Computer and Modernization ›› 2016, Vol. 0 ›› Issue (3): 105-110.doi: 10.3969/j.issn.1006-2475.2016.03.021

Previous Articles     Next Articles

A Dynamic Recognition System of Unknown Malicious Programs Based on Host Characteristics

  

  1. (1. Beijing Guodiantong Network Technology Co., Ltd., Beijing 100070, China; 2. Information and Telecommunication Branch, State Grid Zhejiang Electric Power Company, Hangzhou 310007, China; 3. School of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai 200240, China)
  • Received:2015-10-21 Online:2016-03-17 Published:2016-03-17

Abstract: Characteristics of states changing before/after the execution of unknown malicious programs were analyzed, a novel host characteristics-based unknown malicious programs dynamic recognition system is developed by using virtual execution technology. All suspicious programs were redirected into the special sandbox and executed. The unknown malicious programs were recognized by real-timely monitoring and deeply analyzing files, regedits, processes, services and network systems of the virtual hosts in sandboxes. Next, according to the real-time records in the process of the execution of the unknown malicious programs, early warning strategies were produced to protect the files of the real-world scenarios from being altered or attacked. Experimental results show that the accuracy of this system for unknown malicious programs recognition has been improved significantly. Hence, it can high-efficiently prevent smart grid from being attacked by the unknown malicious programs.

Key words: smart grid, unknown malicious programs, recognition, virtual execution, host characteristics

CLC Number: