Environment simulation and behavior confusion method for resisting anti-sandbox and anti-virtual machine
By dynamically disguising the hardware environment, hiding virtualization features, simulating network environments, user behavior simulation and system time interference, the problem of sandbox and virtual machine technology being unable to fight anti-sandbox and anti-virtual machine is solved, and the normal operation and security analysis of malware in the virtual environment is realized.
Patent Information
- Application Number
- CN202510947608.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-10
- Publication Date
- 2025-08-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing sandbox and virtual machine technologies cannot effectively fight against anti-sandbox and anti-virtual machine behaviors. The malware recognizes the virtual environment through self-detection and adopts a self-protection mechanism to avoid analysis and research.
We adopt methods such as dynamically disguising the hardware environment, hiding virtualization features, simulating network environments, user behavior simulation, system time interference, obfuscating API calls and secure logging analysis to comprehensively optimize sandbox and virtual machine technology, disguising the virtual machine environment, simulating real hardware behavior and hiding virtual features.
Effectively avoid malware to identify the virtualized environment, ensure that malicious samples run normally in the virtual environment, prevent harm from occurring in the real environment, and save resources while fighting anti-sandbox and anti-virtual machine technologies.
Smart Images

Figure CN120455170A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to an environment simulation and behavior obfuscation method for resisting anti-sandbox and anti-virtual machine. Background Art
[0002] Sandbox and virtual machine technologies are currently widely used in the field of network security for malware analysis and threat detection. Sandbox technology executes suspicious files or programs in an isolated environment to observe their behavior and analyze potential threats. Virtual machine technology simulates real hardware environments, providing malware with an execution environment similar to a real operating system. However, traditional sandbox and virtual machine environments often have some obvious virtual characteristics, such as small running memory, the presence of iconic virtual processes, systematic behavior and lack of user characteristics; these virtual characteristics can usually be detected by malware, thereby triggering anti-sandbox and anti-virtual machine behavior; in this environment, malware usually identifies sandbox and virtual machine environments through self-detection and then adopts self-protection mechanisms, such as not starting or self-deleting programs, to avoid analysis and research; upgraded sandbox and virtual machine technologies can mostly only perform local optimization for specific detection methods, but still cannot effectively counter anti-sandbox and anti-virtual machine technologies. Summary of the Invention
[0003] The purpose of the present invention is to solve the shortcomings of the prior art and to propose an environment simulation and behavior obfuscation method to resist anti-sandbox and anti-virtual machine.
[0004] To achieve the above object, the present invention adopts the following technical solutions: A method for environmental simulation and behavior obfuscation against anti-sandbox and anti-virtual machine environments, comprising the following steps: S1: Dynamic camouflage hardware environment; Dynamically simulate and disguise the hardware environment inside the virtual machine through virtual machine monitoring programs such as VMware and VirtualBox, including CPU parameter disguise, memory information disguise, hard disk information disguise, and other device disguise; The following sub-steps are included: S11: Disguise CPU parameters; The CPU parameter disguise includes disguising the number of CPU cores, disguising the CPU architecture, turning on or off advanced functions, etc. Generates random CPU core counts based on real hardware distribution to simulate different CPU configurations; the core counts include 4-core, 6-core, and 8-core; masquerades different CPU architectures, such as Intel and AMD, and generates configurations based on actual hardware; and enables or disables specific advanced features in the virtualized environment, including encryption acceleration and virtualization technology support. S12: Disguise memory information; The memory information disguise includes disguising the memory size, memory brand and model, etc.; Randomly simulate different memory sizes, such as 8GB, 16GB, 32GB, etc., and disguise different memory brands and models; S13: Disguise hard disk information; The hard disk information disguise includes disguising the hard disk capacity, interface type, etc.; Dynamically generate hard drive capacities such as 500GB, 1TB, 2TB, etc., and disguise the hard drive interface type, model, and brand; S14: Disguise other devices; The other devices disguised include graphics cards, network cards, USB interfaces, etc. Simulate different graphics card models and brands and randomly generate graphics card drivers and performance data; disguise network card type, manufacturer, MAC address, etc.; simulate the hardware characteristics of a real computer by dynamically adjusting the number and model of USB ports.
