POSTER: Toward Automating the Generation of Malware Analysis Reports Using the Sandbox Logs

POSTER: Toward Automating the Generation of Malware Analysis Reports Using the Sandbox Logs
复制标题

DOI:
10.1145/2976749.2989064
复制
发表时间:
2016-10
期刊:
Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Bo Sun;Akinori Fujino;Tatsuya Mori
Bo Sun;Akinori Fujino;Tatsuya Mori
中科院分区:
其他
文献类型:
--
作者:
Bo Sun;Akinori Fujino;Tatsuya Mori

文献摘要

被引文献

相似文献

近年来,恶意软件的新实例数量持续增加。为了创建有效的对策,安全专家通常必须手动检查动态分析方法生成的大量沙箱日志。相反,反病毒供应商通常会在他们的网站上发布恶意软件分析报告。由于恶意软件分析报告和沙盒日志没有直接联系,在分析沙盒日志时,安全专家无法从此类专家报告中描述的信息中受益。为了解决这个问题,我们开发了一个名为Regenerator的系统,该系统通过利用防病毒供应商发布的现有报告自动生成与沙箱日志相关的报告。我们的系统结合了几种技术,包括Jaccard相似性、自然语言处理(NLP)和生成(NLG),为安全专家生成简明的人类可读的描述恶意行为的报告。
In recent years, the number of new examples of malware has continued to increase. To create effective countermeasures, security specialists often must manually inspect vast sandbox logs produced by the dynamic analysis method. Conversely, antivirus vendors usually publish malware analysis reports on their website. Because malware analysis reports and sandbox logs do not have direct connections, when analyzing sandbox logs, security specialists can not benefit from the information described in such expert reports. To address this issue, we developed a system called ReGenerator that automates the generation of reports related to sandbox logs by making use of existing reports published by antivirus vendors. Our system combines several techniques, including the Jaccard similarity, Natural Language Processing (NLP), and Generation (NLG), to produce concise human-readable reports describing malicious behavior for security specialists.