Dimitrio, Kaleb (2026) Pembuatan Dataset Aktivitas Malware dengan Simulasi Aktivitas Pengguna di Belakang Layar. Other thesis, Institut Teknologi Sepuluh Nopember.
|
Text
5025221317-Undergraduate_Thesis.pdf Restricted to Repository staff only Download (3MB) | Request a copy |
Abstract
Analisis malware dinamis makin terkendala teknik penghindaran sandbox, sebab sebagian malware modern memeriksa kehadiran pengguna nyata dengan mendeteksi ketiadaan aktivitas wajar untuk membedakan korban asli dari lingkungan analisis otomatis. Penelitian ini membangun dan mengevaluasi alur pembuatan dataset perilaku malware per detik pada Cuckoo3 yang menyatukan simulasi aktivitas pengguna latar belakang dari penelitian terdahulu bersama modul pemantauan tambahan ke dalam agent Windows 10, mencakup aplikasi native dan utilitas sistem serta gerakan mouse. Evaluasi memakai desain berpasangan atas 500 sampel dari yang dijalankan pada dua kondisi identik kecuali kehadiran simulasi, yaitu kondisi dengan usersim dan kondisi tanpa usersim, sehingga menghasilkan 1.000 run valid mencakup 59 keluarga, dengan tiap run menyimpan event Sysmon dan threemon beserta berkas PCAP lalu diringkas menjadi 48 parameter per detik yang sebagiannya dikaitkan pada aktivitas proses malwar. Modul simulasi berjalan andal pada 98,23% pemanggilan. Pada sisi deteksi, kehadiran simulasi tidak mengubah hasil, sedangkan pada sisi perilaku pergerakan terjadi dua arah dengan proporsi kenaikan tiap parameter berkisar dari 1% hingga 22% pada parameter yang dikaitkan ke aktivitas malware, namun sekitar 91% pergerakan itu terserap variasi antar run. Sebagai langkah tambahan, dilakukan penyaringan bertahap dari 500 pasang menjadi 273 pasang berdurasi setara, lalu 17 kandidat, hingga lima studi kasus lintas instrumen yang memperlihatkan simulasi berasosiasi dengan perilaku C2 dan persistensi yang tidak muncul pada kondisi tanpa usersim maupun pada benign. Temuan dinyatakan sebagai bukti positif yang sugestif, bukan bukti pasti pengaruh simulasi aktivitas pengguna.
==================================================================================================================================
Dynamic malware analysis is increasingly hindered by sandbox evasion techniques, as some modern malware checks for the presence of a real user by detecting the absence of natural activity in order to distinguish genuine victims from automated analysis environments. This research builds and evaluates a pipeline for generating a per-second malware behavior dataset on Cuckoo3 that integrates background user-activity simulation from prior work together with an additional monitoring module into a Windows 10 agent, covering native applications and system utilities as well as OS-level mouse movement. The evaluation uses a paired design over 500 samples from MalwareBazaar run under two conditions that are identical except for the presence of the simulation, namely the usersim condition and the no-usersim condition, yielding 1,000 valid runs across 59 families, with each run storing Sysmon and threemon events along with a PCAP file and then summarized into 48 per-second parameters, some of which are attributed to the malware process activity, plus 60 benign control runs. The simulation module ran reliably on 98.23% of its invocations. On the detection side, the presence of the simulation did not change the outcome, whereas on the behavioral side the movement occurred in both directions, with the proportion of increases per parameter ranging from 1% to 22% on the malware-attributed parameters, yet about 91% of that movement was absorbed by run-to-run variation. As an additional step, a staged filtering was carried out from 500 pairs down to 273 duration-matched pairs, then 17 candidates, and finally five cross-instrument case studies showing that the simulation is associated with C2 and persistence behaviors that are absent in both the no-usersim condition and the benign controls. The findings are stated as suggestive positive evidence rather than definitive proof of the effect of user-activity simulation.
| Item Type: | Thesis (Other) |
|---|---|
| Uncontrolled Keywords: | Dataset Malware, Analisis Dinamis, Cuckoo3, Sandbox Evasion, Aktivitas Pengguna Latar Belakang, Keamanan Siber, Malware Dataset, Dynamic Analysis, Cuckoo3, Sandbox Evasion, Background User Activity, Cybersecurity. |
| Subjects: | Q Science > QA Mathematics > QA76.9.A25 Computer security. Digital forensic. Data encryption (Computer science) |
| Divisions: | Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Informatics Engineering > 55201-(S1) Undergraduate Thesis |
| Depositing User: | Kaleb Dimitrio |
| Date Deposited: | 30 Jul 2026 03:45 |
| Last Modified: | 30 Jul 2026 03:45 |
| URI: | http://repository.its.ac.id/id/eprint/139580 |
Actions (login required)
![]() |
View Item |
