US2022030016A1PendingUtilityA1

Malware analysis method, malware analysis device, and malware analysis system

Assignee: NEC CORPPriority: Mar 30, 2017Filed: Aug 9, 2021Published: Jan 27, 2022
Est. expiryMar 30, 2037(~10.7 yrs left)· nominal 20-yr term from priority
H04L 63/145G06F 21/554G06F 2221/033G06F 21/562G06F 21/566G06F 16/22H04L 63/1416
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A malware analysis device 10 includes: a dynamic analysis unit 11 which performs dynamic analysis of malware; a communication determination unit 12 which determines whether communication by the malware occurs when the dynamic analysis unit 11 performs dynamic analysis; a static analysis requesting unit 13 which suspends communication when the communication determination unit 12 determines that the communication by the malware occurs to present a request to perform static analysis; and a setting changing unit 14 which sets a device as a communication destination of the malware to make a response obtained by the static analysis as being expected by the malware.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A malware analysis method for performing dynamic analysis of malware, comprising:
 determining whether communication by the malware occurs when the malware is dynamically analyzed;   suspending communication when the communication by the malware occurs to present a request to perform static analysis; and   setting a device as a communication destination of the malware to make a response obtained by the static analysis as being expected by the malware.   
     
     
         2 . The malware analysis method according to  claim 1 , further comprising:
 resuming the communication by the malware after setting the device as the communication destination of the malware to make the response expected by the malware.   
     
     
         3 . The malware analysis method according to  claim 1 , further comprising:
 storing the response obtained by the static analysis as being expected by the malware in a response storing database.   
     
     
         4 . The malware analysis method according to  claim 2 , further comprising:
 storing the response obtained by the static analysis as being expected by the malware in a response storing database.   
     
     
         5 . A malware analysis device comprising:
 a dynamic analysis unit which performs dynamic analysis of malware;   a communication determination unit which determines whether communication by the malware occurs when the dynamic analysis unit performs dynamic analysis;   a static analysis requesting unit which suspends communication when the communication determination unit determines that the communication by the malware occurs to present a request to perform static analysis; and   a setting changing unit which sets a device as a communication destination of the malware to make a response obtained by the static analysis as being expected by the malware.   
     
     
         6 . The malware analysis device according to  claim 5 , further comprising a communication resuming unit which resumes the communication by the malware after the device as the communication destination of the malware is set to make the response expected by the malware. 
     
     
         7 . The malware analysis device according to  claim 5 , wherein the setting changing unit stores, in a response storing database, the response obtained by the static analysis as being expected by the malware. 
     
     
         8 . The malware analysis device according to  claim 6 , wherein the setting changing unit stores, in a response storing database, the response obtained by the static analysis as being expected by the malware. 
     
     
         9 . A malware analysis system including a malware analysis device and a pseudo response server which transmits, to malware, a pseudo response as a response expected by the malware, wherein
 the malware analysis device comprises:
 a dynamic analysis unit which performs dynamic analysis of the malware; 
 a communication determination unit which determines whether communication by the malware occurs when the dynamic analysis unit performs dynamic analysis; 
 a static analysis requesting unit which suspends communication when the communication determination unit determines that the communication by the malware occurs to present a request to perform static analysis; and 
 a setting changing unit which sets the pseudo response server to make a response obtained by the static analysis as being expected by the malware. 
   
     
     
         10 . The malware analysis system according to  claim 9 , wherein the malware analysis device further comprises a communication resuming unit which resumes the communication by the malware after the pseudo response server is set to make the response expected by the malware. 
     
     
         11 . The malware analysis system according to  claim 9 ,
 wherein the malware analysis device is configured to communicate with the pseudo response server through an open flow switch controlled by an open flow controller, and   wherein the setting changing unit transmits, to the open flow controller, an instruction to update a flow table of the open flow switch so that a communication destination of the malware will become the pseudo response server.   
     
     
         12 . The malware analysis system according to  claim 10 ,
 wherein the malware analysis device is configured to communicate with the pseudo response server through an open flow switch controlled by an open flow controller, and   wherein the setting changing unit transmits, to the open flow controller, an instruction to update a flow table of the open flow switch so that a communication destination of the malware will become the pseudo response server.

Join the waitlist — get patent alerts

Track US2022030016A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.