计算机与现代化

• 信息安全 • 上一篇    下一篇

一种基于主机特征的未知恶意程序动态识别系统

  

  1. (1.北京国电通网络技术有限公司,北京 100070; 2.国网浙江省电力公司信息通信分公司,浙江 杭州 310007; 3.上海交通大学电子信息与电气工程学院,上海 200240)
  • 收稿日期:2015-10-21 出版日期:2016-03-17 发布日期:2016-03-17
  • 作者简介:刘志永(1963-),男,河北定兴人,北京国电通网络技术有限公司高级工程师,本科,研究方向:电力系统信息安全; 王红凯(1984-),男,浙江绍兴人,国网浙江省电力公司信息通信分公司高级工程师,硕士,研究方向:企业级网络,信息安全,信息系统; 李高磊(1992-),男,河南杞县人,上海交通大学电子信息与电气工程学院博士研究生,研究方向:信息安全; 伍军(1979-),男,湖南人,副研究员,博士,研究方向:信息安全,工控安全; 宿雅婷(1991-),女,甘肃会宁人,工程师,本科,研究方向:电力系统信息安全。
  • 基金资助:
    国家电网科技项目(524681140009)

A Dynamic Recognition System of Unknown Malicious Programs Based on Host Characteristics

  1. (1. Beijing Guodiantong Network Technology Co., Ltd., Beijing 100070, China; 2. Information and Telecommunication Branch, State Grid Zhejiang Electric Power Company, Hangzhou 310007, China; 3. School of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai 200240, China)
  • Received:2015-10-21 Online:2016-03-17 Published:2016-03-17

摘要: 分析可疑程序执行前后的主机状态变化,利用虚拟执行技术设计一种新型的基于主机特征的未知恶意程序动态识别系统。所有可疑程序被重定向到特定沙箱中执行,通过对沙箱中的文件、注册表、进程、服务和网络的实时监控与深度分析识别未知恶意程序,再根据其执行过程记录动态生成告警信息,从而保护真实环境文件不受篡改、破坏。实验表明,该系统能显著提高对未知恶意程序攻击的识别精度,从而高效防御智能电网遭受未知恶意程序的攻击。

关键词: 智能电网, 未知恶意程序, 识别, 虚拟执行, 主机特征

Abstract: Characteristics of states changing before/after the execution of unknown malicious programs were analyzed, a novel host characteristics-based unknown malicious programs dynamic recognition system is developed by using virtual execution technology. All suspicious programs were redirected into the special sandbox and executed. The unknown malicious programs were recognized by real-timely monitoring and deeply analyzing files, regedits, processes, services and network systems of the virtual hosts in sandboxes. Next, according to the real-time records in the process of the execution of the unknown malicious programs, early warning strategies were produced to protect the files of the real-world scenarios from being altered or attacked. Experimental results show that the accuracy of this system for unknown malicious programs recognition has been improved significantly. Hence, it can high-efficiently prevent smart grid from being attacked by the unknown malicious programs.

Key words: smart grid, unknown malicious programs, recognition, virtual execution, host characteristics

中图分类号: