首页> 外文会议>IEEE Workshop on Secure Network Protocols >A Behavior Based Malware Detection Scheme for Avoiding False Positive
【24h】

A Behavior Based Malware Detection Scheme for Avoiding False Positive

机译:基于行为的恶意软件检测方案,以避免误报

获取原文

摘要

The number of malware is increasing rapidly and a lot of malware use stealth techniques such as encryption to evade pattern matching detection by anti-virus software. To resolve the problem, behavior based detection method which focuses on malicious behaviors of malware have been researched. Although they can detect unknown and encrypted malware, they suffer a serious problem of false positives against benign programs. For example, creating files and executing them are common behaviors performed by malware, however, they are also likely performed by benign programs thus it causes false positives. In this paper, we propose a malware detection method based on evaluation of suspicious process behaviors on Windows OS. To avoid false positives, our proposal focuses on not only malware specific behaviors but also normal behavior that malware would usually not do. Moreover, we implement a prototype of our proposal to effectively analyze behaviors of programs. Our evaluation experiments using our malware and benign program datasets show that our malware detection rate is about 60% and it does not cause any false positives. Furthermore, we compare our proposal with completely behavior-based anti-virus software. Our results show that our proposal puts few burdens on users and reduces false positives.
机译:恶意软件的数量正在迅速增加,并且许多恶意软件使用隐形技术,例如加密来避免防病毒软件的模式匹配检测。解决问题,研究了基于行为的检测方法,其侧重于恶意软件的恶意行为。虽然他们可以检测到未知和加密的恶意软件,但它们遭受了对良性程序的严重问题的严重问题。例如,创建文件和执行它们是恶意软件执行的常见行为,但是,它们也可能由良性程序执行,因此它会导致误报。在本文中,我们提出了一种基于Windows OS上可疑过程行为的评估的恶意软件检测方法。为避免误报,我们的建议不仅关注恶意软件特定行为,而且侧重于恶意软件通常不会做的正常行为。此外,我们实施了我们提案的原型,以有效分析计划的行为。我们使用我们恶意软件和良性计划数据集的评估实验表明,我们的恶意软件检测率约为60%,并且不会导致任何误报。此外,我们将我们的提案与完全行为的防病毒软件进行比较。我们的结果表明,我们的提案对用户的负担很少,并减少误报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号