作者: Angelos D. Keromytis , Salvatore J. Stolfo
DOI:
关键词:
摘要: Methods, media, and systems for detecting an anomalous sequence of function calls are provided. The methods can include compressing a made by the execution program using compression model; determining presence in based on extent to which is compressed. further executing at least one known program; observing assigning each type call unique identifier; creating part model recording identifiers.