节点文献
模型检验下蠕虫病毒检测器的设计与实现
Design and implementation of worm detector based on model checking
【摘要】 现在蠕虫病毒检测技术主要是基于病毒特征库,通过特征码的匹配来确定。这种方法的主要缺点是病毒特征库的更新总是滞后于病毒的发布,实时性效果较差。这里提出了一种新的方法,采用模型检验技术的方法,结合蠕虫病毒的入侵原理,改进计算逻辑树的规范设计,从汇编代码层面对蠕虫病毒行为进行特征提取,有效建模,实验结果显示这种方法能够有效地检测蠕虫病毒及其变种。
【Abstract】 Currently,worm detection method is mainly based on virus signatures to ascertain one worm if the detected file contains one of the signatures.The update of database is always later than the release of a worm variant.Meanwhile,its real-time performance is unsatisfactory.A novel method to detect the worm virus by using model checking is proposed.After proper analysis of the worm intrusion principle and effective improvement of CTL specification,the worm behavior signature can be extracted from assembly level and modeling.The experiments demonstrate that the technique is able to detect the worm(variants) with efficiency.
- 【文献出处】 现代电子技术 ,Modern Electronics Technique , 编辑部邮箱 ,2012年03期
- 【分类号】TN915.08
- 【下载频次】30