首页    期刊浏览 2025年07月09日 星期三
登录注册

文章基本信息

  • 标题:Isolating Intrusions by Automatic Experiments
  • 作者:Stephan Neuhaus
  • 期刊名称:OASIcs : OpenAccess Series in Informatics
  • 电子版ISSN:2190-6807
  • 出版年度:2006
  • 卷号:3
  • DOI:10.4230/OASIcs.TrustworthySW.2006.696
  • 出版社:Schloss Dagstuhl -- Leibniz-Zentrum fuer Informatik
  • 摘要:When dealing with malware infections, one of the first tasks is to find the processes that were involved in the attack. We introduce Malfor, a system that isolates those processes automatically. In contrast to other methods that help analyze attacks, Malfor works by experiments: first, we record the interaction of the system under attack; after the intrusion has been detected, we replay the recorded events in slightly different configurations to see which processes were relevant for the intrusion. This approach has three advantages over deductive approaches: first, the processes that are thus found have been experimentally shown to be relevant for the attack; second, the amount of evidence that must then be analyzed to find the attack vector is greatly reduced; and third, Malfor itself cannot make wrong deductions. In a first experiment, Malfor was able to extract the three processes responsible for an attack from 32 candidates in about six minutes.
  • 关键词:Intrusion Analysis; Malware; Experimentation
Loading...
联系我们|关于我们|网站声明
国家哲学社会科学文献中心版权所有