检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]国防科技大学计算机学院,湖南长沙410073
出 处:《信息安全与技术》2014年第8期19-24,41,共7页
摘 要:恶意代码行为捕获是进行恶意代码行为分析,提高防御恶意代码能力的基础。当前,随着恶意代码技术的发展,恶意代码结构及其通信活动日益复杂,使得传统的恶意代码行为捕获技术难以有效应对恶意代码的攻击与破坏。如何更加有效地捕获恶意代码行为成了目前信息安全领域的研究热点。基于此目的,本文在充分利用Agent的自主性和适应性,实时采集目标系统的状态信息的基础上,提出了一种基于多Agent的恶意代码行为捕获方案,分析了其行为捕获流程,介绍了功能模块组成,并基于Windows平台实现了该方案,为下一步针对恶意代码分析及防御提供了良好的基础。Capturing the behavior of malicious code is the foundation of malicious code analyzing as wel as improving the ability of defending against malicious code. With the development of technologies, malicious code is becoming more complex in structures and communication activities, making it dif icult for traditional capturing technologies to deal ef ectively with the at acks and destructions brought by malicious codes. Therefore, how to capture the behavior of malicious code more ef ectively has become a hot topic in the field of information security now. In this paper, we propose a Multi-Agent scheme to capture malicious code behavior, which is based on real-time capture of the target system status information through making ful use of the autonomy, adaptability of Agent. As wel , the paper analyses the behavior capturing process, describes the components of the system, and makes an implementation on Windows, which provides a good basis for further analysis and researches on defending against malicious code.
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.91