Застосування методів машинного навчання для поведінкового виявлення прихованих процесів
Abstract
Досліджено проблему виявлення прихованих процесів операційної системи, які можуть бути пов’язані з діяльністю шкідливого програмного забезпечення класу руткіт. Такі програми характеризуються здатністю маскувати власну присутність у системі, змінювати поведінку процесів та приховувати системні ресурси. This study examines the problem of detecting hidden operating system processes that may be associated with the activity of rootkit-class malware. Such programs are characterized by their ability to mask their presence in the system, alter process behavior, and conceal system resources. Traditional signature-based protection methods are insufficiently effective for detecting new or modified malware samples. The use of a behavioral approach to anomaly detection based on the Isolation Forest algorithm is proposed. The system architecture is discussed, which includes a module for collecting operating system process telemetry, a machine learning module for assessing the abnormality of process behavior, and an analytical module for interpreting the results. It is shown that the use of the Isolation Forest algorithm allows for the effective detection of atypical process behavior without the use of signature databases.
URI:
https://ir.lib.vntu.edu.ua/handle/123456789/53343