[0005] S2: Hide virtualization features; Hiding virtualization features includes hiding virtual machine traces, hiding virtual machine files, and hiding network features. The steps are as follows: S21: Hide virtual machine traces; Hiding virtual machine traces includes modifying the file name of the virtual machine process, hiding the virtual machine background service, and virtualizing the CPUID instruction; Use a process renaming tool to change the virtual machine process's file name to a normal system process name; manually edit registry entries to disguise the virtual machine's background service as a Windows system service, and modify the return value of the CPUID instruction to simulate the response of a physical machine; S22: Hide virtual machine files; Hiding virtual machine files includes hiding virtual machine file paths, deleting virtual machine related registry information, and cleaning up virtualization software traces; Place the virtual machine configuration file in an inconspicuous folder, delete the specific registry entries created by the virtualization software, and delete the installation logs, configuration files, and other traces of the virtualization software; S23: hidden network features; The hidden network features include modifying the virtual machine network card address, simulating virtual machine network delay, responding to false domain names, etc. Manually change the specific network card address used by the virtual machine to a common network card address; use a network delay simulation tool to introduce network delay fluctuations into the virtual machine; set up DNS masquerading to map the virtual machine's dedicated domain name to a fake response.
[0006] S3: simulated network environment; The following sub-steps are included: S31: camouflage network connection; Use common intranet IP addresses to disguise network connections, and set rules in the router or firewall to ensure that the real public IP address is not leaked when using the intranet IP address; Use the tc command to simulate network latency and set the latency fluctuation range. Use the tc command to simulate packet loss and configure the probability range for packet loss. Periodically modify the latency fluctuation range and packet loss probability range to simulate dynamic changes in the network environment. S32: Build an intelligent DNS response platform; Use DNS server software to build a DNS response platform, and use DNS filtering software combined with machine learning algorithms to disguise suspicious domain names. When the DNS query finds a malicious or unknown domain name, the server returns a normal public DNS address.
[0007] S4: User behavior simulation; The following sub-steps are included: S41: simulate intelligent mouse operation; The Markov chain model is used to set the mouse's movement speed and direction, making the mouse's trajectory show random but regular changes, simulating the human thinking and operation process when using a mouse; When the mouse approaches a key action button or link, a hover time is set to simulate the thinking process of a human user before clicking; the hover time is random; Furthermore, multiple different style templates are defined to adjust the mouse movement style according to different scenarios, including browsing web pages, filling out forms, etc. S42: Simulating dynamic keyboard input based on behavioral entropy model; Use behavioral entropy models to control input rhythm, simulate different input speeds and changes; dynamically adjust input speed according to different input scenarios; The behavioral entropy model has built-in multiple common input error types to simulate the deletion behavior of real people when inputting; S43: Optimize user operating habits through the intelligent operating habit system; The intelligent operation habit system collects and analyzes the target user's operation habits, breaks down the operation steps, and constructs the operation steps into a natural workflow; the intelligent operation habit system adjusts the operation habits according to the user's different operation needs, such as work mode, entertainment mode, leisure mode, etc. Intelligent fluctuations are added to the operation intervals, and the size of the fluctuations is dynamically adjusted according to the specific operation and the importance of the task; S44: Realize human operation logic simulation through intelligent adjustment system; Simulate human operating habits and behaviors when performing tasks to ensure that the intelligent adjustment system responds to actual user operations; reduce unnecessary computing and resource consumption through caching strategies and behavior optimization.
[0008] S5: Perform system time interference; The following sub-steps are included: S51: Perform clock source camouflage; Adjust the clock synchronization mechanism in the operating system to make the difference between the operating system clock and the CPU clock reasonable; Disguising the system's operating time by artificially adding time periods to the system, where the time periods range from several months to several years; By adjusting the system's time zone settings or directly modifying the system clock value, the attack target's geographical location can be disguised as the local time of the target area; S52: Handling special scenarios; Implement time hooks in the operating system to monitor and synchronize time changes, and intercept system time API calls to ensure that different threads and programs react correctly when time changes; By introducing a locking mechanism or synchronization variable to ensure that no race conditions occur when the time changes, time synchronization between threads can be achieved; Dynamically adjust the timestamp of events to ensure that the time characteristics are consistent with the system time at all times.
