A Malware Sample Capturing and Tracking System
Xiao Yu Jiang, Zhiyu Hao, Yanming Wang · 2010
In this paper, we present an effective approach to capture malware samples and track them by simulating and monitoring their network behavior. Furthermore, we design and implement a Malware Sample Capturing and Tracking System (MSCTS), which consists of unknown malware acquisition, automatic analysis, network behavior simulation and information statistics. Experimental results show that MSCTS can effectively capture malware samples, analyze and track them with a better precision. We also discuss some key methods of bot behavior analysis and botnet tracking with MSCTS.