引用本文:张一弛,庞建民,赵荣彩.基于证据推理的程序恶意性判定方法.软件学报,2012,23(12):3149-3160
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 4160次   下载 7130 本文二维码信息
码上扫一扫!
分享到: 微信 更多
基于证据推理的程序恶意性判定方法
张一弛, 庞建民, 赵荣彩
解放军信息工程大学 信息工程学院,河南 郑州 450002
摘要:
针对可执行程序恶意性难以判定的情况,提出一种基于证据推理的程序恶意性判定方法.首先,建立程序恶意性判定模型;然后,通过对程序进行反编译,抽取影响程序安全性的特征,建立程序行为集合;使用BP神经网络对模型进行训练得到各个行为的概率分配函数BPAF(basic probability assignment functions),并使用加权和形式的合成法则对程序行为进行合成;最后,实现对程序恶意性的判定.实验结果表明了该方法的有效性.
关键词:  恶意代码检测  证据推理  神经网络  程序行为  相似度
DOI:10.3724/SP.J.1001.2012.04221
分类号:
基金项目:国家高技术研究发展计划(863)(2006AA01Z408, 2009AA01Z434); 河南省重大科技攻关项目(092101210501)
Evidential Reasoning Method for Decision of Program Maliciousness
ZHANG Yi-Chi, PANG Jian-Min, ZHAO Rong-Cai
Institute of Information Engineering, PLA Information Engineering University, Zhengzhou 450002, China
Abstract:
Considering the fact that the determination of the executable file maliciousness is hard to achieve, an approach based on the evidence theory is presented in this paper. First, a model for determining the maliciousness is established. Then characters compromising security are extracted to construct the set of program behaviors through decompiling the program. The model is trained using the BP neural network to gain the basic probability assignment functions (BPAF) of each behavior, and the weighted sum method is applied to combine the program behaviors, determining the executable file maliciousness. Experimental results demonstrate the validity of the approach which uses the evidence theory to determine the maliciousness of program.
Key words:  malware detection  evidence reason  neural network  program behavior  similarity

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: