Mostrar el registro sencillo del ítem

dc.contributor.authorPérez Sánchez, Antonioes-ES
dc.contributor.authorPalacios Hielscher, Rafaeles-ES
dc.date.accessioned2025-11-05T15:29:26Z
dc.date.available2025-11-05T15:29:26Z
dc.date.issued2023-06-23es_ES
dc.identifier.urihttp://hdl.handle.net/11531/106942
dc.descriptionCapítulos en libroses_ES
dc.description.abstractes-ES
dc.description.abstractThe detection and classification of threats in computer systems has been one of the main problems researched in Cybersecurity. As technology evolves, the tactics employed by adversaries have also become more sophisticated to evade detection systems. In consequence, systems that previously detected and classified those threats are now outdated. This paper proposes a detection system based on the analysis of events and matching the risk level with the MITRE ATT&CK matrix and Cyber Kill Chain. Extensive testing of attacks, using nine malware codes and applying three different obfuscation techniques, was performed. Each malicious code was analyzed using the proposed event management system and also executed in a controlled environment to examine if commercial malware detection systems (antivirus) were successful. The results show that evading techniques such as obfuscation and in-memory extraction of malicious payloads, impose unexpected difficulties to standard antivirus software.en-GB
dc.language.isoen-GBes_ES
dc.publisherInstituto Nacional de Ciberseguridad; Universidade de Vigo (Vigo, España)es_ES
dc.rightses_ES
dc.rights.uries_ES
dc.sourceLibro: VIII Jornadas Nacionales de Investigación en Ciberseguridad - JNIC 2023, Página inicial: 569-570, Página final:es_ES
dc.subject.otherInstituto de Investigación Tecnológica (IIT)es_ES
dc.titleEvaluation of local security event management system vs. standard antivirus softwarees_ES
dc.typeinfo:eu-repo/semantics/bookPartes_ES
dc.description.versioninfo:eu-repo/semantics/publishedVersiones_ES
dc.rights.accessRightsinfo:eu-repo/semantics/restrictedAccesses_ES
dc.keywordses-ES
dc.keywordsSIEM; antivirus; event-based threat detection; MITRE; Cyber Kill Chainen-GB


Ficheros en el ítem

FicherosTamañoFormatoVer

No hay ficheros asociados a este ítem.

Este ítem aparece en la(s) siguiente(s) colección(ones)

  • Artículos
    Artículos de revista, capítulos de libro y contribuciones en congresos publicadas.

Mostrar el registro sencillo del ítem