通信学报

• • 上一篇    下一篇

恶意代码自动分析系统的研究

赵 毅,龚 俭,杨 望   

  1. 东南大学 计算机科学与工程学院,江苏 南京 211189
  • 出版日期:2014-10-25 发布日期:2014-12-16

Study on modern malware analysis system

  • Online:2014-10-25 Published:2014-12-16

摘要: 恶意代码的网络行为分析是网络安全领域的一个重要研究视角。针对现有系统普遍存在的网络行为分析不全面、不深入的问题,归纳了恶意代码的功能模块,提出了较为全面的网络行为分析内容。通过对比已有系统的网络行为分析功能,选取合适的系统CUCKOO作为基础平台。通过实例对其网络行为分析功能进行详细分析,并提出了优化、扩展方案。

Abstract: The analysis of malicious code’s network behavior is an important research field of network security. This function of existed systems is incomplete and not deep. The functions of malicious code are summarized and a comprehensive content is presented. Moreover the network behavior analysis function of existed analysis systems is introduced and CUCKOO which is able to satisfy the requirements of involved study is found. Finally the advantage and points of this application platform were summarized, and an expansion of the system was proposed.

No Suggested Reading articles found!