Fighting Evasive Malware: How to Pass the Reverse Turing Test By Utilizing a VMI-Based Human Interaction Simulator
Zusammenfassung
Sandboxes are an indispensable tool in dynamic malware analysis today. However, modern malware often employs sandbox-detection methods to exhibit non-malicious behavior within sandboxes and therefore evade automatic analysis. One category of sandbox-detection techniques are reverse Turing tests (RTTs) to determine the presence of a human operator. In order to pass these RTTs, we propose a novel approach which builds upon virtual machine introspection (VMI) to automatically reconstruct the graphical user interface, determine clickable buttons and inject human interface device events via direct control of virtualized human interface devices in a stealthy way. We extend the VMI-based open-source sandbox DRAKVUF with our approach and show that it successfully passes RTTs commonly employed by malware in the wild to detect sandboxes
- Vollständige Referenz
- BibTeX
Gruber, J. & Freiling, F. C.,
(2022).
Fighting Evasive Malware: How to Pass the Reverse Turing Test By Utilizing a VMI-Based Human Interaction Simulator.
In:
Christian Wressnegger, D. R.
(Hrsg.),
GI SICHERHEIT 2022.
Gesellschaft für Informatik, Bonn.
(S. 49-64).
DOI: 10.18420/sicherheit2022_03
@inproceedings{mci/Gruber2022,
author = {Gruber, Jan AND Freiling, Felix C.},
title = {Fighting Evasive Malware: How to Pass the Reverse Turing Test By Utilizing a VMI-Based Human Interaction Simulator},
booktitle = {GI SICHERHEIT 2022},
year = {2022},
editor = {Christian Wressnegger, Delphine Reinhardt} ,
pages = { 49-64 } ,
doi = { 10.18420/sicherheit2022_03 },
publisher = {Gesellschaft für Informatik, Bonn},
address = {}
}
author = {Gruber, Jan AND Freiling, Felix C.},
title = {Fighting Evasive Malware: How to Pass the Reverse Turing Test By Utilizing a VMI-Based Human Interaction Simulator},
booktitle = {GI SICHERHEIT 2022},
year = {2022},
editor = {Christian Wressnegger, Delphine Reinhardt} ,
pages = { 49-64 } ,
doi = { 10.18420/sicherheit2022_03 },
publisher = {Gesellschaft für Informatik, Bonn},
address = {}
}
Sollte hier kein Volltext (PDF) verlinkt sein, dann kann es sein, dass dieser aus verschiedenen Gruenden (z.B. Lizenzen oder Copyright) nur in einer anderen Digital Library verfuegbar ist. Versuchen Sie in diesem Fall einen Zugriff ueber die verlinkte DOI: 10.18420/sicherheit2022_03
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
ISBN: 978-3-88579-717-3
ISSN: 1617-5468
Datum: 2022
Sprache:
(en)
(en)
