节点文献

恶意代码的分析和防治

Analysis and Prevention of Malicious Code

【作者】 沈维

【导师】 黄征; 项闪飞;

【作者基本信息】 上海交通大学 , 计算机技术, 2007, 硕士

【摘要】 随着信息技术的飞速发展和普及,计算机和网络技术在给人们带来方便和效率的同时,也带来了各种各样的安全方面的问题。恶意代码就是这些安全威胁中最常见的一种。由于其非常普遍,造成的危害也非常大,从影响计算机正常工作,到丢失数据,情况严重者,连计算机硬件也可能被破坏。因此深入地研究恶意代码,研究更好的检测它的方法,研究更强的防范和对抗恶意代码的技术有着重要的意义。本论文研究了恶意代码的历史和发展过程,讨论了恶意代码的定义和分类,把恶意代码分成计算机病毒(Computer Virus)、蠕虫(Worms)、特洛伊木马(Trojan Horse)、逻辑炸弹(Logic Bombs)、恶意移动代码、后门等。然后从恶意代码的传播机制、触发条件、破坏机制以及它的加密技术(变形病毒)等方面对恶意代码的工作原理进行了研究。在分析了恶意代码的工作原理以后,总结了网络环境下恶意代码的新特点,讨论了防范恶意代码的技术,对于特征代码、校验和、行为监测、软件模拟等现在常用的检测恶意代码的技术进行了研究和总结。在研究了恶意代码工作原理和现有的检测和防范技术的基础上,再根据自己的工作经验,总结了一套对恶意代码的防范规则。

【Abstract】 With the rapid development of information technology, computers and network bring us not only productivity but also security problems. Malicious Code is one of these problems. Because Malicious Code widely spread, They are very dangerous. They can damage data, even computer hardware. So, it is important to study better Malicious Code technique.Malicious Code include Computer Virus、Worms、Trojan Horse、Logic Bombs、Malicious Mobile Code、Backdoor, etc. The techniques Malicious Code using affection, trigger, destruction and the cryptography technique.The article discussed Malicious Code technique, include signature code, check sum, software emulation, etc. After studying the working principle of malicious code and the existing detection and prevention technology on the basis of the basis of their own experience, A summary of the malicious code prevention rules

  • 【分类号】TP309.5
  • 【被引频次】10
  • 【下载频次】959
节点文献中: