Behavioural API based Virus Analysis and Detection

نویسندگان

  • Sulaiman Al amro
  • Antonio Cau
چکیده

The growing number of computer viruses and the detection of zero day malware have been the concern for security researchers for a large period of time. Existing antivirus products (AVs) rely on detecting virus signatures which do not provide a full solution to the problems associated with these viruses. The use of logic formulae to model the behaviour of viruses is one of the most encouraging recent developments in virus research, which provides alternatives to classic virus detection methods. To address the limitation of traditional AVs, we proposed a virus detection system based on extracting Application Program Interface (API) calls from virus behaviours. The proposed research uses a temporal logic and behaviour-based detection mechanism to detect viruses at both user and kernel level. Interval Temporal Logic (ITL) will be used for virus specifications, properties and formulae based on the analysis of API calls representing the behaviour of computer viruses. Keywords-computer viruses; virus behaviour; API calls; interval temporal logic

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

DyVSoR: dynamic malware detection based on extracting patterns from value sets of registers

To control the exponential growth of malware files, security analysts pursue dynamic approaches that automatically identify and analyze malicious software samples. Obfuscation and polymorphism employed by malwares make it difficult for signature-based systems to detect sophisticated malware files. The dynamic analysis or run-time behavior provides a better technique to identify the threat. In t...

متن کامل

Development of SYBR Green I Based Real-Time RT-PCR Assay for Specific Detection of Watermelon silver mottle Virus

Background: Watermelon silver mottle virus (WSMoV), which belongs to the genus Tospovirus, causes significant loss in Cucurbitaceae plants. Objectives: Development of a highly sensitive and reliable detection method for WSMoV. Materials and Methods: Recombinant plasmids for targeting the sequence of nucleocapsid protein gene of WSMoV were constructed. SYBR Green I real-time PCR was established...

متن کامل

Molecular Detection and Phylogenetic Analysis of Equine Herpes Virus-1 in Horses with History or Clinical Signs in Four Provinces of Iran

BACKGROUND: Equine herpes virus-1 (EHV-1) is a major cause of economic loss in horse industry and is well recognized as a cause of abortion, respiratory disease, neurologic disorders and death of neonatal foals.OBJECTIVES: The aim of this study was to evaluate the frequency of EHV-1 in horses with clinical signs and/or history associated with this virus from four provinces of Iran (Golest...

متن کامل

Virus Detection Method based on Behavior Resource Tree

Due to the disadvantages of signature-based computer virus detection techniques, behavior-based detection methods have developed rapidly in recent years. However, current popular behavior-based detection methods only take API call sequences as program behavior features and the difference between API calls in the detection is not taken into consideration. This paper divides virus behaviors into ...

متن کامل

Antibody detection of feline infectious peritonitis virus (FIPV) in sera of companion cats in Ahvaz, south west of Iran

Feline infectious peritonitis virus (FIPV) is ubiquitous in domestic cats, especially in young cats and multi-cat environments. In the present study, a total of 248 companion cats of different ages were examined for serum antibody detection of FIPV by immunochromatography assay. The cats were selected from those referring to Veterinary Hospital of Ahvaz University, southwestern Iran from Decemb...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012