Detecting Environment-Sensitive Malware

被引:0
|
作者
Lindorfer, Martina [1 ]
Kolbitsch, Clemens [1 ]
Comparetti, Paolo Milani [1 ]
机构
[1] Vienna Univ Technol, Secure Syst Lab, Vienna, Austria
来源
RECENT ADVANCES IN INTRUSION DETECTION | 2011年 / 6961卷
关键词
Malware; Dynamic Analysis; Sandbox Detection; Behavior Comparison;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The execution of malware in an instrumented sandbox is a widespread approach for the analysis of malicious code, largely because it sidesteps the difficulties involved in the static analysis of obfuscated code. As malware analysis sandboxes increase in popularity, they are faced with the problem of malicious code detecting the instrumented environment to evade analysis. In the absence of an "undetectable", fully transparent analysis sandbox, defense against sandbox evasion is mostly reactive: Sandbox developers and operators tweak their systems to thwart individual evasion techniques as they become aware of them, leading to a never-ending arms race. The goal of this work is to automate one step of this fight: Screening malware samples for evasive behavior. Thus, we propose novel techniques for detecting malware samples that exhibit semantically different behavior across different analysis sandboxes. These techniques are compatible with any monitoring technology that can be used for dynamic analysis, and are completely agnostic to the way that malware achieves evasion. We implement the proposed techniques in a tool called DISARM, and demonstrate that it can accurately detect evasive malware, leading to the discovery of previously unknown evasion techniques.
引用
收藏
页码:338 / 357
页数:20
相关论文
共 50 条
  • [1] Detecting Environment-Sensitive Malware Based on Taint Analysis
    Shi, Dawei
    Tang, Xiucun
    Ye, Zhibin
    PROCEEDINGS OF 2017 8TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS 2017), 2017, : 322 - 327
  • [2] FindEvasion: An Effective Environment-Sensitive Malware Detection System for the Cloud
    Jia, Xiaoqi
    Zhou, Guangzhe
    Huang, Qingjia
    Zhang, Weijuan
    Tian, Donghai
    DIGITAL FORENSICS AND CYBER CRIME, ICDF2C 2017, 2018, 216 : 3 - 17
  • [3] Environment-sensitive intrusion detection
    Giffin, JT
    Dagon, D
    Jha, S
    Lee, W
    Miller, BP
    RECENT ADVANCES IN INTRUSION DETECTION, 2006, 3858 : 185 - 206
  • [4] Environment-Sensitive cloning in images
    Zhang, Yun
    Tong, Ruofeng
    VISUAL COMPUTER, 2011, 27 (6-8): : 739 - 748
  • [5] Environment-Sensitive cloning in images
    Yun Zhang
    Ruofeng Tong
    The Visual Computer, 2011, 27 : 739 - 748
  • [6] Discovery of environment-sensitive fluorescent probes for detecting and inhibiting metallo-?-lactamase
    Chen, Cheng
    Xiang, Yang
    Yang, Ke-Wu
    BIOORGANIC CHEMISTRY, 2022, 128
  • [7] ENVIRONMENT-SENSITIVE MACHINING OF NONMETALS
    WESTWOOD, AR
    AMERICAN CERAMIC SOCIETY BULLETIN, 1972, 51 (04): : 319 - &
  • [8] ENVIRONMENT-SENSITIVE FRACTURE - DESIGN CONSIDERATIONS
    TOMKINS, B
    SCOTT, PM
    METALS TECHNOLOGY, 1982, 9 (JUN): : 240 - 248
  • [9] Environment-Sensitive Nanofibers and Anchoring of Dyes
    Ge, Liqin
    Wang, Weichen
    Yao, Chong
    Xu, Zeying
    ASIAN JOURNAL OF CHEMISTRY, 2013, 25 (03) : 1270 - 1274
  • [10] Environment-sensitive hydrogels for drug delivery
    Qiu, Yong
    Park, Kinam
    ADVANCED DRUG DELIVERY REVIEWS, 2012, 64 : 49 - 60