Malware Detection in Cloud Computing

Malware Detection in Cloud Computing
复制标题

DOI:
10.14569/ijacsa.2014.050427
复制
发表时间:
2017-03
影响因子:
0.9
通讯作者:
Safaa Salam Hatem;M. Wafy;M. El-khouly
Safaa Salam Hatem;M. Wafy;M. El-khouly
中科院分区:
--
文献类型:
--
作者:
Safaa Salam Hatem;M. Wafy;M. El-khouly

文献摘要

被引文献

相似文献

检测恶意软件是一个复杂的问题。庞大且不断增长的恶意软件和工具生态系统对网络运营商和IT管理员提出了严峻的挑战。防病毒软件是用于检测和阻止恶意和不需要的软件的最广泛使用的工具之一。然而,现代恶意软件的复杂性越来越高,这意味着任何一家供应商都难以为每一个新的威胁开发签名。事实上,微软最近的一项调查发现,在2006年下半年,有超过45,000种新的后门、木马和机器人变种。在本文中,我们提出了一个新的模式,目前基于主机的防病毒软件执行的检测功能。本文件的特点是两个关键的变化。将恶意软件检测作为网络服务:首先,目前由基于主机的防病毒软件提供的检测功能可以更高效和有效地作为云内网络服务提供。与其在每个终端主机上运行复杂的分析软件,我们建议每个终端主机运行一个轻量级进程来检测新文件,将它们发送到网络服务进行分析,然后根据网络服务返回的报告允许访问或隔离它们。多检测技术:其次,恶意软件和有害软件的识别应该分别由多个不同的检测引擎来确定。建议恶意软件检测系统应利用多个集合检测引擎的检测功能,以更有效地确定恶意和不需要的文件。未来,随着消费者越来越多地转向移动的平台以满足其计算需求,我们将看到对云计算的依赖性增加。云技术已经通过结核病成为可能,以便在多个虚拟机(VM)之间共享物理服务器资源。这种方法的优点包括可以为每个物理服务器提供服务的客户端数量的增加以及提供软件即服务(SaaS)的能力。在本文中,已经介绍了以前关于恶意软件检测的工作,包括传统的和存在云存储的情况,以确定在云中检测的最佳方法[2]。我们还讨论了在整个云中进行多个检测的好处,并提出了一种新的方法来协调整个云中的检测。第二部分介绍了研究领域的背景和相关工作,具体为:云技术、云中安全系统、恶意软件检测和云中检测。第三节,我们解释我们的建议系统。第四节我们展示了我们的系统的备注。最后,第五部分对本文提出的观点进行了总结,并对今后的工作提出了一些设想.
Detecting malicious software is a complex problem. The vast, ever-increasing ecosystem of malicious software and tools presents a daunting challenge for network operators and IT administrators. Antivirus software is one of the most widely used tools for detecting and stopping malicious and unwanted software. However, the elevating sophistication of modern malicious software means that it is increased challenging for any single vendor to develop signatures for every new threat. Indeed, a recent Microsoft survey found more than 45,000 new variants of backdoors, Trojans, and bots during the second half of 2006 [1]. In this paper, we suggest a new model for the detection functionality currently performed by host-based antivirus software. This paper is characterized by two key changes.  Malware detection as a network service: First, the detection capabilities currently provided by host-based antivirus software can be more efficiently and effectively provided as an in-cloud network service. Instead of running complex analysis software on every end host, we suggest that each end host runs a lightweight process to detect new files, send them to a network service for analysis, and then permit access or quarantine them based on a report returned by the network service.  Multi-detection techniques: Second, the identification of malicious and unwanted software should be determined by multiple, Different detection engines Respectively. Suggest that malware detection systems should leverage the detection capabilities of multiple, Collection detection engines to more effectively determine malicious and unwanted files. In the future, we will see an increase in the dependence of cloud computing as consumers increasingly move to mobile platforms for their computing needs. Cloud technologies have become possible by tuberculation in order to share physical server resources between multiple virtual machines (VMs). The advantages of this approach include an increase in the number of clients that can be served for every physical server and the ability to provide software as a service (SaaS). In this paper, previous work on malware detection had been presented, both conventional and in the presence of cloud as storage in order to determine the best approach for detection in the cloud [2]. We also argue the benefits of multiple detection throughout the cloud and present a new approach to coordinate detection across the cloud. Section II provides background and related work the research area, specifically: cloud technologies, security system in the cloud, malware detection and detection in the cloud. Section III, we explain our Proposed System. Section IV we show Remarks of our system. Finally, section V Conclusions the points raised in this paper and provide some ideas for future work.