Model and Method of Policy-Driven Backdoor Detection on Endpoints with Secure Signature Distribution and Optimized Scan Execution

Вантажиться...
Ескіз

Дата

2026

Науковий керівник

Назва журналу

Номер ISSN

Назва тому

Видавець

КПІ ім. Ігоря Сікорського

Анотація

This paper proposes a policy-driven model for backdoor detection on endpoints, in which signature-based scanning is combined with scan execution policies and secure rule-set updates. The practical implementation of the approach is oriented toward a prototype that includes an endpoint agent, a trusted local cache of signature sets, scanning profiles, and a YARA-compatible engine. A priority function is proposed that takes into account whether an object belongs to autorun locations, whether it has been modified recently, whether it is located in a privileged area, and whether it lacks a digital signature. Secure signature updates include verification of the signature, hash, and version number of the rule set. The result of the work is a structural diagram of the prototype, a fragment of a YARA rule, and an experimental evaluation scheme focused on comparing full and priority-based scanning.

Опис

Ключові слова

backdoor, endpoint, signature-based detection, scanning policy, YARA, secure signature distribution

Бібліографічний опис

Protsyshyn, I. I. Model and Method of Policy-Driven Backdoor Detection on Endpoints with Secure Signature Distribution and Optimized Scan Execution / I. I. Protsyshyn, I. V. Stopochkina // Теоретичні і прикладні проблеми фізики, математики та інформатики : матеріали XXIV Всеукраїнської науково-практичної конференції студентів, аспірантів та молодих вчених, [Київ], 13–16 травня 2026 р. / КПІ ім. Ігоря Сікорського. – Київ, 2026. – С. 258-260.

ORCID

DOI