作者
Katsunari Yoshioka, Tsutomu Matsumoto
发表日期
2010/1/1
期刊
IEICE transactions on fundamentals of electronics, communications and computer sciences
卷号
93
期号
1
页码范围
210-218
出版商
The Institute of Electronics, Information and Communication Engineers
简介
Malware sandbox analysis, in which a malware sample is actually executed in a testing environment (i.e. sandbox) to observe its behavior, is one of the promising approaches to tackling the emerging threats of exploding malware. As a lot of recent malware actively communicates with remote hosts over the Internet, sandboxes should also support an Internet connection, otherwise important malware behavior may not be observed. In this paper, we propose a multi-pass sandbox analysis with a controlled Internet connection. In the proposed method, we start our analysis with an isolated sandbox and an emulated Internet that consists of a set of dummy servers and hosts that run vulnerable services, called Honeypots in the Sandbox (HitS). All outbound connections from the victim host are closely inspected to see if they could be connected to the real Internet. We iterate the above process until no new behaviors are …
引用总数
201020112012201320142015201620172018201920202021202220232652421121
学术搜索中的文章
K Yoshioka, T Matsumoto - IEICE transactions on fundamentals of electronics …, 2010