首页> 美国政府科技报告 >Using Anticipative Malware Analysis to Support Decision Making.
【24h】

Using Anticipative Malware Analysis to Support Decision Making.

机译:使用预期恶意软件分析来支持决策。

获取原文

摘要

A software tool allowing the safe monitoring of the execution of malicious software (malware), or more generally, programs that cannot be trusted is commonly referred to as a sandbox. Most of the time, a sandbox is implemented in a virtual machine or a simulated operating system and allows the behaviour of the program to be studied from the host's point of view. We are investigating the usefulness of a sandbox in the context of decision making. More specifically, we have designed and implemented a network sandbox, i.e. a sandbox that allows us to study malware behaviour from the network perspective. We plan to use this sandbox to generate malware-sample profiles that can be used by decision making algorithms to help network administrators and security officers decide on a course of action to be followed upon detection of a malware threat. This paper focuses on the implementation details of the sandbox. It is flexible enough to allow the study of malware behaviour in the presence of any given configuration of software and operating system. It also allows the user to specify the network topology to be used.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号