Supervised Detection of Infected Machines Using Anti-virus Induced Labels - (Extended Abstract)
نویسندگان
چکیده
Traditional antivirus software relies on signatures to uniquely identify malicious files. Malware writers, on the other hand, have responded by developing obfuscation techniques with the goal of evading content-based detection. A consequence of this arms race is that numerous new malware instances are generated every day, thus limiting the effectiveness of static detection approaches. For effective and timely malware detection, signature-based mechanisms must be augmented with detection approaches that are harder to evade. We introduce a novel detector that uses the information gathered by IBM’s QRadar SIEM (Security Information and Event Management) system and leverages anti-virus reports for automatically generating a labelled training set for identifying malware. Using this training set, our detector is able to automatically detect complex and dynamic patterns of suspicious machine behavior and issue high-quality security alerts. We believe that our approach can be used for providing a detection scheme that complements signature-based detection and is harder to circumvent.
منابع مشابه
Localization of Herpes Simplex Virus Type 1 DNA in Latently Infected BALB/c Mice Neurons Using in situ Polymerase Chain Reaction
Background: Herpes simplex virus type-1 (HSV-1) establishes a lifelong latent infection in neurons following primary infection. The existence of latent HSV-1 DNA in the trigeminal ganglia of infected BALB/c mice was examined using a direct in situ PCR technique, based on Digoxigenin-11-dUTP detection system with anti-digoxigenin-peroxidase and 3,3'-diaminobenzidine (DAB) substrate. Methods: Eig...
متن کاملThe Potential Effect of Glycyrrhiza Glabra on Early Step of Influenza Virus Replication
Background and Aims: The emergence of drug-resistant influenza viruses has become a serious threat for human and animal populations. Glycyrrhiza glabra (Gg) is a traditional medicine clinically used for the treatment of viral respiratory infection symptoms in most countries. We evaluated the effects of the herb on influenza virus replication in human lung cultured cells (A549) following the det...
متن کاملMolecular detection of hepatitis delta virus in blood donors with RT-PCR
Abstract Background and Objective: Hepatitis delta virus is an imperfect virus with RNA and its activity depends on the presence of hepatitis B virus. This virus can lead to acute and chronic diseases in the liver. This study aimed to detect the hepatitis delta virus in blood donors with positive Hepatitis B Surface Antigens (HBsAg). Material and Methods: In this Study, 350 serum sa...
متن کاملDetection of SENV Virus in Healthy, Hepatitis B- and Hepatitis C-Infected Individuals in Yazd Province, Iran
Background: SEN virus (SENV) is the latest virus proposed as a cause of unknown hepatitis cases. Among nine detected genotypes of the virus, genotypes D and H are more frequent in hepatitis cases of unknown origin. The aim of this study was to determine the frequency of SENV-D and SENV-H genotypes in the sera of healthy individuals and hepatitis B and C patients. Methods: Totally, 200 serum sam...
متن کاملApplying conserved peptides of NS1 Protein of avian influenza virus to differentiate infected from vaccinated chickens
Avian influenza (AI) is a highly contagious disease in poultry and outbreaks can have dramatic economic and health implications. For effective disease surveillance, rapid and sensitive assays are needed to detect antibodies against AI virus (AIV) proteins. In order to support eradication efforts of avian influenza (AI) infections in poultry, the implementation of “DIVA” vaccination strategies, ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2017