基于特征码病毒扫描技术的研究  被引量:2

Study on Virus Signatures based on Matching in Virus-detecting Technologies

在线阅读下载全文

作  者:关欣[1] 朱冰[1] 陈震[1] 彭雪海 

机构地区:[1]清华大学计算机系,北京100084 [2]北京经信委社会信息化处,北京100029

出  处:《信息网络安全》2013年第4期8-13,共6页Netinfo Security

基  金:国家973项目[2012CB315800];国家自然科学A3重点基金项目[61161140320]

摘  要:随着互联网的快速发展,病毒以极其迅猛的速度大量出现并蔓延。病毒总数以爆炸性的速度增长。因此,增强对病毒的防范,加强对反病毒技术的研究,成为了当务之急。文章研究病毒扫描技术,重点研究了利用病毒的特征码进行病毒扫描的技术,尤其是基于十六进制特征码和MD5特征码的扫描算法。对基于十六进制特征码的算法,改进了其原来的二叉树结构,提出新的Hash表结构,从而加快了处理速度。然后,提出采用Hash表结构的基于MD5特征码的算法,对其性能进行了测试,并展望了其发展前景。As the computing technology flourishes recently, the computing world is also in the peril of viruses. Network transferred viruses, such as worms, which threat millions of hosts in Internet. As countermeasure of such attacks, the research work for Anti-Virus is urgent affairs and a big problem. This paper describes an implementation of Anti-Virus engine. It focuses on technologies for scanning viruses by the use of virus signatures based on Hex Sig and MD5 Sig. The author implements two Hex-Sig-based scanning algorithms by using binary tree and hash table, and compares the performances of the two algorithms. Some conceived experiments are conducted, and results show that the hash-table-based algorithm achieves better performance in terms of the scanning speed. The author also investigates into a MDS-Sig-based scanning algorithm, and evaluates its performance. Finally, future work is planned and prospected.

关 键 词:反病毒 特征码 二叉树 HASH表 MD5 

分 类 号:TP309.5[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象