https://scholars.lib.ntu.edu.tw/handle/123456789/500947
Title: | Malware profiler based on innovative behavior-awareness technique | Authors: | Dai, S.-Y. Fyodor, Y. Kuo, S.-Y. Wu, M.-W. Huang, Y. SY-YEN KUO |
Keywords: | complete resource topology; dynamic analysis; malvertising; malware; virtual machine | Issue Date: | 2011 | Start page/Pages: | 314-319 | Source: | Proceedings of IEEE Pacific Rim International Symposium on Dependable Computing, PRDC | Abstract: | In order to steal valuable data, hackers are uninterrupted research and development new techniques to intrude computer systems. Opposite to hackers, security researchers are uninterrupted analysis and tracking new malicious techniques for protecting sensitive data. There are a lot of existing analyzers can be used to help security researchers to analyze and track new malicious techniques. However, these existing analyzers cannot provide sufficient information to security researchers to perform precise assessment and deep analysis. In this paper, we introduce a behavior-based malicious software profiler, named Holography platform, to assist security researchers to obtain sufficient information. Holography platform analyzes virtualization hardware data, including CPU instructions, CPU registers, memory data and disk data, to obtain high level behavior semantic of all running processes. High level behavior semantic can provide sufficient information to security researchers to perform precise assessment and deep analysis new malicious techniques, such as malicious advertisement attack(malvertising attack). © 2011 IEEE. |
URI: | https://scholars.lib.ntu.edu.tw/handle/123456789/500947 | DOI: | 10.1109/PRDC.2011.53 | SDG/Keyword: | Behavior-based; Disk data; Malicious software; malvertising; malware; Malwares; Research and development; Running process; Sensitive datas; Virtual machines; Virtualizations; Computer crime; Dynamic analysis; Holography; Network security; Personal computing; Semantics; Research |
Appears in Collections: | 電機工程學系 |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.