摘要
在深入分析恶意代码及其检测技术特征的基础上,提出一种基于硬件虚拟机的恶意代码检测系统,轻量级虚拟机是基于硬件虚拟化技术实现的小型虚拟机,为文件检测提供环境。行为监控模块负责监控被检测文件的所有行为,并把这些行为记录下来为后面的分析提供依据。行为分析模块是系统的数据处理模块,需要对数据进行收集、分类、分析处理然后归纳得出测试结果。
Based on in-depth analysis of the characteristics and detection technology of malicious code, a new malicious code detection model based on hardware-assisted virtualization technology is proposed. Lightweight virtual machine is a small virtual machine based on hardware virtualization technology and provides the environment for file detection. Behaviors monitoring module monitors all the behaviors of the detected file, and records these behaviors, thus to provide a basis for the subsequent analysis. The behaviors analysis module, as a data processing module of the system, implements data collection, classification, analysis and processing and summarizes the obtained test results.
出处
《信息安全与通信保密》
2013年第5期79-81,共3页
Information Security and Communications Privacy
关键词
恶意代码
硬件虚拟化
检测系统
malicious code
hardware-assisted virtualization
detection system