|
Based on analysis of the behavior of the virus signature extraction and detection is an important work of Symantec Corporation content. Through various types of computer virus analysis technology research, including PE file structure , reverse analysis techniques, black-box analysis methods, white box analysis methods, and the shell of the virus be analyzed to extract the virus signatures, virus killing realization the purpose of allowing users overall safety performance can be guaranteed. This paper, based on viral malicious behavior of computer viruses for the overall classification , citing various characteristics of the virus and the degree of harm . Describes several virus signature extraction methods for different virus types , select the appropriate signature extraction methods to extract its signature in order to improve risk killing rate and reduce false positives . Virus and virus signatures for the extraction , analysis and design to achieve a viral virus signature detection automated implementation system . System to complete two major functions: first , the virus samples analyzed automatically analyze and generate reports ; Second , the detection rate of killing virus signatures . System implementation relies on the Python scripting language , MySQL database , and virtual machines. This paper analyzes the main elements , including viruses , virus signature extraction and analysis and virus signature detection system automatically . In which the system automatically work including system functional requirements, build environment and the final realization of system functions . Finally, a summary of the entire thesis work and evaluation , the paper pointed out the deficiencies and future research work .
|