Análise Automatizada de Logs de Instrumentação Binária Dinâmica para Identificação de Comportamentos Evasivos em Executáveis Windows
Resumo
Este trabalho propõe o FluxTrace, um pipeline automatizado para análise e correlação de múltiplos logs de instrumentação binária dinâmica (DBI) associados à execução de uma mesma amostra de arquivos Portable Executable (PE) do Windows. A abordagem organiza rastros de execução, extrai evidências comportamentais, correlaciona sinais provenientes de diferentes fontes de instrumentação e mapeia os eventos observados para categorias relacionadas à evasão e técnicas da matriz MITRE ATT&CK, produzindo relatórios comportamentais estruturados associados a atividades evasivas. A avaliação inicial, conduzida sobre 14 amostras PE potencialmente evasivas, mostrou a presença de 11 técnicas evasão, demonstrando que a correlação entre múltiplos logs melhora a interpretação contextual das evidências observadas durante a análise dinâmica. A comparação com relatórios comportamentais do VirusTotal também revelou convergência significativa em nível de técnica-pai, apesar das diferenças de granularidade entre as abordagens.Referências
Apostolopoulos, T., Katos, V., Choo, K.-K. R., and Patsakis, C. (2021). Resurrecting anti-virtualization and anti-debugging: Unhooking your hooks. Future Generation Computer Systems, 116:393–405.
Balzarotti, D. et al. (2010). Efficient detection of split personalities in malware. In NDSS.
Botacin, M., Rocha, V. F. d., Geus, P. L. d., and Grégio, A. (2017). Analysis, anti-analysis, anti-anti-analysis: An overview of the evasive malware scenario. In Anais do Simpósio Brasileiro em Segurança da Informação e de Sistemas Computacionais, pages 250–263. SBC.
Bruening, D. et al. (2004). Efficient, transparent, and comprehensive runtime code manipulation. In CGO, pages 133–144. IEEE.
Campelo, H. B., Neto, F. S., and Feitosa, E. L. (2025). Contradef: Uma ferramenta de instrumentação binária dinâmica para análise de malware evasivo. In Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 11–19. SBC.
Egele, M., Scholte, T., Kirda, E., and Kruegel, C. (2012). A survey on automated dynamic malware-analysis techniques and tools. ACM Computing Surveys, 44(2):1–42.
Frida Developers (2014). Frida: Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers. [link]. Accessed: 2026-05-20.
Greamo, C. (2011). Sandboxing. Packt Publishing.
Issa, A. (2012). Anti-virtual machines and emulations. Journal in Computer Virology, 8(4):141–149.
Kirat, D. et al. (2011). Barebox: Efficient malware analysis on bare-metal. In ACSAC, pages 403–412. ACM.
Luk, C.-K. et al. (2005). Pin: Building customized program analysis tools with dynamic instrumentation. In PLDI, pages 190–200. ACM.
Nethercote, N. and Seward, J. (2007). Valgrind: A framework for heavyweight dynamic binary instrumentation. ACM SIGPLAN Notices, 42(6):89–100.
Neto, F. S., Campelo, H. B., Silva, E. V., and Feitosa, E. L. (2025). Mitigando técnicas de anti-instrumentação em dbi: Contramedidas baseadas em overhead e transparência. In Simpósio Brasileiro de Cibersegurança (SBSeg), pages 1114–1121. SBC.
Or-Meir, O., Nissim, N., Elovici, Y., and Rokach, L. (2019). Dynamic malware analysis in the modern era—a state of the art survey. ACM Computing Surveys, 52(5):1–48.
Polino, M., Continella, A., Mariani, S., D’Alessio, S., Fontana, L., Gritti, F., and Zanero, S. (2017). Measuring and defeating anti-instrumentation-equipped malware. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, pages 73–96. Springer.
Rodriguez, R. et al. (2016). Towards transparent and stealthy malware analysis systems using dbi. In SAC, pages 1964–1971. ACM.
Seifert, C., Steenson, R., Welch, I., Komisarczuk, P., and Endicott-Popovsky, B. (2007). Capture – a behavioral analysis tool for applications and documents. Digital Investigation, 4:S23–S30.
Shi, H. and Mirkovic, J. (2017). Hiding debuggers from malware with apate. In Proceedings of the ACM Symposium on Applied Computing, pages 1703–1710. ACM.
Shields, T. (2009). Anti-debugging – a developers view. Proceedings of the 2009 Information Security Curriculum Development Conference, pages 1–15.
Sun, K. et al. (2016). Break out of the truman sandbox: An emerging threat of native code to virtual machine introspection. In CCS, pages 969–982. ACM.
Ugarte-Pedrero, X. et al. (2019). A survey on malware analysis techniques. IEEE Access, 7:103783–103803.
