יובל אלוביץ

אקדמי בכיר

Method for detecting unknown malicious executables

Boris Rozenberg, Ehud Gudes,Yuval Elovici, Yuval Fledel

We present a method for detecting new malicious executables, which comprises the steps of: (a) in a training phase, finding a collection of system call sequences that are characteristic only to malicious files, and storing said sequences in a database; (b) in a runtime phase, for each running executable, continuously monitoring its issued run-time system calls and comparing with the stored sequences within the database, and when a match is found, declaring said executable as malicious.

שפת פרסום אנגלית
דפים 376-377
סטטוס פרסום פורסם - 01.01.2009

ASJC Scopus subject areas

Theoretical Computer Science
General Computer Science
גישה למסמך
10.1007/978-3-642-04342-0_31
קבצים וקישורים אחרים
Link to publication in Scopus