Neural Network Analysis of System Call Timing for Rootkit Detection

Neural Network Analysis of System Call Timing for Rootkit Detection
复制标题

Rootkit 检测的系统调用时序的神经网络分析

DOI:
10.1109/cybersec.2016.008
复制
发表时间:
2016
期刊:
2016 Cybersecurity Symposium (CYBERSEC)
影响因子:
--
通讯作者:
Joel A. Dawson
Joel A. Dawson
中科院分区:
--
文献类型:
--
作者:
Patrick Luckett;J. McDonald;Joel A. Dawson

文献摘要

被引文献

相似文献

在网络安全领域,rootkit 对个人、公司和政府构成了可信的威胁。通过各种技术,Rootkit 不仅能够感染计算机系统,而且通常能够通过操纵系统软件在主机中长时间不被发现。本文的目的是描述 Rootkit 是什么、它们如何运行以及它们与其他类型的恶意软件有何关系。将提供历史数据和统计数据,以显示 Rootkit 如何用于网络攻击。将描述不同类型的 Rootkit,包括用户、内核和管理程序 Rootkit,以及用于防御 Rootkit 的各种方法。然后,我们将介绍一个案例研究,其中使用神经网络来分析未感染和感染 Rootkit 的系统的行为,并将生成的系统调用分类为异常或正常。
In the realm of cybersecurity, rootkits pose a credible threat to individuals, corporations, and governments. Through various techniques, rootkits are not only able to infect computer systems, but often times are able to remain undetected in a host for an extended amount of time by manipulating system software. The purpose of this paper is to describe what a rootkit is, how they operate, and how they relate to other types of malware. Historical data and statistics will be presented in order to show how rootkits have been employed in cyber attacks. Different types of rootkits, including user, kernel, and hypervisor rootkits will be described, as well as the various methods used todefend against rootkits. We will then present a case study where neural networks were used to analyze the behavior of a system both not infected and infected with a rootkit, and categorize the resulting system calls as anomalous or not.