• Title/Summary/Keyword: Antivirus

Search Result 42, Processing Time 0.026 seconds

VirtAV: an Agentless Runtime Antivirus System for Virtual Machines

  • Tang, Hongwei;Feng, Shengzhong;Zhao, Xiaofang;Jin, Yan
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • v.11 no.11
    • /
    • pp.5642-5670
    • /
    • 2017
  • Antivirus is an important issue to the security of virtual machine (VM). According to where the antivirus system resides, the existing approaches can be categorized into three classes: internal approach, external approach and hybrid approach. However, for the internal approach, it is susceptible to attacks and may cause antivirus storm and rollback vulnerability problems. On the other hand, for the external approach, the antivirus systems built upon virtual machine introspection (VMI) technology cannot find and prohibit viruses promptly. Although the hybrid approach performs virus scanning out of the virtual machine, it is still vulnerable to attacks since it completely depends on the agent and hooks to deliver events in the guest operating system. To solve the aforementioned problems, based on in-memory signature scanning, we propose an agentless runtime antivirus system VirtAV, which scans each piece of binary codes to execute in guest VMs on the VMM side to detect and prevent viruses. As an external approach, VirtAV does not rely on any hooks or agents in the guest OS, and exposes no attack surface to the outside world, so it guarantees the security of itself to the greatest extent. In addition, it solves the antivirus storm problem and the rollback vulnerability problem in virtualization environment. We implemented a prototype based on Qemu/KVM hypervisor and ClamAV antivirus engine. Experimental results demonstrate that VirtAV is able to detect both user-level and kernel-level virus programs inside Windows and Linux guest, no matter whether they are packed or not. From the performance aspect, the overhead of VirtAV on guest performance is acceptable. Especially, VirtAV has little impact on the performance of common desktop applications, such as video playing, web browsing and Microsoft Office series.

Effective Evaluation about the Antivirus Solution for Smart Phone

  • Shin, Suk-Jo;Kim, Seon-Joo;Jiang, Chun-Yan;Jo, In-Jun
    • Journal of information and communication convergence engineering
    • /
    • v.9 no.6
    • /
    • pp.695-700
    • /
    • 2011
  • Smartphone has formed a new market and introduced a new environment. They have an operating system like PCs, enabling free installation and removal of application programs. As the number of Smartphone users is increasing, more personal information is also exposed to malicious codes. There are problem of modification and deletion of files, battery consumption, and information leakage due to malicious codes. As the needs of Smartphone antivirus solutions are increasing, the antivirus solutions should be evaluated with quality characteristics. In this paper, we propose an effective evaluation method for functionality and performance of Smartphone antivirus solutions, and the best practices for evaluation.

A Study on Malicious Code Detection Using Blockchain and Deep Learning (블록체인과 딥러닝을 이용한 악성코드 탐지에 관한 연구)

  • Lee, Deok Gyu
    • KIPS Transactions on Computer and Communication Systems
    • /
    • v.10 no.2
    • /
    • pp.39-46
    • /
    • 2021
  • Damages by malware have recently been increasing. Conventional signature-based antivirus solutions are helplessly vulnerable to unprecedented new threats such as Zero-day attack and ransomware. Despite that, many enterprises have retained signature-based antivirus solutions as part of the multiple endpoints security strategy. They do recognize the problem. This paper proposes a solution using the blockchain and deep learning technologies as the next-generation antivirus solution. It uses the antivirus software that updates through an existing DB server to supplement the detection unit and organizes the blockchain instead of the DB for deep learning using various samples and forms to increase the detection rate of new malware and falsified malware.

Antimicrobial and antiviral activity of Saururus chinensis extract by n-Hexane (n-Hexane에 의한 삼백초 추출물의 항균 및 항바이러스 활성)

  • Lee, Ju-Hyun;Choe, Yeong-Ho;Park, Yoon-Jin;Zhang, Xiao-Wan;Kim, Byeong-Soo
    • Korean Journal of Veterinary Service
    • /
    • v.36 no.2
    • /
    • pp.87-93
    • /
    • 2013
  • This study was conducted to investigate the antimicrobial, antivirus properties of Saururus chinensis extracts. The n-hexane extracts from Saururus chinensis showed the active antimicrobial activity against gram-positive bacteria. Minimum inhibitory concentration (MIC) of Saururus chiensis n-hexane extracts was 1.25 mg/ml against B. subtilis and 2.5 mg/ml against S. aureus. The cytotoxicity effects on MDBK (Madin-Darby bovine kidney) cell were observed at the various n-hexane extract concentrations. In $TCID_{50}$ assay, 0.6 mg/ml of n-hexane extracts decreased BVD (bovine viral diarrhea) virus by 1.4 log, whereas other extracts did not show antiviral activity. In this study, The results suggested that n-hexane extracts and fractions of Saururus chinensis can be a candidate materal of feed additive to chemical antibiotics and antivirus substances.

