首页> 外文会议>Stabilization, safety, and security of distributed systems >TrumanBox: Improving Dynamic Malware Analysis by Emulating the Internet
【24h】

TrumanBox: Improving Dynamic Malware Analysis by Emulating the Internet

机译:TrumanBox:通过模拟Internet改进动态恶意软件分析

获取原文
获取原文并翻译 | 示例

摘要

Dynamic analysis of malicious software (malware) is a powerful tool in countering modern threats on the Internet. In dynamic analysis, a malware sample is executed in a controlled environment and its actions are logged. Through dynamic analysis, an analyst can quickly obtain an overview of malware behavior and can decide whether or not to indulge into tedious manual analysis of the sample. However, usual dynamic analysis exposes the Internet to the threats of an executed malware (like portscans) because advanced concealment techniques of malware often require full Internet access. For example, a missing link to the Internet or the unavailability of a specific server often causes the malware to not trigger its malicious behavior. In this paper, we present TrumanBox, a technique to emulate relevant parts of the Internet to enhance dynamic malware analysis. We show that TrumanBox not only prevents many threats but also enlarges the scope of the types of malware that can be analyzed dynamically.
机译:动态分析恶意软件(malware)是抵抗Internet上现代威胁的强大工具。在动态分析中,恶意软件样本在受控环境中执行,并记录其操作。通过动态分析,分析人员可以快速获得恶意软件行为的概述,并可以决定是否沉迷于样本的繁琐的手动分析中。但是,通常的动态分析会将Internet暴露于已执行恶意软件的威胁下(例如portcan),因为恶意软件的高级隐藏技术通常需要完全访问Internet。例如,缺少Internet链接或特定服务器不可用通常会导致恶意软件无法触发其恶意行为。在本文中,我们介绍了TrumanBox,这是一种模拟Internet相关部分以增强动态恶意软件分析的技术。我们证明TrumanBox不仅可以防止许多威胁,而且可以动态分析的恶意软件类型也扩大了范围。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号