计算机科学 ›› 2010, Vol. 37 ›› Issue (9): 161-163.

• 软件工程 • 上一篇    下一篇

一种采用免疫原理的恶意软件检测方法

张福勇,齐德昱   

  1. (华南理工大学计算机系统研究所 广州510640)
  • 出版日期:2018-12-01 发布日期:2018-12-01
  • 基金资助:
    本文受国家技术创新基金项目(08026214411198),粤港关键领域重点突破项目(2008A011400010),广州市创新基金项目(2007V41C0301)资助.

Immune-based Method for Malware Detection

ZHANG Fu-yong.QI De-yu   

  • Online:2018-12-01 Published:2018-12-01

摘要: 针对现有恶意软件检测方法的不足,提出一种采用免疫原理的恶意软件检测方法。该方法采用程序运行时产生的IRP请求序列作为抗原,定义系统中的正常程序为自体、恶意程序为非自体,通过选定数量的抗体,采用人工免疫原理识别非自体。实验结果表明,此方法在恶意软件的检测方面具有较高的准确率,且误报和漏报率较低。

关键词: 人工免疫,恶意软件,恶意软件检测,反病毒

Abstract: In order to solve the problems existing in the current malware detection, a new malware detection method based on immune was proposed. In this method, the IRP request sectuences created by running programs are regarded as antigen, and the normal programs in operating system arc self, malwares arc nonsclf. I}he nonself will be detected by some antibodies using artificial immunology. Experimental results reveal that this model has high true positive rate, and low false positive and false negative rate.

Key words: Artificial immune, Malware, Malware detection, Anti-virus

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!