摘要
通过分析病毒程序的典型传染行为模式,总结传染模块中相对稳定的病毒表达模式,在此基础上提出了一种针对未知病毒的检测方法———基于程序行为的病毒检测方法,并采用语义网络对病毒表达模式进行形式化描述。该方法是通过抽取程序的行为模式,将之与病毒的行为模式进行匹配,达到检测未知病毒的目的。
Through analysing the typical infection behavior model of different viruses and summing up virus express model in the module of infection, a new virus detection method based on program behavior to detect unknown viruses is proposed. By extracting the program behavior pattern which matches with virus's behavior pattern, thus the purpose of detecting unknown viruses is reached.
出处
《青岛大学学报(自然科学版)》
CAS
2006年第2期61-65,共5页
Journal of Qingdao University(Natural Science Edition)
关键词
计算机病毒
传染行为
病毒检测
语义网络
computer viruses
infection behavior
virus detection
semantic net