标题: 动态恶意程式分析环境中安全及透明的网路流量之重播、重导及转送
Secure and Transparent Network Traffic Replay, Redirect and Relay in a Dynamic Malware Analysis Environment
作者: 施宗笔
Shih, Tzung-Bi
林盈达
Lin, Ying-Dar
资讯科学与工程研究所
关键字: 动态分析;封闭网路;开放网路;导向;Dynamic Analysis;Closed Network;Open Network;Retarget
公开日期: 2010
摘要: 典型的动态分析会搭配封闭的网路环境以避免恶意程式在分析过程攻击到网际网路上的机器。然而,现今的恶意程式大多需要连线到网际网路以运作。由于连线到网际网路的流量被阻挡,搭配封闭网路的分析环境用途遭受限制。我们提出一个系统,允许动态恶意程式分析环境拥有看似无限制的网际网路存取权,并且透明地将恶意流量导向系统内的诱捕器,同时允许无害的控制流量存取网际网路。在2000多只可疑的恶意程式中,我们首先选择被四套防毒软体标记的124只恶意程式。接着,我们排除那些没有网路行为或者无法成功连线到它们设计好的机器的恶意程式。最后,我们总共有12只恶意程式样本。实验结果显示,我们的系统可以看到的网路行为平均是封闭网路的3.35倍,在分析发送垃圾信件的恶意程式的情况下,我们甚至更胜于开放网路环境。同时,网际网路的安全性也会被改善。
Dynamic analysis is typically performed in a closed network environment to prevent malware under analysis from attacking machines on the Internet. However, many of today’s malware require Internet connections to operate. A closed network analysis environment will be of limited use for such malware as Internet bound connections are blocked. We propose a system to allow malware in a dynamic analysis environment to have seemingly unrestricted Internet access. Our system transparently retargets malicious network connections to compatible decoys within our system while allowing Internet access for harmless control traffic in unknown protocols. Among more than 2000 suspicious malwares, we first select 124 malwares that are flagged by all anti-virus scanners from 4 different vendors. Then, we exclude those malwares that exhibit no network activities or cannot connect to their designed machines on the Internet. Finally, we have 12 malware samples. The evaluation result shows that our system can allow the malware to exhibit more network activities than a closed network environment (3.35 times more on average) and even outperform a baseline open network environment for the case of spammer-type malwares. In the meantime, Internet security is significantly improved.
URI: http://140.113.39.130/cdrfb3/record/nctu/#GT079955502
http://hdl.handle.net/11536/50422
显示于类别:Thesis


文件中的档案:

  1. 550201.pdf

If it is a zip file, please download the file and unzip it, then open index.html in a browser to view the full text content.