首页> 外文期刊>Mathematical Problems in Engineering >Osiris: A Malware Behavior Capturing System Implemented at Virtual Machine Monitor Layer
【24h】

Osiris: A Malware Behavior Capturing System Implemented at Virtual Machine Monitor Layer

机译:Osiris:在虚拟机监控器层实施的恶意软件行为捕获系统

获取原文
获取原文并翻译 | 示例
       

摘要

To perform behavior based malware analysis, behavior capturing is an important prerequisite. In this paper, we present Osiris system which is a tool to capture behaviors of executable files in Windows system. It collects API calls invoked not only by main process of the analysis file, but also API calls invoked by child processes which are created by main process, injected processes if process injection happens, and service processes if the main process creates services. By modifying the source code of Qemu, Osiris is implemented at the virtual machine monitor layer and has the following advantages. First, it does not rewrite the binary code of analysis file or interfere with its normal execution, so that behavior data are obtained more stealthily and transparently. Second, it employs a multi-virtual machine framework to simulate the network environment for malware analysis, so that network behaviors of a malware are stimulated to a large extend. Third, besides network environment, it also simulates most common host events to stimulate potential malicious behaviors of a malware. The experimental results show that Osiris automates the malware analysis process and provides good behavior data for the following detection algorithm.
机译:要执行基于行为的恶意软件分析,行为捕获是重要的前提。在本文中,我们介绍了Osiris系统,它是一种捕获Windows系统中可执行文件行为的工具。它不仅收集由分析文件的主流程调用的API调用,还收集由主流程创建的子流程,如果发生流程注入而注入的流程以及由主流程创建服务的服务流程所调用的子流程调用的API调用。通过修改Qemu的源代码,Osiris在虚拟机监视层上实现,并具有以下优点。首先,它不会重写分析文件的二进制代码,也不会干扰其正常执行,因此可以更隐蔽和透明地获取行为数据。其次,它采用了多虚拟机框架来模拟网络环境以进行恶意软件分析,从而极大地激发了恶意软件的网络行为。第三,除了网络环境外,它还模拟最常见的主机事件,以激发恶意软件的潜在恶意行为。实验结果表明,Osiris可自动执行恶意软件分析过程,并为以下检测算法提供良好的行为数据。

著录项

  • 来源
    《Mathematical Problems in Engineering》 |2013年第4期|402438.1-402438.11|共11页
  • 作者单位

    School of Computer Science and Technology, Xidian University, P.O. Box 167, Xi'an, Shaanxi 710071, China;

    School of Computer Science and Technology, Xidian University, P.O. Box 167, Xi'an, Shaanxi 710071, China;

    School of Computer Science and Technology, Xidian University, P.O. Box 167, Xi'an, Shaanxi 710071, China;

    College of Computer Science and Technology, Chongqing University of Posts and Telecommunications, Chongqing, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

  • 入库时间 2022-08-17 13:54:34

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号