【24h】

Prevention of malware propagation in AMI

机译:防止在AMI中的恶意软件传播

获取原文

摘要

Malware can disrupt the operation of services in advanced metering infrastructure (AMI), which is at risk due to connectivity with the global Internet. In motion, malware may hide within the data payloads of legitimate AMI control traffic, implying the need for deep packet inspection. Some of the inspections one may make look for consistency with respect to data available only at the application layer, requiring one to position the analysis high in the protocol stack. Towards this end we propose a policy engine that examines both ingress and egress traffic to the AMI application layer. Policy engine rules may refer to the structure and behavior of the AMI protocol, and may also perform multi-stage analysis of data payloads looking for evidence that executable code is carried, rather than data. Our experimental results demonstrate that the policy engine is able to accurately distinguish between legitimate traffic and malware bearing traffic.
机译:恶意软件可能会扰乱高级计量基础设施(AMI)的服务的运行,这是由于与全球互联网的连接而受到风险。在运动中,恶意软件可能隐藏在合法的AMI控制流量的数据有效载荷中,这意味着需要深度数据包检查。其中一些检查可以在应用层的数据中寻找可用的数据的一致性,要求一个用于在协议栈中定位高度的分析。在此目的,我们提出了一个策略引擎,该引擎将入口和出口流量审视到AMI应用层。策略引擎规则可以参考AMI协议的结构和行为,并且还可以执行寻找携带可执行代码而不是数据的证据的数据有效载荷的多级分析。我们的实验结果表明,策略引擎能够准确地区分合法的交通和恶意软件承载流量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号