期刊文献+

一种基于主机特征的未知恶意程序动态识别系统 预览 被引量:1

A Dynamic Recognition System of Unknown Malicious Programs Based on Host Characteristics
在线阅读 下载PDF
收藏 分享 导出
摘要 分析可疑程序执行前后的主机状态变化,利用虚拟执行技术设计一种新型的基于主机特征的未知恶意程序动态识别系统。所有可疑程序被重定向到特定沙箱中执行,通过对沙箱中的文件、注册表、进程、服务和网络的实时监控与深度分析识别未知恶意程序,再根据其执行过程记录动态生成告警信息,从而保护真实环境文件不受篡改、破坏。实验表明,该系统能显著提高对未知恶意程序攻击的识别精度,从而高效防御智能电网遭受未知恶意程序的攻击。 Characteristics of states changing before / after the execution of unknown malicious programs were analyzed,a novel host characteristics-based unknown malicious programs dynamic recognition system is developed by using virtual execution technology. All suspicious programs were redirected into the special sandbox and executed. The unknown malicious programs were recognized by real-timely monitoring and deeply analyzing files,regedits,processes,services and network systems of the virtual hosts in sandboxes. Next,according to the real-time records in the process of the execution of the unknown malicious programs,early warning strategies were produced to protect the files of the real-world scenarios from being altered or attacked. Experimental results show that the accuracy of this system for unknown malicious programs recognition has been improved significantly. Hence,it can high-efficiently prevent smart grid from being attacked by the unknown malicious programs.
作者 刘志永 王红凯 李高磊 伍军 宿雅婷 LIU Zhi-yong , WANG Hong-kai, LI Gao-lei, WU Jun, SU Ya-ting (1. Beijing Guodiantong Network Technology Co. , Ltd. , Beijing 100070, China; 2. Information and Telecommunication Branch, State Grid Zhejiang Electric Power Company, Hangzhou 310007, China; 3. School of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai 200240, China)
出处 《计算机与现代化》 2016年第3期105-110,共6页 Computer and Modernization
基金 国家电网科技项目(524681140009)
关键词 智能电网 未知恶意程序 识别 虚拟执行 主机特征 smart grid unknown malicious programs recognition virtual execution host characteristics
  • 相关文献

参考文献18

二级参考文献277

共引文献1166

同被引文献4

引证文献1

二级引证文献1

投稿分析
职称考试

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部 意见反馈