[0009] S6: Obfuscate and disguise API calls; The following sub-steps are included: S61: Randomly inserting harmless calls to disrupt malware monitoring of the system; Select harmless API calls that have no actual impact on system operation and dynamically insert them before and after the actual critical API calls. The order and number of inserted harmless calls are randomized each time the program is executed. S62: Call the disguise chain; Record the call history of the target software and analyze the API call patterns of different types of software; simulate the call chain and dynamically generate different call chains based on the software type each time it is run; adjust the order, frequency and time interval of API calls by generating log files or storing in a database to disguise the API call history.
[0010] S7: Dynamic behavior adjustment; Real-time monitoring of the execution behavior of malicious samples in virtualized environments to capture anti-VM instructions contained therein. When anti-VM instructions are detected, the camouflage strength is enhanced by increasing the variation of hardware parameters and expanding the range of network latency fluctuations. Specifically, the hardware parameters of the virtual machine are dynamically adjusted according to the execution requirements of the malicious sample, including increasing the operating frequency of the virtual CPU, memory size, or hard disk capacity, to enhance the camouflage strength; By expanding the range of network delay fluctuations, such as dynamically simulating the processing time of network requests and changing parameters such as transmission rate and throughput in network transmission protocols, the camouflage strength can be enhanced.
[0011] S8: Security log record analysis; Use encrypted differential log technology to record the system's original state before operation and the system state after disguise; For key behavioral events, such as file execution, process startup, network communication, etc., digital signatures are added synchronously when recording.
[0012] Compared with the prior art, the present invention has the following beneficial effects: This method comprehensively optimizes and upgrades sandbox and virtual machine technologies from eight aspects: dynamic environment camouflage, virtualization feature hiding, network environment simulation, user behavior simulation, system time interference, API obfuscation call, dynamic behavior, and security log record analysis and adjustment; it makes it difficult for malware or attack tools to determine whether the system is in a virtualized environment, thereby effectively avoiding detection and analysis; while saving resources as much as possible, it fights against the anti-sandbox and anti-virtual machine technologies of malicious Trojan files, allowing malicious sample files to run normally in a virtual environment for research and analysis, avoiding damage to devices and networks in a real environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 This is a flowchart of the steps of the environment simulation and behavior obfuscation method for resisting anti-sandbox and anti-virtual machine of the present invention. DETAILED DESCRIPTION
[0014] In order to provide a further understanding of the purpose, structure, features, and functions of the present invention, the present invention is described in detail below with reference to the embodiments.
[0015] like Figure 1As shown, a method for environmental simulation and behavior obfuscation against anti-sandbox and anti-virtual machine environments includes the following steps: S1: Dynamic camouflage hardware environment; Dynamically simulate and disguise the hardware environment inside the virtual machine through virtual machine monitoring programs such as VMware and VirtualBox, including CPU parameter disguise, memory information disguise, hard disk information disguise, and other device disguise; The following sub-steps are included: S11: Disguise CPU parameters; The CPU parameter disguise includes disguising the number of CPU cores, disguising the CPU architecture, turning on or off advanced functions, etc. Generates random CPU core counts based on real hardware distribution to simulate different CPU configurations; the core counts include 4-core, 6-core, and 8-core; masquerades different CPU architectures, such as Intel and AMD, and generates configurations based on actual hardware; and enables or disables specific advanced features in the virtualized environment, including encryption acceleration and virtualization technology support. S12: Disguise memory information; The memory information disguise includes disguising the memory size, memory brand and model, etc.; Randomly simulate different memory sizes, such as 8GB, 16GB, 32GB, etc., and disguise different memory brands (such as Samsung, Kingston, etc.) and models; S13: Disguise hard disk information; The hard disk information disguise includes disguising the hard disk capacity, interface type, etc.; Dynamically generate hard drive capacities such as 500GB, 1TB, and 2TB, and disguise the hard drive interface type (SATA, NVMe), model, and brand (Western Digital, Seagate, etc.); S14: Disguise other devices; The other devices disguised include graphics cards, network cards, USB interfaces, etc. Simulate different graphics card models and brands and randomly generate graphics card drivers and performance data; disguise network card type, manufacturer, MAC address, etc.; simulate the hardware characteristics of a real computer by dynamically adjusting the number and model of USB ports.
