节点文献

基于关联规则的未知恶意程序检测技术

New Malicious Executables Detection Based on Association Rules

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 章文郑烇帅建梅陈超

【Author】 ZHANG Wen,ZHENG Quan,SHUAI Jian-mei,CHEN Chao(Department of Automation,University of Science & Technology of China,Hefei 230027)

【机构】 中国科学技术大学自动化系

【摘要】 针对当前基于特征码病毒检测技术不能检测出未知病毒的缺点,通过研究某些病毒及其变种版本在执行过程中应用程序接口(API)调用序列的规律,提出一种基于数据挖掘的检测技术,采用Apriori算法从已知病毒的API调用序列中提取有价值的关联规则,用于指导病毒检测。实验结果表明该方法对未知病毒检测有良好的效果。

【Abstract】 In order to improve the current malicious detection technology based on signature,this paper presents a method based on data mining.By researching the rules of API calling sequences during executing viruses,the method uses Apriori algorithms to extract some valuable related rules which hide out in a lot of API calling sequences of viruses.These rules can be used to detect Viruses.Experimental results validate its effection.

【基金】 国家“863”计划基金资助项目(2006AA01Z449)
  • 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2008年24期
  • 【分类号】TP309.5
  • 【被引频次】8
  • 【下载频次】130
节点文献中: 

本文链接的文献网络图示:

本文的引文网络