首页> 外文会议>International ISC Conference on Information Security and Cryptology >Behavior and system based backdoor detection focusing on CMD phase
【24h】

Behavior and system based backdoor detection focusing on CMD phase

机译:基于行为和系统的后门检测,重点是CMD阶段

获取原文

摘要

Backdoor as a mechanism surreptitiously introduced into a computer system is widely used in performing network attacks. In this article, it is considered to detect its presence while helping an attacker to bypass normal authentication methods of a computer to maintain the access gained. In the latest researches have been done on this field so far, it is emphasized on analyzing only the behavior of backdoors. However, in this paper we propose a novel approach, combining systemic and behavioral features focusing on the "CMD" phase that the attacker sends commands to the victim. Through the detection method driven in this article, at first we gather the systemic and behavioral alerts produced while the attacker is installing and utilizing the backdoor interactively and then categorize them by specific features selected to give scores to the both aspects seen. Scores are given in two steps. The first step based on the prominent systemic alerts selected which are specified to backdoors and in the second step we give scores to the behavior it has in the command phase by creating and running a Markov Model. Literally, the scores are normalized and aggregated to determine the probability of backdoor residence on the computer monitored. We evaluated the algorithm in six different scenarios and by a group of well-known backdoors to make distinction between the proposed method and prior works.
机译:后门作为一种秘密地引入计算机系统的机制,被广泛用于执行网络攻击。在本文中,可以考虑检测到它的存在,同时帮助攻击者绕过计算机的常规身份验证方法来维护获得的访问权限。迄今为止,在该领域的最新研究中,仅着重分析后门的行为。但是,在本文中,我们提出了一种新颖的方法,结合了系统和行为功能,重点是攻击者向受害者发送命令的“ CMD”阶段。通过本文中介绍的检测方法,首先,我们收集在攻击者以交互方式安装和利用后门时生成的系统警报和行为警报,然后通过选择的特定功能对它们进行分类,以对所看到的两个方面进行评分。分数分为两个步骤。第一步基于选定的重要系统警报,这些警报指定给后门,第二步,我们通过创建和运行马尔可夫模型为命令阶段的行为评分。从字面上看,对分数进行归一化和汇总以确定后门驻留在受监控计算机上的可能性。我们在六种不同的情况下以及一组知名的后门程序中对该算法进行了评估,以区分所提出的方法和先前的工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号