Journal of Beijing University of Posts and Telecommunications

  • EI核心期刊

JOURNAL OF BEIJING UNIVERSITY OF POSTS AND TELECOM ›› 2011, Vol. 34 ›› Issue (3): 58-61.doi: 10.13190/jbupt.201103.58.lianghl

• Papers • Previous Articles     Next Articles

A File System for Malware Analysis and Protection

  

  • Received:2010-09-07 Revised:2011-02-19 Online:2011-06-28 Published:2011-03-29

Abstract:

Malwares and their resulting threats are growing urgently. A method at the file system level is provided for analysis and defense against malwares with reducing the loss as possible, and implements a file system for malware analysis and protection (MAPFS). With checkpoint and file versioning technology, MAPFS can record the modifications in file systems during the process. These records are important for analysis of malware behavior, and may be used to recover the files damaged by the malwares. Experiments show that this method is effective in analysis and defense of malwares, and MAPFS only brings a little loss lower than 10 percent.

Key words: malware, file system, versioning, hook, recovery

CLC Number: