Font Size: a A A

Research Of Malicious Software Detection Technology Base On Clean Data

Posted on:2012-08-17Degree:MasterType:Thesis
Country:ChinaCandidate:P F LiFull Text:PDF
GTID:2218330338967649Subject:Computer application technology
Abstract/Summary:PDF Full Text Request
With the continuous development of internet technology, the number and variety of malicious software (trojans, viruses, etc.) are growing increasingly, intrusion technology continues to upgrade, the traditional method of anti-virus software of black-listing model cannot prevent malicious attacks effectively, so triggered the professionals to explore more effective anti-virus technology.The thesis aims at the increasing threat of malware, low efficiency of traditional anti-virus and the lack of the high rate of false positives, introduces malicious software detection technology base on clean data to double check and improve the efficiency of virus detection under the research in the traditional anti-virus.The thesis works in the following areas:(1) Study the collection of a clean file, clean file structure (PE structure, digital signature), clean file characteristics and extraction; (2) Create a clean data set, divide the clean data into two parts according to the level of abstraction of data:high-level data and low-level data, and study the database model of clean data management system;(3) Introduce reputation technology and research files' confidence and the model of reputation.(4) With the distributed network, designed and implemented clean data management system based on three-tier structure of cloud computing technology, study False Positives Logging System module, data upload and query module;research a fast mechanism for handling of false positives, clean data query and mutual cooperation between each module;(5) Study implementation and application of clean data management in malware detection, include the applications of False Positives Logging System, Reputation module and clean data upload and query module.By analyzing the product results related to the module show that malicious software detection technology base on clean data is feasible and effective in application. In addition, it has high efficiency and low rate of false positives when use clean data in traditional anti-virus compare with only use black-listing model in malicious software detection tools.
Keywords/Search Tags:clean file, clean data, malicious software, false positive, reputation evaluation
PDF Full Text Request
Related items