首页> 外文会议>2011 IEEE International Carnahan Conference on Security Technology >Design and prototyping of framework for automated continuous malware collection and analysis
【24h】

Design and prototyping of framework for automated continuous malware collection and analysis

机译:自动进行连续恶意软件收集和分析的框架的设计和原型制作

获取原文

摘要

In this paper, design of a framework for malware collection and analysis is described. The framework enables researchers to collect malware samples for analysis continuously, to develop counter measures and to generate pattern signatures for detection. By using this framework security analysts and operators are able to minimize their workload. Five components of malware collection unit, malware database, dynamic analysis unit, static analysis unit, signature generation and response unit have been developed and with certain level of manual operation these units are functional and are able to reduce workload of analysts for counter malware activities. Functionality to manage resources for integrated units such as virtual machines, virtual networks etc is being developed. Development of automated generation of signature would be key for this solution. An approach which compare network traffic generated by machines with malicious executable running and innocent network traffic collected from network used in daily operation which is assumed not to include malicious traffic is proposed. Under the situation with increasing number of newly created malware development of automation and continuity of counter malware scheme has been significant issues. This proposed framework is considered possible solution for such problem in the area of computer and network security.
机译:在本文中,描述了恶意软件收集和分析框架的设计。该框架使研究人员能够连续收集恶意软件样本以进行分析,制定对策并生成用于检测的特征码签名。通过使用此框架,安全分析人员和操作员可以最大程度地减少工作量。已经开发了恶意软件收集单元,恶意软件数据库,动态分析单元,静态分析单元,签名生成和响应单元的五个组件,并且通过一定程度的手动操作,这些单元可以正常工作,并且能够减少分析人员用于反恶意软件活动的工作量。正在开发用于管理诸如虚拟机,虚拟网络等的集成单元的资源的功能。开发自动生成签名将是此解决方案的关键。提出了一种方法,该方法将具有恶意可执行文件运行的机器生成的网络流量与从日常操作中使用的网络收集的无恶意网络流量(假定不包括恶意流量)进行比较。在新创建的恶意软件数量不断增加的情况下,自动化和反恶意软件方案的连续性发展已成为重大问题。所提出的框架被认为是解决计算机和网络安全领域中此类问题的可能解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号