首页> 外文会议>International conference on current trends in theory and practice of computer science >Characterising Malicious Software with High-Level Behavioural Patterns
【24h】

Characterising Malicious Software with High-Level Behavioural Patterns

机译:使用高级行为模式表征恶意软件

获取原文
获取外文期刊封面目录资料

摘要

Current research trends concerning malicious software indicate preferring malware behaviour over malware structure analysis. Detection is heading to methods employing malware models on higher level of abstraction, not purely on the level of program's code. Specification of applicable level of abstraction for investigation and detection of malware may present a serious challenge. Many approaches claim using high-level abstraction of malware behaviour but they are still based on sequences of instructions which form the malicious program. Techniques which rely on syntactic representation potentially fail whenever malware writers employ mutation or obfuscation of malicious code. Our work presents a different strategy. We utilised freely available information about malicious programs which were already inspected and tried to find patterns in malware behaviour, which are not bound to syntactic representation of malicious samples and so should withstand malware mutation on the syntactic level.
机译:有关恶意软件的当前研究趋势表明,与恶意软件结构分析相比,它更喜欢恶意软件行为。检测正朝着在更高的抽象级别而不是纯粹在程序代码级别上使用恶意软件模型的方法迈进。规范用于调查和检测恶意软件的适用抽象级别可能会带来严峻的挑战。许多方法声称使用了恶意软件行为的高级抽象,但是它们仍然基于形成恶意程序的指令序列。每当恶意软件编写者对恶意代码进行突变或混淆时,依赖于语法表示的技术都可能会失败。我们的工作提出了不同的策略。我们利用关于恶意程序的免费可用信息,这些信息已经过检查,并试图在恶意软件行为中查找模式,这些模式与恶意样本的语法表示无关,因此应能够承受语法级别的恶意软件变异。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号