本文已被:浏览 1656次 下载 3472次
Received:May 20, 2012 Revised:August 18, 2012
Received:May 20, 2012 Revised:August 18, 2012
中文摘要: 通过设计一个简单感染型病毒, 发现主流杀毒软件主动防御策略无法对其进行有效拦截. 根据在正常情况下系统PE文件不会发生变化的特性, 提出通过拦截对已有PE文件写操作来实现主动防御的方法, 并设计相应系统PEPS. 仿真实验表明, 该方法对于感染型病毒的防御效果优于主流杀毒软件.
Abstract:After designing a simple infectious virus, we find the Active Defense Strategy of mainstream anti-virus software can’t intercept the infectious operations effectively. Under normal circumstances, the original PE files of the system cannot be modified. According to this characteristic, the following article develops a way to realize initiative recovery by monitoring illegal write operation of original PE file and design a system–PEPS. The simulation experiments show that the method is more effective on the defense of infectious viruses than mainstream anti-virus software.
keywords: PE infectious viruses write operation interception PEPS
文章编号: 中图分类号: 文献标志码:
基金项目:广东省自然科学基金(9151027501000054,s2011010003409);2011年华南师范大学大学生创新实验计划
Author Name | Affiliation |
ZHENG Huan-Xin | School of Computer, South China Normal University, Guangzhou 510631, China |
YE Xiao-Ping | School of Computer, South China Normal University, Guangzhou 510631, China |
Author Name | Affiliation |
ZHENG Huan-Xin | School of Computer, South China Normal University, Guangzhou 510631, China |
YE Xiao-Ping | School of Computer, South China Normal University, Guangzhou 510631, China |
引用文本:
郑焕鑫,叶小平.感染型病毒防御系统.计算机系统应用,2013,22(2):15-18
ZHENG Huan-Xin,YE Xiao-Ping.Defense of Infectious Viruses.COMPUTER SYSTEMS APPLICATIONS,2013,22(2):15-18
郑焕鑫,叶小平.感染型病毒防御系统.计算机系统应用,2013,22(2):15-18
ZHENG Huan-Xin,YE Xiao-Ping.Defense of Infectious Viruses.COMPUTER SYSTEMS APPLICATIONS,2013,22(2):15-18