摘要
时下病毒、木马传播猖獗,在系统中如何捕捉成为一个难题,文中提出另一种设计思路,先由系统自建系统及相关系统软件、应用软件的进程数据库,记录有关进程的多种信息,在随后的计算机运行过程中,及时捕捉当前正在运行的安全进程列表中有无新增加进程,并遍历进程数据库,进一步对比确定该新增的进程是否合法注册,以辨别其合法性。
Nowadays, virus and Trojan Horse are spreading increasingly rampant. How to capture them has become a technical problem in computer system. This paper proposes a one new design in capturing, analyzing and tracing them through monitoring multiple process information from system, and comparing the newly-emerged processes with every record in the system-process database. And thus the illegal process could be successfully captured.
出处
《信息安全与通信保密》
2009年第10期73-74,77,共3页
Information Security and Communications Privacy
关键词
病毒
木马
监控进程
监控数据库
virus
Trojan Horse
monitor process
monitor database