Abstract

Nowadays, antivirus is one of the most popular tools used to protect computer systems. Diverse antivirus vendors are established to protect their customers against malware. However, antivirus is facing some critical problems, such as significant detection windows, vulnerability inside antivirus, and long scanning time. In this paper, we recommend a cloud-based real-time defense mechanism named Skywalker to allow users to safely utilize antivirus without the above problems. After Skywalker is installed in a host, the host does not need to install any antivirus. However, Skywalker guarantees that the host only executes programs that have been verified by a cloud-based scanner, such as VirusTotal. VirusTotal uses 56 antivirus engines to check whether a program is malware. Research shows that the more antivirus engines are used, the more accurate the result is. Because the above scan is performed right before the execution of every program, Skywalker provides 24/7 real-time protection to a system. Besides, Skywalker eliminates the need to spend a lot of time scanning all files in a host. Experimental results show that after a program has been executed once, it takes Skywalker, at most, 0.47091 s to start the program again. Meanwhile, VirusTotal provides a secure protection to client hosts.

Highlights

  • A Cloud-Based Real-Time Mechanism to Protect EndFu-Hau Hsu 1 , Chia-Hao Lee 1 , Ting Luo 1 , Ting-Cheng Chang 2 and Min-Hao Wu 2, *

  • Diverse antivirus companies are established to defense various systems, because every day tremendous malware, worms, Trojans, and malicious content are created and spread over the Internet, which brings severe threats to computer systems and networks

  • VirusTotal provides a secure protection to client hosts

Read more

Summary

A Cloud-Based Real-Time Mechanism to Protect End

Fu-Hau Hsu 1 , Chia-Hao Lee 1 , Ting Luo 1 , Ting-Cheng Chang 2 and Min-Hao Wu 2, *. College of Information and Mechanical & Electrical Engineering, Ningde Normal University, Ningde 352100, China. Received: 23 August 2019; Accepted: 1 September 2019; Published: 8 September 2019. Featured Application: Authors are encouraged to provide a concise description of the specific application or a potential application of the work.

Introduction
Background
Windows System Service
System Services Descriptor Table
SSDT Hooking
VirusTotal
System Design
Evaluation
Scan Registration Time
Result
Effective Evaluation
Limitations
Related Work
Conclusions

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.