首页> 外文会议>International Conference on Convergence Information Technology >Network-based Executable File Detection Reconstruction System for Malware Detection
【24h】

Network-based Executable File Detection Reconstruction System for Malware Detection

机译:用于恶意软件检测的基于网络的可执行文件检测和重建系统

获取原文

摘要

As the hackers' intension has been changed from fast and widespread malware propagation, to more sophisticated "targeted" attacks such as spy/adware, password stealers, ransom ware, botnets etc., malware detection has become one of the most important security issues. The malware analysis has to be preceded for the malware detection. Therefore, before it is analyzed in suspicious executable files, it has to be collected. The malwares could be gathered from the attacked systems, but it means that an attack already has succeeded The suspicious file collection has to be possible before an attack succeeds in order to overcome this situation. For that, in this paper we propose the network-based executable file (Windows PE file) detection and reconstruction system (NEFDRS). The NEFDRS proposed in this paper can collect the executable files from the network packets, however, all the malwares are due to be executable so the suspicious executable file can be collected earlier than it is currently possible. Therefore the executable file could be quickly provided for the existing malware detection system. The NEFDRS can help the malware detection system which is able to detect and protect the malwares before the attack succeeds.
机译:由于黑客的内涵从快速和广泛的恶意软件传播变为更加复杂的“目标”攻击,如间谍/广告软件,密码窃取器,赎金洁具,刚度,僵尸网络等,恶意软件检测已成为最重要的安全问题之一。必须在恶意软件检测之前进行恶意软件分析。因此,在在可疑可执行文件中分析之前,必须收集。棕褐版可以从攻击的系统中收集,但这意味着在攻击成功之前,攻击已经成功了可疑文件集合以克服这种情况。为此,在本文中,我们提出了基于网络的可执行文件(Windows PE文件)检测和重建系统(Nefdr)。本文提出的NEFDR可以从网络数据包中收集可执行文件,但是,所有恶魔都是由于可执行文件,因此可以比目前可能收集可疑的可执行文件。因此,可以为现有恶意软件检测系统快速提供可执行文件。在攻击成功之前,Nefdr可以帮助恶意软件检测系统,该系统能够在攻击之前检测和保护恶意。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号