首页 | 本学科首页   官方微博 | 高级检索  
     

基于SVM的计算机病毒检测系统
引用本文:张波云,殷建平,蒿敬波. 基于SVM的计算机病毒检测系统[J]. 计算机工程与科学, 2007, 29(9): 19-22
作者姓名:张波云  殷建平  蒿敬波
作者单位:国防科技大学计算机学院,湖南,长沙,410073;湖南公安高等专科学校计算机系,湖南,长沙,410138;国防科技大学计算机学院,湖南,长沙,410073
基金项目:国家自然科学基金 , 湖南省教育厅青年基金
摘    要:自从第一例计算机病毒被发现以来,特征码法一直是病毒检测的基本方法。但是,病毒的复杂化和变形病毒的出现,限制了该法的有效应用。本文提出一种基于支持SVM的通用病毒智能检测方法,通过支持SVM算法的应用,使得检测系统在小样本的情形下仍具有良好的泛化能力。然后,以系统API函数调用执行迹为例,测试了该法的检测性能,并
将实验结果与其他检测方法进行了比较。实验表明,API函数调用序列在区分正常与恶意PE格式程序文件上有很好的辨别力,发现基于支持SVM的病毒检测系统所需要的先验知
知识小于其他方法。而且,当检测性能相当时,系统的训练时间将会缩短。

关 键 词:计算机病毒  支持向量机  病毒检测
文章编号:1007-130X(2007)09-0019-04
修稿时间:2006-03-03

A SVM-Based Computer Virus Detection System
ZHANG Bo-yun,YIN Jian-ping,HAO Jing-bo. A SVM-Based Computer Virus Detection System[J]. Computer Engineering & Science, 2007, 29(9): 19-22
Authors:ZHANG Bo-yun  YIN Jian-ping  HAO Jing-bo
Affiliation:1. School of Computer Science,National University of Defense Technology,Changsha 410073; 2. Department of Computer Science, Hnnan Public Security College, Changsha 410138, China
Abstract:Since the first computer virus was found, scanning detection has been used as a primary method in virus detection systems. As viruses become more complex and sophisticated, the scanning detection method is no longer able to detect the various forms of malicious code effectively. We explore the idea of automatically detecting viruses based on Support Vector Machine ( SVM) and not strictly dependent on certain viruses. By utilizing SVM, the generalizing ability of virus detection systems is still good when the sample size is small. An experiment using the system API function call trace is given to illustrate the performance of this method. Finally,the comparison of detection abilities between the above detection method and others is given. Evidence shows that the sequences of the operating system API function calls executed by the running programs are a good discriminator between benign and malicious PE files,the detection system based on SVM needs less priori knowledge than other methods,and can shorten the training time under the same detection performance condition.
Keywords:computer virus  support vector machine  virus detection
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机工程与科学》浏览原始摘要信息
点击此处可从《计算机工程与科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号