...
首页> 外文期刊>Computers & Security >Automated containment of rootkits attacks
【24h】

Automated containment of rootkits attacks

机译:自动遏制Rootkit攻击

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Rootkit attacks are a serious threat to computer systems. Packaged with other malwares such as worms, viruses and spyware, rootkits pose a more potent threat than ever before by allowing malware to evade detection. In the absence of appropriate tools to counter such attacks, compromised machines stay undetected for extended periods of time. Leveraging virtual machine technology, we propose a solution for real-time automated detection and containment of rootkit attacks. We have developed a prototype using VMware Workstation to illustrate the solution. Our analysis and experimental results indicate that this approach can very successfully detect and contain the effects of a large percentage of rootkits found for Linux today. We also demonstrate with an example, how this approach is particularly effective against malwares that use rootkits to hide.
机译:Rootkit攻击是对计算机系统的严重威胁。 Rootkit与蠕虫,病毒和间谍软件等其他恶意软件打包在一起,通过允许恶意软件逃避检测,构成了比以往更强大的威胁。如果没有适当的工具来应对此类攻击,则受感染的计算机会长时间未被检测到。利用虚拟机技术,我们提出了一种实时自动检测和遏制Rootkit攻击的解决方案。我们使用VMware Workstation开发了一个原型来说明该解决方案。我们的分析和实验结果表明,这种方法可以非常成功地检测并包含当今针对Linux发现的大量rootkit的影响。我们还将通过一个示例演示这种方法如何特别有效地抵御使用rootkit进行隐藏的恶意软件。

著录项

  • 来源
    《Computers & Security》 |2008年第8期|323-334|共12页
  • 作者单位

    Department of Computer Science, Rutgers University, 110 Frelinghuysen Road, Piscataway, NJ, United States;

    Department of Computer Science, Rutgers University, 110 Frelinghuysen Road, Piscataway, NJ, United States;

    VMware Inc, 3145 Porter Drive, Palo Alto, CA, United States;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    rootkits; stealth malware; intrusion; containment; virtual machines;

    机译:rootkits;隐形恶意软件;入侵遏制;虚拟机;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号