An APT Trojans Detection Method for Cloud Computing Based on Memory Analysis and FCM
Liang Ge, Lianhai Wang, Lijuan Xu · 2016
With memory information as characteristic, a classified method to detect APT (Advanced Persistent Threat)Trojans in cloud computing is proposed in this paper. Memory analysis and fuzzy C-means (FCM) algorithm based on the optimized initial cluster centers detects the similarity of the APT Trojans. Without influence normal operation of virtual machine in cloud, the classifier can determine whether it is malware or not. The method can overcome the shortage of feature scanning technology which could not recognize unknown Trojans, and could significantly improve the detection speed since it does not need to unpack, decrypt, and other complex operations. Experiment results show that the detection method has good accuracy, so there is a certain practical value.