作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程

所属专题: 云计算专题

• 云计算专题 • 上一篇    下一篇

基于云计算的恶意程序检测平台设计与实现

韩 奕1,2,姜建国2,仇新梁2,马新建2,赵 双2   

  1. (1. 北京交通大学计算机与信息技术学院,北京 100044;2. 中国科学院信息工程研究所,北京 100093)
  • 收稿日期:2013-10-10 出版日期:2014-04-15 发布日期:2014-04-14
  • 作者简介:韩 奕(1988-),女,硕士研究生,主研方向:云计算,恶意代码检测;姜建国,研究员、博士生导师;仇新梁,高级工程师;马新建,博士研究生;赵 双,助理工程师。
  • 基金资助:
    国家自然科学基金资助项目(61372062)。

Design and Implementation of Malware Detection Platform Based on Cloud Computing

HAN Yi  1,2, JIANG Jian-guo  2, QIU Xin-liang  2, MA Xin-jian  2, ZHAO Shuang  2   

  1. (1. School of Computer and Information Technology, Beijing Jiaotong University, Beijing 100044, China; 2. Institute of Information Engineering, China Academy of Sciences, Beijing 100093, China)
  • Received:2013-10-10 Online:2014-04-15 Published:2014-04-14

摘要: 针对当前恶意程序种类繁多、分析工作量大的问题,利用VMware vSphere虚拟化技术,设计并实现云环境下的恶意程序自动检测平台。该平台通过轮询机制获得服务器虚拟机资源的负载情况,将收集的可疑样本分类预处理,调用相应的服务器资源进行检测,可为用户终端节点提供多样化的虚拟环境,实现恶意程序文件、注册表、进程以及网络4类主机行为的自动分析,并自动生成分析报告。在真实样本上的实验结果表明,与金山火眼、Threat Expert平台相比,该平台能够更准确地反映恶意程序的特点及危害性。

关键词: VMware vSphere技术, 恶意代码, 自动分析, 行为特征, 虚拟机, 检测

Abstract: Aiming at the problem of wide range of malware and large analysis workload, in this paper, with the use of VMware vSphere virtualization technology, an automatic malware detection system upon the cloud platform is designed and implemented. This platform adopts polling mechanism to monitor the load of virtual machines in servers, conducts preprocessing of collected suspicious samples according to their type and tests the samples using correspond server resources. It can offer users a variety of virtual environment, automatic analysis malware’s four host behavior of files, registry, processes and network, provides online analysis report, and effectively responses to the problem of wide range of malicious programs, eliminates the analyzing workload, improves the efficiency of analysis. Experimental result on real samples shows that this platform can provide more precise character and threat information of analyzed samples compared with Jinshan Fireeye and Threat Expert platform.

Key words: VMware vSphere technology, malicious code, automatic analysis, behavioral characteristics, virtual machine, detection

中图分类号: