The invention discloses a
system and a method for automatically analyzing, detecting and classifying a malicious
program behavior. The
system comprises a
static analysis module, a sandbox dispatching management module, a sandbox monitoring module, a behavior abstraction module and a detection and classification module. Compared with the prior art, the
system has the advantages that 1, the system is based on a
behavior monitoring technology in an
instruction set simulation environment; and 2, a virtual Internet is established in a sandbox through means of environment configuration,
server program modification and the like, and a common
network service is simulated, so that operations such as
domain name server (DNS) resolution, http access, file download, Email login and mailing initiated by a malicious program can be successfully executed, the malicious program is inveigled to generate a malicious
network behavior, the network behaviors are prevented from damaging a
host machine and a real network, and the defects that the malicious program
network behavior cannot be fully expressed during dynamic behavior analysis of a malicious program and the like are overcome.