计算机科学 ›› 2012, Vol. 39 ›› Issue (6): 93-97.

• 计算机网络与信息安全 • 上一篇    下一篇

基于控制流信息的克里普克结构生成方法

牛小鹏,李清宝,谢晓东   

  1. (解放军信息工程大学信息工程学院 郑州 450002)
  • 出版日期:2018-11-16 发布日期:2018-11-16

Kripke Structure Generating with Control Flow Information

  • Online:2018-11-16 Published:2018-11-16

摘要: 恶意程序检测是信息安全技术研究的重要内容,基于程序行为特征的检测可以弥补二进制特征码检测方法的很多不足。使用模型检验技术可以对程序的操作行为做属性验证,它需要对目标程序进行建模,得到一个符合克里普克结构的迁移系统。通过对模型检验技术和克里普克结构的研究分析,提出了一种以完整控制流信息为基础、采用贪婪归一策略的克里普克迁移系统生成方法。则试分析表明,利用该方法生成的迁移系统可以完整地描述控制流信息,也可以精确地刻画系统状态的改变。

关键词: 模型检测,克里普克结构,控制流,系统状态,标记函数

Abstract: Malware detection is an important part of information security technology. The detection based on program behavior characteristics can remedy the limits of binary signature detection method. Model checking technology can verify a program's specific behavior property, which requires a model for the target program, in order to obtain a transition system which is coincident with Kripke structure. Current model checking technology and Kripke structure were thoroughly analyzed, and then the method of generating Kripkc structure was proposed, which is based on the full control flow information and greed strategy. I}he generated transition system can fully represent the control flow information and describe the changes of target system status.

Key words: Model checking, Kripke structure, Control flow, System status, Lable function

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!