Anti-bacterial properties and safety evaluation of disinfectant using Dendropanax morbifera (Hwangchil) extract for passenger cabin in the subway (지하철 객실 적용을 위한 황칠 추출물 소독제의 항균특성 및 안전성 평가)

  • Bui, Vu Khac Hoang;Park, Jae-Seok;Lee, Young-Chul
    • Particle and aerosol research
    • /
    • v.18 no.2
    • /
    • pp.37-50
    • /
    • 2022
  • Due to the syndrome coronavirus 2 (SARS-CoV-2) pandemic, the subway passenger cabin should be continuously sterilized. However, a disinfectant such as chlorine is toxic and can lead to different issues to human health. In this paper, we introduced a novel disinfectant based on natural product (Dendropanax morbifera extract). Via ultra-high performance liquid chromatography - mass spectrometer (UHPLC-MS), different compounds from Dendropanax morbifera extract showed antivirus potentials. Antimicrobial experiments confirmed that the air-disinfectant containing Dendropanax morbifera can eliminate harmful microorganisms including Gram (-), Gram (+), and yeast within 5 mins. The as-prepared air-disinfectant also showed high antivirus activity against H1N1, HRV, and EV71. Deodorization test also indicates that the as-prepared air-disinfectant can lower the harmful gas such as ammonia and trimethylamine in the atmosphere. To evaluate the potential of air-disinfectant containing Dendropanax morbifera in practical applications, different safety tests including acute oral toxicity, acute skin irritation, and eye irritation were conducted. Results showed that the as-prepared disinfectant did not negatively affect tested animals during these safety investigations.

MWMon: A Software Defined Network-based Malware Monitor

  • Jo, Min Jae;Shin, Ji Sun
    • Journal of Korea Society of Industrial Information Systems
    • /
    • v.20 no.5
    • /
    • pp.37-44
    • /
    • 2015
  • An antivirus is a widely used solution for detecting malicious softwares in client devices. The performance of antivirus solutions in the mobile client environment is critical due to its resource constrains. Many solutions light-weighting client's overhead in the mobile client environment have been developed. However, most solutions require platform modifications or software installations and it decreases their realizations in practice. In this paper, we propose a solution detecting malwares on networks using the Software Defined Network (SDN). Our main goal is designing a solution detecting malwares of mobile client without involving the client into the work. We contribute to provide a solution that does not require client-side installations or modifications and so is easily applicable in practice.

Research on security technology to respond to edge router-based network attacks (Edge 라우터 기반 네트워크 공격에 대응하는 보안기술 연구)

  • Hwang, Seong-Kyu
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.26 no.9
    • /
    • pp.1374-1381
    • /
    • 2022
  • Existing research on security technology related to network attack response has focused on research using hardware network security technology, network attacks that wiretap and wiretap network packets, denial of service attack that consumes server resources to bring down the system, and network by identifying vulnerabilities before attack. It is classified as a scanning attack. In addition, methods for increasing network security, antivirus vaccines and antivirus systems have been mainly proposed and designed. In particular, many users do not fully utilize the security function of the router. In order to overcome this problem, it is classified according to the network security level to block external attacks through layered security management through layer-by-layer experiments. The scope of the study was presented by examining the security technology trends of edge routers, and suggested methods and implementation examples to protect from threats related to edge router-based network attacks.

