Addressing Evasive Malware
Addressing Evasive Malware
批准号:
2107021
负责人:
金额:
$0.0万
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2018
资助国家:
英国
项目状态:
已结题
起止时间:
2018 至 --
中文摘要
这项研究的主要兴趣领域是解决可以检测虚拟沙箱环境的恶意软件,以便它们可以避开分析环境。简单的沙盒规避机制的一个例子是使用DNS查询的WannaCry恶意软件。通过注册正确的域并以正确的方式响应,该恶意软件被关闭。这种方法之所以奏效,是因为沙盒通常会响应给出目标设备在线状态的DNS查询。恶意软件作者知道这一点,并编程WannaCry在收到对未注册域名的响应时关闭。通过沙箱进行的恶意软件分析侧重于尝试镜像物理系统,以使它们对被测试的示例程序透明。在实践中,事实证明,这很难实现,因为恶意软件作者编写了他们的软件来寻找环境是虚拟的指示器。从历史上看,存在一种模式,即恶意软件作者迅速找到解决方案,以工程方式尝试隐藏沙箱环境,使其不受恶意软件的影响。这导致了一场无休止的“猫捉老鼠|”的游戏,安全工程师不得不响应恶意软件作者检测沙盒环境的新方法。一种常见的方法是重新配置沙盒环境,使其看起来更像物理环境,但这并不是没有问题,因为一些更改可能会导致测试环境和主题程序之间的不兼容。本博士进行的研究将寻求检测恶意软件的沙盒检测机制,并使恶意软件作者的环境分析技术针对它们。这些方法包括查看样本在第一次执行时试图了解其环境时执行的活动的总和。一些例子包括:在执行时捕获样本生成的网络流量,使用挂钩来查看恶意软件进行的系统调用,查看恶意软件可能生成的NOP的数量,并查看差异行为分析,即如果移除检测机制,则样本是否变得更加活跃。之所以关注第一次执行样本的时间,是因为在恶意软件激活其有效负载或被编程为保持休眠和逃避分析之前,通常会有一些活跃的询问。这可以被认为是恶意软件在第一次分析环境时产生的一种‘噪音’,这也是本项目的目标。将探索机器学习或可能的BAME理论,以查看是否有可能对这些恶意软件交互进行建模,以便对软件样本进行分类,从而向安全分析师表明需要在物理环境中进行进一步的调查。之所以需要自适应方法而不是绝对方法,是因为有时程序对环境的询问被认为是正常行为。这些交互的组合有可能指向试图逃避沙箱中分析的样本
英文摘要
The main areas of interest of this research is addressing malware that can detect virtual sandbox environments so that they can avoid analysis environments. An example of a simple sandbox evasion mechanism is the WannaCry malware which uses a DNS query. This malware was shut down by registering the correct domain and responding in the correct manner. This method worked because sandboxes often respond to DNS queries giving the appearance of a target device being online. The malware author had knowledge of this and programmed WannaCry to shut down when a response to an unregistered domain was received. Malware analysis through sandboxes focus on trying to mirror physical systems so that they appear transparent to the sample program being tested. In practice, this has proved difficult to achieve with malware authors programming their software to look for indicators that an environment is virtual. Historically it has been shown that there is a pattern of malware authors quickly finding solutions to engineering attempts to hide a sandbox environment from the malware. This leads to an endless game of "cat and mouse|, with security engineers having to respond to malware authors new ways of detecting a sandbox environment. A common approach is to reconfigure the sandbox environment to make it seem more like a physical environment, but this is not without its issues because some of the changes can lead to incompatibility between the test environment and the subject programmes.The research undertaken in this PhD will seek to detect the malware's sandbox detection mechanisms and turn the malware authors' techniques of environmental analysis against them. These methods include looking at the sum of the activities that a sample performs whilst it is trying to learn about its environment when it is first executed. Some examples are: capturing the network traffic generated by the sample on execution, using hooks to look at system calls made by the malware, looking at the number of NOPs that a malware may generate and looking at differential behaviour analysis i.e. if a detection mechanism is removed, does the sample become more active. The reason for focussing on when a sample is first executed is that there is typically some active interrogation before the malware activates its payload or is programmed to stay dormant and evade analysis. This can be considered a form of 'noise' that the malware makes when it is analysing the environment in the first instance and this is what the project will be targeting.Machine learning or possibly bame theory will be explored to see if it is possible to model these malware interactions in order to classify the software sample on a scale which can indicate to security analysts that further investigation in a physical environment is required. The reason an adaptive approach is required rather than an absolute approach is because sometimes interrogation of an environment by a program is considered normal behaviour. It is possible that a combination of these interactions will point to a sample looking to evade analysis in a sandbox
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金