Spotless Sandboxes: Evading Malware Analysis Systems Using Wear-and-Tear Artifacts
Najmeh Miramirkhani, Mahathi Priya Appini, Nick Nikiforakis, Michalis Polychronakis
Abstract
Malware sandboxes, widely used by antivirus companies, mobile application marketplaces, threat detection appliances, and security researchers, face the challenge of environment-aware malware that alters its behavior once it detects that it is being executed on an analysis environment. Recent efforts attempt to deal with this problem mostly by ensuring that well-known properties of analysis environments are replaced with realistic values, and that any instrumentation artifacts remain hidden. For sandboxes implemented using virtual machines, this can be achieved by scrubbing vendor-specific drivers, processes, BIOS versions, and other VM-revealing indicators, while more sophisticated sandboxes move away from emulation-based and virtualization-based systems towards bare-metal hosts. We observe that as the fidelity and transparency of dynamic malware analysis systems improves, malware authors can resort to other system characteristics that are indicative of artificial environments. We present a novel class of sandbox evasion techniques that exploit the "wear and tear" that inevitably occurs on real systems as a result of normal use. By moving beyond how realistic a system looks like, to how realistic its past use looks like, malware can effectively evade even sandboxes that do not expose any instrumentation indicators, including bare-metal systems. We investigate the feasibility of this evasion strategy by conducting a large-scale study of wear-and-tear artifacts collected from real user devices and publicly available malware analysis services. The results of our evaluation are alarming: using simple decision trees derived from the analyzed data, malware can determine that a system is an artificial environment and not a real user device with an accuracy of 92.86%. As a step towards defending against wear-and-tear malware evasion, we develop statistical models that capture a system's age and degree of use, which can be used to aid sandbox operators in creating system images that exhibit a realistic wear-and-tear state.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f679d293-4eac-46e3-b39a-eeeff2783960Cited by top-tier papers12
- Survivalism: Systematic Analysis of Windows Malware Living-Off-The-LandFrederick Barr-Smith, Xabier Ugarte-Pedrero, Mariano Graziano, Riccardo Spolaor et al.S&P 2021 · 73 citations
- DeepReflect: Discovering Malicious Functionality through Binary ReconstructionEvan Downing, Yisroel Mirsky, Kyuhong Park, Wenke LeeUSENIX Security 2021 · 43 citations
- Decoding the Secrets of Machine Learning in Malware Classification: A Deep Dive into Datasets, Feature Extraction, and Model PerformanceSavino Dambra, Yufei Han, Simone Aonzo, Platon Kotzias et al.CCS 2023 · 28 citations
- Schrödinger's RAT: Profiling the Stakeholders in the Remote Access Trojan EcosystemMohammad Rezaeirad, Brown Farinholt, Hitesh Dharmdasani, Paul Pearce et al.USENIX Security 2018 · 22 citations
- U Can't Debug This: Detecting JavaScript Anti-Debugging Techniques in the WildMarius Musch, Martin JohnsUSENIX Security 2021 · 8 citations
Related papers
- The Droid is in the Details: Environment-aware Evasion of Android SandboxesBrian Kondracki, Babak Amin Azad, Najmeh Miramirkhani, Nick NikiforakisNDSS 2022
- Does Every Second Count? Time-based Evolution of Malware Behavior in SandboxesAlexander Küchler, Alessandro Mantovani, Yufei Han, Leyla Bilge et al.NDSS 2021
- DRSM: De-Randomized Smoothing on Malware Classifier Providing Certified RobustnessShoumik Saha, Wenxiao Wang, Yigitcan Kaya, Soheil Feizi et al.ICLR 2024 · 6 citations
- Things You May Not Know About Android (Un)Packers: A Systematic Study based on Whole-System EmulationYue Duan, Mu Zhang, Abhishek Vasisht Bhaskar, Heng Yin et al.NDSS 2018 · 87 citations
- Towards Transparent and Stealthy Android OS Sandboxing via Customizable Container-Based VirtualizationWenna Song, Jiang Ming, Lin Jiang, Yi Xiang et al.CCS 2021 · 11 citations
