节点文献

恶意代码动态分析对抗与反对抗技术综述

Survey on malicious code dynamic analysis evasion and anti-evasion techniques

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 王晨阳; 彭国军; 杨秀璋; 周逸林;

【Author】 WANG Chenyang;PENG Guojun;YANG Xiuzhang;ZHOU Yilin;Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education;School of Cyber Science and Engineering, Wuhan University;State Key Laboratory of Public Big Data, Guizhou University;

【机构】 空天信息安全与可信计算教育部重点实验室; 武汉大学国家网络安全学院; 贵州大学公共大数据国家重点实验室;

【摘要】 动态分析是恶意代码分析与检测的关键技术,能够刻画样本在运行时的真实行为特征。在攻防博弈的过程中,恶意代码采用动态分析对抗技术逃避分析,安全研究人员则通过反对抗技术提升分析系统应对规避型恶意软件的能力。已有综述大多聚焦于攻防技术的设计与实现,缺乏对其与恶意代码动态分析各核心环节之间关联的系统梳理。为此,该研究以恶意代码动态分析的工作流程为主线,从攻防对抗的视角出发,对相关技术进行了系统综述。首先,介绍了动态分析的典型工作流程;其次,总结了对抗技术的设计与实现方式,包括恶意载荷隐藏、分析环境感知、行为捕获逃避及分析模型欺骗技术,剖析其规避机制;再次,整理与归纳了相应的反对抗技术,包括恶意载荷捕获、环境感知规避、行为触发与监控增强及分析模型增强技术,揭示动态分析系统演变背后的攻防对抗逻辑;最后,探讨了恶意代码动态分析领域未来的发展趋势与重点研究方向,以期为恶意代码分析与检测研究提供参考。

【Abstract】 Dynamic analysis serves as a fundamental technique in malicious code analysis and detection, enabling the observation of real-time behaviors exhibited by malicious samples. In the ongoing adversarial arms race, malicious code employs dynamic analysis evasion techniques to evade detection, while defenders develop countermeasures to enhance the capability of dynamic analysis systems to cope with evasive malware. Existing surveys predominantly focus on the design and implementation of individual offensive and defensive techniques, lacking a comprehensive examination of their integration with the core stages of dynamic malicious code analysis. To address this limitation, a systematic survey of evasion techniques and anti-evasion techniques was conducted from an adversarial perspective, structured around the dynamic analysis workflow. First, the typical workflow of malicious code dynamic analysis was introduced. Next, the design and implementation methods of evasion techniques were summarized, including malware payload hiding, environment detection, behavior capture evasion, and analysis model deception, and their evasion strategies were analyzed. Then, the corresponding countermeasures were reviewed, including malicious payload extraction, evasion-resistant environment construction, behavior triggering and monitoring enhancements, and model hardening, and the adversarial interplay driving the evolution of dynamic analysis systems was revealed. Finally, the future development trends and key research directions in the field of dynamic analysis of malicious code were discussed, with the aim of providing references for the research on malicious code analysis and detection.

【基金】 国家自然科学基金(62172308,61972297,62172144,62562012);贵州省基础研究计划(MS[2025]686)~~
  • 【文献出处】 网络与信息安全学报 ,Chinese Journal of Network and Information Security , 编辑部邮箱 ,2025年06期
  • 【分类号】TP309;TP311.5
  • 【下载频次】50
节点文献中: 

本文链接的文献网络图示:

本文的引文网络