期刊论文详细信息
Journal of computer sciences
Rule-Based Approach to Detect IoT Malicious Files
article
Faisal Alsattam1  Mousa Al-Akhras2  Marwah M. Almasri1  Mohammed Alawairdhi1 
[1] Saudi Electronic University;The University of Jordan
关键词: Digital Forensics;    IoT Forensics;    LOKI;    YARA Rules;    IoT Malware;   
DOI  :  10.3844/jcssp.2020.1203.1211
学科分类:计算机科学(综合)
来源: Science Publications
PDF
【 摘 要 】

The current immersive increase of cyber-attacks requires constant evolution of the used security solutions. Current malware detection solutions are only able to identify known malwares that were previously detected. They also lack the ability to deeply investigate every file in the system. Therefore, new detection techniques are needed to fill this gab. In this study, a flexible and an effective rule-based approach is proposed to detect malicious files by searching for specific types of strings that should not exist in normal legitimate files. The proposed detection technique relies on the use of LOKI as a scanning agent that uses customized YARA rules with different complexities to search for the needed strings. The proposed methodology has been tested and it detected all malwares successfully.

【 授权许可】

CC BY   

【 预 览 】
附件列表
Files Size Format View
RO202107250000277ZK.pdf 761KB PDF download
  文献评价指标  
  下载次数:2次 浏览次数:0次