TY - JOUR
T1 - Task-based behavior detection of illegal codes
AU - Han, Lansheng
AU - Fu, Cai
AU - Zou, Deqing
AU - Lee, Chang Hoon
AU - Jia, Wenjing
PY - 2012/1
Y1 - 2012/1
N2 - Detecting unseen illegal codes is always a challenging task. As the main action to deal with this problem, the behavior detection is unsatisfactory in both effectiveness and efficiency. This paper proposes task-based behavior detection (TBBD) which detects new illegal codes based on the user's task instead of only on the software behavior. First, the paper proposes three prerequisites of TBBD and four judgment rules, i.e., resource abnormal rule, relation abnormal rule, space abnormal rule and time abnormal rule. Then, by analyzing the effectiveness and comparison of the four judgment rules, we present an explicit judgment process of TBBD. Finally, the paper carries on the experiments. The test result verifies the validity and feasibility of TBBD.
AB - Detecting unseen illegal codes is always a challenging task. As the main action to deal with this problem, the behavior detection is unsatisfactory in both effectiveness and efficiency. This paper proposes task-based behavior detection (TBBD) which detects new illegal codes based on the user's task instead of only on the software behavior. First, the paper proposes three prerequisites of TBBD and four judgment rules, i.e., resource abnormal rule, relation abnormal rule, space abnormal rule and time abnormal rule. Then, by analyzing the effectiveness and comparison of the four judgment rules, we present an explicit judgment process of TBBD. Finally, the paper carries on the experiments. The test result verifies the validity and feasibility of TBBD.
KW - Computer security
KW - Illegal codes
KW - Malicious codes
KW - Task-based behavior detection
UR - https://www.scopus.com/pages/publications/82755194886
U2 - 10.1016/j.mcm.2011.01.052
DO - 10.1016/j.mcm.2011.01.052
M3 - Article
AN - SCOPUS:82755194886
SN - 0895-7177
VL - 55
SP - 80
EP - 86
JO - Mathematical and Computer Modelling
JF - Mathematical and Computer Modelling
IS - 1-2
ER -