Please use this identifier to cite or link to this item: http://repositorio.unicamp.br/jspui/handle/REPOSIP/86371
Type: Artigo de evento
Title: Ontology For Malware Behavior: A Core Model Proposal
Author: Grecio A.
Bonacin R.
Nabuco O.
Afonso V.M.
De Geus P.L.
Jino M.
Abstract: The ubiquity of Internet-connected devices motivates attackers to create malicious programs (malware) to exploit users and their systems. Malware detection requires a deep understanding of their possible behaviors, one that is detailed enough to tell apart suspicious programs from benign, legitimate ones. A step to effectively address the malware problem leans toward the development of an ontology. Current efforts are based on an obsolete hierarchy of malware classes that defines a malware family by one single prevalent behavior (e.g., viruses infect other files, worms spread and exploit remote systems autonomously, Trojan horses disguise themselves as benign programs, and so on). In order to address the detection of modern, complex malware families whose infections involve sets of multiple exploit methods, we need an ontology broader enough to deal with these suspicious activities performed on the victim's system. In this paper, we propose a core model for a novel malware ontology that is based on their exhibited behavior, filling a gap in the field.
Editor: IEEE Computer Society
Rights: fechado
Identifier DOI: 10.1109/WETICE.2014.72
Address: http://www.scopus.com/inward/record.url?eid=2-s2.0-84908432472&partnerID=40&md5=5a9e3c2506acb7a77e966c341fc1eb9c
Date Issue: 2014
Appears in Collections:Unicamp - Artigos e Outros Documentos

Files in This Item:
File Description SizeFormat 
2-s2.0-84908432472.pdf210.22 kBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.