Next-generation antivirus endowed with web-server Sandbox applied to audit fileless attack.

Autor: Lima, Sidney M. L., Silva, Sthéfano H. M. T., Pinheiro, Ricardo P., Souza, Danilo M., Lopes, Petrônio G., de Lima, Rafael D. T., de Oliveira, Jemerson R., Monteiro, Thyago de A., Fernandes, Sérgio M. M., Albuquerque, Edison de Q., Silva, Washington W. A. da, dos Santos, Wellington P.
Předmět:
Zdroj: Soft Computing - A Fusion of Foundations, Methodologies & Applications; Feb2023, Vol. 27 Issue 3, p1471-1491, 21p
Abstrakt: Almost all malwares running on web-server are php codes. Then, the present paper creates a next generation antivirus (NGAV) expert in auditing threats web-based, specifically from php files, in real time. In our methodology, the malicious behaviors, of the personal computer, serve as input attributes of the statistical learning machines. In all, our dynamic feature extraction monitors 11,777 behaviors that the web fileless attack can do when launched directly from a malicious web-server to a listening service in a personal computer. Our NGAV achieves an average 99.95% accuracy in the distinction between benign and malware web scripts. Distinct initial conditions and kernels of neural networks classifiers are investigated in order to maximize the accuracy of our NGAV. Our NGAV can supply the limitations of the commercial antiviruses as for the detection of Web fileless attack. In opposition of analysis of individual events, our engine employs authorial Web-server Sandbox, machine learning, and artificial intelligence in order to identify malicious Web-sites. [ABSTRACT FROM AUTHOR]
Databáze: Complementary Index