Method for Distributed Detection Malicious Activity Based on Analysis of Execution Behavior
Pavlo Rehida, Олег Савенко, Antonina Kashtalian, Anatoliy Sachenko · 2024
This article explores the challenges of detecting malware that employs various evasion techniques. Key malware masking techniques are described and analysed. The impact of polymorphism techniques on the execution of low-level instructions is examined in detail. A method is presented for forming program execution behaviour. The proposed approach involves a software tool consisting of an emulator and a sandbox. An approach for forming program behaviour based on compiled states is introduced. The method involving the computer system, modified isolated environments, and analysis of program execution behaviour is demonstrated. Experiments are described, and conclusions are drawn regarding the improvement of malware detection accuracy using the proposed approach.