首页 | 本学科首页   官方微博 | 高级检索  
     

基于云计算的恶意程序检测平台设计与实现
引用本文:韩奕,姜建国,仇新梁,马新建,赵双. 基于云计算的恶意程序检测平台设计与实现[J]. 计算机工程, 2014, 0(4): 26-31
作者姓名:韩奕  姜建国  仇新梁  马新建  赵双
作者单位:[1]北京交通大学计算机与信息技术学院,北京100044 [2]中国科学院信息工程研究所,北京100093
基金项目:基金项目:国家自然科学基金资助项目(61372062).
摘    要:针对当前恶意程序种类繁多、分析工作量大的问题,利用VMware vSphere虚拟化技术,设计并实现云环境下的恶意程序自动检测平台。该平台通过轮询机制获得服务器虚拟机资源的负载情况,将收集的可疑样本分类预处理,调用相应的服务器资源进行检测,可为用户终端节点提供多样化的虚拟环境,实现恶意程序文件、注册表、进程以及网络4类主机行为的自动分析,并自动生成分析报告。在真实样本上的实验结果表明,与金山火眼、Threat Expert平台相比,该平台能够更准确地反映恶意程序的特点及危害性。

关 键 词:VMware vSphere技术  恶意代码  自动分析  行为特征  虚拟机  检测

Design and Implementation of Malware Detection Platform Based on Cloud Computing
HAN Yi,JIANG Jian-guo,QIU Xin-liang,MA Xin-jian,ZHAO Shuang. Design and Implementation of Malware Detection Platform Based on Cloud Computing[J]. Computer Engineering, 2014, 0(4): 26-31
Authors:HAN Yi  JIANG Jian-guo  QIU Xin-liang  MA Xin-jian  ZHAO Shuang
Affiliation:1. School of Computer and Information Technology, Beijing Jiaotong University, Beijing 100044, China; 2. Institute of Information Engineering, China Academy of Sciences, Beijing 100093, China)
Abstract:Aiming at the problem of wide range of malware and large analysis workload, in this paper, with the use of VMware vSphere virtualization technology, an automatic malware detection system upon the cloud platform is designed and implemented. This platform adopts polling mechanism to monitor the load of virtual machines in servers, conducts preprocessing of collected suspicious samples according to their type and tests the samples using correspond server resources. It can offer users a variety of virtual environment, automatic analysis malware's four host behavior of files, registry, processes and network, provides online analysis report, and effectively responses to the problem of wide range of malicious programs, eliminates the analyzing workload, improves the efficiency of analysis. Experimental result on real samples shows that this platform can provide more precise character and threat information of analyzed samples compared with Jinshan Fireeye and Threat Expert platform.
Keywords:VMware vSphere technology  malicious code  automatic analysis  behavioral characteristics  virtual machine  detection
本文献已被 CNKI 维普 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号