摘要
反虚拟化是当前影响恶意代码动态分析系统全面获取样本行为数据的重要因素.本文提出从恶意代码动态分析环境的主机环境,网络环境和用户交互环境进行系统的反虚拟化对抗方法,并将反虚拟化对抗实现在已有的动态分析系统上,实验结果表明反虚拟化对抗有效的增强了动态分析系统获取样本行为数据的能力.
Anti-virtualization is currently an important factor affecting the overall acquisition of sample behaviour data by a dynamic analysis system of malicious code.This study proposes a systematic anti-virtualization confrontation method from host environment,network environment,and user interaction environment of dynamic analysis environment of malicious code,and implements the anti-virtualization confrontation in the existing dynamic analysis system. Experimental results show that the anti-virtualization confrontation effectively enhances the dynamic analysis system's ability to capture sample behavior data.
作者
莫建平
应凌云
苏璞睿
王嘉捷
MO Jian-Ping;YING Ling-Yun;SU Pu-Rui;WANG Jia-Jie(Institute of Software Chinese Academy of Sciences,University of Chinese Academy of Sciences,Beijing 100190,China;University of Chinese Academy of Sciences,Beijing 100049,China;China Information Technology Security Evaluation Center,Beijing 100085,China)
出处
《计算机系统应用》
2018年第12期1-8,共8页
Computer Systems & Applications
基金
国家自然科学基金(61502468
U1736209)
"十三五"全军共用信息系统装备预研基金(6140134040216ZK65002)~~
关键词
恶意代码分析
动态分析
反虚拟化
malicious code analysis
dynamic analysis
anti-virtualization