[Zurück]


Beiträge in Tagungsbänden:

M. Lindorfer, C. Kolbitsch, P. Milani Comparetti:
"Detecting Environment-Sensitive Malware";
in: "Proceedings of the 14th International Symposium on Recent Advances in Intrusion Detection (2011)", Springer, 2011, ISBN: 978-3-642-23643-3.



Kurzfassung englisch:
The execution of malware in an instrumented sandbox is a widespread approach for the analysis of malicious code, largely because it sidesteps the difficulties involved in the static analysis of obfuscated code. As malware analysis sandboxes increase in popularity, they are faced with the problem of malicious code detecting the instrumented environment to evade analysis. In the absence of an "undetectable", fully transparent analysis sandbox, defense against sandbox evasion is mostly reactive: Sandbox developers and operators tweak their systems to thwart individual evasion techniques as they become aware of them, leading to a never-ending arms race.
The goal of this work is to automate one step of this fight: Screening malware samples for evasive behavior. Thus, we propose novel techniques for detecting malware samples that exhibit semantically different behavior across different analysis sandboxes. These techniques are compatible with any monitoring technology that can be used for dynamic analysis, and are completely agnostic to the way that malware achieves evasion. We implement the proposed techniques in a tool called Disarm, and demonstrate that it can accurately detect evasive malware, leading to the discovery of previously unknown evasion techniques.

Schlagworte:
Malware, Dynamic Analysis, Sandbox Detection, Behavior Comparison


Elektronische Version der Publikation:
http://publik.tuwien.ac.at/files/PubDat_204766.pdf



Zugeordnete Projekte:
Projektleitung Paolo Milani Comparetti:
i-Code: Real-time Malicious Code Identification

Projektleitung Christian Platzer:
A European Network of Excellence in Managing Threats and Vulnerabilities in the Future Internet: Europe for the World

Projektleitung Gilbert Wondracek:
TRUDIE - Trust Relationships in Underground IT Economies


Erstellt aus der Publikationsdatenbank der Technischen Universität Wien.