跳至主導覽 跳至搜尋 跳過主要內容

MAPMon: A host-based malware detection tool

  • Shih Yao Dai
  • , Sy Yen Kuo*
  • *此作品的通信作者
  • National Taiwan University
  • National Taiwan University of Science and Technology

研究成果: 圖書/報告稿件的類型會議稿件同行評審

12 引文 斯高帕斯(Scopus)

摘要

In order for financial-motivated malware programs such as spyware, virus and worm to survive after system rebooted, they have to modify entries in auto start extensibility points (ASEPs), system calls or system files on a comprised system. We call these system resources which a malware program could attack once it intrudes a host as Malware Attacking Points (MAPs). Based on this observation, we design and implement MAPMon, a monitoring mechanism to detect any suspicious change of Malware Attacking Points. This paper describes the design and implementation trade-off of the MAPMon tool. The effectiveness of the MAPMon tool for malware detection is evaluated by using real-world malware programs including those that do not have signatures.

原文英語
主出版物標題Proceedings - 13th Pacific Rim International Symposium on Dependable Computing, PRDC 2007
頁面346-356
頁數11
DOIs
出版狀態已出版 - 2007
對外發佈
事件13th Pacific Rim International Symposium on Dependable Computing, PRDC 2007 - Melbourne, VIC, 澳大利亞
持續時間: 17 12 200719 12 2007

出版系列

名字Proceedings - 13th Pacific Rim International Symposium on Dependable Computing, PRDC 2007

Conference

Conference13th Pacific Rim International Symposium on Dependable Computing, PRDC 2007
國家/地區澳大利亞
城市Melbourne, VIC
期間17/12/0719/12/07

指紋

深入研究「MAPMon: A host-based malware detection tool」主題。共同形成了獨特的指紋。

引用此