摘要
提出利用工作在内核态的文件系统过滤驱动,捕获用户应用程序发往目标文件系统驱动的磁盘操作请求,直接对文件内容与特征码库中的病毒特征码进行匹配,检查是否含有病毒,有效地防止硬盘文件被病毒感染,降低系统调用的层数,避免状态的切换,因而有极高的效率,可以进行实时动态扫描。
Uses file system filter driver to capture user application sent to the target file system driver disk operation requests,directly match the document with the signature library of virus signatures,check whether they contain viruses,it is effectively to prevent the hard disk file is infected,reduces the system call layer,avoids the state switch,which has high efficiency,can be real-time dynamic scanning.
出处
《现代计算机》
2011年第9期16-19,共4页
Modern Computer