Transmitted File Extraction And Reconstruction From Network Packets

2015 WORLD CONGRESS ON INTERNET SECURITY (WORLDCIS)(2015)

引用 0|浏览10
暂无评分
摘要
When hackers try to attack a target system, their first goal is to install a malware to the target system. It is because hackers can do anything what they want if a malware is installed. In the past, most of the malwares were Microsoft PE files, however they have been changed to various file formats such as pdf, jpg, doc, jar and so on. Under this circumstances some network security systems such as network forensics systems have to reconstruct those malwares from network packets to analyze the malwares. For that, we propose a file type signature and network protocol analysis based transmitted file reconstruction technique which can reconstruct various file types from network packets. In this paper, we show the implementation and file reconstruction results.
更多
查看译文
关键词
Transmitted file reconstruction,network forensics,malware collection
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要