State-based Sandbox Tool for Distributed Malware Detection with Avoid Techniques

A. Sachenko,O. Savenko,P. Rehida,George Markowsky
DOI: https://doi.org/10.1109/DESSERT61349.2023.10416467
2023-10-13
Abstract:This paper deals with the problem of detecting the malware by using emulation approach. Modern malware include various avoid techniques, to hide its anomaly actions. Advantages of using sandbox and emulation technologies are described. Various anti-emulation techniques that are used in modern malware considered. Obfuscation as one primary approach to hide malware malicious actions described and discussed. State of emulator is presented, and the advantages of its usage are covered. Distributed model for malware detection is considered. Basic emulator and its current capabilities presented. Prepared files that represent malware are described. Experimental results for developed files that differs with included avoid techniques are presented. Disadvantages of proposed approach is described. Future research and sandbox improvement are described.
Computer Science
What problem does this paper attempt to address?