Model and Method of Policy-Driven Backdoor Detection on Endpoints with Secure Signature Distribution and Optimized Scan Execution
Вантажиться...
Дата
2026
Науковий керівник
Назва журналу
Номер ISSN
Назва тому
Видавець
КПІ ім. Ігоря Сікорського
Анотація
This paper proposes a policy-driven model for backdoor detection on endpoints, in which signature-based scanning is combined with scan execution policies and secure rule-set updates. The practical implementation of the approach is oriented toward a prototype that includes an endpoint agent, a trusted local cache of signature sets, scanning profiles, and a YARA-compatible engine. A priority function is proposed that takes into account whether an object belongs to autorun locations, whether it has been modified recently, whether it is located in a privileged area, and whether it lacks a digital signature. Secure signature updates include verification of the signature, hash, and version number of the rule set. The result of the work is a structural diagram of the prototype, a fragment of a YARA rule, and an experimental evaluation scheme focused on comparing full and priority-based scanning.
Опис
Ключові слова
backdoor, endpoint, signature-based detection, scanning policy, YARA, secure signature distribution
Бібліографічний опис
Protsyshyn, I. I. Model and Method of Policy-Driven Backdoor Detection on Endpoints with Secure Signature Distribution and Optimized Scan Execution / I. I. Protsyshyn, I. V. Stopochkina // Теоретичні і прикладні проблеми фізики, математики та інформатики : матеріали XXIV Всеукраїнської науково-практичної конференції студентів, аспірантів та молодих вчених, [Київ], 13–16 травня 2026 р. / КПІ ім. Ігоря Сікорського. – Київ, 2026. – С. 258-260.