首页> 外文会议>Recent Advances in Intrusion Detection >Detecting Malicious Software by Monitoring Anomalous Windows Registry Accesses
【24h】

Detecting Malicious Software by Monitoring Anomalous Windows Registry Accesses

机译:通过监视异常的Windows注册表访问来检测恶意软件

获取原文

摘要

We present a host-based intrusion detection system (IDS) for Microsoft Windows. The core of the system is an algorithm that detects attacks on a host machine by looking for anomalous accesses to the Windows Registry. The key idea is to first train a model of normal registry behavior on a windows host, and use this model to detect abnormal registry accesses at run-time. The normal model is trained using clean (attack-free) data. At run-time the model is used to check each access to the registry in real time to determine whether or not the behavior is abnormal and (possibly) corresponds to an attack. The system is effective in detecting the actions of malicious software while maintaining a low rate of false alarms.
机译:我们介绍用于Microsoft Windows的基于主机的入侵检测系统(IDS)。该系统的核心是一种算法,该算法通过查找对Windows注册表的异常访问来检测对主机的攻击。关键思想是首先在Windows主机上训练正常注册表行为的模型,然后使用该模型在运行时检测异常的注册表访问。使用干净的(无攻击)数据训练普通模型。在运行时,该模型用于实时检查对注册表的每次访问,以确定行为是否异常以及(可能)与攻击相对应。该系统可有效检测恶意软件的行为,同时保持较低的误报率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号