Selectively introducing security issues in a sandbox environment to elicit malicious application behavior
One example method includes configuring the virtual machine environment to introduce one or more security issues within the virtual machine environment, wherein each security issue elicits a particular malicious application to perform malicious actions when introduced during execution of the particular malicious application; executing a software application within the virtual machine environment; detecting at least one of the malicious actions being performed by the software application during execution within the virtual machine environment; and initiating an analysis action in response to detecting at least one of the malicious actions being performed by the software application.
1 . A computer-implemented method executed by one or more processors for analyzing software application behavior within a virtual machine environment, the method comprising:
configuring the virtual machine environment to introduce one or more security issues within the virtual machine environment, wherein each security issue elicits a particular malicious application to perform malicious actions when introduced during execution of the particular malicious application;
executing a software application within the virtual machine environment;
detecting at least one of the malicious actions being performed by the software application during execution within the virtual machine environment;
initiating an analysis action in response to detecting at least one of the malicious actions being performed by the software application.
2 . The method of claim 1 , wherein the analysis action includes initiating a capture of a video signal from the virtual machine environment.
3 . The method of claim 1 , wherein the analysis action includes initiating a trace on actions performed by the software application within the virtual machine environment.
4 . The method of claim 1 , wherein configuring the virtual machine environment to introduce the one or more security issues includes placing sensitive data in an unsecure location within the virtual machine environment, and the malicious actions include accessing the sensitive data.
5 . The method of claim 4 , wherein the unsecure location is a location particular to a type of data associated with the sensitive data.
6 . The method of claim 4 , wherein the sensitive data includes at least one of passwords, credit card numbers, account information, or social security numbers.
7 . The method of claim 1 , wherein configuring the virtual machine environment to introduce the one or more security issues includes configuring the virtual machine environment with a default password.
8 . The method of claim 1 , wherein configuring the virtual machine environment to introduce the one or more security issues includes configuring the virtual machine environment with a particular security feature disabled.
9 . The method of claim 1 , wherein configuring the virtual machine environment to introduce the one or more security issues includes configuring the virtual machine environment without a specific security update installed.
10 . The method of claim 1 , wherein configuring the virtual machine environment to introduce the one or more security issues includes configuring the virtual machine environment with a particular version of a particular software component.
11 . A system comprising:
one or more processors configured to execute computer program instructions; and
computer storage media encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:
configuring the virtual machine environment to introduce one or more security issues within the virtual machine environment, wherein each security issue elicits a particular malicious application to perform malicious actions when introduced during execution of the particular malicious application;
executing a software application within the virtual machine environment;
detecting at least one of the malicious actions being performed by the software application during execution within the virtual machine environment;
initiating an analysis action in response to detecting at least one of the malicious actions being performed by the software application.
12 . The system of claim 11 , wherein the analysis action includes initiating a capture of a video signal from the virtual machine environment.
13 . The system of claim 11 , wherein the analysis action includes initiating a trace on actions performed by the software application within the virtual machine environment.
14 . The system of claim 11 , wherein configuring the virtual machine environment to introduce the one or more security issues includes placing sensitive data in an unsecure location within the virtual machine environment, and the malicious actions include accessing the sensitive data.
15 . The system of claim 14 , wherein the unsecure location is a location particular to a type of data associated with the sensitive data.
16 . The system of claim 14 , wherein the sensitive data includes at least one of passwords, credit card numbers, account information, or social security numbers.
17 . The system of claim 11 , wherein configuring the virtual machine environment to introduce the one or more security issues includes configuring the virtual machine environment with a default password.
18 . The system of claim 11 , wherein configuring the virtual machine environment to introduce the one or more security issues includes configuring the virtual machine environment with a particular security feature disabled.
19 . The system of claim 11 , wherein configuring the virtual machine environment to introduce the one or more security issues includes configuring the virtual machine environment without a specific security update installed.
20 . A computer storage media encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:
configuring the virtual machine environment to introduce one or more security issues within the virtual machine environment, wherein each security issue elicits a particular malicious application to perform malicious actions when introduced during execution of the particular malicious application;
executing a software application within the virtual machine environment;
detecting at least one of the malicious actions being performed by the software application during execution within the virtual machine environment;
initiating an analysis action in response to detecting at least one of the malicious actions being performed by the software application