
יובל אלוביץ
אקדמי בכיר
Method for detecting unknown malicious executables
We present a method for detecting new malicious executables, which comprises the steps of: (a) in a training phase, finding a collection of system call sequences that are characteristic only to malicious files, and storing said sequences in a database; (b) in a runtime phase, for each running executable, continuously monitoring its issued run-time system calls and comparing with the stored sequences within the database, and when a match is found, declaring said executable as malicious.
| שפת פרסום | אנגלית |
| דפים | 376-377 |
| סטטוס פרסום | פורסם - 01.01.2009 |
ASJC Scopus subject areas
Theoretical Computer Science
General Computer Science