menu
{ "item_title" : "Behavior-Based Spyware Detection", "item_author" : [" Manuel Egele "], "item_description" : "Generating good signatures for the current anti-spyware toolkits and deploying them in a timely fashion is a demanding task. Even if the signatures are up-to-date, signature based detection techniques usually suffer from the inability to detect novel and unknown threats. We believe that behavior-based approaches are capable of overcoming this drawback. To this end, we implemented TQAna. Our tool is based on taint analysis and function call hooking to provide dynamic analysis that is carried out on an emulated system. Taint analysis, as implemented with TQAna, provides the ability to track data throughout the whole system on hardware level. The observed functions cover most aspects of the Windows operating system, such as network-, and file system access, shared memory, or the dynamic loader. This book addresses system and security researchers in the fields of operating systems and malicious software analysis.", "item_img_path" : "https://covers4.booksamillion.com/covers/bam/3/63/902/206/3639022068_b.jpg", "price_data" : { "retail_price" : "52.92", "online_price" : "52.92", "our_price" : "52.92", "club_price" : "52.92", "savings_pct" : "0", "savings_amt" : "0.00", "club_savings_pct" : "0", "club_savings_amt" : "0.00", "discount_pct" : "10", "store_price" : "" } }
Behavior-Based Spyware Detection|Manuel Egele

Behavior-Based Spyware Detection

local_shippingShip to Me
In Stock.
FREE Shipping for Club Members help

Overview

Generating good signatures for the current anti-spyware toolkits and deploying them in a timely fashion is a demanding task. Even if the signatures are up-to-date, signature based detection techniques usually suffer from the inability to detect novel and unknown threats. We believe that behavior-based approaches are capable of overcoming this drawback. To this end, we implemented TQAna. Our tool is based on taint analysis and function call hooking to provide dynamic analysis that is carried out on an emulated system. Taint analysis, as implemented with TQAna, provides the ability to track data throughout the whole system on hardware level. The observed functions cover most aspects of the Windows operating system, such as network-, and file system access, shared memory, or the dynamic loader. This book addresses system and security researchers in the fields of operating systems and malicious software analysis.

This item is Non-Returnable

Details

  • ISBN-13: 9783639022063
  • ISBN-10: 3639022068
  • Publisher: VDM Verlag Dr. Mueller E.K.
  • Publish Date: May 2008
  • Dimensions: 9 x 6 x 0.16 inches
  • Shipping Weight: 0.25 pounds
  • Page Count: 76

Related Categories

You May Also Like...

    1

BAM Customer Reviews