透過您的圖書館登入
IP:3.17.150.89
  • 會議論文
  • OpenAccess

植基於檔案異動行為建模與備援之勒索軟體防禦機制

摘要


網路攻擊與惡意軟體日益猖獗,本論文提出一針對檔案異動攻擊之偵測與防禦方法,用以在實體的網路世界中,偵測惡意軟體例如勒索軟體或是病毒攻擊,並利用電腦系統的核心模式來對於檔案資料的輸入/輸出請求進行檔案備份,並且利用使用行為特徵與備份檔案資料進行比對,進而降低電腦系統因為被惡意軟體攻擊時而造成之檔案刪除、檔案修改、檔案更名、檔案加密等威脅影響,達到輕量化備份降低資源耗損的目的。研究結果顯示透過本論文所提出之防禦機制可有效偵測檔案異動行為,並確保電腦系統內遭異動檔案的完整性。

並列摘要


Cyberattack and the threat of malicious software are becoming more rampant nowadays. This paper proposes a method for detecting and defending against malicious software such as ransomware or virus. The proposed scheme performs file backup on the input/output request of the archive data by the Kernel-mode. The backup module reduces the resource cost by comparing the user behavior and the features of the backup files, and thus mitigate the effect from the detection to achieve a lightweight backup module. The research results show that the proposed defense mechanism can effectively detect the file transaction behavior and ensure the integrity of the file in the computer system.

並列關鍵字

Malware Kernel Driver Lightweight Backup

延伸閱讀