首页> 外文会议>International Conference on Security Management >PPSAM: Proactive PowerShell Anti-Malware: Customizable Comprehensive Tool to Supplement Commercial AVs
【24h】

PPSAM: Proactive PowerShell Anti-Malware: Customizable Comprehensive Tool to Supplement Commercial AVs

机译:PPSAM:主动PowerShell防恶意软件:可定制的综合工具来补充商业AVS

获取原文

摘要

This research first explores the different types of Anti-Malware solution approaches, evaluating the pros and cons, and concentrating on their potential weaknesses and drawbacks. The malware technologies analyzed include Windows Direct Kernel Object Manipulation (DKOM), Kernel Patch Protection, Data Execution Prevention, Address Space Layout Randomization, Driver Signing, Windows Service Hardening, Ghostbuster, Assembly Reverse Analysis, and Virtual CloudAV. Furthermore, a proactive comprehensive solution is provided by utilizing the Windows PowerShell 2.0 utility that is available for Windows Vista, 7, 2008 and 2008 R2. The proposed Proactive PowerShell Anti-Malware (PPSAM) is a utility that monitors the system via health checks with shell scripts that can be fully customized and have the ability to be executed on remote systems. PPSAM is designed to be a proactive complement that attempts to promote early discovery of intrusions and malicious applications, and to provide triggers and reports utilizing the scripts' output.
机译:本研究首先探讨了不同类型的反恶意软件解决方案方法,评估利弊,并集中在潜在的弱点和缺点上。分析的恶意软件技术包括Windows Direct Kernel对象操作(DKOM),内核修补程序保护,数据执行预防,地址空间布局随机化,驱动程序签名,Windows服务硬化,Ghostbuster,装配反向分析和虚拟CloudAv。此外,通过利用适用于Windows Vista,7,2008和2008 R2的Windows PowerShell 2.0实用程序来提供主动全面解决方案。提出的主动力激发力壳反恶意软件(PPSAM)是一种实用程序,它通过Health Checks监视系统,可以通过Shell脚本进行完全自定义,并且能够在远程系统上执行能力。 PPSAM旨在成为一个主动补充,试图促进入侵和恶意应用的早期发现,并提供利用脚本输出的触发和报告。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号