首页> 外文会议>International Conference on Information and Communications Security >PiDicators: An Efficient Artifact to Detect Various VMs
【24h】

PiDicators: An Efficient Artifact to Detect Various VMs

机译:PIDICATOR:有效的伪像来检测各种VM

获取原文

摘要

Most malwares use evasion technologies to prevent themselves from being analyzed by sandbox systems. For example, they would hide their maliciousness if the presence of Virtual Machine (VM) is detected. A popular idea of detecting VM is to utilize the difference in instruction semantics between virtual environment and physical environment. Semantic detection has been widely studied, but existing works either have limited detection range (e.g. detect VMs on specific hyper-visor) or cost too much time. And most methods are not available for various kinds of VMs while introducing acceptable performance overhead. In this paper, we proposed FindPiDicators, a new approach to select a few indicators (e.g. registers) and cases (instruction execution) through complete experiments and statistical analysis. Using FindPiDicators, we obtain PiDicators, a lightweight artifact that consists of some test cases and indicators. We use PiDicators to detect the presence of VM and it offers several benefits. 1) It could accurately detect VM without the influence of operating system, hardware environment and hypervisor. 2) PiDicators does not rely on API calls, thus it is transparent and hard to resist. 3) The detection based on PiDicators is time-efficient, for only 31 cases are considered and four registers' values are required for each case.
机译:大多数恶魔队使用逃避技术来防止自己被沙箱系统分析。例如,如果检测到虚拟机(VM)的存在,它们会隐藏恶意性。检测VM的流行思想是利用虚拟环境与物理环境之间的指令语义的差异。语义检测已被广泛研究,但现有的作品具有有限的检测范围(例如,检测特定超遮阳板上的VM)或花费太多时间。在引入可接受的性能开销时,大多数方法都不适用于各种VM。在本文中,我们提出了FindPidicator,通过完整实验和统计分析选择一些指标(例如寄存器)和案例(指令执行)的新方法。使用FindPidicators,我们获取PIDICATORS,这是一个由某些测试用例和指标组成的轻量级工件。我们使用PIDICATOR来检测VM的存在,它提供了几个好处。 1)它可以准确地检测VM,而无需操作系统,硬件环境和虚拟机管理程序的影响。 2)PIDICATOR不依赖于API呼叫,因此它是透明且难以抗蚀的。 3)基于PIDICETA的检测是时间效率,仅考虑31例,每种情况都需要四个寄存器值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号