Using code signing in the detection of malware – A Trojan horse case study

碩士 === 華梵大學 === 資訊管理學系碩士班 === 99 === Anti-virus software is major for the computer of malware defense mechanism, its operation based on Signature-based to detect malware. However, it needs some time to product of virus pattern, publish batch and update the computer. It makes the Anti-virus software...

Full description

Bibliographic Details
Main Authors: Tsai, Pei-Wen, 蔡佩彣
Other Authors: Chu, Huei-Chung
Format: Others
Language:zh-TW
Published: 2011
Online Access:http://ndltd.ncl.edu.tw/handle/40557602528150744568
Description
Summary:碩士 === 華梵大學 === 資訊管理學系碩士班 === 99 === Anti-virus software is major for the computer of malware defense mechanism, its operation based on Signature-based to detect malware. However, it needs some time to product of virus pattern, publish batch and update the computer. It makes the Anti-virus software latency a period, and the user's computer will suffer the threat of malware attack. So we solve anti-virus software’s window period, resulting malware intrusion’s problem. We use malware intrusion and behavioral module, analysis and analysis tool, and use Code Signing to verify PE’s integrity. This conduct detect the computer have malware to intrusion or not. That could assist anti-virus software to protect the computer. The subject of the study will be based Trojan for Windows operating system environment, system and network monitoring program of activities. Reduce the system security of the Anti-virus latency risk. This case study was to install AntiVir in Windows operating system environment. The result above methods has proved that this method can assist anti-virus software, reducing the Anti-virus latency risk.