[0016] By disguising the hardware environment, the environment in which the virtual machine runs looks like a real physical machine, making it difficult for external systems or detection tools to identify it, thereby improving the concealment of the virtual machine and reducing the risk of being identified by anti-sandbox or anti-virtual machine mechanisms.
[0017] S2: Hide virtualization features; Hiding virtualization features includes hiding virtual machine traces, hiding virtual machine files, and hiding network features. The steps are as follows: S21: Hide virtual machine traces; Hiding virtual machine traces includes modifying the file name of the virtual machine process, hiding the virtual machine background service, and virtualizing the CPUID instruction; Use a process renaming tool to change the virtual machine process's file name to a normal system process name; manually edit registry entries to disguise the virtual machine's background service as a Windows system service, and modify the return value of the CPUID instruction to simulate the response of a physical machine; S22: Hide virtual machine files; Hiding virtual machine files includes hiding virtual machine file paths, deleting virtual machine related registry information, and cleaning up virtualization software traces; Place the virtual machine configuration file in an inconspicuous folder, delete the specific registry entries created by the virtualization software, and delete the installation logs, configuration files, and other traces of the virtualization software; S23: hidden network features; The hidden network features include modifying the virtual machine network card address, simulating virtual machine network delay, responding to false domain names, etc. Manually change the specific network card address used by the virtual machine to a common network card address; use a network delay simulation tool to introduce network delay fluctuations into the virtual machine; set up DNS masquerading to map the virtual machine's dedicated domain name to a fake response.
[0018] By hiding the virtual machine's processes and traces, we ensure that anti-virtual machine technology cannot identify its operating environment by analyzing the virtual machine's traces, prevent the virtual machine's operating traces from being tracked or exploited by detection software, and protect the system from being monitored or hacked.
[0019] S3: simulated network environment; The following sub-steps are included: S31: camouflage network connection; Use common intranet IP addresses (such as 192.168.xx, 172.10.xx, etc.) to disguise network connections, and set rules in the router or firewall to ensure that the real public IP address is not leaked when using the intranet IP address; Use the tc command to simulate network latency and set the latency fluctuation range. Use the tc command to simulate packet loss and configure the probability range for packet loss. Periodically modify the latency fluctuation range and packet loss probability range to simulate dynamic changes in the network environment. S32: Build an intelligent DNS response platform; Use DNS server software to build a DNS response platform, and use DNS filtering software combined with machine learning algorithms to disguise suspicious domain names. When the DNS query finds a malicious or unknown domain name, the server returns a normal public DNS address.
[0020] S4: User behavior simulation; The following sub-steps are included: S41: simulate intelligent mouse operation; The Markov chain model is used to set the mouse's movement speed and direction, making the mouse's trajectory show random but regular changes, simulating the human thinking and operation process when using a mouse; When the mouse approaches a key action button or link, a hover time is set to simulate the thinking process of a human user before clicking; the hover time is random; Furthermore, multiple different style templates are defined to adjust the mouse movement style according to different scenarios, including browsing web pages, filling out forms, etc. S42: Simulating dynamic keyboard input based on behavioral entropy model; Use behavioral entropy models to control input rhythm, simulate different input speeds and changes; dynamically adjust input speed according to different input scenarios; The behavioral entropy model has built-in multiple common input error types to simulate the deletion behavior of real people when inputting; For example, when entering longer texts, the algorithm introduces some randomness, such as small pauses between typing and rhythm fluctuations; S43: Optimize user operating habits through the intelligent operating habit system; The intelligent operation habit system collects and analyzes the operation habits of target users, breaks down the operation steps, and constructs the operation steps into a natural workflow; for example: first open the browser → search → click on the link → read; The intelligent operation habit system adjusts the operation habits according to the different operation needs of users, including work mode, entertainment mode, leisure mode, etc. For example, in work mode, the system may optimize browsing speed and search efficiency, while in entertainment mode, it may provide a more comfortable viewing experience.
