期刊文献+

基于云计算的恶意程序检测平台设计与实现 被引量:10

Design and Implementation of Malware Detection Platform Based on Cloud Computing
下载PDF
导出
摘要 针对当前恶意程序种类繁多、分析工作量大的问题,利用VMware vSphere虚拟化技术,设计并实现云环境下的恶意程序自动检测平台。该平台通过轮询机制获得服务器虚拟机资源的负载情况,将收集的可疑样本分类预处理,调用相应的服务器资源进行检测,可为用户终端节点提供多样化的虚拟环境,实现恶意程序文件、注册表、进程以及网络4类主机行为的自动分析,并自动生成分析报告。在真实样本上的实验结果表明,与金山火眼、Threat Expert平台相比,该平台能够更准确地反映恶意程序的特点及危害性。 Aiming at the problem of wide range of malware and large analysis workload, in this paper, with the use of VMware vSphere virtualization technology, an automatic malware detection system upon the cloud platform is designed and implemented. This platform adopts polling mechanism to monitor the load of virtual machines in servers, conducts preprocessing of collected suspicious samples according to their type and tests the samples using correspond server resources. It can offer users a variety of virtual environment, automatic analysis malware's four host behavior of files, registry, processes and network, provides online analysis report, and effectively responses to the problem of wide range of malicious programs, eliminates the analyzing workload, improves the efficiency of analysis. Experimental result on real samples shows that this platform can provide more precise character and threat information of analyzed samples compared with Jinshan Fireeye and Threat Expert platform.
出处 《计算机工程》 CAS CSCD 2014年第4期26-31,共6页 Computer Engineering
基金 国家自然科学基金资助项目(61372062)
关键词 VMWARE vSphere技术 恶意代码 自动分析 行为特征 虚拟机 检测 VMware vSphere technology malicious code automatic analysis behavioral characteristics virtual machine detection
  • 相关文献

参考文献11

  • 1维基百科.沙箱[EB/OL].[2013-09-10].http://zh.wikipedia.org/w/index.php?title=%E6%B2%99%E7%9B%92&varianzh-cn. 被引量:1
  • 2Norman Co.. Norman Sandbox Whitepaper[EB/OL]. [2013- 09-10]. http://download.norman.no/whitepapers/whitepaper_ Norman SandBox.pdf. 被引量:1
  • 3Willems C, Holz T, Freiling F. Toward Automated Dynamic Malware Analysis Using CWSandbox[J]. IEEE Security and Privacy, 2007, 5(2): 32-39. 被引量:1
  • 4Joebox Team. Joebox: A Secure Sandbox Application for Windows to Analyse the Behaviour of Malware[EB/OL]. [2013-09-10]. http://www.j oebox.org/concept.php. 被引量:1
  • 5陈康,郑纬民.云计算:系统实例与研究现状[J].软件学报,2009,20(5):1337-1348. 被引量:1311
  • 6VMware Inc.. vSphere说明[EB/OL]. [2013-09-10]. http:// pubs.vmware.com/vsphere-51/index.jsp. 被引量:1
  • 7GoogleInc..vSphereSDKforpython说明[EB/OL].[2013-09-10].http://code.google.com/p/pysphere/. 被引量:1
  • 8张帆等编著..Windows驱动开发技术详解[M].北京:电子工业出版社,2008:530.
  • 9WinPcap Team. WinPcap: The Windows Packet Capture Li- brary[EB/OL]. [2013-09-10]. http://www.winpcap.org. 被引量:1
  • 10谭玉玲.基于正则表达式的数据处理应用[J].武汉理工大学学报(信息与管理工程版),2010,32(2):249-252. 被引量:9

二级参考文献39

  • 1陈怡,卿锋.在C语言中使用正则表达式[J].华南金融电脑,2004,12(4):57-59. 被引量:5
  • 2李村合,孙运雷.正则表达式在Oracle中的应用与实现[J].微计算机应用,2005,26(2):240-240. 被引量:2
  • 3王振辉,吴广茂.SQL查询语句优化研究[J].计算机应用,2005,25(B12):207-208. 被引量:29
  • 4Sims K. IBM introduces ready-to-use cloud computing collaboration services get clients started with cloud computing. 2007. http://www-03.ibm.com/press/us/en/pressrelease/22613.wss 被引量:1
  • 5Boss G, Malladi P, Quan D, Legregni L, Hall H. Cloud computing. IBM White Paper, 2007. http://download.boulder.ibm.com/ ibmdl/pub/software/dw/wes/hipods/Cloud_computing_wp_final_8Oct.pdf 被引量:1
  • 6Zhang YX, Zhou YZ. 4VP+: A novel meta OS approach for streaming programs in ubiquitous computing. In: Proc. of IEEE the 21st Int'l Conf. on Advanced Information Networking and Applications (AINA 2007). Los Alamitos: IEEE Computer Society, 2007. 394-403. 被引量:1
  • 7Zhang YX, Zhou YZ. Transparent Computing: A new paradigm for pervasive computing. In: Ma JH, Jin H, Yang LT, Tsai JJP, eds. Proc. of the 3rd Int'l Conf. on Ubiquitous Intelligence and Computing (UIC 2006). Berlin, Heidelberg: Springer-Verlag, 2006. 1-11. 被引量:1
  • 8Barroso LA, Dean J, Holzle U. Web search for a planet: The Google cluster architecture. IEEE Micro, 2003,23(2):22-28. 被引量:1
  • 9Brin S, Page L. The anatomy of a large-scale hypertextual Web search engine. Computer Networks, 1998,30(1-7): 107-117. 被引量:1
  • 10Ghemawat S, Gobioff H, Leung ST. The Google file system. In: Proc. of the 19th ACM Symp. on Operating Systems Principles. New York: ACM Press, 2003.29-43. 被引量:1

共引文献1318

同被引文献74

引证文献10

二级引证文献16

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部