摘要
提出了一种在虚拟执行技术支持下基于病毒行为序列的未知病毒分析检测技术。该技术可以克服病毒特征代码扫描法不能识别未知病毒的特点。在模拟的虚拟执行环境中对该方法进行了测试,测试表明了该方法的可行性和较高的准确性。
A algorithm to detect and analyze computer virus based on its behavior sequence under the support of virtual execution technology is presented in this paper.It can overcome the shortage of normal virus scanner,which could not detect unknown virus.Tests in a simulating virtual execution environment indicated that this algorithm is feasible and accurate.
出处
《计算机安全》
2010年第5期4-5,共2页
Network & Computer Security
关键词
计算机病毒
虚拟执行
行为序列
病毒检测
Computer virus
Virtual execution
Behavior sequence
Virus detection