An APT Trojans Detection Method for Cloud Computing Based on Memory Analysis and FCM

Liang Ge, Lianhai Wang, Lijuan Xu · 2016

With memory information as characteristic, a classified method to detect APT (Advanced Persistent Threat)Trojans in cloud computing is proposed in this paper. Memory analysis and fuzzy C-means (FCM) algorithm based on the optimized initial cluster centers detects the similarity of the APT Trojans. Without influence normal operation of virtual machine in cloud, the classifier can determine whether it is malware or not. The method can overcome the shortage of feature scanning technology which could not recognize unknown Trojans, and could significantly improve the detection speed since it does not need to unpack, decrypt, and other complex operations. Experiment results show that the detection method has good accuracy, so there is a certain practical value.

Read the paper · More papers on PaperTik