首页> 外文期刊>International Journal of Applied Engineering Research >Malicious Process Detection using OSA on a DFXML Evidence File
【24h】

Malicious Process Detection using OSA on a DFXML Evidence File

机译:使用OSA在DFXML证据文件上使用OSA进行恶意进程检测

获取原文
获取原文并翻译 | 示例
       

摘要

Cyber-Crime by running malicious processes on workstation are becoming rampant in information industries. Malicious processes tend to be dangerous to sensitive information and must be detected as and when they are triggered. Various tools and techniques are available to detect such dangerous processes out of which, we have set our focus on the DFXML (Digital Forensics XML) language that is used to exchange structured Cyber-Forensic information. We have an evidence file in the DFXML format captured from a malicious computer system which contains all running processes metadata and other related information. We have applied the OSA (Optimal String Alignment) algorithm to detect malicious processes from collected evidences in DFXML format. This has lessened the manual work of the cyber forensic investigators to a greater extent of comparing all running processes along with valid white-hat processes, aiding in faster malicious processes detection in Cyber Forensic Investigations.
机译:通过在工作站上运行恶意进程的网络犯罪在信息产业中变得猖獗。 恶意过程往往是敏感信息危险的,并且必须在触发时检测到。 可以使用各种工具和技术来检测此类危险过程,我们已经将专注于用于交换结构化网络法医信息的DFXML(数字取证XML)语言。 我们在从恶意计算机系统中捕获的DFXML格式中有一个证据文件,其中包含所有正在运行的进程元数据和其他相关信息。 我们已应用OSA(最佳字符串对齐)算法以检测来自DFXML格式的收集证据的恶意进程。 这使得Cyber法医调查人员的手工工作减少到更大程度的比较所有运行过程以及有效的白帽流程,帮助在网络法医调查中更快的恶意过程检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号