Customized Normalcy Profiles for the Detection of Targeted Attacks
Clicks: 88
ID: 271058
2012
Article Quality & Performance Metrics
Overall Quality
Improving Quality
0.0
/100
Combines engagement data with AI-assessed academic quality
Reader Engagement
Emerging Content
0.9
/100
3 views
3 readers
Trending
AI Quality Assessment
Not analyzed
Abstract
Functionality is the highest semantic level of the software behavior pyramid that reflects goals of the software rather than its specific implementation. Detection of malicious functionalities presents an effective way to detect malware in behavior-based IDS. A technology for mining system call data, discussed herein, results in the detection of functionalities representing operation of legitimate software within a closed network environment. The set of such functionalities combined with the frequencies of their execution constitutes a normalcy profile typical for this environment. Detection of deviations from this normalcy profile, new functionalities and/or changes in the execution frequencies, provides evidence of abnormal activity in the network caused by malware. This approach could be especially valuable for the detection of targeted zero-day attacks. The paper presents the results of the implementation and testing of the described technology on the computer network testbed.
| Reference Key |
antonakos2012computercustomized
Use this key to autocite in the manuscript while using
SciMatic Manuscript Manager or Thesis Manager
|
|---|---|
| Authors | Victor Skormin,Tomas Nykodym,Andrey Dolgikh,James Antonakos;Victor Skormin;Tomas Nykodym;Andrey Dolgikh;James Antonakos; |
| Journal | Computer Vision |
| Year | 2012 |
| DOI |
10.1007/978-3-642-29178-4_49
|
| URL | |
| Keywords |
Citations
No citations found. To add a citation, contact the admin at info@scimatic.org
Comments
No comments yet. Be the first to comment on this article.