Hypervisor-assisted dynamic malware analysis  

在线阅读下载全文

作  者:Roee SLeon Michael Kiperberg Anat Anatey Leon Zabag Nezer Jacob Zaidenberg 

机构地区:[1]Shenkar College,Ramat Gan,Israel [2]Department of Software Engineering,Shamoon College of Engineering,Beer-Sheva,Israel [3]College of Management Academic Studies,Rishon LeTsiyon Israel [4]University of Jyväskylä,Jyväskylä,Finland

出  处:《Cybersecurity》2021年第1期278-291,共14页网络空间安全科学与技术(英文)

摘  要:Malware analysis is a task of utmost importance in cyber-security.Two approaches exist for malware analysis:static and dynamic.Modern malware uses an abundance of techniques to evade both dynamic and static analysis tools.Current dynamic analysis solutions either make modifications to the running malware or use a higher privilege component that does the actual analysis.The former can be easily detected by sophisticated malware while the latter often induces a significant performance overhead.We propose a method that performs malware analysis within the context of the OS itself.Furthermore,the analysis component is camouflaged by a hypervisor,which makes it completely transparent to the running OS and its applications.The evaluation of the system’s efficiency suggests that the induced performance overhead is negligible.

关 键 词:DYNAMIC ANALYSIS TRANSPARENT 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象