Title of article :
A pilot comparative analysis of the Cuckoo and Drakvuf sandboxes: An end-user perspective
Author/Authors :
Ilić ، Slaviša Ž. Ministry of Defense of the Republic of Serbia , Gnjatović ، Milan J. University of Criminal Investigation and Police Studies , Popović ، Brankica M. University of Criminal Investigation and Police Studies , Maček ، Nemanja D. School of Electrical and Computer Engineering - Academy of Technical and Art Applied Studies
From page :
372
To page :
392
Abstract :
Introduction/purpose: This paper reports on a pilot comparative analysis of the Cuckoo and Drakvuf sandboxes. These sandboxes are selected as the subjects of the analysis because of their popularity in the professional community and their complementary approaches to analyzing malware behavior. Methods: Both sandboxes were set up with basic configurations and confronted with the same set of malware samples. The evaluation was primarily conducted with respect to the question of to what extent a sandbox is helpful to the human analyst in malware analysis. Thus, only the information available in Web console reports was considered. Results: Drakvuf is expected to perform better when confronted with evasive malware and so-called file-less malware. Although still not mature in terms of integration, customization and tools, this sandbox is considered a second generation sandbox because of its agentless design. On the other hand, the Cuckoo sandbox creates a better overall experience: it is supported through good documentation and strong professional community, better integrated with various tools, support more virtualization, operating system and sample types, and generates more informative reports. Even with a smaller capacity to prevent evasive malware, its Python 2 agent script makes it more powerful than Drakvuf. Conclusion: To achieve the optimal open-source sandbox-based protection, it is recommended to apply both the Cuckoo and Drakvuf sandboxes. In circumstances of limited resources, applying the Cuckoo sandbox is preferable, especially if exposure to malware deploying evading techniques is not frequently expected.
Keywords :
Sandbox , Cuckoo , Drakvuf , Malware behavior analysis
Journal title :
Military Technical Courier
Journal title :
Military Technical Courier
Record number :
2714450
Link To Document :
بازگشت