【24h】

The Nepenthes Platform: An Efficient Approach to Collect Malware

机译:猪笼草平台:一种收集恶意软件的有效方法

获取原文
获取原文并翻译 | 示例

摘要

Up to now, there is little empirically backed quantitative and qualitative knowledge about self-replicating malware publicly available. This hampers research in these topics because many counter-strategies against malware, e.g., network- and host-based intrusion detection systems, need hard empirical data to take full effect. We present the nepenthes platform, a framework for large-scale collection of information on self-replicating malware in the wild. The basic principle of nepenthes is to emulate only the vulnerable parts of a service. This leads to an efficient and effective solution that offers many advantages compared to other honeypot-based solutions. Furthermore, nepenthes offers a flexible deployment solution, leading to even better scalability. Using the nepenthes platform we and several other organizations were able to greatly broaden the empirical basis of data available about self-replicating malware and provide thousands of samples of previously unknown malware to vendors of host-based IDS/anti-virus systems. This greatly improves the detection rate of this kind of threat.
机译:到目前为止,关于可自我复制的恶意软件公开可用的经验支持的定量和定性知识很少。由于许多针对恶意软件的反策略,例如基于网络和主机的入侵检测系统,都需要硬性的经验数据才能完全发挥作用,这阻碍了对这些主题的研究。我们提供了nepenthes平台,该平台用于在野外大规模收集有关自我复制恶意软件的信息。猪笼草的基本原理是仅模仿服务的脆弱部分。与其他基于蜜罐的解决方案相比,这导致了一种高效且有效的解决方案,具有许多优势。此外,猪笼草提供了灵活的部署解决方案,从而带来了更好的可扩展性。通过使用猪笼草平台,我们和其他几个组织得以大大扩展了有关自我复制恶意软件的可用数据的经验基础,并向基于主机的IDS /防病毒系统的供应商提供了成千上万个以前未知的恶意软件样本。这大大提高了这种威胁的检测率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号