An anti virus scheme using digital signature and anomaly detection techniques

Among all the computer security breaches, viruses are the most frequent and destructive. Current anti- virus solutions focus too much on virus recognition techniques, causing new viruses to escape detection. Thus, this work proposes an anti-virus scheme that simply defends the data in the computer r...

Full description

Saved in:
Bibliographic Details
Main Author: Subramaniam, Suresh Babu
Format: Thesis
Language:English
Published: 2003
Subjects:
Online Access:http://eprints.utm.my/id/eprint/42601/1/SureshBabuSubramaniamFKE2003.pdf
http://eprints.utm.my/id/eprint/42601/
http://libraryopac.utm.my/client/en_AU/main/search/detailnonmodal/ent:$002f$002fSD_ILS$002f0$002fSD_ILS:360506/one?qu=An+anti+virus+scheme+using+digital+signature+and+anomaly+detection+techniques
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.utm.42601
record_format eprints
spelling my.utm.426012017-10-17T14:56:57Z http://eprints.utm.my/id/eprint/42601/ An anti virus scheme using digital signature and anomaly detection techniques Subramaniam, Suresh Babu QA76 Computer software Among all the computer security breaches, viruses are the most frequent and destructive. Current anti- virus solutions focus too much on virus recognition techniques, causing new viruses to escape detection. Thus, this work proposes an anti-virus scheme that simply defends the data in the computer regardless of the type and name of virus. The scheme comprises two layers of protection, where the first layer implements digital signature technique while the second layer implements anomaly detection technique. In the scheme, newly downloaded files that have been digitally signed using SHA-l and RSA algorithms are verified at the first layer. Here the source and integrity of the files are determined and the executables with authentic and genuine signatures are accepted and logged into a watch list. At the second layer, the behaviour of the new executables; the ones in the watch list, are monitored closely at the lowest level for any anomalies. These anomalies are either blocked or ignored depending on the configurations set by user. One of the main ideas of the proposed scheme is to focus on new executables alone, as viruses originate only from newly downloaded files, either from email attachments, shared files and folders or new software installation. To realize the proposed scheme a prototype has been developed for Microsoft Windows 98. Meanwhile, to verify the functionality of the prototype, a test program that simulates most of the virus behaviour is also devised. Test results have proven that the proposed scheme can offer users the desired protection against all kinds of malicious programs. 2003 Thesis NonPeerReviewed application/pdf en http://eprints.utm.my/id/eprint/42601/1/SureshBabuSubramaniamFKE2003.pdf Subramaniam, Suresh Babu (2003) An anti virus scheme using digital signature and anomaly detection techniques. Masters thesis, Universiti Teknologi Malaysia, Faculty of Electrical Engineering. http://libraryopac.utm.my/client/en_AU/main/search/detailnonmodal/ent:$002f$002fSD_ILS$002f0$002fSD_ILS:360506/one?qu=An+anti+virus+scheme+using+digital+signature+and+anomaly+detection+techniques
institution Universiti Teknologi Malaysia
building UTM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknologi Malaysia
content_source UTM Institutional Repository
url_provider http://eprints.utm.my/
language English
topic QA76 Computer software
spellingShingle QA76 Computer software
Subramaniam, Suresh Babu
An anti virus scheme using digital signature and anomaly detection techniques
description Among all the computer security breaches, viruses are the most frequent and destructive. Current anti- virus solutions focus too much on virus recognition techniques, causing new viruses to escape detection. Thus, this work proposes an anti-virus scheme that simply defends the data in the computer regardless of the type and name of virus. The scheme comprises two layers of protection, where the first layer implements digital signature technique while the second layer implements anomaly detection technique. In the scheme, newly downloaded files that have been digitally signed using SHA-l and RSA algorithms are verified at the first layer. Here the source and integrity of the files are determined and the executables with authentic and genuine signatures are accepted and logged into a watch list. At the second layer, the behaviour of the new executables; the ones in the watch list, are monitored closely at the lowest level for any anomalies. These anomalies are either blocked or ignored depending on the configurations set by user. One of the main ideas of the proposed scheme is to focus on new executables alone, as viruses originate only from newly downloaded files, either from email attachments, shared files and folders or new software installation. To realize the proposed scheme a prototype has been developed for Microsoft Windows 98. Meanwhile, to verify the functionality of the prototype, a test program that simulates most of the virus behaviour is also devised. Test results have proven that the proposed scheme can offer users the desired protection against all kinds of malicious programs.
format Thesis
author Subramaniam, Suresh Babu
author_facet Subramaniam, Suresh Babu
author_sort Subramaniam, Suresh Babu
title An anti virus scheme using digital signature and anomaly detection techniques
title_short An anti virus scheme using digital signature and anomaly detection techniques
title_full An anti virus scheme using digital signature and anomaly detection techniques
title_fullStr An anti virus scheme using digital signature and anomaly detection techniques
title_full_unstemmed An anti virus scheme using digital signature and anomaly detection techniques
title_sort anti virus scheme using digital signature and anomaly detection techniques
publishDate 2003
url http://eprints.utm.my/id/eprint/42601/1/SureshBabuSubramaniamFKE2003.pdf
http://eprints.utm.my/id/eprint/42601/
http://libraryopac.utm.my/client/en_AU/main/search/detailnonmodal/ent:$002f$002fSD_ILS$002f0$002fSD_ILS:360506/one?qu=An+anti+virus+scheme+using+digital+signature+and+anomaly+detection+techniques
_version_ 1643650943972016128
score 13.15806