메뉴 건너뛰기
.. 내서재 .. 알림
소속 기관/학교 인증
인증하면 논문, 학술자료 등을  무료로 열람할 수 있어요.
한국대학교, 누리자동차, 시립도서관 등 나의 기관을 확인해보세요
(국내 대학 90% 이상 구독 중)
로그인 회원가입 고객센터 ENG
주제분류

추천
검색

논문 기본 정보

자료유형
학술저널
저자정보
조우진 (충남대 컴퓨터공학과) 김형식 (충남대학교)
저널정보
한국정보처리학회 JIPS(Journal of Information Processing Systems) JIPS(Journal of Information Processing Systems) 제17권 제4호
발행연도
2021.8
수록면
851 - 865 (15page)
DOI
10.3745/JIPS.03.0163

이용수

표지
📌
연구주제
📖
연구배경
🔬
연구방법
🏆
연구결과
AI에게 요청하기
추천
검색

초록· 키워드

오류제보하기
Enterprise networks in the PyeongChang Winter Olympics were hacked in February 2018. According to adomestic security company’s analysis report, attackers destroyed approximately 300 hosts with the aim ofinterfering with the Olympics. Enterprise have no choice but to rely on digital vaccines since it is overwhelmingto analyze all programs executed in the host used by ordinary users. However, traditional vaccines cannotprotect the host against variant or new malware because they cannot detect intrusions without signatures formalwares. To overcome this limitation of signature-based detection, there has been much research conductedon the behavior analysis of malwares. However, since most of them rely on a sandbox where only analysistarget program is running, we cannot detect malwares intruding the host where many normal programs arerunning. Therefore, this study proposes a method to detect malware variants in the host through logs rather thanthe sandbox. The proposed method extracts common behaviors from variants group and finds characteristicbehaviors optimized for querying. Through experimentation on 1,584,363 logs, generated by executing 6,430malware samples, we prove that there exist the common behaviors that variants share and we demonstrate thatthese behaviors can be used to detect variants.

목차

등록된 정보가 없습니다.

참고문헌 (6)

참고문헌 신청

함께 읽어보면 좋을 논문

논문 유사도에 따라 DBpia 가 추천하는 논문입니다. 함께 보면 좋을 연관 논문을 확인해보세요!

이 논문의 저자 정보

최근 본 자료

전체보기

댓글(0)

0