Paper Abstract and Keywords |
Presentation |
2022-11-21 16:20
Outsourcing Malware Dynamic Analysis without Disclosing File Contents Keisuke Hamajima, Daisuke Kotani, Yasuo Okabe (Kyoto Univ.) IA2022-44 |
Abstract |
(in Japanese) |
(See Japanese page) |
(in English) |
Malware dynamic analysis requires specialized skills. If there are no security experts in the organization and it is difficult to analyze malware, one way to get the results of the analysis is to ask an analyst outside the organization to analyze a suspicious file. However, if the file to be analyzed contains confidential information, it is undesirable to disclose the confidential information to the analyst outside the organization. In this study, we propose a method to outsource dynamic analysis. Executing a file in the local environment and keeping the file secret from the analyst. During the analysis, information about API calls and the memory pointed to by the pointers as their argument is shared with the external environment. We evaluate the effectiveness and limitations of the proposed method for evasion techniques. |
Keyword |
(in Japanese) |
(See Japanese page) |
(in English) |
Malware / Dynamic Analysis / Evasion Technique / Privacy / Hooking API calls / / / |
Reference Info. |
IEICE Tech. Rep., vol. 122, no. 268, IA2022-44, pp. 47-51, Nov. 2022. |
Paper # |
IA2022-44 |
Date of Issue |
2022-11-14 (IA) |
ISSN |
Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
Download PDF |
IA2022-44 |
Conference Information |
Committee |
IA |
Conference Date |
2022-11-21 - 2022-11-21 |
Place (in Japanese) |
(See Japanese page) |
Place (in English) |
Bandai Civic Hall (Niigata) |
Topics (in Japanese) |
(See Japanese page) |
Topics (in English) |
Student Sessions, etc. (cosponsored by Committee on Internet Technology) |
Paper Information |
Registration To |
IA |
Conference Code |
2022-11-IA |
Language |
Japanese |
Title (in Japanese) |
(See Japanese page) |
Sub Title (in Japanese) |
(See Japanese page) |
Title (in English) |
Outsourcing Malware Dynamic Analysis without Disclosing File Contents |
Sub Title (in English) |
|
Keyword(1) |
Malware |
Keyword(2) |
Dynamic Analysis |
Keyword(3) |
Evasion Technique |
Keyword(4) |
Privacy |
Keyword(5) |
Hooking API calls |
Keyword(6) |
|
Keyword(7) |
|
Keyword(8) |
|
1st Author's Name |
Keisuke Hamajima |
1st Author's Affiliation |
Kyoto University (Kyoto Univ.) |
2nd Author's Name |
Daisuke Kotani |
2nd Author's Affiliation |
Kyoto University (Kyoto Univ.) |
3rd Author's Name |
Yasuo Okabe |
3rd Author's Affiliation |
Kyoto University (Kyoto Univ.) |
4th Author's Name |
|
4th Author's Affiliation |
() |
5th Author's Name |
|
5th Author's Affiliation |
() |
6th Author's Name |
|
6th Author's Affiliation |
() |
7th Author's Name |
|
7th Author's Affiliation |
() |
8th Author's Name |
|
8th Author's Affiliation |
() |
9th Author's Name |
|
9th Author's Affiliation |
() |
10th Author's Name |
|
10th Author's Affiliation |
() |
11th Author's Name |
|
11th Author's Affiliation |
() |
12th Author's Name |
|
12th Author's Affiliation |
() |
13th Author's Name |
|
13th Author's Affiliation |
() |
14th Author's Name |
|
14th Author's Affiliation |
() |
15th Author's Name |
|
15th Author's Affiliation |
() |
16th Author's Name |
|
16th Author's Affiliation |
() |
17th Author's Name |
|
17th Author's Affiliation |
() |
18th Author's Name |
|
18th Author's Affiliation |
() |
19th Author's Name |
|
19th Author's Affiliation |
() |
20th Author's Name |
|
20th Author's Affiliation |
() |
21st Author's Name |
|
21st Author's Affiliation |
() |
22nd Author's Name |
|
22nd Author's Affiliation |
() |
23rd Author's Name |
|
23rd Author's Affiliation |
() |
24th Author's Name |
|
24th Author's Affiliation |
() |
25th Author's Name |
|
25th Author's Affiliation |
() |
26th Author's Name |
/ / |
26th Author's Affiliation |
()
() |
27th Author's Name |
/ / |
27th Author's Affiliation |
()
() |
28th Author's Name |
/ / |
28th Author's Affiliation |
()
() |
29th Author's Name |
/ / |
29th Author's Affiliation |
()
() |
30th Author's Name |
/ / |
30th Author's Affiliation |
()
() |
31st Author's Name |
/ / |
31st Author's Affiliation |
()
() |
32nd Author's Name |
/ / |
32nd Author's Affiliation |
()
() |
33rd Author's Name |
/ / |
33rd Author's Affiliation |
()
() |
34th Author's Name |
/ / |
34th Author's Affiliation |
()
() |
35th Author's Name |
/ / |
35th Author's Affiliation |
()
() |
36th Author's Name |
/ / |
36th Author's Affiliation |
()
() |
Speaker |
Author-1 |
Date Time |
2022-11-21 16:20:00 |
Presentation Time |
25 minutes |
Registration for |
IA |
Paper # |
IA2022-44 |
Volume (vol) |
vol.122 |
Number (no) |
no.268 |
Page |
pp.47-51 |
#Pages |
5 |
Date of Issue |
2022-11-14 (IA) |