发新话题
打印

An EmailWorm Vaccine Architecture

An EmailWorm Vaccine Architecture

We present an architecture for detecting “zero-day” worms and viruses in incoming email. Our main idea is to intercept every incoming message, prescan it for potentially dangerous attachments, and only deliver messages that are deemed safe. Unlike traditional scanning techniques that rely on some form of pattern matching (signatures), we use behavior-based anomaly detection. Under our approach, we “open” all suspicious attachments inside an instrumented virtual machine looking for dangerous actions, such as writing to the Windows registry, and ag suspicious messages.
附件: 您所在的用户组无法下载或查看附件

TOP

发新话题