期刊文献+

基于虚拟执行技术的高级恶意软件攻击在线检测系统 被引量:4

An Online Detection System for Advanced Malware Based on Virtual Execution Technology
下载PDF
导出
摘要 随着新一代网络技术的不断发展,针对工业控制网络的高级恶意软件大量出现,使以智能电网为代表的工业信息系统面临着巨大的信息安全威胁。目前主流的恶意软件检测技术主要是沙箱技术,其原理是在漏洞利用阶段之后,对恶意软件的行为进行分析。但是随着网络攻击技术的不断发展,高级恶意软件通过多态和变形技术掩饰自己的恶意行为。为了抵御智能电网中的高级恶意软件攻击,文章设计了一种基于虚拟执行技术的高级恶意软件攻击在线检测系统,在传统静态检测的基础上,增加了动态检测引擎。动态检测采用和传统的沙箱检测不同的虚拟执行技术,通过系统调用跟踪来分析软件的行为特征,深入观察分析内存和指令属性的变化,有效规避了高级恶意软件漏洞利用后的逃避行为,在漏洞利用阶段发现高级恶意软件攻击。实验表明,在线检测系统能够有效避免智能电网遭受高级恶意软件的攻击。 The current mainstream of malware detection technologies includes sandbox technologies which are mainly based on malware behavior analysis. However, with the continuous development of network attack techniques, advanced malware technology will hide their malicious behavior through multi-state and deformation. In order to protect the information security of the smart grid, this paper presents an advanced online malware detection system based on virtual execution technology. The detection system increases a dynamic detection engine as well as in support of the traditional static test. Dynamic detection engine can detect advanced malware attacks through observation and analysis the changes of instruction and memory properties in depth using a virtual execution technology which is different from the traditional sandbox detection. Smart grid can effectively avoid suffering from advanced malware attacks if the online testing system is used in smart grid.
出处 《信息网络安全》 2016年第1期29-33,共5页 Netinfo Security
关键词 高级恶意软件 虚拟执行 在线检测 智能电网 advanced malware virtual execution online detection smart grid
  • 相关文献

参考文献7

二级参考文献46

  • 1徐磊.智能电网的网络通信架构及关键技术[J].电气技术,2010,11(8):16-20. 被引量:16
  • 2操丰梅,任雁铭,王照,晋阳珺,魏春峰,郁惊一.变电站自动化系统互操作实验建议[J].电力系统自动化,2005,29(3):86-89. 被引量:42
  • 3张结.应用IEC61850实现产品互操作性的思考[J].电力系统自动化,2005,29(3):90-94. 被引量:32
  • 4何卫,王永福,缪文贵,张祥文,杨玲,俞奇琦.IEC 61850深层次互操作试验方案[J].电力系统自动化,2007,31(6):103-107. 被引量:29
  • 5H. Khurana, M. Hadley, Ning Lu, D.A.Frincke, Smart Grid Security Issues[J]. IEEE Security & Privacy, 2010, 8(01): 81-85.
  • 6NIST Smartgrid[EB/OL]. http://www.nist.gov/smartgrid/, 2012-07-12.
  • 7NIST Framework and Roadmap for Smart Grid Interoperability Standards, Release 1.0 (NIST SP 1108)[EB/OL]. http://www.nist.gov/public_affairs/ releases/upload/smartgrid_interoperability_final.pdf, 2009-09/2012-07-12.
  • 8NIST IR 7628. Guidelines for Smart Grid Cyber Security [EB/ OL]. http:/ /csrc.nist.gov/publications/nistir/ir7628/introduction-to- nistir-7628.pdf, 2010-08/2012-07-12.
  • 9Y.Yan, Y.Qian, H.Sharif, D.Tipper, A Survey on Cyber Security for Smart Grid Communications[J]. IEEE Communications Surveys & Tutorials, 2012, (99): 1-13.
  • 10Y. Mo, T.H.-J. Kim, K.Brancik, D. Dickinson, Heejo Lee; A.Perrig, B.Sinopoli, Cyber-Physical Security of a Smart Grid Infrastructure[J], Proceedings of the IEEE, 2012, 100(01): 195-209.

共引文献20

同被引文献16

引证文献4

二级引证文献29

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部