Vis enkel innførsel

dc.contributor.authorBanin, Sergii
dc.contributor.authorDyrkolbotn, Geir Olav
dc.date.accessioned2020-09-02T12:13:26Z
dc.date.available2020-09-02T12:13:26Z
dc.date.created2020-08-31T13:39:49Z
dc.date.issued2020
dc.identifier.issn0302-9743
dc.identifier.urihttps://hdl.handle.net/11250/2676052
dc.description.abstractAs more vulnerabilities are being discovered every year [17], malware constantly evolves forcing improvements and updates of security and malware detection mechanisms. Malware is used directly on the attacked systems, thus anti-virus solutions tend to neutralize malware by not letting it launch or even being stored in the system. However, if malware is launched it is important to stop it as soon as the maliciousness of a new process has been detected. Following the results from [8] in this paper we show, that it is possible to detect running malware before it becomes malicious. We propose a novel malware detection approach that is capable of detecting Windows malware on the earliest stage of execution. The accuracy of more than 99% has been achieved by finding distinctive low-level behavior patterns generated before malware reaches it’s entry point. We also study the ability of our approach to detect malware after it reaches it’s entry point and to distinguish between benign executables and 10 malware families.en_US
dc.language.isoengen_US
dc.publisherSpringeren_US
dc.titleDetection of Running Malware Before it Becomes Maliciousen_US
dc.typePeer revieweden_US
dc.typeJournal articleen_US
dc.description.versionacceptedVersionen_US
dc.source.journalLecture Notes in Computer Science (LNCS)en_US
dc.identifier.doi10.1007/978-3-030-58208-1_4
dc.identifier.cristin1826240
dc.description.localcodeThis is a post-peer-review, pre-copyedit version of an article. The final authenticated version is available online at: http://dx.doi.org/10.1007/978-3-030-58208-1_4en_US
cristin.ispublishedtrue
cristin.fulltextpostprint
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel