资源描述:
《基于行为关联的恶意代码分析技术分析》由会员上传分享,免费在线阅读,更多相关内容在工程资料-天天文库。
1、AbstractWiththerapiddevelopmentofInternettechnology,peopleenjoytheconvenienceofthenetwork,butallkindsofnetworksecurityproblemsfollowatthesametime.Inmanynetworksecurityproblems,maliciouscodeisundoubtedlythebiggestthreat•Itisthefocusofnetworksecurityresearchsubject,
2、somanymethodsofmaliciouscoderesearchhavebeenproposed.Inthispaper,weanalyzetheexistingtechnologyofmaliciouscodeanalysisanddetectionmethodsindetail,andproposeamaliciouscodeanalysistechnologybasedonbehaviorassociation.Wefocusontheabstractdescriptionofmaliciouscodebeh
3、avior,intendingtoclarifytherelationshipbetweenbehaviorsratherthanconsideringthemaliciousnessofasinglebehavi0匚Thepurposeistocomprehensivelyanalyzethemaliciouscodebehaviorandreducethemisjudgmentofmaliciouscode.WeextractthebehaviorpointsofmaliciouscodethroughtheAPI(A
4、pplicationProgrammingInterface)monitoringtechnology,andusefivetuplestoabstractbehaviorpoints,thenusethedatadependenceofbehaviorstoestablisharelationshipshowedbyassociationgraphbetweenbehaviors.Onthebasisoftheassociation,weproposeajudgmentmethodbasedonpushdownautom
5、ata.Wedesignamaliciouscodedetectionprototypesystemcontainingthreelayers,monitoringlayer,organizationlevel,andjudgmentlayer.Weusemaliciouscodesamplesfromourlabtoanalyzethedetectionprototypesystem・Theexperimentalresultsshowthattheprototypesystemcanwelldescribethebeh
6、aviorofthemaliciouscode,andcansuccessfullyidentifymaliciousbehaviorintheprogram.Keywords:Maliciouscode,Behaviormonitor,Behaviorassociation,Pushdownautomation摘要IAbstractII1绪论1.1课题背景和研究意义(1)1.2国内外研究现状(2)1.3主要研究内容(4)1.4论文组织结构(4)2恶意代码分类及其检测技术2.1恶意代码分类(5)2.2恶意代码检测技术(7)
7、2.3本章小节(11)3基于行为尖联的恶意代码检测模型3.1关联行为的定义(12)3.2关联行为的构建(13)3.3关联行为的恶意判别(18)3.4本章小节(22)4基于行为尖联的恶意代码检测系统设计4.1总体设计(23)4.2监控层设计(23)4.3组织层设计(28)4.4判断层设计(30)4.5本章小节(31)5实验及结果分析5.1测试环境(32)5.2检测模型的测试(32)5.3本章小节(37)6总结与展望(38)6.1总结(38)6.2研究展望(38)致谢(40)参考文献(41)1绪论1.1课题背景和研究意义随着计
8、算机技术的飞速发展,计算机已经深入到人们生活的各个方面了,计算机的开放性和灵活性带来了便利也带来了各种安全性问题,现在病毒、木马、僵尸网络等恶意软件在社会的各行各业造成的损失屡见不鲜,恶意代码已经成为威胁互联网安全的主要因素Z-O据国家互联网应急中心CNCERT2012年中国互联网网络安全报告⑴分析,2