DocumentCode :
2314948
Title :
A Bray-Curtis Weighted Automaton for Detecting Malicious Code Through System-Call Analysis
Author :
Pungila, Ciprian
Author_Institution :
Comput. Sci. Dept., West Univ. of Timisoara, Timisoara, Romania
fYear :
2009
fDate :
26-29 Sept. 2009
Firstpage :
392
Lastpage :
400
Abstract :
Malicious code detection is one of the top subjects of interest for intrusion detection systems in today´s computer security research areas. In this paper we propose a new heuristic method for detecting malicious code through system call matching, which also takes in consideration the time of the system call, by using an adaptive search for an extended Aho-Corasick automaton supporting a subset of the regular expressions language, through the use of a normalization technique known as the Bray-Curtis (Sorensen) distance. We will also discuss how this technique can be applied to enrich the set of existing rules from the knowledge base for improving the detection rate.
Keywords :
automata theory; formal languages; security of data; Aho-Corasick automaton; Bray-Curtis distance; Bray-Curtis weighted automaton; Sorensen distance; computer security; detection rate; intrusion detection; knowledge base; malicious code detection; normalization technique; regular expression language; system call matching; system call time; system-call analysis; Algorithm design and analysis; Automata; Computer science; Informatics; Intrusion detection; Mathematics; Pattern analysis; Performance analysis; Scientific computing; Viruses (medical); Aho-Corasick automata; Bray-Curtis distance; Sorensen distance; dynamic analysis; intrusion detection system; malicious code detection; normalization; static analysis; system call timing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Symbolic and Numeric Algorithms for Scientific Computing (SYNASC), 2009 11th International Symposium on
Conference_Location :
Timisoara
Print_ISBN :
978-1-4244-5910-0
Electronic_ISBN :
978-1-4244-5911-7
Type :
conf
DOI :
10.1109/SYNASC.2009.41
Filename :
5460823
Link To Document :
بازگشت