计算机应用 ›› 2010, Vol. 30 ›› Issue (12): 3357-3359.

• 信息安全 • 上一篇    下一篇

基于虚拟机技术的可疑文件自动检测系统

钟明全,李焕洲,唐彰国,张健   

  1. 四川师范大学物理与电子工程学院
  • 收稿日期:2010-06-18 修回日期:2010-07-24 发布日期:2010-12-22 出版日期:2010-12-01
  • 通讯作者: 钟明全

Auto-detection system of suspicious file based on virtual machine technology

  • Received:2010-06-18 Revised:2010-07-24 Online:2010-12-22 Published:2010-12-01

摘要: 针对特征码技术不能检测新型未知非法程序的特点,提出了一种基于虚拟机技术和行为分析技术的可疑文件自动检测系统。重点介绍了检测系统的工作流程图,给出了系统的管理中心和检测中心的模块架构,详细分析了两个中心的技术原理。测试结果表明,基于自定义的判定规则库,系统能够快速判断被检测文件的危险等级,生存周期长。

关键词: 非法程序, 虚拟机, 行为分析, 误报率, 漏报率

Abstract: Concerning the feature that the technology of characteristic code is unable to detect new and unknown baleful program, an auto-detection system of suspicious file based on technology of virtual machine and behavior analysis was proposed. Work diagram of detection system was introduced with emphasis, module framework of management center and detection center of the system was given, and the technical principle of management center and detection center was analyzed in detail. The experimental results show that the system can judge rapidly the dangerous level of one detected file and the system has long life cycle.

Key words: baleful program, Virtual Machine (VM), behavior analysis, misinformation rate, unreported rate