How to Locate a Target Binary Process and Its Derivatives in System Emulator
Hyung Chan Kim, Daisuke Inoue, Masashi Eto, Jungsuk Song, Koji Nakao · 2010
Many parties for analyzing malwares have been deployed several types of dynamic binary analysis systems. In such systems, a given malware specimen is inserted and monitoring modules profile the behavior of the malware to compile analysis results. However, many malwares generate derivative processes by making child processes and/or interposing behavior into other processes. In this paper, we describe an architecture of an extended system emulator (Livex) to instrument sample malware processes in parallel. Livex is built upon QEMU whole system emulator. For a given target binary specimen, our system tries to probe its derivative processes and monitor them together with the main process. This paper includes experiments to look at the applicability of our method with synthetic programs as well as real malware specimens.