A malware detection system inspired on the human immune system


Autoria(s): De Oliveira, Isabela Liane; Grégio, André Ricardo Abed; Cansian, Adriano Mauro
Contribuinte(s)

Universidade Estadual Paulista (UNESP)

Data(s)

27/05/2014

27/05/2014

23/07/2012

Resumo

Malicious programs (malware) can cause severe damage on computer systems and data. The mechanism that the human immune system uses to detect and protect from organisms that threaten the human body is efficient and can be adapted to detect malware attacks. In this paper we propose a system to perform malware distributed collection, analysis and detection, this last inspired by the human immune system. After collecting malware samples from Internet, they are dynamically analyzed so as to provide execution traces at the operating system level and network flows that are used to create a behavioral model and to generate a detection signature. Those signatures serve as input to a malware detector, acting as the antibodies in the antigen detection process. This allows us to understand the malware attack and aids in the infection removal procedures. © 2012 Springer-Verlag.

Formato

286-301

Identificador

http://dx.doi.org/10.1007/978-3-642-31128-4_21

Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), v. 7336 LNCS, n. PART 4, p. 286-301, 2012.

0302-9743

1611-3349

http://hdl.handle.net/11449/73443

10.1007/978-3-642-31128-4_21

WOS:000308289700021

2-s2.0-84863940774

Idioma(s)

eng

Relação

Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)

Direitos

closedAccess

Palavras-Chave #data mining #human immune system #malicious code #Antigen detections #Behavioral model #Execution trace #Human bodies #Human immune systems #Malicious codes #Malware attacks #Malware detection #Malwares #Network flows #Chemical detection #Computer aided network analysis #Computer crime #Data mining #Detectors #Network security #Immunology
Tipo

info:eu-repo/semantics/conferencePaper