Abstract

The paper presents the results a research of changes in the state of the operating environment when it is damaged by malware. The Windows operating system of various versions and builds was selected as a test environment. The research was carried out using polymorphic malware abc, cheeba, december_3, stasi, otario, dm, v-sign, tequila, flip. The research was conducted to obtain the value of operating system signatures for subsequent training of neural networks. Context triggered piecewise hashing and performance testing methods were used for research the assessment of changes in the state of the operating environment when it is damaged by malware. Simulation of the developed method was carried out in the Hyper-V virtual environment.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call