A Method of Detecting Abnormal Malicious Remote Control Codes using Network Domain Information

  • Oh, Hyung-Geun
  • Seo, Jung-Taek
  • Lim, Jong In
  • Moon, Jong-sub
Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

Since the malicious code used in the latest APT (Advanced Persistent Threat) attacks new, hitherto unknown security, vulnerabilities, it is almost impossible to detect with the conventional pattern-based information security system. Consequently, various targeted attacks such as internal data leakage and system demolition have inflicted great damage, thereby raising the need for a new concept of malicious code detection. This paper proposes a new method of detecting abnormal connections by observing the status of connection of an attack system connected to a target system over the network. This method can detect the connection of new malicious codes very efficiently using only the existing network data, and can intercept the leakage of internal data or the transfer of attack commands.

키워드

Remote Control MalwareAbnormal Malicious CodeDomain Name InformationAbnormal Network ConnectionExtrusion DetectionIntrusion Detection
제목
A Method of Detecting Abnormal Malicious Remote Control Codes using Network Domain Information
저자
Oh, Hyung-GeunSeo, Jung-TaekLim, Jong InMoon, Jong-sub
발행일
2012-05
유형
Article
저널명
Information
15
5
페이지
2181 ~ 2192