首页> 外文会议>World Congress on Internet Security >A practical business security framework to combat malware threat
【24h】

A practical business security framework to combat malware threat

机译:应对恶意软件威胁的实用业务安全框架

获取原文
获取原文并翻译 | 示例

摘要

Malware threats are continuously growing with sophistication. Though multiple layers of defense are provided at perimeter, network, host, application and data levels, it is still becoming a challenge to address malware related problems. They have grown in number as well as complexity and are responsible for attacks ranging from denial-of-service to compromising online banking accounts. In recent times, blended attacks are popular with high severity of damage and are difficult to address using signature based anti-malware solutions. Signature based anti-malware solutions are not able to completely detect and block malware behavior. Though heuristic based anti-malware solutions are able to increase the detection rate, their false positive rate is high. Application whitelisting is effective but creates rigidity on environment. Through this paper we analyzed positive as well as negative security models and proposed a practical security framework for combating malware threat, considering the nature of Information Technology (IT) systems and their business objective.
机译:恶意软件的威胁日益复杂。尽管在外围,网络,主机,应用程序和数据级别提供了多层防御,但解决与恶意软件相关的问题仍然是一项挑战。它们的数量和复杂性都在增长,并负责从拒绝服务到危害在线银行帐户的攻击。近年来,混合攻击以破坏的严重性很普遍,并且很难使用基于特征码的反恶意软件解决方案来解决。基于签名的反恶意软件解决方案无法完全检测和阻止恶意软件行为。尽管基于启发式的反恶意软件解决方案能够提高检测率,但其误报率很高。将应用程序列入白名单是有效的,但会增加环境的刚性。通过本文,我们考虑了信息技术(IT)系统的性质及其业务目标,分析了积极和消极的安全模型,并提出了一种用于抵御恶意软件威胁的实用安全框架。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号