DocumentCode
1999122
Title
Application of CLIPS Expert System to Malware Detection System
Author
Zhou Ruili ; Pan Jianfeng ; Tan Xiaobin ; Xi Hongsheng
Author_Institution
Dept. of Autom., Univ. of Sci. & Technol. of China, China
Volume
1
fYear
2008
fDate
13-17 Dec. 2008
Firstpage
309
Lastpage
314
Abstract
Malware detection is a crucial aspect of software security. Traditional signature-based detection method cannot detect zero-day attacks and some malware adopting some circumvention techniques such as polymorphic, metamorphic, obfuscation and packer. So some anomaly-based detection techniques are introduced to overcome this drawback, but these techniques have high false alarm rate and the complexity involved in determining what features should be learned in the training phase. In order to overcome these shortcomings, we propose a malware detection system based on expert systems in this paper. This system integrates signature-based analysis and anomaly-detection technique together. The signature is anomaly behavioral signatures. Accord to expertise about malware¿s major suspicious behaviors, we build the knowledge base of the expert system. And we design a behavior gathering component to intercept anomaly behaviors happened in the operating system and get significant traces leaved by malware, then present these behaviors and traces as facts. The expert system uses the knowledge base and behaviors facts to infer and give the results. This system can detect not only known malware, but some zero-day attacks using known techniques and also malware adopting low-level techniques, such as polymorphic and packer.
Keywords
digital signatures; expert systems; invasive software; CLIPS expert system; anomaly-based detection techniques; malware detection system; signature-based detection method; software security; Application software; Automation; Computational intelligence; Data mining; Expert systems; Inspection; Intrusion detection; Operating systems; Phase detection; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Computational Intelligence and Security, 2008. CIS '08. International Conference on
Conference_Location
Suzhou
Print_ISBN
978-0-7695-3508-1
Type
conf
DOI
10.1109/CIS.2008.100
Filename
4724664
Link To Document