Skip to main navigation Skip to search Skip to main content

Prevention of information attacks by run-time detection of self-replication in computer codes

  • State University of New York Binghamton University

Research output: Contribution to journalArticlepeer-review

13 Scopus citations

Abstract

This paper describes a novel approach for preventative protection from both known and previously unknown malicious software. It does not rely on screening the code for signatures of known viruses, but instead it detects attempts by the executable code in question to self-replicate during run time. Self-replication is the common feature of most malicious codes, allowing them to maximize their impact. This approach is an extension of the earlier developed method for detecting previously unknown viruses in script based computer codes. The paper presents a software tool implementing this technique for behavior-based run-time detection and suspension of self-replicating functionality in executable codes for Microsoft Windows operating systems.

Original languageEnglish
Pages (from-to)273-302
Number of pages30
JournalJournal of Computer Security
Volume15
Issue number2
DOIs
StatePublished - 2007

Keywords

  • Kerner-level monitoring
  • Malware detection
  • Run-time replication detection
  • Sequences of system codes

Fingerprint

Dive into the research topics of 'Prevention of information attacks by run-time detection of self-replication in computer codes'. Together they form a unique fingerprint.

Cite this