计算机应用 ›› 2010, Vol. 30 ›› Issue (1): 207-209.

• 信息安全 • 上一篇    下一篇

改进的进程行为检测模型及实现

唐彰国,李焕洲,钟明全,张健   

  1. 四川师范大学物理与电子工程学院
  • 收稿日期:2009-07-09 修回日期:2009-08-11 发布日期:2010-01-01 出版日期:2010-01-01
  • 通讯作者: 唐彰国
  • 基金资助:
    四川省应用基础研究项目

Improved model of process behavior detection and implementation

  • Received:2009-07-09 Revised:2009-08-11 Online:2010-01-01 Published:2010-01-01

摘要: 为了检测恶意程序,分析了现有各类检测机制的不足,重新界定了进程行为概念的外延,提出了差量对比与进程动态行为分析的检测模型,给出了关键技术和实现方法。测试结果表明该检测模型在通用性和有效性方面优于传统检测方法。

关键词: 恶意程序, 差量对比, 检测模型, API函数

Abstract: To detect malicious program, the disadvantages of current detection mechanism were analyzed. The extension of process behavior concept was redefined. A detection model of difference comparison and process dynamic behavior analysis was proposed. The critical technology and realization were given. The experimental results indicate that the detection model excels traditional detection method in versatility and effectiveness.

Key words: vicious procedure, difference comparison, detection model, API function