2012
DOI: 10.1007/978-3-642-29860-8_10
|View full text |Cite
|
Sign up to set email alerts
|

NORT: Runtime Anomaly-Based Monitoring of Malicious Behavior for Windows

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
2
0
2

Year Published

2013
2013
2019
2019

Publication Types

Select...
4
3

Relationship

0
7

Authors

Journals

citations
Cited by 9 publications
(4 citation statements)
references
References 7 publications
0
2
0
2
Order By: Relevance
“…Speci cally, in [22], the authors use system call tracing to implement intrusion detection systems (IDS). Also, in [25] and [60], the authors proposed anomaly detection mechanism based on information obtained from system calls behavior analysis. In these cases, the implementation of the security tools resulted too heavy in terms of system overhead.…”
Section: Related Workmentioning
confidence: 99%
“…Speci cally, in [22], the authors use system call tracing to implement intrusion detection systems (IDS). Also, in [25] and [60], the authors proposed anomaly detection mechanism based on information obtained from system calls behavior analysis. In these cases, the implementation of the security tools resulted too heavy in terms of system overhead.…”
Section: Related Workmentioning
confidence: 99%
“…A seminal idea of Forrest et al [11] for behavior-based analysis was to profile benign and malign processes on the basis of characteristic system call sequences (n-grams). This approach was later refined and combined machine learning methods to improve classification effectiveness [21,14,19,23,31]. Similar ideas were also used to classify malware w.r.t.…”
Section: Related Workmentioning
confidence: 99%
“…Например, существует алгоритм, который использует аргументы системных вызовов для того, чтобы раз-делить последовательность вызовов на подпоследовательности, которые работают с одними и теми же дескрипторами (Milea, 2012).…”
Section: предыдущие работыunclassified
“…Аналогичные тесты были проведены при работе над системой NORT (Milea, 2012). Эта система замедляла работу ОС не более чем на 10%.…”
Section: тесты производительности монитораunclassified