ISCAS OpenIR  > 基础软件国家工程研究中心
面向恶意软件分析及保护的文件系统
Liang Hong-Liang; Dong Shou-Ji; Liu Shu-Chang
2011
SourceBeijing Youdian Daxue Xuebao/Journal of Beijing University of Posts and Telecommunications
ISSN10075321
Volume34Issue:3Pages:58-61
English Abstract为应对危害日益严重的恶意软件,提出在文件系统层对恶意软件进行分析和防御,并尽可能减少其影响的方法,设计实现了面向恶意软件分析和保护的文件系统(MAPFS).该系统通过文件版本化技术和钩子技术,可记录1个进程在其生命过程中对文件系统的一系列修改.这些行为记录可作为分析恶意软件的重要依据,也可用于对被破坏的重要文件进行恢复保护.实验结果表明,该方法可有效用于恶意软件的分析及保护,MAPFS在性能方面的影响低于10%.
AbstractMalwares and their resulting threats are growing urgently. A method at the file system level is provided for analysis and defense against malwares with reducing the loss as possible, and implements a file system for malware analysis and protection (MAPFS). With check-point and file versioning technology, MAPFS can record the modifications in file systems during the process. These records are important for analysis of malware behavior, and may be used to recover the files damaged by the malwares. Experiments show that this method is effective in analysis and defense of malwares, and MAPFS only brings a little loss lower than 10 percent.
Keyword恶意软件 文件系统 版本化 钩子 恢复
Department(1) School of Computer Science, Beijing University of Posts and Telecommunications, Beijing 100876, China; (2) Institute of Software, Chinese Acad. of Sci., Beijing 100190, China; (3) Institute of National Security Science and Technology, Beijing 100044, China; (4) School of Computer and Information Technology, Beijing Jiaotong University, Beijing 100044, China
Language中文
Content Type期刊论文
URIhttp://ir.iscas.ac.cn/handle/311060/13835
Collection基础软件国家工程研究中心
Recommended Citation
GB/T 7714
Liang Hong-Liang,Dong Shou-Ji,Liu Shu-Chang. 面向恶意软件分析及保护的文件系统[J]. Beijing Youdian Daxue Xuebao/Journal of Beijing University of Posts and Telecommunications,2011,34(3):58-61.
APA Liang Hong-Liang,Dong Shou-Ji,&Liu Shu-Chang.(2011).面向恶意软件分析及保护的文件系统.Beijing Youdian Daxue Xuebao/Journal of Beijing University of Posts and Telecommunications,34(3),58-61.
MLA Liang Hong-Liang,et al."面向恶意软件分析及保护的文件系统".Beijing Youdian Daxue Xuebao/Journal of Beijing University of Posts and Telecommunications 34.3(2011):58-61.
Files in This Item:
File Name/Size DocType Version Access License
面向恶意软件分析及保护的文件系统.pdf(1106KB) 开放获取--Application Full Text
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[Liang Hong-Liang]'s Articles
[Dong Shou-Ji]'s Articles
[Liu Shu-Chang]'s Articles
Baidu academic
Similar articles in Baidu academic
[Liang Hong-Liang]'s Articles
[Dong Shou-Ji]'s Articles
[Liu Shu-Chang]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[Liang Hong-Liang]'s Articles
[Dong Shou-Ji]'s Articles
[Liu Shu-Chang]'s Articles
Terms of Use
No data!
Social Bookmark/Share
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.