דילוג לניווט ראשי דילוג לחיפוש דילוג לתוכן הראשי

Auto-Sign: An automatic signature generator for high-speed malware filtering devices

  • Gil Tahan
  • , Chanan Glezer
  • , Yuval Elovici
  • , Lior Rokach

פרסום מחקרי: פרסום בכתב עתמאמרביקורת עמיתים

13 ציטוטים ‏(Scopus)

תקציר

This research proposes a novel automatic method (termed Auto-Sign) for extracting unique signatures of malware executables to be used by high-speed malware filtering devices based on deep-packet inspection and operating in real-time. Contrary to extant string and token-based signature generation methods, we implemented Auto-Sign an automatic signature generation method that can be used on large-size malware by disregarding signature candidates which appear in benign executables. Results from experimental evaluation of the proposed method suggest that picking a collection of executables which closely represents commonly used code, plays a key role in achieving highly specific signatures which yield low false positives.

שפה מקוריתאנגלית
עמודים (מ-עד)91-103
מספר עמודים13
כתב עתJournal in Computer Virology
כרך6
מספר גיליון2
מזהי עצם דיגיטלי (DOIs)
סטטוס פרסוםפורסם - 2010
פורסם באופן חיצוניכן

טביעת אצבע

להלן מוצגים תחומי המחקר של הפרסום 'Auto-Sign: An automatic signature generator for high-speed malware filtering devices'. יחד הם יוצרים טביעת אצבע ייחודית.

פורמט ציטוט ביבליוגרפי