A Large Language Model Approach to Generating Bypass Rules for Malware Evasion in Analysis Sandbox

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sui, Zhiyong, Noureddine, Lamine, Khatun, Mst Eshita, Bello, Sideeq, Woodring, Justin, Ali-Gombe, Aisha
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916033504215040
author Sui, Zhiyong
Noureddine, Lamine
Khatun, Mst Eshita
Bello, Sideeq
Woodring, Justin
Ali-Gombe, Aisha
author_facet Sui, Zhiyong
Noureddine, Lamine
Khatun, Mst Eshita
Bello, Sideeq
Woodring, Justin
Ali-Gombe, Aisha
contents Sandbox evasion remains a critical challenge for automated malware analysis, as modern malware employs environment checks to detect analysis platforms and suppress malicious behavior. Existing approaches rely on manually crafted bypass rules that require deep reverse engineering of each evasion mechanism -an approach that cannot scale against rapidly evolving evasion techniques. In this paper, we leverage large language models (LLMs) to automatically generate YARA rules that bypass evasion checks in sandbox environments. We propose ABLE, which analyzes execution traces from malware terminated due to potentially evasive behavior and employs multiple reasoning strategies to generate targeted bypass rules. To address syntactic errors and improve the efficacy of the bypass rules in the LLM outputs, we introduce an auto-sanitization pipeline and feedback-driven iterative refinement. We evaluate ABLE on 334 real-world malware samples across four open-weight LLMs. ABLE achieves a 79% bypass success rate, with iterative refinement contributing 29.5% of successful cases. Compared to existing analysis platforms, ABLE identifies 47% more malware family classifications and exposes previously hidden behaviors.
format Preprint
id arxiv_https___arxiv_org_abs_2605_21821
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle A Large Language Model Approach to Generating Bypass Rules for Malware Evasion in Analysis Sandbox
Sui, Zhiyong
Noureddine, Lamine
Khatun, Mst Eshita
Bello, Sideeq
Woodring, Justin
Ali-Gombe, Aisha
Cryptography and Security
Sandbox evasion remains a critical challenge for automated malware analysis, as modern malware employs environment checks to detect analysis platforms and suppress malicious behavior. Existing approaches rely on manually crafted bypass rules that require deep reverse engineering of each evasion mechanism -an approach that cannot scale against rapidly evolving evasion techniques. In this paper, we leverage large language models (LLMs) to automatically generate YARA rules that bypass evasion checks in sandbox environments. We propose ABLE, which analyzes execution traces from malware terminated due to potentially evasive behavior and employs multiple reasoning strategies to generate targeted bypass rules. To address syntactic errors and improve the efficacy of the bypass rules in the LLM outputs, we introduce an auto-sanitization pipeline and feedback-driven iterative refinement. We evaluate ABLE on 334 real-world malware samples across four open-weight LLMs. ABLE achieves a 79% bypass success rate, with iterative refinement contributing 29.5% of successful cases. Compared to existing analysis platforms, ABLE identifies 47% more malware family classifications and exposes previously hidden behaviors.
title A Large Language Model Approach to Generating Bypass Rules for Malware Evasion in Analysis Sandbox
topic Cryptography and Security
url https://arxiv.org/abs/2605.21821