Malware analysis method, malware analysis device, and malware analysis system
Abstract
A malware analysis device 10 includes: a dynamic analysis unit 11 which performs dynamic analysis of malware; a communication determination unit 12 which determines whether communication by the malware occurs when the dynamic analysis unit 11 performs dynamic analysis; a static analysis requesting unit 13 which suspends communication when the communication determination unit 12 determines that the communication by the malware occurs to present a request to perform static analysis; and a setting changing unit 14 which sets a device as a communication destination of the malware to make a response obtained by the static analysis as being expected by the malware.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A malware analysis method for performing dynamic analysis of malware, comprising:
determining whether communication by the malware occurs when the malware is dynamically analyzed; suspending communication when the communication by the malware occurs to present a request to perform static analysis; and setting a device as a communication destination of the malware to make a response obtained by the static analysis as being expected by the malware.
2 . The malware analysis method according to claim 1 , further comprising:
resuming the communication by the malware after setting the device as the communication destination of the malware to make the response expected by the malware.
3 . The malware analysis method according to claim 1 , further comprising:
storing the response obtained by the static analysis as being expected by the malware in a response storing database.
4 . The malware analysis method according to claim 2 , further comprising:
storing the response obtained by the static analysis as being expected by the malware in a response storing database.
5 . A malware analysis device comprising:
a dynamic analysis unit which performs dynamic analysis of malware; a communication determination unit which determines whether communication by the malware occurs when the dynamic analysis unit performs dynamic analysis; a static analysis requesting unit which suspends communication when the communication determination unit determines that the communication by the malware occurs to present a request to perform static analysis; and a setting changing unit which sets a device as a communication destination of the malware to make a response obtained by the static analysis as being expected by the malware.
6 . The malware analysis device according to claim 5 , further comprising a communication resuming unit which resumes the communication by the malware after the device as the communication destination of the malware is set to make the response expected by the malware.
7 . The malware analysis device according to claim 5 , wherein the setting changing unit stores, in a response storing database, the response obtained by the static analysis as being expected by the malware.
8 . The malware analysis device according to claim 6 , wherein the setting changing unit stores, in a response storing database, the response obtained by the static analysis as being expected by the malware.
9 . A malware analysis system including a malware analysis device and a pseudo response server which transmits, to malware, a pseudo response as a response expected by the malware, wherein
the malware analysis device comprises:
a dynamic analysis unit which performs dynamic analysis of the malware;
a communication determination unit which determines whether communication by the malware occurs when the dynamic analysis unit performs dynamic analysis;
a static analysis requesting unit which suspends communication when the communication determination unit determines that the communication by the malware occurs to present a request to perform static analysis; and
a setting changing unit which sets the pseudo response server to make a response obtained by the static analysis as being expected by the malware.
10 . The malware analysis system according to claim 9 , wherein the malware analysis device further comprises a communication resuming unit which resumes the communication by the malware after the pseudo response server is set to make the response expected by the malware.
11 . The malware analysis system according to claim 9 ,
wherein the malware analysis device is configured to communicate with the pseudo response server through an open flow switch controlled by an open flow controller, and wherein the setting changing unit transmits, to the open flow controller, an instruction to update a flow table of the open flow switch so that a communication destination of the malware will become the pseudo response server.
12 . The malware analysis system according to claim 10 ,
wherein the malware analysis device is configured to communicate with the pseudo response server through an open flow switch controlled by an open flow controller, and wherein the setting changing unit transmits, to the open flow controller, an instruction to update a flow table of the open flow switch so that a communication destination of the malware will become the pseudo response server.Join the waitlist — get patent alerts
Track US2022030016A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.