基于校验和法比较法与夹角余弦公式的变形病毒检测算法  被引量:2

Deformation Virus Detection Algorithm Based on Checksum Comparison Method and Included Angle Cosine Formula

在线阅读下载全文

作  者:朱俚治 ZHU Lizhi(Information Office,Nanjing University of Aeronautics and Astronautics,Nanjing 210016,China)

机构地区:[1]南京航空航天大学信息化处,南京210016

出  处:《计算机测量与控制》2022年第4期165-171,共7页Computer Measurement &Control

摘  要:长度比较法、校验和法以及基于行为的检测算法是3种经典的病毒检测算法,因此将这3种算法相互结合而提出一种新的病毒检测算法,该算法的思路是:首先通过相应的算法检测某个程序的校验和与程序的长度是否发生了变化;如果发生了变化,则采用计算机病毒代码权值计算公式,判断该程序是否被未知病毒感染了;如果成了未知病毒的宿主,则在虚拟机中将该代码进行运行,判断未知病毒的功能属性,同时采用夹角余弦公式对未知病毒进行了相似性计算,根据检测算法来判断该未知病毒属于那种类的病毒,从而达到对计算机未知病毒检测的目的。Length comparison method,checksum method and behavior-based detection algorithm are three classic virus detection algorithms.Therefore,a new virus detection algorithm is proposed by combining three algorithms.The idea of algorithm first detect whether the program checksumand the programlength have changed.If there is any change,the weightcalculation formula for computer virus codeis used to determine whether the program is infected by an unknown virus.If it becomes the host of an unknown virus,the virtual machinecodeis runto determine the functional attributes forthe unknown virus.At the same time,the angle cosine formula is used to calculate the similarity of unknown virus,and the detection algorithm is used to determine whether the unknown virus belongs to whichkind of virus,thus the purpose of detecting unknown viruses on the computer is achieved.

关 键 词:校验和 权值 病毒 夹角余弦 比较法 

分 类 号:TP274[自动化与计算机技术—检测技术与自动化装置]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象