A Self­learning Av Scanner

نویسنده

  • Andrew Walenstein
چکیده

The nonzero "response time" of AV technologies offers a lacuna for hackers to exploit. By the time an AV company responds with a signature to detect a malicious sample, a hacker may release thousands of new variants. We present a self-learning AV scanner that effectively zeroes the response time needed to detect variants. The scanner uses methods from information retrieval research to determine whether a suspected sample is a variant of existing, known variant using an inexact match approach. The system is self-learning in that it is trained initially on known malicious samples in the AV research lab, but in the simplest case the knowledge base is not updated automatically. Utilizing the inexact matching properties of the scanner, this paper introduces several schemes for implementing automatic self-learning on top of the basic Vilo system, both for “in the cloud” learning and by integrating it into existing end-point scanners.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Amplitude-modulated stimuli reveal auditory-visual interactions in brain activity and brain connectivity

The temporal congruence between auditory and visual signals coming from the same source can be a powerful means by which the brain integrates information from different senses. To investigate how the brain uses temporal information to integrate auditory and visual information from continuous yet unfamiliar stimuli, we used amplitude-modulated tones and size-modulated shapes with which we could ...

متن کامل

Fileprint analysis for Malware Detection

June 19, 2005 1 Review Draft Fileprint analysis for Malware Detection Salvatore J. Stolfo, Ke Wang, Wei-Jen Li Columbia University Abstract Malcode can be easily hidden in document files and embedded in application executables. We demonstrate this opportunity of stealthy malcode insertion in several experiments using a standard COTS Anti-Virus (AV) scanner. In the case of zero-day malicious exp...

متن کامل

Diffusion anisotropy changes in the brains of professional boxers.

BACKGROUND AND PURPOSE Professional boxing may result in brain injury. We hypothesize that quantitative MR diffusion imaging may be useful in determining early white matter changes. METHODS Forty-nine professional boxers (age 30 +/- 4.5 years) and 19 healthy control subjects (age 32 +/- 9.5 years) were imaged on a clinical 1.5T scanner. None of the subjects had neurologic disorder or deficit....

متن کامل

Towards Stealthy Malware Detection1

Malcode can be easily hidden in document files and go undetected by standard technology. We demonstrate this opportunity of stealthy malcode insertion in several experiments using a standard COTS Anti-Virus (AV) scanner. Furthermore, in the case of zero-day malicious exploit code, signature-based AV scanners would fail to detect such malcode even if the scanner knew where to look. We propose th...

متن کامل

An Authentication and Ballot Layout Attack Against an Optical Scan Voting Terminal

Recently, two e-voting technologies have been introduced and used extensively in election procedures: direct recording electronic (DRE) systems and optical scanners. The latter are typically deemed safer as many recent security reports have discovered substantial vulnerabilities in a variety of DRE systems. In this paper we present an attack against the Diebold Accuvote optical scan voting term...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008