Wu, Y. et al. (2023). A survey on dynamic binary instrumentation frameworks and their security applications. ACM Computing Surveys, 55(9):1–36.
You, I. and Yim, K. (2010). Malware obfuscation techniques: A brief survey. 2010 International Conference on Broadband, Wireless Computing, Communication and Applications, pages 297–300.
Zhechev, M. (2018). Security analysis of dynamic binary instrumentation frameworks. Master’s thesis, University of Twente.
Balzarotti, D. et al. (2010). Efficient detection of split personalities in malware. In NDSS.
Botacin, M., Rocha, V. F. d., Geus, P. L. d., and Grégio, A. (2017). Analysis, anti-analysis, anti-anti-analysis: An overview of the evasive malware scenario. In Anais do Simpósio Brasileiro em Segurança da Informação e de Sistemas Computacionais, pages 250–263. SBC.
Bruening, D. et al. (2004). Efficient, transparent, and comprehensive runtime code manipulation. In CGO, pages 133–144. IEEE.
Campelo, H. B., Neto, F. S., and Feitosa, E. L. (2025). Contradef: Uma ferramenta de instrumentação binária dinâmica para análise de malware evasivo. In Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 11–19. SBC.
Egele, M., Scholte, T., Kirda, E., and Kruegel, C. (2012). A survey on automated dynamic malware-analysis techniques and tools. ACM Computing Surveys, 44(2):1–42.
Frida Developers (2014). Frida: Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers. [link]. Accessed: 2026-05-20.
Greamo, C. (2011). Sandboxing. Packt Publishing.
Issa, A. (2012). Anti-virtual machines and emulations. Journal in Computer Virology, 8(4):141–149.
Kirat, D. et al. (2011). Barebox: Efficient malware analysis on bare-metal. In ACSAC, pages 403–412. ACM.
Luk, C.-K. et al. (2005). Pin: Building customized program analysis tools with dynamic instrumentation. In PLDI, pages 190–200. ACM.
Nethercote, N. and Seward, J. (2007). Valgrind: A framework for heavyweight dynamic binary instrumentation. ACM SIGPLAN Notices, 42(6):89–100.
Neto, F. S., Campelo, H. B., Silva, E. V., and Feitosa, E. L. (2025). Mitigando técnicas de anti-instrumentação em dbi: Contramedidas baseadas em overhead e transparência. In Simpósio Brasileiro de Cibersegurança (SBSeg), pages 1114–1121. SBC.
Or-Meir, O., Nissim, N., Elovici, Y., and Rokach, L. (2019). Dynamic malware analysis in the modern era—a state of the art survey. ACM Computing Surveys, 52(5):1–48.
Polino, M., Continella, A., Mariani, S., D’Alessio, S., Fontana, L., Gritti, F., and Zanero, S. (2017). Measuring and defeating anti-instrumentation-equipped malware. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, pages 73–96. Springer.
Rodriguez, R. et al. (2016). Towards transparent and stealthy malware analysis systems using dbi. In SAC, pages 1964–1971. ACM.
Seifert, C., Steenson, R., Welch, I., Komisarczuk, P., and Endicott-Popovsky, B. (2007). Capture – a behavioral analysis tool for applications and documents. Digital Investigation, 4:S23–S30.
Shi, H. and Mirkovic, J. (2017). Hiding debuggers from malware with apate. In Proceedings of the ACM Symposium on Applied Computing, pages 1703–1710. ACM.
Shields, T. (2009). Anti-debugging – a developers view. Proceedings of the 2009 Information Security Curriculum Development Conference, pages 1–15.
Sun, K. et al. (2016). Break out of the truman sandbox: An emerging threat of native code to virtual machine introspection. In CCS, pages 969–982. ACM.
Ugarte-Pedrero, X. et al. (2019). A survey on malware analysis techniques. IEEE Access, 7:103783–103803.
Wu, Y. et al. (2023). A survey on dynamic binary instrumentation frameworks and their security applications. ACM Computing Surveys, 55(9):1–36.
You, I. and Yim, K. (2010). Malware obfuscation techniques: A brief survey. 2010 International Conference on Broadband, Wireless Computing, Communication and Applications, pages 297–300.
Zhechev, M. (2018). Security analysis of dynamic binary instrumentation frameworks. Master’s thesis, University of Twente.
Publicado
01/09/2026
Como Citar
BARROS, Margefson M.; S. NETO, Francisco S.; DELLOSO, Juan M.; SOARES, Yan; FEITOSA, Eduardo L..
Análise Automatizada de Logs de Instrumentação Binária Dinâmica para Identificação de Comportamentos Evasivos em Executáveis Windows. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 127-142.
DOI: https://doi.org/10.5753/sbseg.2026.29293.