[0021] Intelligent fluctuations are added to the operation intervals, and the size of the fluctuations is dynamically adjusted according to the specific operation and the importance of the task; S44: Realize human operation logic simulation through intelligent adjustment system; Simulate human operating habits and behaviors when performing tasks to ensure that the intelligent adjustment system responds to actual user operations; reduce unnecessary computing and resource consumption through caching strategies and behavior optimization.
[0022] Through methods such as intelligent mouse operation and dynamic keyboard input, the operation behavior of real users is imitated to reduce the risk of virtual machine environment being identified; diversified operation behaviors and interaction modes are used to prevent them from being detected as non-human operations through behavioral analysis.
[0023] S5: Perform system time interference; The following sub-steps are included: S51: Perform clock source camouflage; Adjust the clock synchronization mechanism in the operating system to make the difference between the operating system clock and the CPU clock reasonable; Disguising the system's operating time by artificially adding time periods to the system, where the time periods range from several months to several years; By adjusting the system's time zone settings or directly modifying the system clock value, the attack target's geographical location can be disguised as the local time of the target area; S52: Handling special scenarios; Implement time hooks in the operating system to monitor and synchronize time changes, and intercept system time API calls to ensure that different threads and programs react correctly when time changes; By introducing locking mechanisms or synchronization variables (such as condition variables and mutex locks), we can ensure that no race conditions occur when time changes, and achieve time synchronization between threads. Dynamically adjust the timestamp of events to ensure that the time characteristics are consistent with the system time at all times.
[0024] By disguising and interfering with the system clock, the judgment of time analysis technology can be broken, preventing anti-virtual machine tools from identifying the virtual machine environment through time characteristics, and avoiding the identification risk caused by the time difference between the inside and outside of the virtual machine.
[0025] S6: Obfuscate and disguise API calls; The following sub-steps are included: S61: Randomly inserting harmless calls to disrupt malware monitoring of the system; Select harmless API calls that have no actual impact on system operation (such as querying system fonts with GetFontResourceInfo and obtaining screen resolution with GetSystemMetrics), and dynamically insert these harmless API calls before and after actual critical API calls (such as file reading and network requests). The order and number of inserted harmless calls are randomized each time the program is executed; S62: Call the disguise chain; Record the call history of the target software and analyze the API call patterns of different types of software; simulate the call chain and dynamically generate different call chains based on the software type each time it is run; adjust the order, frequency and time interval of API calls by generating log files or storing in a database to disguise the API call history.
[0026] By inserting harmless API calls or disguising call chains, the analysis path of anti-sandbox technology is destroyed, making the behavior of malware difficult to monitor and track; disguising the sequence and time interval of API calls prevents the anti-sandbox system from identifying the behavior patterns of virtual machines through regularity analysis.
[0027] S7: Dynamic behavior adjustment; Real-time monitoring of the execution behavior of malicious samples in virtualized environments to capture anti-VM instructions contained therein. When anti-VM instructions are detected, the camouflage strength is enhanced by increasing the variation of hardware parameters and expanding the range of network latency fluctuations. Specifically, the hardware parameters of the virtual machine are dynamically adjusted according to the execution requirements of the malicious sample, including increasing the operating frequency of the virtual CPU, memory size, or hard disk capacity, to enhance the camouflage strength; By expanding the range of network delay fluctuations, such as dynamically simulating the processing time of network requests and changing parameters such as transmission rate and throughput in network transmission protocols, the camouflage strength can be enhanced.
[0028] By real-time monitoring and automatically enhancing camouflage strength, the virtual machine environment becomes more covert, ensuring that malicious samples can continue to execute while avoiding being discovered by virtual machine detection tools.
[0029] S8: Security log record analysis; Use encrypted differential log technology to record the system's original state before operation and the system state after disguise; For key behavioral events, such as file execution, process startup, network communication, etc., digital signatures are added synchronously when recording; Furthermore, when a user clicks on a malicious sample file, encrypted differential logging technology records in detail in the log all the malware's operations in the system, including file modifications, process startups, registry changes, network connections, etc., and tracks and records system changes, such as memory data, file system structure, process changes, etc.
[0030] Using encrypted differential logging technology to record system changes can track the entire process of malicious behavior when it occurs, preventing the virtual machine environment from being quickly identified and countered; logging and encrypting key events helps to trace and analyze events in the event of an attack, ensuring system security.
