基于免疫的Windows未知病毒检测方法

Immun-Based Approach for Detection of Unknown Windows Virus

  • 摘要: Windows未知病毒令传统反病毒技术疲于应付、防不胜防,且查杀效果不佳。该文借鉴人工免疫思想,在深入剖析Windows PE病毒逻辑结构基础上,提出利用病毒重定位模块作为病毒基因来生成抗体以检测病毒的方法,且建立了自体与非自体、抗原提呈以及抗体生成的动态演化数学模型。实验表明,该方法对于未知Windows PE病毒的检测率较高,且具有自适应、自学习能力。

     

    Abstract: To effectively detect unknown Windows PE viruses,a novel approach that roots in artificial immune system and uses the self-relocation module to generate antibodies is presented.The logical structure of Windows PE virus is briefly described.The dynamic evolution of self and nonself,the presentation of antigen,and the generation of antibody are proposed.The experiment results indicate that this approach not only has relatively high detection rate of unknown Windows PE virus,but also has better capability of self-adaptive and self-learning.

     

/

返回文章
返回