English  |  正體中文  |  简体中文  |  全文筆數/總筆數 : 94201/94201 (100%)
造訪人次 : 81539586      線上人數 : 3086
RC Version 7.0 © Powered By DSPACE, MIT. Enhanced by NTU Library IR team.
搜尋範圍 查詢小技巧:
  • 您可在西文檢索詞彙前後加上"雙引號",以獲取較精準的檢索結果
  • 若欲以作者姓名搜尋,建議至進階搜尋限定作者欄位,可獲得較完整資料
  • 進階搜尋


    請使用永久網址來引用或連結此文件: https://ir.lib.ncu.edu.tw/handle/987654321/106301


    題名: Antivirus software shield against antivirus terminators
    作者: 許富皓;Hsu, Fu-Hau;Wu, Min-Hao;Tso, Chang-Kuo;Hsu, Chi-Hsien;Chen, Chieh-Wen
    貢獻者: 資訊電機學院資訊工程學系
    關鍵詞: Anti-virus software;Antivirus software;API;API hooking;Computer information security;Computer programs;Computer viruses;Computers;Cybersecurity;Malware;Materials;Process control;Programmers;Reverse engineering;Shields;Software;Tables (data)
    日期: 2012-09-20
    上傳時間: 2026-04-23 13:17:05 (UTC+8)
    出版者: Institute of Electrical and Electronics Engineers Inc.;New York: IEEE
    摘要: 摘要: In the last several decades, the arms race between malware writers and antivirus programmers has become more and more severe. The simplest way for a computer user to secure his computer is to install antivirus software on his computer. As antivirus software becomes more sophisticated and powerful, evading the detection of antivirus software becomes an important part of malware. As a result, malware writers have developed various approaches to increase the survivability and concealment of their malware. One of these technologies is to terminate antivirus software right after the execution of the malware. In this paper, we propose a mechanism, called ANtivirus Software Shield (ANSS), to prevent antivirus software from being terminated without the consciousness of the antivirus software users. ANSS uses System Service Descriptor Table (SSDT) hooking to intercept specific Windows APIs and analyzes them to filter out hazardous API calls that will terminate antivirus software. When using several pieces of malware that can terminate various brands of antivirus applications to make our experiments, the results show that ANSS can protect antivirus software from being terminated by them with at most 0.42% CPU performance overhead and 1.77% memory write performance overhead.
    其他題名: TIFS
    出版者: New York: IEEE
    出版日期: 2012-10-01
    出處: IEEE Transactions on Information Forensics and Security, 2012-10, Vol.7 (5), p.1439-1447
    資源來源: IEEE Electronic Library (IEL)
    版權: Copyright The Institute of Electrical and Electronics Engineers, Inc. (IEEE) Oct 2012
    識別號: ISSN: 1556-6013
    識別號: EISSN: 1556-6021
    識別號: DOI: 10.1109/TIFS.2012.2206028
    識別號: CODEN: ITIFA6
    顯示於類別:[資訊工程學系] 期刊論文

    文件中的檔案:

    檔案 描述 大小格式瀏覽次數
    index.html0KbHTML18檢視/開啟


    在NCUIR中所有的資料項目都受到原著作權保護.

    社群 sharing

    ::: Copyright National Central University. | 國立中央大學圖書館版權所有 | 收藏本站 | 設為首頁 | 最佳瀏覽畫面: 1024*768 | 建站日期:8-24-2009 :::
    DSpace Software Copyright © 2002-2004  MIT &  Hewlett-Packard  /   Enhanced by   NTU Library IR team Copyright ©   - 隱私權政策聲明