摘要
利用PE文件剖析器、00A规则生成器、可疑文件扫描器按照主动防御系统原理,生成了基于数据挖掘技术的DMAV病毒主动防御系统。通过对比不同杀毒软件的变形病毒、未知病毒检测效果,发现新设计的DMAV病毒主动防御系统较其他杀毒软件杀毒范围更广、效率更高。
According to the principle of active defense system, the PE file parser, 00A rule generator and suspicious file scanner arc used to generate the DMAV virus active defense system based on data mining technology. By comparing the detec- tion effects of different antivirus softwares dealing with deformation virus and unknown virus, it is found the new designed DMAV active virus defense system has wider antivirus scope and higher efficiency than those of other antivirus softwares.
作者
于丽
YU Li(Department of Information Security Engineering, Xinjiang Police College, Urumchi 830011, China)
出处
《现代电子技术》
北大核心
2016年第21期120-122,126,共4页
Modern Electronics Technique
关键词
数据挖掘
网络病毒
变形病毒
防御系统
data mining
network virus
deformation virus
defense system