作者
Daisuke Inoue, Katsunari Yoshioka, Masashi Eto, Yuji Hoshizawa, Koji Nakao
发表日期
2009/5/1
期刊
IEICE transactions on information and systems
卷号
92
期号
5
页码范围
945-954
出版商
The Institute of Electronics, Information and Communication Engineers
简介
Malware has been recognized as one of the major security threats in the Internet . Previous researches have mainly focused on malware's internal activity in a system. However, it is crucial that the malware analysis extracts a malware's external activity toward the network to correlate with a security incident. We propose a novel way to analyze malware: focus closely on the malware's external (i.e., network) activity. A malware sample is executed on a sandbox that consists of a real machine as victim and a virtual Internet environment. Since this sandbox environment is totally isolated from the real Internet, the execution of the sample causes no further unwanted propagation. The sandbox is configurable so as to extract specific activity of malware, such as scan behaviors. We implement a fully automated malware analysis system with the sandbox, which enables us to carry out the large-scale malware analysis. We …
引用总数
20092010201120122013201420152016201720182019202020212022202320241316543422871421
学术搜索中的文章
D Inoue, K Yoshioka, M Eto, Y Hoshizawa, K Nakao - IEICE transactions on information and systems, 2009