The invention relates to the technical field of malicious
software protection, in particular to a malicious
firmware vulnerability utilization detection
system based on sandbox behavior analysis, which comprises a protocol analysis constraint establishment module for loading to-be-detected
firmware according to a sandbox environment, configuring a register address range of a
virtual network card and a virtual
USB controller, generating a virtual
peripheral protocol analysis tree, and establishing a virtual
peripheral protocol analysis result; and traversing leaf nodes in the virtual
peripheral protocol
parse tree. According to the method, in combination with interrupt
time sequence discrete analysis, the hidden interrupt
hooking behavior can be recognized from the microscopic time dimension by continuously recording the instruction execution
clock cycle number corresponding to the target interrupt vector and calculating the time-consuming window and the dispersion value, and the limitation that a traditional sandbox only pays attention to the function level is overcome; malicious codes hidden in a bottom layer are pulled out by using the
time sequence side channel characteristics, so that the detection success rate and the
false alarm suppression capability aiming at unknown
vulnerability utilization and persistent attacks of
firmware are improved, and the deep security
threat of embedded equipment is perceived.