发新话题
打印

[转载]An EmailWorm Vaccine Architecture

[转载]An EmailWorm Vaccine Architecture

信息来源:http://www1.cs.columbia.edu/~angelos/

We present an architecture for detecting “zero-day” worms and viruses in incoming email. Our main idea is to intercept every incoming message, prescan it for potentially dangerous attachments, and only deliver messages that are deemed safe. Unlike traditional scanning techniques that rely on some form of pattern matching (signatures), we use behavior-based anomaly detection. Under our approach, we “open” all suspicious attachments inside an instrumented virtual machine looking for dangerous actions, such as writing to the Windows registry, and ag suspicious messages.

附件

email-worm.rar (166 KB)

2006-3-15 22:17, 下载次数: 47

曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题