Pith. sign in

REVIEW 2 cited by

SoK: An Essential Guide For Using Malware Sandboxes In Security Applications: Challenges, Pitfalls, and Lessons Learned

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2403.16304 v1 pith:BVXOTW4G submitted 2024-03-24 cs.CR

classification cs.CR
keywords sandboxesapplicationsguidelinesmalwaresandboxsecurityusersderive
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Malware sandboxes provide many benefits for security applications, but they are complex. These complexities can overwhelm new users in different research areas and make it difficult to select, configure, and use sandboxes. Even worse, incorrectly using sandboxes can have a negative impact on security applications. In this paper, we address this knowledge gap by systematizing 84 representative papers for using x86/64 malware sandboxes in the academic literature. We propose a novel framework to simplify sandbox components and organize the literature to derive practical guidelines for using sandboxes. We evaluate the proposed guidelines systematically using three common security applications and demonstrate that the choice of different sandboxes can significantly impact the results. Specifically, our results show that the proposed guidelines improve the sandbox observable activities by at least 1.6x and up to 11.3x. Furthermore, we observe a roughly 25% improvement in accuracy, precision, and recall when using the guidelines to help with a malware family classification task. We conclude by affirming that there is no "silver bullet" sandbox deployment that generalizes, and we recommend that users apply our framework to define a scope for their analysis, a threat model, and derive context about how the sandbox artifacts will influence their intended use case. Finally, it is important that users document their experiment, limitations, and potential solutions for reproducibility

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SaMOSA: Sandbox for Malware Orchestration and Side-Channel Analysis

    cs.CR 2025-08 conditional novelty 6.0 of 10

    A modular Linux sandbox that simultaneously captures syscall, network, disk, and hardware-counter traces across three architectures, demonstrated on ransomware, a remote-access trojan, and a cryptominer.

  2. MLRan: A Behavioural Dataset for Ransomware Analysis and Detection

    cs.CR 2025-05 conditional novelty 6.0 of 10

    A new open behavioural ransomware dataset with 64 families and balanced goodware, plus guidelines and a feature selection pipeline that reaches about 98% binary detection accuracy.

Pith tools