首页> 外文会议>IASTED International Conference on Internet and Multimedia Systems and Applications >A SYSTEM FOR PROGRAM EXECUTION IDENTIFICATION ON THE MICROSOFT WINDOWS PLATFORMS
【24h】

A SYSTEM FOR PROGRAM EXECUTION IDENTIFICATION ON THE MICROSOFT WINDOWS PLATFORMS

机译:Microsoft Windows平台上的程序执行识别系统

获取原文

摘要

This paper describes a system for identification execution of programs using execution events of the programs. This system is based on a model of program execution for security purposes, and is implemented on the Microsoft Windows platforms using an operating system technique called DLL (Dynamic Linked Library) replacement. Compared to other related works, this paper has two key contributions: It describes a systematic way to retain all system DLLs made by application programs dynamically and in real-time on the Microsoft Windows platforms. It also presents a new model of program execution, in which frequencies of program execution events are considered in addition to their patterns. Our experiment data indicate improved results.
机译:本文介绍了一种用于使用程序的执行事件识别程序的系统。该系统基于用于安全目的的程序执行模型,并使用名为DLL(动态链接库)替换的操作系统技术在Microsoft Windows平台上实现。与其他相关工程相比,本文有两个主要贡献:它描述了一种系统的方法,可以在Microsoft Windows平台上动态地且实时地保留应用程序所做的所有系统DLL。它还提出了一种新的程序执行模型,其中除了它们的模式之外还考虑了程序执行事件的频率。我们的实验数据表明了改进的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号