Detecting Malicious Software by Monitoring Anomalous Windows Registry Accesses
Detecting Malicious Software by Monitoring Anomalous Windows Registry Accesses
复制标题
通过监控异常 Windows 注册表访问来检测恶意软件
DOI:
--
复制
发表时间:
2002
期刊:
影响因子:
--
通讯作者:
S. Stolfo
中科院分区:
文献类型:
--
作者:
Frank Apap;A. Honig;Shlomo Hershkop;E. Eskin;S. Stolfo
We present a host-based intrusion detection system (IDS) for Microsoft Windows. The core of the system is an algorithm that detects attacks on a host machine by looking for anomalous accesses to the Windows Registry. The key idea is to first train a model of normal registry behavior on a windows host, and use this model to detect abnormal registry accesses at run-time. The normal model is trained using clean (attack-free) data. At run-time the model is used to check each access to the registry in real time to determine whether or not the behavior is abnormal and (possibly) corresponds to an attack. The system is effective in detecting the actions of malicious software while maintaining a low rate of false alarms