Analysis on Research Trend of Studies Related with Scutellariae Radix in Korea (황금(黃芩)에 관한 국내 연구 동향에 관한 소고)

  • Kim, Kang-San;Kim, Lae-Hee;Rhee, Yun-Jin;Lee, Su-Hyoun;Choi, Ji-Hye;Ko, Ha-Neul
    • Journal of Physiology & Pathology in Korean Medicine
    • /
    • v.25 no.6
    • /
    • pp.1095-1101
    • /
    • 2011
  • Scutellariae Radix has been used as a traditional medicine for anti-oxidant, anti-inflammatory, anti-allergic function. But most study methods were restricted to in vitro and in vivo. Therefore to perform for clinical trials further for a new natural drug development is necessary and this study will be used as a basis for it. The studies selected from domestic academic database included the following key words; '황금', '黃芩', 'skullcap', 'Scutellariae Radix', 'scutellaria baicalensis' and considered were those published from 1990 to July, 2011. All 1080 studies were found to include the keywords related to the study subjects either in their title of contents or abstracts. and 298 studies were finally selected as subjects for this study. 243 studies among 293 studies were published between 2000 to 2011. Classification was proceeded according to study subjects as followed; anti-Inflammatory effect and antiallergic and antihistamin effect(66), antibacterial and antivirus effect(61), antioxidant effect(51), neuronal cell apoptosis and neuronal cell protective effect(22), liver cell protective effect(20). According to method type of study, 194 studies practicing in vitro, 60 studies practicing in vivo, 37 studies practicing in both. and 5 studies on documentary records. Most study methods were restricted in vitro and in vivo. For developmenting of function of anti-inflammatory effect and antiallergic, antihistamin effect & atopic dermatitis effect, antibacterial and antivirus effect, antioxidant effect, case report on various fields and multicenter clinical trials is necessary.

Factors Influencing Health Behavior of Patients with Chronic Hepatitis B (만성 B형 간염환자의 건강행위 수준 및 영향요인)

  • Lee, Jung-Eun;Kim, So-Sun;Kim, Sun-Ah;Han, Kwang-Hyub;Kim, Soo-Hyun;Ji, Eun-Joo;Oh, Eui-Geum
    • Korean Journal of Adult Nursing
    • /
    • v.23 no.1
    • /
    • pp.20-30
    • /
    • 2011
  • Purpose: The aim of this study was to examine patients with Chronic Hepatitis B (CHB) and their level of knowledge of their disease, uncertainty, stress and health behaviors and to identify factors influencing their health behavior. Methods: A cross-sectional, descriptive design was used. The sample included 136 patients in a gastroenterology outpatient department at one hospital located in Seoul. The mean age of the subjects was 41 and 77.2% were male. Data were collected using a structured questionnaire from April to June 2009. The collected data were analyzed using SPSS/WIN 15.0. Results: The reported scores for knowledge of the disease, uncertainty, stress, and health behaviors were 14.43, 81.50, 26.50, 52.11, respectively. There were statistically difference between health behaviors and gender, age, marital status and antivirus treatment. A positive correlation existed between knowledge of disease and health behaviors (r=.199, p=.020). In contrast, there was a negative correlation between uncertainty and health behaviors (r=-.250, p=.003). The factors influencing health behaviors were knowledge of disease, gender, age, uncertainty, antivirus treatment, and marital status ($R^2$=.267, p<.001). Conclusion: These findings support that strategies for enhancing knowledge of disease and reducing uncertainty are needed to promote health behavior in patients with CHB.

A Study on Mobile Game Security Threats by Analyzing Malicious Behavior of Auto Program of Clash of Clans (클래시 오브 클랜 오토 프로그램의 악성 행위 분석을 통한 모바일 게임 보안 위협에 관한 연구)

  • Heo, Geon Il;Heo, Cheong Il;Kim, Huy Kang
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.25 no.6
    • /
    • pp.1361-1376
    • /
    • 2015
  • Recently, the size of the mobile game market and the number of mobile game users are growing. Also, as the mobile game's life cycle is increasing at the same time, auto program issue reappears which has been appeared in PC online games. Gamers usually tend to ignore warning messages from antivirus programs and even worse they delete antivirus program to execute auto programs. Therefore, mobile game users are easily compromised if the auto program performs malicious behaviors not only for the original features. In this paper, we analyze whether seven auto programs of "clash of clans" which has a lot more users for a long time perform malicious behaviors or not. We forecast the possible security threats in near future and proposed countermeasures based on this analysis. By analyzing auto programs of highly popular mobile game of today, we can acquire the knowledge on auto program's recent trend such as their development platform, operating mode, etc. This analysis will help security analysts predict auto program's evolving trends and block potential threats in advance.