SecBox: A Lightweight Container-based Sandbox for Dynamic Malware Analysis

Jan von der Assen, Alberto Huertas Celdrán, Adrian Zermin, Raffael Mogicato, Gérôme Bovet, Burkhard Stiller · 2023

Cybersecurity solutions based on machine learning (ML) and behavioral fingerprinting have demonstrated their suitability when detecting heterogeneous malware. However, most solutions are black boxes missing explainable and visual capabilities needed to analyze relevant metrics and malicious behaviors to be collected. In this demonstration, SecBox, a dynamic malware analysis platform with integrated data collection and visualization for malware execution, is presented. To provide a lightweight sandboxing approach, the architecture relies on Linux containers for isolation. The sandboxing and data analysis components of the SecBox architecture are deployed in a test bed to show the analysis of two malware families. In the presented scenario, the Monti ransomware and CoinMiner, a Monero-based cryptojacker are analyzed after obtaining them from a public database.

Read the paper · More papers on PaperTik