首页> 外文会议>Internet and Multimedia Systems and Applications >A SYSTEM FOR PROGRAM EXECUTION IDENTIFICATION ON THE MICROSOFT WINDOWS PLATFORMS
【24h】

A SYSTEM FOR PROGRAM EXECUTION IDENTIFICATION ON THE MICROSOFT WINDOWS PLATFORMS

机译:微软视窗平台上的程序执行识别系统

获取原文

摘要

This paper describes a system for identification execution of programs using execution events of the programs. This system is based on a model of program execution for security purposes, and is implemented on the Microsoft Windows platforms using an operating system technique called DLL (Dynamic Linked Library) replacement. Compared to other related works, this paper has two key contributions: It describes a systematic way to retain all system DLLs made by application programs dynamically and in real-time on the Microsoft Windows platforms. It also presents a new model of program execution, in which frequencies of program execution events are considered in addition to their patterns. Our experiment data indicate improved results.
机译:本文描述了一种使用程序的执行事件来识别程序执行的系统。为了安全起见,该系统基于程序执行模型,并且使用称为DLL(动态链接库)替换的操作系统技术在Microsoft Windows平台上实现。与其他相关工作相比,本文有两个主要贡献:它描述了一种系统的方式,可以动态地,实时地在Microsoft Windows平台上保留由应用程序生成的所有系统DLL。它还提出了一种新的程序执行模型,其中除了其模式外,还考虑了程序执行事件的频率。我们的实验数据表明结果有所改善。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号