论文阅读笔记-You Are What You Do: Hunting Stealthy Malware via Data Provenance Analysis
NDSSYou Are What You Do: Hunting Stealthy Malware via Data Provenance Analysis链接:https://www.ndss-symposium.org/wp-content/uploads/2020/02/24167-paper.pdf第一章 简介1.文中介绍了现阶段的恶意软件多采用免杀技术来防范安全软件的检测,如进程重命名、文件重命名等,一般的恶意软件会把payload直接存在盘上,而这种经过免杀处理的恶意软件会把恶意逻辑