[0031] The present invention has been described with reference to the above embodiments. However, the above embodiments are merely exemplary embodiments of the present invention. It should be noted that the disclosed embodiments do not limit the scope of the present invention. On the contrary, modifications and improvements that do not depart from the spirit and scope of the present invention are intended to be protected by the present invention.
Claims
1. A method for environmental simulation and behavior obfuscation against anti-sandbox and anti-virtual machine environments, characterized by: The following steps are involved: S1: Dynamic camouflage hardware environment; Dynamically simulate and camouflage the hardware environment inside the virtual machine through the virtual machine monitor, including the following sub-steps: S11: Disguise CPU parameters; S12: Disguise memory information; S13: Disguise hard disk information; S14: Disguise other devices; S2: Hide virtualization features; The following sub-steps are included: S21: Hide virtual machine traces; S22: Hide virtual machine files; S23: hidden network features; S3: simulated network environment; The following sub-steps are included: S31: camouflage network connection; S32: Build an intelligent DNS response platform; S4: User behavior simulation; The following sub-steps are included: S41: simulate intelligent mouse operation; S42: Simulating dynamic keyboard input based on behavioral entropy model; S43: Optimize user operating habits through the intelligent operating habit system; S44: Realize human operation logic simulation through intelligent adjustment system; S5: Perform system time interference; The following sub-steps are included: S51: Perform clock source camouflage; S52: Handling special scenarios; S6: Obfuscate and disguise API calls; The following sub-steps are included: S61: Randomly inserting harmless calls to disrupt malware monitoring of the system; S62: Call the disguise chain; S7: Dynamic behavior adjustment; Monitor the execution behavior of malicious samples in virtualized environments in real time and capture the anti-VM instructions contained therein; when anti-VM instructions are detected, enhance the camouflage strength; S8: Security log record analysis; Use encrypted differential log technology to record the system's original state before operation and the system state after disguise.
2. The method for environmental simulation and behavior obfuscation against anti-sandbox and anti-virtual machine environments as claimed in claim 1, characterized in that: The specific contents of step S1 are as follows: S11: Disguise CPU parameters; Generate random CPU core counts based on real hardware distribution to simulate different CPU configurations; spoof different CPU architectures and generate configurations based on actual hardware; enable or disable specific advanced features in the virtualized environment; S12: Disguise memory information; Randomly simulate different memory sizes and disguise different memory brands and models; S13: Disguise hard disk information; Dynamically generate hard drive capacity, disguise the hard drive interface type, model, and brand; S14: Disguise other devices; Simulate different graphics card models and brands and randomly generate graphics card drivers and performance data; disguise the network card type, manufacturer, MAC address, and simulate the hardware characteristics of a real computer by dynamically adjusting the number and model of USB ports.
3. The method for environmental simulation and behavior obfuscation against anti-sandbox and anti-virtual machine environments as claimed in claim 1, characterized in that: The specific contents of step S2 are as follows: S21: Hide virtual machine traces; Hiding virtual machine traces includes modifying the file name of the virtual machine process, hiding the virtual machine background service, and virtualizing the CPUID instruction; Use a process renaming tool to change the virtual machine process's file name to a normal system process name; manually edit registry entries to disguise the virtual machine's background service as a Windows system service, and modify the return value of the CPUID instruction to simulate the response of a physical machine; S22: Hide virtual machine files; Hiding virtual machine files includes hiding virtual machine file paths, deleting virtual machine related registry information, and cleaning up virtualization software traces; Place the virtual machine configuration file in an inconspicuous folder, delete the specific registry entries created by the virtualization software, and delete the installation logs, configuration files, and other traces of the virtualization software; S23: hidden network features; The hidden network features include modifying the virtual machine network card address, simulating virtual machine network delay, and responding to fake domain names; Manually change the specific network card address used by the virtual machine to a common network card address; use a network delay simulation tool to introduce network delay fluctuations into the virtual machine; set up DNS masquerading to map the virtual machine's dedicated domain name to a fake response.
