Supervised Detection of Infected Machines Using Anti-virus Induced Labels - (Extended Abstract)

نویسندگان

  • Tomer Cohen
  • Danny Hendler
  • Dennis Potashnik
چکیده

Traditional antivirus software relies on signatures to uniquely identify malicious files. Malware writers, on the other hand, have responded by developing obfuscation techniques with the goal of evading content-based detection. A consequence of this arms race is that numerous new malware instances are generated every day, thus limiting the effectiveness of static detection approaches. For effective and timely malware detection, signature-based mechanisms must be augmented with detection approaches that are harder to evade. We introduce a novel detector that uses the information gathered by IBM’s QRadar SIEM (Security Information and Event Management) system and leverages anti-virus reports for automatically generating a labelled training set for identifying malware. Using this training set, our detector is able to automatically detect complex and dynamic patterns of suspicious machine behavior and issue high-quality security alerts. We believe that our approach can be used for providing a detection scheme that complements signature-based detection and is harder to circumvent.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Localization of Herpes Simplex Virus Type 1 DNA in Latently Infected BALB/c Mice Neurons Using in situ Polymerase Chain Reaction

Background: Herpes simplex virus type-1 (HSV-1) establishes a lifelong latent infection in neurons following primary infection. The existence of latent HSV-1 DNA in the trigeminal ganglia of infected BALB/c mice was examined using a direct in situ PCR technique, based on Digoxigenin-11-dUTP detection system with anti-digoxigenin-peroxidase and 3,3'-diaminobenzidine (DAB) substrate. Methods: Eig...

متن کامل

The Potential Effect of Glycyrrhiza Glabra on Early Step of Influenza Virus Replication

Background and Aims: The emergence of drug-resistant influenza viruses has become a serious threat for human and animal populations. Glycyrrhiza glabra (Gg) is a traditional medicine clinically used for the treatment of viral respiratory infection symptoms in most countries. We evaluated the effects of the herb on influenza virus replication in human lung cultured cells (A549) following the det...

متن کامل

Molecular detection of hepatitis delta virus in blood donors with RT-PCR

Abstract Background and Objective: Hepatitis delta virus is an imperfect virus with RNA and its activity depends on the presence of hepatitis B virus. This virus can lead to acute and chronic diseases in the liver. This study aimed to detect the hepatitis delta virus in blood donors with positive Hepatitis B Surface Antigens (HBsAg). Material and Methods: In this Study, 350 serum sa...

متن کامل

Detection of SENV Virus in Healthy, Hepatitis B- and Hepatitis C-Infected Individuals in Yazd Province, Iran

Background: SEN virus (SENV) is the latest virus proposed as a cause of unknown hepatitis cases. Among nine detected genotypes of the virus, genotypes D and H are more frequent in hepatitis cases of unknown origin. The aim of this study was to determine the frequency of SENV-D and SENV-H genotypes in the sera of healthy individuals and hepatitis B and C patients. Methods: Totally, 200 serum sam...

متن کامل

Applying conserved peptides of NS1 Protein of avian influenza virus to differentiate infected from vaccinated chickens

Avian influenza (AI) is a highly contagious disease in poultry and outbreaks can have dramatic economic and health implications. For effective disease surveillance, rapid and sensitive assays are needed to detect antibodies against AI virus (AIV) proteins. In order to support eradication efforts of avian influenza (AI) infections in poultry, the implementation of “DIVA” vaccination strategies, ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2017