节点文献

面向未知病毒检测方法与系统实现技术研究

【作者】 张凡

【导师】 蔡皖东;

【作者基本信息】 西北工业大学 , 计算机应用技术, 2003, 硕士

【摘要】 随着计算机网络技术的高速发展,利用广泛开放的网络环境进行全球通信已成为时代发展的趋势。但是网络在给人们带来巨大便利的同时也带来了各种各样的安全威胁,其中计算机病毒就是其中之一,并且随着互联网的发展,计算机病毒传播的速度越来越快,给人们带来的危害也越来越大,因此如何对计算机病毒进行防治对于计算机安全来说就显得非常关键。 当前的计算机病毒检测技术主要基于特征检测法,其基本思想是提取已知病毒样本的特征,并将此特征数据添加到病毒特征库中,在病毒检测时通过搜寻病毒特征库查找是否存在相匹配的病毒特征来发现病毒。这种检测方法只能用于检测已知的病毒,对于新出现的病毒的检测无能为力。为了解决这一问题,本文采用数据挖掘的分类方法对病毒的类型、不同类型病毒行为特征提取方法以及数据分类算法等因素进行了分析,提出一种具有通用性和扩展性的未知病毒检测方法,并利用病毒程序与正常程序的行为特征差异性进行分类,从而达到检测未知病毒的目的。 在上述检测方法的基础上,本文设计了未知邮件病毒检测系统,采用基于网络的部署方式,能够对大规模网络范围内的电子邮件系统进行病毒检测,并且在发现病毒后能够及时报警和进行事故处理从而防止病毒的扩散,同时系统能够自动升级,保证了对未知病毒检测的有效性。 通过对该系统已完成的功能进行的实验,结果表明该系统的设计和实现方案是可行的。

【Abstract】 With the rapid development of computer networks, global communications with widespread open net environments have become the dominant trend in the future. But not only networks bring us great convenience but also bring us many kinds of security threat, computer virus is one of them, and with the expanding of Internet, the spread of computer virus has become more and more quickly, and damage to the people become larger and larger, so how to defend against computer virus is very important to the computer security.Currently, most techniques for detecting computer virus are feature-based. Within this framework, a unique feature vector for each virus is extracted, thus a virus feature database can be established. Virus detection is performed as search and matching process in this database. This framework is effective, but current methods cannot detect unknown viruses. To solve this problem, this paper use the idea of data mining, analyzed types of virus, use different feature extraction and classify algorithm for each type, and then presents a more common and extendable method for detecting unknown virus, and we try to use the different behavior features between normal programs and viruses to distinct them from each other, so use this we can detect unknown virus.Based on this detect method this paper designed a system which named unknown e-mail virus detect system, we deploy this system based on networks, aims at detect virus within email system in a large area of networks, and this system can give an alarm and process incident handle when it found viruses, and then it can stop the spreading of the virus, and this system can update automatically, so it can ensure the validity of unknown virus detection.The result of testing of this system shows that the design and implementation of this system are feasible.

  • 【分类号】TP309.5
  • 【被引频次】12
  • 【下载频次】522
节点文献中: