基于PE文件结构异常的未知病毒检测  被引量:5

Unknown Virus Detection Based on Exceptional PE File Structure

在线阅读下载全文

作  者:樊震[1] 杨秋翔[1] 

机构地区:[1]中北大学电子与计算机科学技术学院,山西太原030051

出  处:《计算机技术与发展》2009年第10期160-163,共4页Computer Technology and Development

基  金:山西省自然科学基金(20011040)

摘  要:目前基于行为分析的未知病毒检测方法,需要可执行文件运行后才能检测到,无法检测出以静态形式存在计算机中的病毒文件。文中提出了一种基于静态文件的未知病毒检测新技术,通过分析PE文件结构中的异常值,运用贝叶斯方法和支持向量机来识别静态和非静态的未知病毒。相比基于行为分析的未知病毒检测方法,在不需要运行可执行文件的情况下即可检测出是否可能为未知病毒文件。本方法相比基于函数调用API序列的数据挖掘方法的病毒检测方法,不需要对文件进行脱壳等复杂计算处理,明显提高了检测速度。试验结果表明,该方法对未知病毒有较快的检测速度、较高的识别率和较低的误判率。Behavior- based analysis of currently unknown virus detection methods, necessary to run an executable file can be detected after, can not be detected in static form of computer virus file. In this paper, a document based on the static unknown virus detection of new technologies, by analyzing the PE file structure of the abnormal value, the use of Bayesian methods and support vector machine to identify the static and non- static unknown virus. Compared to behavior- based analysis of the unknown virus detection methods, do not need to run the executable file in the case of the possibility to detect the virus file is unknown. The method is compared to API function call scquence based on the data mining method of virus detection methods, the documents do not need to shell deal with such complex calculations clearly improve the detection speed. Test results indicate that the method of the unknown virus detecter has faster detection speed, higher recognition rate and lower rate of misjudgment.

关 键 词:静态文件 PE文件 未知病毒检测 

分 类 号:TP309.5[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象