首页> 外文会议>Pacific Rim International Conference Dependable Computing >A Stateful Approach to Spyware Detection and Removal
【24h】

A Stateful Approach to Spyware Detection and Removal

机译:一种间谍软件检测和拆卸的状态方法

获取原文

摘要

Spyware, a type of potentially unwanted programs (PUPs), has become a significant threat to most Internet users as it introduces serious privacy disclosure and potential security breach to the systems. Current anti-spyware tools use signatures to detect spyware programs. Over time, spyware programs have grown more resilient to this technique; they utilize critical areas of the system to survive reboots and set up mini-installers that re-install a spyware program after it's been detected and removed. Since existing anti-spyware tools are stateless in the sense that they do not remember and monitor the spyware programs that were removed, they fail to permanently remove these self-healing spyware programs. This paper proposes STARS (Stateful Threat-Aware Removal System): a tool that at run time intercepts critical system accesses and assures removed spyware does not re-install itself after a successful removal of spyware program in the system. If a re-installation (self-healing) is detected, STARS infers the source of such activities and discovers additional "suspicious" programs. Experimental results show that STARS is effective in removing self-healing spyware programs that existing anti-spyware tools fail to do.
机译:间谍软件,一种潜在的不需要的程序(PUP),对大多数互联网用户的重大威胁,因为它引入了严重的隐私披露和潜在的安全漏洞到系统。当前的防间谍软件工具使用签名来检测间谍软件程序。随着时间的推移,间谍软件程序已经增加了这种技术的有弹性;它们利用系统的关键区域来生存重新启动,并设置在检测到并删除后重新安装间谍软件程序的迷你安装程序。由于现有的反间谍软件工具无状态,因此他们不记得并监视已删除的间谍软件程序,因此他们无法永久删除这些自修复间谍软件程序。本文提出了Stars(有状态威胁感知删除系统):在运行时拦截关键系统访问的工具,并确保删除的间谍软件在成功删除系统中的间谍程序后不会重新安装。如果检测到重新安装(自我修复),则STARS INFERS这些活动的来源,并发现额外的“可疑”程序。实验结果表明,恒星可有效地去除现有的防间谍软件工具无法做到的自我修复间谍软件程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号