摘要
提出一种基于信息隐藏技术的方法来防范和对付PE病毒。该方法利用PE文件结构和PE病毒只侵袭可执行文件而不攻击数据文件的特性,将可执行文件头隐藏于数据文件之中,达到保护可执行文件的目的。实验验证了该方法的可行性。分析了该方法的长处和不足,与其它防病毒方法相比,该方法具有很好的信息隐藏量,能防范已知的可执行文件类计算机病毒,也能防范未知的和未来的该类计算机病毒。
The PE virus is one type of the most quantity in virus family, and it has great destructiveness. This algorithm, utilizing PE file structure and PE virus characteristic of only attacking the executable file without attacking the data file, hides the PE file head in the data file to achieve the goal of protecting the executable file. This paper presents the algorithm of hiding PE file head into an image and the algorithm of picking out the file from the image. The experiment has verified the feasibility of this algorithm. Compared with the situation that other defends the virus method, this method has very good hiding amount of information, can take precautions against the executable file computer virus that has already known, ones that can be taken precautions against unknownly too and this kind of computer virus in the future.
出处
《计算机应用与软件》
CSCD
北大核心
2007年第6期9-11,86,共4页
Computer Applications and Software
基金
国家自然科学基金(No.60372072)
陕西省科技攻关基金(No.2004K05-G25)
关键词
计算机病毒
信息隐藏
PE文件
信息安全
Computer virus Information hiding PE file Information security