首页> 外文OA文献 >An Automatic Unpacking Method for Computer Virus Effective in the Virus Filter Based on Paul Grahamu27s Bayesian Theorem
【2h】

An Automatic Unpacking Method for Computer Virus Effective in the Virus Filter Based on Paul Grahamu27s Bayesian Theorem

机译:基于Paul Graham贝叶斯定理的一种有效的病毒过滤器自动解压方法。

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Recently, the appearance frequency of computer virus variants has increased. Updates to virus information using the normal pattern matching method are increasingly unable to keep up with the speed at which viruses occur, since it takes time to extract the characteristic patterns for each virus. Therefore, a rapid, automatic virus detection algorithm using static code analysis is necessary. However, recent computer viruses are almost always compressed and obfuscated. It is difficult to determine the characteristics of the binary code from the obfuscated computer viruses. Therefore, this paper proposes a method that unpacks compressed computer viruses automatically independent of the compression format. The proposed method unpacks the common compression formats accurately 80% of the time, while unknown compression formats can also be unpacked. The proposed method is effective against unknown viruses by combining it with the existing known virus detection system like Paul Grahamu27s Bayesian Virus Filter etc.
机译:近来,计算机病毒变体的出现频率已经增加。使用普通模式匹配方法对病毒信息进行更新越来越无法跟上病毒发生的速度,因为提取每种病毒的特征模式需要花费时间。因此,使用静态代码分析的快速,自动病毒检测算法是必要的。但是,近来的计算机病毒几乎总是被压缩和混淆。从混淆的计算机病毒很难确定二进制代码的特征。因此,本文提出了一种独立于压缩格式自动解压缩压缩计算机病毒的方法。所提出的方法可以在80%的时间内准确地解压缩常见压缩格式,而未知压缩格式也可以解压缩。通过将其与Paul Graham的贝叶斯病毒过滤器等现有已知病毒检测系统结合使用,该方法可以有效地防御未知病毒。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号