Honeytrap Resilience: A Study of Malware Redirection Awareness
Eric Edge, James H. Jones, Kathryn Blackmond Laskey · 2025
This research investigates the ability of self-propagating malware to detect network redirection, a technique that reroutes malicious traffic to a controlled environment for analysis. We hypothesized that malware programs might use round-trip time (RTT) as a signal to detect redirection. To test this, we executed a large dataset of malware samples in a controlled environment and analyzed their behavior, measured by application programming interface (API) call patterns. Our results indicate that the malware samples were not sensitive to network redirection, as there were no significant differences in their behavior between redirected and nonredirected scenarios. These findings suggest that network redirection remains a valuable tool for analyzing malicious traffic, even in the face of potential evasion techniques.