited to solve this challenge. As such, this paper proposes a new dynamic analysis scheme to deal with this problem by applying the concept of speculative execution in this new context. Specifically, by providing multiple dynamically created, parallel, and virtual environment spaces, we speculatively execute a malware sample and adaptively switch to the right environment during the analysis. Interestingly, while our approach appears to trade space for speed, we show that it can actually use less memory space and achieve much higher speed than existing schemes. We have implemented a prototype system,GoldenEye, and evaluated it with a large real-world malware dataset. The experimental results show thatGoldenEyeoutperforms existing solutions and can effectively and efficiently expose malware’s targeted environment, thereby speeding up the analysis in the critical battle against the emerging targeted malware threat.