使用Hyper-V套接字从恶意软件分析沙箱中进行实时数据提取
Using Hyper-V Sockets for Real-time Data Extraction from a Malware Analysis Sandbox
首次发表
浏览论文内容
中文总结 AI 辅助
本研究提出将Hyper-V套接字用作恶意软件分析沙箱的实时通信通道,对比其与WinSock TCP套接字的特性及吞吐量差异,为恶意软件分析提供新的通信方案。
中文摘要 AI 辅助
我们展示了Hyper-V套接字如何用作恶意软件分析沙箱的实时通信通道。与WinSock TCP套接字相比,Hyper-V套接字不受TCP/IP层阻塞影响,也不会被常见TCP连接列表工具枚举。我们比较了两种通信通道的吞吐量与缓冲区大小的函数关系。
英文摘要
We present how Hyper-V sockets can be used as a real-time communication channel for a malware analysis sandbox. We show that, compared to WinSock TCP sockets, Hyper-V sockets are not subject to TCP/IP-layer blocking and are not enumerated by common TCP connection listing tools. We compare the throughput of the two communication channels as a function of buffer size.
发表机构
- Technical University of Cluj-Napoca(克卢日-纳波卡技术大学)
- Bitdefender(比特梵德)
机构由 AI 辅助整理,请以论文原文为准。