4. The method for environmental simulation and behavior obfuscation against anti-sandbox and anti-virtual machine environments as claimed in claim 1, characterized in that: The specific contents of step S3 are as follows: S31: camouflage network connection; Use common intranet IP addresses to disguise network connections, and set rules in the router or firewall to ensure that the real public IP address is not leaked when using the intranet IP address; Use the tc command to simulate network delay and set the delay fluctuation range. Also use the tc command to simulate packet loss and configure the packet loss probability range. Periodically modify the delay fluctuation range and packet loss probability range to simulate dynamic changes in the network environment. S32: Build an intelligent DNS response platform; Use DNS server software to build a DNS response platform, and use DNS filtering software combined with machine learning algorithms to disguise suspicious domain names. When the DNS query finds a malicious or unknown domain name, the server returns a normal public DNS address.
5. The method for environmental simulation and behavior obfuscation against anti-sandbox and anti-virtual machine environments as claimed in claim 1, characterized in that: The specific contents of step S4 are as follows: S41: simulate intelligent mouse operation; The Markov chain model is used to set the mouse's movement speed and direction, making the mouse's trajectory show random but regular changes, simulating the human thinking and operation process when using a mouse; When the mouse approaches a key action button or link, a hover time is set to simulate the thinking process of a human user before clicking; the hover time is random; Define multiple different style templates to adjust the mouse movement style according to different scenarios; S42: Simulating dynamic keyboard input based on behavioral entropy model; Use behavioral entropy models to control input rhythm, simulate different input speeds and changes; dynamically adjust input speed according to different input scenarios; The behavioral entropy model has built-in multiple common input error types to simulate the deletion behavior of real people during input; S43: Optimize user operating habits through the intelligent operating habit system; The intelligent operation habit system collects and analyzes the operation habits of target users, breaks down the operation steps, and constructs the operation steps into a natural workflow; The intelligent operation habit system adjusts the operation habits according to the different operation needs of users; Intelligent fluctuations are added to the operation intervals, and the size of the fluctuations is dynamically adjusted according to the specific operation and the importance of the task; S44: Realize human operation logic simulation through intelligent adjustment system; Simulate human operating habits and behaviors when performing tasks to ensure that the intelligent adjustment system responds to actual user operations; reduce unnecessary computing and resource consumption through caching strategies and behavior optimization.
6. The method for environmental simulation and behavior obfuscation against anti-sandbox and anti-virtual machine environments as claimed in claim 1, characterized in that: The specific contents of step S5 are as follows: S51: Perform clock source camouflage; Adjust the clock synchronization mechanism in the operating system to make the difference between the operating system clock and the CPU clock reasonable; Disguising the system's operating time by artificially adding time periods to the system, where the time periods range from several months to several years; By adjusting the system's time zone settings or directly modifying the system clock value, the attack target's geographical location can be disguised as the local time of the target area; S52: Handling special scenarios; Implement time hooks in the operating system to monitor and synchronize time changes, and intercept system time API calls to ensure that different threads and programs react correctly when time changes; By introducing a locking mechanism or synchronization variable to ensure that no race conditions occur when time changes, time synchronization between threads can be achieved; Dynamically adjust the timestamp of events to ensure that the time characteristics are consistent with the system time at all times.
7. The method for environmental simulation and behavior obfuscation against anti-sandbox and anti-virtual machine environments as claimed in claim 1, characterized in that: The specific contents of step S6 are as follows: S61: Randomly inserting harmless calls to disrupt malware monitoring of the system; Select harmless API calls that have no actual impact on system operation and dynamically insert them before and after the actual critical API calls. The order and number of inserted harmless calls are randomized each time the program is executed. S62: Call the disguise chain; Record the call history of the target software and analyze the API call patterns of different types of software; simulate the call chain and dynamically generate different call chains based on the software type each time it is run; adjust the order, frequency and time interval of API calls by generating log files or storing in a database to disguise the API call history.
Citation Information
Patent Citations
Anti-detection system of virtual machine system
CN103077351A
Method and system for preventing malicious code from identifying sandbox on the basis of sandbox environment modification
CN105718793A
Sandbox construction method based on simulation execution
CN113918950A
Detection method and system for anti-virtualization malicious program
CN117540381A
Mitigation of anti-sandbox malware techniques
GB201610600D0