The invention relates to a malicious
software dynamic analysis-oriented automatic
interaction method for data between a
virtual machine and a host, which comprises the following steps of: S1, initializing the
virtual machine,
copying a
daemon and a dynamic execution program to the
virtual machine, and storing a current virtual
machine snapshot; s2, resetting the virtual
machine to the stored virtual
machine snapshot, compressing a to-be-detected sample program, sending the compressed to-be-detected sample program to the virtual machine, and starting a
daemon; s3, the virtual machine decompresses the compressed sample, and a dynamic execution program is used for testing; s4, the host program sends a keyboard event to simulate keyboard keys, and
file copying is executed; and S5, when the host program detects that the virtual machine
daemon program is ended, decompressing the compressed track flow file to a specified
directory, finishing transmission of the decompressed track flow file, resetting the state of the virtual machine until the snapshot is stored, analyzing the track flow file, and finishing analysis and test of the malicious
software. A network port and a shared
directory do not need to be opened, risks caused in the transmission process are reduced, and the implementation is
safer.