节点文献
基于关联规则的未知恶意程序检测技术
New Malicious Executables Detection Based on Association Rules
【摘要】 针对当前基于特征码病毒检测技术不能检测出未知病毒的缺点,通过研究某些病毒及其变种版本在执行过程中应用程序接口(API)调用序列的规律,提出一种基于数据挖掘的检测技术,采用Apriori算法从已知病毒的API调用序列中提取有价值的关联规则,用于指导病毒检测。实验结果表明该方法对未知病毒检测有良好的效果。
【Abstract】 In order to improve the current malicious detection technology based on signature,this paper presents a method based on data mining.By researching the rules of API calling sequences during executing viruses,the method uses Apriori algorithms to extract some valuable related rules which hide out in a lot of API calling sequences of viruses.These rules can be used to detect Viruses.Experimental results validate its effection.
【基金】 国家“863”计划基金资助项目(2006AA01Z449)
- 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2008年24期
- 【分类号】TP309.5
- 【被引频次】8
- 【下载频次】130