摘要
计算机病毒严重威胁着计算机系统的安全,多态病毒采用自动变形技术对抗特征码检测,本文介绍了利用虚拟机技术的病毒检测引擎的工作原理,讨论了目前存在的效率问题,提出一个采用启发式扫描的检测引擎模型。
Computer systems are being severely threatened by computer viruses. Polymorph virus use the auto polymorph mechanism to avoid being detected by Virus Scanner that identifies the virus characteristic code. This article thoroughly discusses the mechanism of Anti-Virus Engine and finds the problem of the Engine. In the end put forward a new method for Anti-Virus Engine base on heuritic strategy.
出处
《微计算机信息》
北大核心
2006年第09X期134-136,共3页
Control & Automation
关键词
多态病毒
检测引擎
虚拟机
病毒行为
Polymorph virus
Anti-Virus Engine
Virtual Machine
Virus Behavior