Đo lường phát hiện máy ảo trong mã độc bằng cách sử dụng DSD tracer

Springer Science and Business Media LLC - Tập 6 - Trang 181-195 - 2008
Boris Lau1, Vanja Svajcer1
1Sophoslabs, Sophos Plc, The Pentagon, Abingdon, UK

Tóm tắt

Hầu hết các phương pháp phát hiện một tiến trình đang chạy trong môi trường ảo, chẳng hạn như VMWare hoặc Microsoft Virtual PC, đều đã được biết đến rộng rãi và bài báo này sẽ tóm tắt một cách ngắn gọn những phương pháp phổ biến nhất được đo trong quá trình nghiên cứu. Các phép đo được thực hiện trên một tập hợp đại diện các tệp mã độc, với sự chú ý đặc biệt đến mã packer. Kết quả được phân chia dựa trên danh mục mã độc, các gia đình mã độc và các packer thương mại cũng như phi thương mại khác nhau, và được trình bày dưới dạng đồ họa và bảng. Quy mô của vấn đề phát hiện máy ảo được ước tính dựa trên kết quả của nghiên cứu. Chủ đề chính của bài báo là đo lường việc sử dụng thực tế các phương pháp phát hiện máy ảo trong mã độc hiện tại. Nghiên cứu sử dụng DSD Tracer, một hệ thống theo dõi động-tĩnh dựa trên một máy ảo Bochs đã được công cụ hóa. Hệ thống sử dụng theo dõi để tạo ra các trình theo dõi thực thi có thể được lập kịch bản hoặc được sử dụng làm cơ sở cho việc phẫu tích/phỏng thực trong IDA Pro kết hợp với một phiên bản tùy chỉnh của IDAEmul (trình giả lập). Bài báo cung cấp cái nhìn tổng quát về thiết kế và cách sử dụng của DSD Tracer.

Từ khóa

#phát hiện máy ảo #mã độc #DSD Tracer #phương pháp phát hiện #hệ thống theo dõi

Tài liệu tham khảo

Lau, B.: DSD-Tracer: experimentation and implementation. In: Virus Bulletin 2007 Conference proceedings (2007) Moser, A., Kruegel, C., Kirda, E.: Exploring Multiple Execution Paths for Malware Analysis (2006) Bayer, U.: TTAnalyze: a tool for analyzing Malware. Master’s Thesis, Technical University of Vienna (2005) Vasudevan, A., Yerraballi, R.: Cobra: fine-grained Malware analysis using stealth localized-executions. In: IEEE and Signature Generation of Exploits on Commodity Software (2006) Willems, A., Holz, C., Freiling, T., Felix A.: Toward Automated Dynamic Malware Analysis Using CWSandbox. http://www.cwsandbox.org/ (2007) Simplified Wrapper and Interface Generator. http://www.swig.org/ (2000) Natvig, K.: Norman sandbox white paper. http://download.norman.no/whitepapers/whitepaper_Norman_SandBox.pdf (2003) Vidstrom, A.: Evading the Norman SandBox Analyzer. BugTraq bulletin (2007) Eagle, C.: Attacking Packed Code with IDA Pro. http://ida-x86emu.sourceforge.net, Black-hat Asia (2006) Bellard, F.: QEMU Emulator User Documentation # GDB usage. http://fabrice.bellard.free.fr/qemu/qemu-doc.html#SEC46 (2005) Ormandy, T.: An empirical study into the security exposure to hosts of hostile virtualized environments, CanSecWest (2007) Ferrie, P.: Attacks on virtual machine emulators (2007) Xu M., et al.: ReTrace: Collecting execution trace with virtual machine deterministic replay (2007) Herrod, S.: The amazing VM record/replay feature in VMware Workstation 6. http://blogs.vmware.com/sherrod/2007/04/the_amazing_vm_.html (2007) Technology, O.: Themida overview. http://www.oreans.com/themida.php (2007) Malyugin, V.: Application debugging with Record/Replay. http://stackframe.blogspot.com/2007/09/application-debugging-with-recordreplay.html (2007) Malyugin, V.: VMware forum thread. http://communities.vmware.com/thread/104296 (2007) Callanan, S.: Terminate-on-error patch for GDBcli. http://sourceware.org/ml/gdb-patches/2005-08/msg00120.html (2005) Schneider, O.: Redpill getting colorless? http://blog.assarbad.net/wp-content/uploads/2007/04/redpill_getting_colorless.pdf (2007) Rutkowska, J.: Red Pill. http://invisiblethings.org/papers/redpill.html (2004) Klein, T.: Jerry. http://www.trapkit.de/research/vmm/jerry/index.html (2005) Klein, T.: Scoopy Doo. http://www.trapkit.de/research/vmm/scoopydoo/index.html (2005) Kato, K.: VMWare Back. http://chitchat.at.infoseek.co.jp/vmware/backdoor.html (2003) Liston, T., Skoudis, E.: On the cutting edge: thwarting virtual machine detection. http://handlers.sans.org/tliston/ThwartingVMDetection_Liston_Skoudis.pdf (2006) O’Dea, H.: Trapping worms in a virtual net. In: Virus Bulletin 2004 Conference Proceedings (2004) Intel.: Intel architecture software developer’s manual, vol 2: instruction set reference manual. http://developer.intel.com/design/pentiumii/manuals/243191.htm (2003) Quist, D.: Vmdetect. http://www.offensivecomputing.net/dc14/vmdetect.cpp (2006)