Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Case Study: Analysis and Mitigation of a Novel Sandbox-Evasion Technique
Genç, Ziya Alper; Lenzini, Gabriele; Sgandurra, Daniele
2019In Proceedings of the Third Central European Cybersecurity Conference
Peer reviewed
 

Files


Full Text
cecc2019GLS.pdf
Author postprint (637.83 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
malware; evasion; stateless; detection; ransomware
Abstract :
[en] Malware is one of the most popular cyber-attack methods in the digital world. According to the independent test company AV-TEST, 350,000 new malware samples are created every day. To analyze all samples by hand to discover whether they are malware does not scale, so antivirus companies automate the process e.g., using sand- boxes where samples can be run, observed, and classified. Malware authors are aware of this fact, and try to evade detection. In this paper we describe one of such evasion technique: unprecedented, we discovered it while analyzing a ransomware sample. Analyzed in a Cuckoo Sandbox, the sample was able to avoid triggering malware indicators, thus scoring significantly below the minimum severity level. Here, we discuss what strategy the sample follows to evade the analysis, proposing practical defense methods to nullify, in our turn, the sample’s furtive strategy.
Research center :
EU's Horizon 2020 Research and Innovation Programme
Disciplines :
Computer science
Author, co-author :
Genç, Ziya Alper ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Lenzini, Gabriele ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Sgandurra, Daniele;  Royal Holloway, University of London > Department of Information Security
External co-authors :
yes
Language :
English
Title :
Case Study: Analysis and Mitigation of a Novel Sandbox-Evasion Technique
Publication date :
2019
Event name :
The Third Central European Cybersecurity Conference
Event organizer :
University of Maribor
ZITiS
Event place :
Munich, Germany
Event date :
14–15 November 2019
Audience :
International
Main work title :
Proceedings of the Third Central European Cybersecurity Conference
Publisher :
ACM, New York, United States
ISBN/EAN :
978-1-4503-7296-1
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
European Projects :
H2020 - 779391 - FutureTPM - Future Proofing the Connected World: A Quantum-Resistant Trusted Platform Module
FnR Project :
FNR13234766 - No More Cryptographic Ransomware, Proof Of Concept, 2018 (01/11/2018-31/01/2021) - Gabriele Lenzini
Funders :
FNR - Fonds National de la Recherche [LU]
CE - Commission Européenne [BE]
Available on ORBilu :
since 02 October 2019

Statistics


Number of views
198 (27 by Unilu)
Number of downloads
169 (6 by Unilu)

Scopus citations®
 
0
Scopus citations®
without self-citations
0
OpenCitations
 
0
WoS citations
 
0

Bibliography


Similar publications



Contact ORBilu