首页> 外文期刊>Future generation computer systems >Enforcing situation-aware access control to build malware-resilient file systems
【24h】

Enforcing situation-aware access control to build malware-resilient file systems

机译:强制执行情况感知访问控件构建恶意软件 - 弹性文件系统

获取原文
获取原文并翻译 | 示例
       

摘要

Traditional non-semantic file systems are not sufficient in protecting file systems against attacks, either caused by ransomware attacks or software-related defects. Furthermore, outbreaks of new malware often cannot provide a large quantity of training samples for machine-learning-based approaches to counter malware campaigns. The malware defense system should aim to achieve the best balance between early detection and detection accuracy. In this paper, we present a situation-aware access control framework to work with existing file systems as a stackable add-on. Our framework enables the access control decision making to be deferred when required, to observe the consequence of such an access request to the file system and to roll back changes if required. As an application against ransomware attacks, it can be applied to preserve file content integrity, by enforcing that all binary files written to the file system have consistent internal file structures with the declared file types, and rolling back changes that violate such constraints. We envision our access control framework to complement existing operating system access control frameworks, to significantly reduce the dimension of data required for machine learning, and to build extra resilience into the operating systems against damages caused by either malware or software defects. We demonstrate the practicality of our framework through a prototype testing, capturing relevant ransomware situations. The experimental results along with a large ransomware dataset show that our framework can be effectively applied in practice.
机译:传统的非语义文件系统不足以保护文件系统免受攻击的保护,无论是由赎金软件攻击还是与软件相关的缺陷造成的。此外,新恶意软件的爆发通常无法为基于机器学习的方法提供大量的培训样本来对抗恶意软件运动。恶意软件防御系统旨在实现早期检测和检测准确性之间的最佳平衡。在本文中,我们展示了一个情况感知访问控制框架,可以使用现有文件系统作为可堆叠的加载项。我们的框架使得访问控制决策能够在需要时延迟,以观察对文件系统的访问请求的后果,并且如果需要,回滚更改。作为违反赎金软件攻击的应用程序,可以应用于保留文件内容完整性,通过执行写入文件系统的所有二进制文件具有一致的内部文件结构与声明的文件类型,并回滚违反此类约束的更改。我们设想我们的访问控制框架来补充现有的操作系​​统访问控制框架,从而大大减少机器学习所需的数据的维度,并在操作系统中构建额外的弹性,以防止由恶意软件或软件缺陷引起的损坏。我们通过原型测试展示了我们框架的实用性,捕获相关的勒索仓库情况。实验结果以及大型勒克斯仓库数据集显示我们的框架可以在实践中有效应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号