A method to detect the presence of virtual environment in the analysis of malware
DOI:
Author:
Affiliation:

Funding:

Ethical statement:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
    Abstract:

    Security Companies usually apply virtual environment to analyze malware,whereas a large amount of current malware already adopts various VMware detection techniques in order to resist analysis. In this paper,three main methods for detecting the presence of virtual environment are presented,as well as their countermeasures. A performance related method to detect the presence of virtual machine or emulator is designed,which can successfully detect the presence of virtual environment,such as VMware and Qemu,etc.

    Reference
    Related
    Cited by
Get Citation

吴发伟,方 勇,刘 亮.一种恶意软件分析中检测虚拟环境的方法[J]. Journal of Terahertz Science and Electronic Information Technology ,2010,8(3):364~367

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
History
  • Received:November 16,2009
  • Revised:December 28,2009
  • Adopted:
  • Online:
  • Published: