Relations between statistical residence time series and effective shooting are analyzed in accordance with the properties of the random residence time of maneuver targets crossing shot area in a given time. An estimat...Relations between statistical residence time series and effective shooting are analyzed in accordance with the properties of the random residence time of maneuver targets crossing shot area in a given time. An estimation method for kill probability is proposed, which solves the probability of number of residence times satisfied effective shooting in given time. Some expressions and their approximate formulae of kill probability are derived, under known the distribution of residence time series. Theoretical analysis and simulation results show that this method is suitable for evaluating the hit ability of fire system for maneuver targets in random shooting.展开更多
传统反病毒架构不能有效利用虚拟化优势解决云平台上的Windows系统所面临的恶意软件威胁,并且传统反病毒软件自身面临安全威胁,针对此问题,提出一种基于KVM的无代理Windows客户机进程在线杀毒技术。通过在KVM内核模块中添加读写内存的函...传统反病毒架构不能有效利用虚拟化优势解决云平台上的Windows系统所面临的恶意软件威胁,并且传统反病毒软件自身面临安全威胁,针对此问题,提出一种基于KVM的无代理Windows客户机进程在线杀毒技术。通过在KVM内核模块中添加读写内存的函数,以及为进程处理模块提供在其中注册钩子的接口等方法,解析客户机当前进程信息。将进程在内存中的PE(portable executable)镜像大致还原成运行前的磁盘文件后,调用开源杀毒引擎Clam AV(Clam Anti Virus)进行扫描查毒。查毒结果返回给决策模块后,由进程处理内核模块对可疑进程进行相应处理,实现对客户机当前进程的无代理查杀。分析及测试结果表明,该技术利用虚拟化优势较好地解决了传统反病毒框架的资源耗费和自身安全性问题。展开更多
基金Sponsored by the National Defense Funds under Grant(9140C300602080C30)Natural Science Foundation of Shanxi Province China(2008011011)
文摘Relations between statistical residence time series and effective shooting are analyzed in accordance with the properties of the random residence time of maneuver targets crossing shot area in a given time. An estimation method for kill probability is proposed, which solves the probability of number of residence times satisfied effective shooting in given time. Some expressions and their approximate formulae of kill probability are derived, under known the distribution of residence time series. Theoretical analysis and simulation results show that this method is suitable for evaluating the hit ability of fire system for maneuver targets in random shooting.
文摘传统反病毒架构不能有效利用虚拟化优势解决云平台上的Windows系统所面临的恶意软件威胁,并且传统反病毒软件自身面临安全威胁,针对此问题,提出一种基于KVM的无代理Windows客户机进程在线杀毒技术。通过在KVM内核模块中添加读写内存的函数,以及为进程处理模块提供在其中注册钩子的接口等方法,解析客户机当前进程信息。将进程在内存中的PE(portable executable)镜像大致还原成运行前的磁盘文件后,调用开源杀毒引擎Clam AV(Clam Anti Virus)进行扫描查毒。查毒结果返回给决策模块后,由进程处理内核模块对可疑进程进行相应处理,实现对客户机当前进程的无代理查杀。分析及测试结果表明,该技术利用虚拟化优势较好地解决了传统反病毒框架的资源耗费和自身安全性问题。
基金supported in part by the National Natural Science Foundation of China(No.11131003)the"985"project from the Ministry of Education in Chinathe Project Funded by the Priority Academic Program Development of Jiangsu Higher Education Institutions