作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (05): 117-119. doi: 10.3969/j.issn.1000-3428.2007.05.041

• 安全技术 • 上一篇    下一篇

基于进程鉴别和隐藏的病毒主动式防御技术

邓璐娟,刘 涛,甘 勇,熊 坤   

  1. (郑州轻工业学院计算机与通信工程学院,郑州 450002)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-03-05 发布日期:2007-03-05

Active Defence Technology with Virus Based on Differentiation and Hiding Process

DENG Lujuan, LIU Tao, GAN Yong, XIONG Kun   

  1. (Dept. of Computer and Communication Engineering, Zhengzhou Institute of Light Industry, Zhengzhou 450002)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-03-05 Published:2007-03-05

摘要: 根据行为自动监控、行为自动分析和行为自动诊断的新思路,利用进程鉴别和隐藏技术对信息安全进行研究。通过VC++6.0工具平台实现了病毒主动防御的目标,实际运行的系统证明该技术可以从根本上克服传统防病毒软件中信息保护滞后于新病毒出现的重大 缺陷。

关键词: 病毒, MD5, 进程隐藏, 伪隐藏, 钩子

Abstract: The paper makes use of the differentiation and hiding technology of the process to research the information security, according to some new thoughts, such as the automation monitor and control of behavior, automation analysis of behavior, automation deduction of behavior. It achieves active defense toward the viruses by using the tool of VC++6.0, the actual system proves that the technology can conquer radically the fatal objection that the new viruses come forth ahead of the information protection in the traditional preventing virus software.

Key words: Virus, MD5, Process hiding, Fake hiding, Hook