https://scholars.lib.ntu.edu.tw/handle/123456789/500947
標題: | Malware profiler based on innovative behavior-awareness technique | 作者: | Dai, S.-Y. Fyodor, Y. Kuo, S.-Y. Wu, M.-W. Huang, Y. SY-YEN KUO |
關鍵字: | complete resource topology; dynamic analysis; malvertising; malware; virtual machine | 公開日期: | 2011 | 起(迄)頁: | 314-319 | 來源出版物: | Proceedings of IEEE Pacific Rim International Symposium on Dependable Computing, PRDC | 摘要: | In order to steal valuable data, hackers are uninterrupted research and development new techniques to intrude computer systems. Opposite to hackers, security researchers are uninterrupted analysis and tracking new malicious techniques for protecting sensitive data. There are a lot of existing analyzers can be used to help security researchers to analyze and track new malicious techniques. However, these existing analyzers cannot provide sufficient information to security researchers to perform precise assessment and deep analysis. In this paper, we introduce a behavior-based malicious software profiler, named Holography platform, to assist security researchers to obtain sufficient information. Holography platform analyzes virtualization hardware data, including CPU instructions, CPU registers, memory data and disk data, to obtain high level behavior semantic of all running processes. High level behavior semantic can provide sufficient information to security researchers to perform precise assessment and deep analysis new malicious techniques, such as malicious advertisement attack(malvertising attack). © 2011 IEEE. |
URI: | https://scholars.lib.ntu.edu.tw/handle/123456789/500947 | DOI: | 10.1109/PRDC.2011.53 | SDG/關鍵字: | Behavior-based; Disk data; Malicious software; malvertising; malware; Malwares; Research and development; Running process; Sensitive datas; Virtual machines; Virtualizations; Computer crime; Dynamic analysis; Holography; Network security; Personal computing; Semantics; Research |
顯示於: | 電機工程學系 |
在 IR 系統中的文件,除了特別指名其著作權條款之外,均受到著作權保護,並且保留所有的權利。