TY - GEN
T1 - Method for detecting unknown malicious executables
AU - Rozenberg, Boris
AU - Gudes, Ehud
AU - Elovici, Yuval
AU - Fledel, Yuval
PY - 2009/1/1
Y1 - 2009/1/1
N2 - We present a method for detecting new malicious executables, which comprises the steps of: (a) in a training phase, finding a collection of system call sequences that are characteristic only to malicious files, and storing said sequences in a database; (b) in a runtime phase, for each running executable, continuously monitoring its issued run-time system calls and comparing with the stored sequences within the database, and when a match is found, declaring said executable as malicious.
AB - We present a method for detecting new malicious executables, which comprises the steps of: (a) in a training phase, finding a collection of system call sequences that are characteristic only to malicious files, and storing said sequences in a database; (b) in a runtime phase, for each running executable, continuously monitoring its issued run-time system calls and comparing with the stored sequences within the database, and when a match is found, declaring said executable as malicious.
UR - https://www.scopus.com/pages/publications/76649088304
U2 - 10.1007/978-3-642-04342-0_31
DO - 10.1007/978-3-642-04342-0_31
M3 - Conference contribution
AN - SCOPUS:76649088304
SN - 3642043410
SN - 9783642043413
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 376
EP - 377
BT - Recent Advances in Intrusion Detection - 12th International Symposium, RAID 2009, Proceedings
PB - Springer Verlag
T2 - 12th International Symposium on Recent Advances in Intrusion Detection, RAID 2009
Y2 - 23 September 2009 through 25 September 2009
ER -