Detecting Malicious Software by Monitoring Anomalous Windows Registry Accesses

Detecting Malicious Software by Monitoring Anomalous Windows Registry Accesses
复制标题

通过监控异常 Windows 注册表访问来检测恶意软件

DOI:
--
复制
发表时间:
2002
期刊:
International Symposium on Recent Advances in Intrusion Detection
影响因子:
--
通讯作者:
S. Stolfo
S. Stolfo
中科院分区:
--
文献类型:
--
作者:
Frank Apap;A. Honig;Shlomo Hershkop;E. Eskin;S. Stolfo

文献摘要

被引文献

相似文献

我们提出了一种适用于 Microsoft Windows 的基于主机的入侵检测系统 (IDS)。该系统的核心是一种算法,通过查找对 Windows 注册表的异常访问来检测对主机的攻击。关键思想是首先在 Windows 主机上训练正常注册表行为的模型,并使用该模型来检测运行时的异常注册表访问。正常模型是使用干净(无攻击)数据进行训练的。在运行时,该模型用于实时检查对注册表的每次访问,以确定行为是否异常以及(可能)对应于攻击。该系统可有效检测恶意软件的行为,同时保持较低的误报率
We present a host-based intrusion detection system (IDS) for Microsoft Windows. The core of the system is an algorithm that detects attacks on a host machine by looking for anomalous accesses to the Windows Registry. The key idea is to first train a model of normal registry behavior on a windows host, and use this model to detect abnormal registry accesses at run-time. The normal model is trained using clean (attack-free) data. At run-time the model is used to check each access to the registry in real time to determine whether or not the behavior is abnormal and (possibly) corresponds to an attack. The system is effective in detecting the actions of malicious software while maintaining a low rate of false alarms