Academic Journal

Metamorphism as a Software Protection for Non-Malicious Code

Λεπτομέρειες βιβλιογραφικής εγγραφής
Τίτλος: Metamorphism as a Software Protection for Non-Malicious Code
Συγγραφείς: Dube, Thomas E.
Πηγή: Theses and Dissertations
Στοιχεία εκδότη: AFIT Scholar
Έτος έκδοσης: 2006
Συλλογή: AFTI Scholar (Air Force Institute of Technology)
Θεματικοί όροι: Software protection, Reverse engineering--Computer programs, Computer viruses, Software Engineering
Περιγραφή: Most organizations are aware that threats from trusted insiders pose a great risk to their organization and are very difficult to protect against. Auditing is recognized as an effective technique to detect malicious insider activities. However, current auditing methods are typically applied with a one-size-fits-all approach and may not be an appropriate mitigation strategy, especially towards insider threats. This research develops a 4-step methodology for designing a customized auditing template for a Microsoft Windows XP operating system. Two tailoring methods are presented which evaluate both by category and by configuration. Also developed are various metrics and weighting factors as a mechanism to evaluate auditing effectiveness for the purpose of optimizing the template according to organizational security requirements. Various industry standard auditing templates are evaluated against a custom designed template. Results indicate that a customized auditing template tailored for an insider threat scenario is more effective at detecting insider malicious activities.
Τύπος εγγράφου: text
Περιγραφή αρχείου: application/pdf
Γλώσσα: unknown
Relation: https://scholar.afit.edu/etd/3469; https://scholar.afit.edu/context/etd/article/4470/viewcontent/AFIT_GIA_ENG_06_04_Dube_T.pdf
Διαθεσιμότητα: https://scholar.afit.edu/etd/3469
https://scholar.afit.edu/context/etd/article/4470/viewcontent/AFIT_GIA_ENG_06_04_Dube_T.pdf
Αριθμός Καταχώρησης: edsbas.7870C9B
Βάση Δεδομένων: BASE
FullText Text:
  Availability: 0
CustomLinks:
  – Url: https://scholar.afit.edu/etd/3469#
    Name: EDS - BASE (ns324271)
    Category: fullText
    Text: View record from BASE
Header DbId: edsbas
DbLabel: BASE
An: edsbas.7870C9B
RelevancyScore: 836
AccessLevel: 3
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 836.004333496094
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Metamorphism as a Software Protection for Non-Malicious Code
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Dube%2C+Thomas+E%2E%22">Dube, Thomas E.</searchLink>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: Theses and Dissertations
– Name: Publisher
  Label: Publisher Information
  Group: PubInfo
  Data: AFIT Scholar
– Name: DatePubCY
  Label: Publication Year
  Group: Date
  Data: 2006
– Name: Subset
  Label: Collection
  Group: HoldingsInfo
  Data: AFTI Scholar (Air Force Institute of Technology)
– Name: Subject
  Label: Subject Terms
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Software+protection%22">Software protection</searchLink><br /><searchLink fieldCode="DE" term="%22Reverse+engineering--Computer+programs%22">Reverse engineering--Computer programs</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+viruses%22">Computer viruses</searchLink><br /><searchLink fieldCode="DE" term="%22Software+Engineering%22">Software Engineering</searchLink>
– Name: Abstract
  Label: Description
  Group: Ab
  Data: Most organizations are aware that threats from trusted insiders pose a great risk to their organization and are very difficult to protect against. Auditing is recognized as an effective technique to detect malicious insider activities. However, current auditing methods are typically applied with a one-size-fits-all approach and may not be an appropriate mitigation strategy, especially towards insider threats. This research develops a 4-step methodology for designing a customized auditing template for a Microsoft Windows XP operating system. Two tailoring methods are presented which evaluate both by category and by configuration. Also developed are various metrics and weighting factors as a mechanism to evaluate auditing effectiveness for the purpose of optimizing the template according to organizational security requirements. Various industry standard auditing templates are evaluated against a custom designed template. Results indicate that a customized auditing template tailored for an insider threat scenario is more effective at detecting insider malicious activities.
– Name: TypeDocument
  Label: Document Type
  Group: TypDoc
  Data: text
– Name: Format
  Label: File Description
  Group: SrcInfo
  Data: application/pdf
– Name: Language
  Label: Language
  Group: Lang
  Data: unknown
– Name: NoteTitleSource
  Label: Relation
  Group: SrcInfo
  Data: https://scholar.afit.edu/etd/3469; https://scholar.afit.edu/context/etd/article/4470/viewcontent/AFIT_GIA_ENG_06_04_Dube_T.pdf
– Name: URL
  Label: Availability
  Group: URL
  Data: https://scholar.afit.edu/etd/3469<br />https://scholar.afit.edu/context/etd/article/4470/viewcontent/AFIT_GIA_ENG_06_04_Dube_T.pdf
– Name: AN
  Label: Accession Number
  Group: ID
  Data: edsbas.7870C9B
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edsbas&AN=edsbas.7870C9B
RecordInfo BibRecord:
  BibEntity:
    Languages:
      – Text: unknown
    Subjects:
      – SubjectFull: Software protection
        Type: general
      – SubjectFull: Reverse engineering--Computer programs
        Type: general
      – SubjectFull: Computer viruses
        Type: general
      – SubjectFull: Software Engineering
        Type: general
    Titles:
      – TitleFull: Metamorphism as a Software Protection for Non-Malicious Code
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Dube, Thomas E.
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 01
              Type: published
              Y: 2006
          Identifiers:
            – Type: issn-locals
              Value: edsbas
            – Type: issn-locals
              Value: edsbas.oa
          Titles:
            – TitleFull: Theses and Dissertations
              Type: main
ResultId 1