Using Hyper-V Sockets for Real-time Data Extraction from a Malware Analysis Sandbox

📅 2026-08-31
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文探讨了使用Hyper-V套接字作为恶意软件分析沙箱的实时数据提取通道,对比了其与WinSock TCP套接字在阻塞和枚举方面的优势,并比较了两者的数据吞吐量。
📝 Abstract
We present how Hyper-V sockets can be used as a real-time communication channel for a malware analysis sandbox. We show that, compared to WinSock TCP sockets, Hyper-V sockets are not subject to TCP/IP-layer blocking and are not enumerated by common TCP connection listing tools. We compare the throughput of the two communication channels as a function of buffer size.
Problem

Research questions and friction points this paper is trying to address.

Hyper-V Sockets
real-time data extraction
malware analysis sandbox
Innovation

Methods, ideas, or system contributions that make the work stand out.

Hyper-V Sockets
Real-time Data Extraction
Malware Analysis Sandbox
I
István-Attila Császár
Technical University of Cluj-Napoca, Bitdefender, Cluj-Napoca, Romania
R
Radu-Marian Portase
Technical University of Cluj-Napoca, Bitdefender, Cluj-Napoca, Romania
A
Adrian Coleşa
Technical University of Cluj-Napoca, Cluj-Napoca, Romania
Adrian Groza
Adrian Groza
Technical University of Cluj-Napoca, European University of Technology (EUt+)
Artificial IntelligenceAgentic AIKnowledge representationExplainable AINeuroSymbolic AI