• DocumentCode
    1999122
  • Title

    Application of CLIPS Expert System to Malware Detection System

  • Author

    Zhou Ruili ; Pan Jianfeng ; Tan Xiaobin ; Xi Hongsheng

  • Author_Institution
    Dept. of Autom., Univ. of Sci. & Technol. of China, China
  • Volume
    1
  • fYear
    2008
  • fDate
    13-17 Dec. 2008
  • Firstpage
    309
  • Lastpage
    314
  • Abstract
    Malware detection is a crucial aspect of software security. Traditional signature-based detection method cannot detect zero-day attacks and some malware adopting some circumvention techniques such as polymorphic, metamorphic, obfuscation and packer. So some anomaly-based detection techniques are introduced to overcome this drawback, but these techniques have high false alarm rate and the complexity involved in determining what features should be learned in the training phase. In order to overcome these shortcomings, we propose a malware detection system based on expert systems in this paper. This system integrates signature-based analysis and anomaly-detection technique together. The signature is anomaly behavioral signatures. Accord to expertise about malware¿s major suspicious behaviors, we build the knowledge base of the expert system. And we design a behavior gathering component to intercept anomaly behaviors happened in the operating system and get significant traces leaved by malware, then present these behaviors and traces as facts. The expert system uses the knowledge base and behaviors facts to infer and give the results. This system can detect not only known malware, but some zero-day attacks using known techniques and also malware adopting low-level techniques, such as polymorphic and packer.
  • Keywords
    digital signatures; expert systems; invasive software; CLIPS expert system; anomaly-based detection techniques; malware detection system; signature-based detection method; software security; Application software; Automation; Computational intelligence; Data mining; Expert systems; Inspection; Intrusion detection; Operating systems; Phase detection; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence and Security, 2008. CIS '08. International Conference on
  • Conference_Location
    Suzhou
  • Print_ISBN
    978-0-7695-3508-1
  • Type

    conf

  • DOI
    10.1109/CIS.2008.100
  • Filename
    4724664