首页> 外文会议>International workshop on security >Detection of Running Malware Before it Becomes Malicious
【24h】

Detection of Running Malware Before it Becomes Malicious

机译:在恶意软件运行之前对其进行检测

获取原文

摘要

As more vulnerabilities are being discovered every year [17], malware constantly evolves forcing improvements and updates of security and malware detection mechanisms. Malware is used directly on the attacked systems, thus anti-virus solutions tend to neutralize malware by not letting it launch or even being stored in the system. However, if malware is launched it is important to stop it as soon as the maliciousness of a new process has been detected. Following the results from [8] in this paper we show, that it is possible to detect running malware before it becomes malicious. We propose a novel malware detection approach that is capable of detecting Windows malware on the earliest stage of execution. The accuracy of more than 99% has been achieved by finding distinctive low-level behavior patterns generated before malware reaches it's entry point. We also study the ability of our approach to detect malware after it reaches it's entry point and to distinguish between benign executables and 10 malware families.
机译:每年,随着越来越多的漏洞被发现[17],恶意软件不断发展,迫使对安全性和恶意软件检测机制进行改进和更新。恶意软件直接在受攻击的系统上使用,因此防病毒解决方案倾向于通过不允许恶意软件启动甚至将其存储在系统中来中和恶意软件。但是,如果启动了恶意软件,则必须在检测到新进程的恶意软件后立即将其停止。根据本文[8]的结果,我们表明,有可能在恶意软件变为恶意软件之前对其进行检测。我们提出了一种新颖的恶意软件检测方法,该方法能够在执行的最早阶段检测Windows恶意软件。通过查找在恶意软件到达其入口点之前生成的独特的低级行为模式,可以实现超过99%的准确性。我们还研究了我们的方法在恶意软件到达其入口点后对其进行检测并区分良性可执行文件和10个恶意软件系列的能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号