首页> 外文会议>International Conference on Data Intelligence and Security >Windows Virtualization Architecture For Cyber Threats Detection
【24h】

Windows Virtualization Architecture For Cyber Threats Detection

机译:网络威胁检测的Windows虚拟化架构

获取原文

摘要

This is very true for the Windows operating system (OS) used by government and private organizations. With Windows, the closed source nature of the operating system has unfortunately meant that hidden security issues are discovered very late and the fixes are not found in real time. There needs to be a reexamination of current static methods of malware detection. This paper presents an integrated system for automated and real-time monitoring and prediction of rootkit and malware threats for the Windows OS. We propose to host the target Windows machines on the widely used Xen hypervisor, and collect process behavior using virtual memory introspection (VMI). The collected data will be analyzed using state of the art machine learning techniques to quickly isolate malicious process behavior and alert system administrators about potential cyber breaches. This research has two focus areas: identifying memory data structures and developing prediction tools to detect malware. The first part of research focuses on identifying memory data structures affected by malware. This includes extracting the kernel data structures with VMI that are frequently targeted by rootkits/malware. The second part of the research will involve development of a prediction tool using machine learning techniques.
机译:这对于政府和私人组织使用的Windows操作系统(OS)非常真实。通过Windows,遗憾的是,操作系统的封闭源特性意味着发现隐藏的安全问题很晚,并且没有实时发现修复程序。需要重新审视当前恶意软件检测的静态方法。本文介绍了用于Windows操作系统的自动化和实时监控和预测rootkit和恶意软件威胁的集成系统。我们建议在广泛使用的Xen虚拟机管理程序上托管目标Windows计算机,并使用虚拟内存内省(VMI)收集流行行为。将使用艺术机器学习技术的状态分析收集的数据,以便快速隔离恶意过程行为和警报系统管理员关于潜在网络漏洞。本研究有两个焦点区域:识别内存数据结构和开发预测工具以检测恶意软件。研究的第一部分侧重于识别受恶意软件影响的内存数据结构。这包括用rootkit /恶意软件频繁定位的VMI提取内核数据结构。研究的第二部分将涉及使用机器学习技术开发预测工具。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号