Безопасность информационных технологий (Mar 2011)
Detecting Software’s Behavior Deviations with Behavior Models
Abstract
The common and most often used models of software’s behavior are described and examined, advantages and disadvantages of every model are viewed as well. Some performance enhancing methods for all the models are proposed — the main idea is to divide the software’s performance into different parts: the first part for the start of software, the second part for software-specific actions and the third part for software’s shutdown. Thus, every model consists of sub-models for different parts of software’s performance, which makes the model more flexible. The series of experiments for detecting irregular behavior with described methods are applied.