Development of Windows Malware Detection System Based on Expert System

周瑞丽,潘剑锋,谭小彬,奚宏生
DOI: https://doi.org/10.3969/j.issn.1009-8054.2009.09.037
2009-01-01
Abstract:Traditional signature-based malware detection method is not able to detect zero-day attacks and some malwares adopting circumvention techniques such as packer. In order to overcome this drawback, this paper proposes a heuristic detection technique based on expert systems. The technique could detect malwares using known techniques, even bottom-level techniques, for example, the rootkit technique. It also can detect those malwares even after they are packed or crypto-protected by any packer or protector. And its detection rate is much higher than some well-known anti-virus tools.
What problem does this paper attempt to address?