Dissertation > Excellent graduate degree dissertation topics show

Malicious code detection and containment technology research

Author: LiuZhi
Tutor: ZhangXiaoSong
School: University of Electronic Science and Technology
Course: Software Engineering
Keywords: Malware Virtual Environment Behavioral Analysis Signature Distributed
CLC: TP393.08
Type: Master's thesis
Year: 2009
Downloads: 298
Quote: 4
Read: Download Dissertation

Abstract


Computer security has become a major area in academic and industry, since the Morris worm broke out in 1980’s. Malware, both in terms of attack and defense, is a fast growing field. Owing to Internet as well as homogeneity of software and hardware, people attach more importance to security issues. As one major form of computer attacks, malware poses great challenges to Internet and users, causing huge losses. However, there are still lots of unsolved problems, because existing detection approaches is ineffective, being incapable of dealing with diverse and sophisticated morphing attacks. False positives and false negative have greatly limited the use of detection systems. Meanwhile, traditional defense architecture is weak against outbreaking, large-scale attacks. Trojan horses are a typical class of host-based malware that aim to steal sensitive data, and they account for the largest proportion of malware classes; network-based malware is represented by worms, which propagate in a distributed fashion, hence it has unforeseeable potential threat, and may give rise to subsequent attacks. Therefore, they both deserve deep research and attention.This thesis surveys the principles, key techniques and detection approaches of malware. We focus on Trojans, viruses and worms. From the perspective of detection and containment, we have the following three contributions:1. We researched and implemented a Trojan/rootkit malware detection technique using virtual execution environment. We defined malware behaviors, security events of affecting operating systems. Data mining is used for detecting unknown samples. Virtual environment decreases the negative affects the malware brings to users. Experiment results showed that compared with our counterparts, our detection approach can detect unknown malware precisely.2. Due to the prevalance of morphing worms, the core technique of misuse detection, signature-based detection has been a bottleneck. Traditional signature generation technique takes a long time to generate as well as having high false positives. We proposed an accurate, effective signature generation technique which can resist morphing attacks, and for the first time, we apply it to viruses and Trojans. Initial experiments showed it can generate high-quality signatures in a short time with low false positives and low negatives, and it also gives quantitative analysis.3. In order to contain outbreaking, large-scale attacks caused by malware, we proposed a new distributed malware response and containment framework. It incorporates behavior-based anomaly detection and signature-based misuse detection. So it can not only detect known malware instances but unknown as well. We designed and implemented the prototype system. This framework considerably reduces human labor; hence it can respond quickly to outbreaking malware. This work is an initial attempt for containing large-scale attacks.

Related Dissertations

  1. Study on Channel Allocation of Multi-Channel MAC Protocol in Ad-Hoc Network,TN929.5
  2. Resrarch on Multisignatures and Multisigncryptions from Identity-based,TN918.1
  3. Subliminal Channel in Multisignature,TN918.1
  4. Study on System of Electronic Documetnt Security Signature,TN918.2
  5. Research of Fault Injection for a Distributed System,TP338.8
  6. The Research of Fault-Tolerant Techniques for Parallel/Distributed Network Simulator PDNS,TP302.8
  7. The Research of Malware Detection Technology Based on Active Mode,TP393.08
  8. Research and Implementation of Retrieval System on Massive Mail,TP393.098
  9. The Research on the Divisibility of E-Cash,F713.36
  10. Research and Design of One Kind of Paper’s QCS That Based on Embedded System,TP368.1
  11. Micro- grid with distributed power control strategy research,TM61
  12. Research of Communication Mechanism in the Distributed Network Based on Mobile Agent,TP393.02
  13. The Problems and Solutions of University’s Ideological and Political Education under Network Environment,G641
  14. The Design and Implementation of Student Information Management System Based on Workflow,TP311.52
  15. M Petrochemical Company CCR unit implementation and management of,F426.72
  16. Based on Modbus Protocol pressure medical gas distribution monitoring system development,R197.39
  17. Port industrial zone planning and layout of the sewage treatment system,X703
  18. Study on Legal Issues in Concluding Electronic Commerce Contract,D923
  19. The Research of Stress Testing Based on Distributed Environments,TP311.52
  20. Research and Implementation of Distributed Data Integration Visual Modeling,TP311.52
  21. Research and Application about Ditributed Transaction Process Protocol,TP311.13

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile