• DocumentCode
    2520989
  • Title

    A Network Based Approach to Malware Detection in Large IT Infrastructures

  • Author

    Kumar, Brijesh ; Katsinis, Constantine

  • Author_Institution
    Goodwin Coll., Drexel Univ., Philadelphia, PA, USA
  • fYear
    2010
  • fDate
    15-17 July 2010
  • Firstpage
    188
  • Lastpage
    191
  • Abstract
    Malware is code that has malicious intent and is designed for malicious purpose such as stealing confidential data, or obtaining root privileges on a system. The current approach to deal with malware threats such as virus and spyware is to use host based anti-malware software. However, this approach leads to many vulnerable machines since many users don´t update their software, their virus signatures, and some even disable their software to avoid the system performance degradation caused by these software. Host based security software require a good deal of administration, with consistent needs for reconfiguration, management, and report analysis. With security administrators supporting an ever growing number of users, such an approach has become impractical. In this paper, we present a novel network based malware detection architecture that uses host security vectors to protect host machines without any intervention from hosts. This architecture provides another layer of security and can complement existing host based solutions. Only central detection server needs to be actively managed instead of individual hosts - hence providing more manageable solution for large IT infrastructures.
  • Keywords
    computer viruses; configuration management; data privacy; software maintenance; antimalware software; confidential data; host machine protection; large IT infrastructure; malicious intent; malicious purpose; malware detection; malware threat; network based approach; report analysis; root privilege; security administrator; security software; security vectors; software management; software reconfiguration; spyware; system performance degradation; virus signature; Computer architecture; Engines; Malware; Network servers; Servers; Software; Infrastructure security; distributed virus detection; host security; malware detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Computing and Applications (NCA), 2010 9th IEEE International Symposium on
  • Conference_Location
    Cambridge, MA
  • Print_ISBN
    978-1-4244-7628-2
  • Type

    conf

  • DOI
    10.1109/NCA.2010.33
  • Filename
    5598211