计算机与现代化 ›› 2011, Vol. 193 ›› Issue (9): 126-129.doi: 10.3969/j.issn.1006-2475.2011.09.034

• 信息安全 • 上一篇    下一篇

基于行为的分布式恶意代码检测技术

闫军伟1,钟求喜1,贾欣2,王茜3   

  1. 1.国防科学技术大学计算机学院,湖南 长沙 410073; 2.总参通信部驻长沙地区军代室,湖南 长沙 410000;3.武警石家庄指挥学院保密档案业务教研室,河北 石家庄 050067
  • 收稿日期:2011-04-28 修回日期:1900-01-01 出版日期:2011-09-22 发布日期:2011-09-22

Distributed Malware Detection Technology Based on Behavior

YAN Jun-wei1, ZHONG Qiu-xi1, JIA Xin2, WANG Qian3   

  1. 1.School of Computer Science, National University of Defense Technology, Changsha 410073, China; 2.Military Representative Office Station at Changsha, CDoGS, Changsha 410000, China; 3.Confidential Files Staff Room of Chinese People’s Armed Police Force Academy in Shijiazhuang, Shijiazhuang 050067, China
  • Received:2011-04-28 Revised:1900-01-01 Online:2011-09-22 Published:2011-09-22

摘要: 针对已有恶意代码检测技术存在不足,研究恶意代码网络传播行为,提取相应行为特征,在此基础上提出基于行为的分布式恶意代码检测技术,并进行NS2仿真实验。实验结果表明该方法具有较低的误报率和漏报率,可有效检测恶意代码。

关键词: 恶意代码, 分布式, 检测, 行为

Abstract: According to the disadvantages in the malware detection technologies used now, this paper gives a research to the propagation behavior of malware, and extracts its signature. A distributed malware detection method is proposed and a set of experiments are made on NS-2. The result shows that this method can effectively detect the malware.

Key words: malware, distributed, detection, behavior

中图分类号: