The other guys: automated analysis of marginalized malware

The other guys: automated analysis of marginalized malware
复制标题

其他人:边缘化恶意软件的自动分析

DOI:
10.1007/s11416-017-0292-8
复制
发表时间:
2018
影响因子:
1.5
通讯作者:
A. Grégio
A. Grégio
中科院分区:
--
文献类型:
--
作者:
Marcus Botacin;P. Geus;A. Grégio

文献摘要

被引文献

相似文献

为了阻止动态分析和绕过保护机制,恶意软件一直在使用多种文件格式和规避技术。虽然公开的动态恶意软件分析系统是研究人员、安全分析师和事件响应专业人员的主要信息来源之一,但它们无法应对所有类型的威胁。因此,很难从公共系统收集有关 CPL、.NET/Mono、64 位、依赖重新启动或针对 Windows XP 更新系统的恶意软件的信息,这导致人们无法了解当前恶意软件在现代操作系统上感染期间的行为方式。在本文中,我们讨论了此类分析系统开发过程中面临的挑战和问题,主要是由于 Windows 操作系统 NT 6.x 内核版本中提供的安全功能。我们还介绍了一个动态分析系统,该系统可以解决上述类型的恶意软件,并提供从分析中获得的结果。
In order to thwart dynamic analysis and bypass protection mechanisms, malware have been using several file formats and evasive techniques. While publicly available dynamic malware analysis systems are one of the main sources of information for researchers, security analysts and incident response professionals, they are unable to cope with all types of threats. Therefore, it is difficult to gather information from public systems about CPL, .NET/Mono, 64-bits, reboot-dependent, or malware targeting systems newer than Windows XP, which result in a lack of understanding about how current malware behave during infections on modern operating systems. In this paper, we discuss the challenges and issues faced during the development of this type of analysis system, mainly due to security features available in NT 6.x kernel versions of Windows OS. We also introduce a dynamic analysis system that addresses the aforementioned types of malware as well as present results obtained from their analyses.