Computer Science ›› 2017, Vol. 44 ›› Issue (11): 246-252, 267.doi: 10.11896/j.issn.1002-137X.2017.11.037

Windows Security Mechanisms Simulation and Sandbox System Implementation Based on Wine

DIAO Ming-zhi, ZHOU Yuan, LI Zhou-jun and ZHAO Yu-fei   

  • Online:2018-12-01 Published:2018-12-01

Abstract: We simulated two Windows security mechanisms,adress space layout randomization (ASLR) and user account control (UAC) Virtualization,based on open source software Wine.The two mechanisms make the Wine’s environment closer to the real operating system and safer.Based on the two security mechanisms,we further presented a relatively real sandbox system,which employs the wineserver mechanism and utilizes the .wine directory of Wine as the running environment for samples to detect the dynamic behavior.The experimental results show that the proposed sandbox system presents the basic characteristics of ASLR and UAC Virtualization.Compared with other sandboxes,our proposed sandbox system can not only effectively detect behaviors of unknown samples,but also has features like low resource utilization,good isolation and fast status rollback,which make it meet the requirements of batch deployment and operation.

Key words: Wine,ASLR,UAC Virtualization,Dynamic behavior detection,Sandbox

