Trabalho apresentado em evento
A malware detection system inspired on the human immune system
Fecha
2012-07-23Registro en:
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), v. 7336 LNCS, n. PART 4, p. 286-301, 2012.
0302-9743
1611-3349
10.1007/978-3-642-31128-4_21
WOS:000308289700021
2-s2.0-84863940774
0095921943345974
0000-0003-4494-1454
Autor
Universidade Estadual Paulista (Unesp)
Renato Archer IT Research Center (CTI/MCT)
Resumen
Malicious programs (malware) can cause severe damage on computer systems and data. The mechanism that the human immune system uses to detect and protect from organisms that threaten the human body is efficient and can be adapted to detect malware attacks. In this paper we propose a system to perform malware distributed collection, analysis and detection, this last inspired by the human immune system. After collecting malware samples from Internet, they are dynamically analyzed so as to provide execution traces at the operating system level and network flows that are used to create a behavioral model and to generate a detection signature. Those signatures serve as input to a malware detector, acting as the antibodies in the antigen detection process. This allows us to understand the malware attack and aids in the infection removal procedures. © 2012 Springer-Verlag.