通信学报
通信學報
통신학보
JOURNAL OF CHINA INSTITUTE OF COMMUNICATIONS
2014年
z1期
52-57
,共6页
赵毅%龚俭%杨望
趙毅%龔儉%楊望
조의%공검%양망
网络安全%恶意代码%自动分析
網絡安全%噁意代碼%自動分析
망락안전%악의대마%자동분석
network security%malware%automated analysis
恶意代码的网络行为分析是网络安全领域的一个重要研究视角。针对现有系统普遍存在的网络行为分析不全面、不深入的问题,归纳了恶意代码的功能模块,提出了较为全面的网络行为分析内容。通过对比已有系统的网络行为分析功能,选取合适的系统CUCKOO 作为基础平台。通过实例对其网络行为分析功能进行详细分析,并提出了优化、扩展方案。
噁意代碼的網絡行為分析是網絡安全領域的一箇重要研究視角。針對現有繫統普遍存在的網絡行為分析不全麵、不深入的問題,歸納瞭噁意代碼的功能模塊,提齣瞭較為全麵的網絡行為分析內容。通過對比已有繫統的網絡行為分析功能,選取閤適的繫統CUCKOO 作為基礎平檯。通過實例對其網絡行為分析功能進行詳細分析,併提齣瞭優化、擴展方案。
악의대마적망락행위분석시망락안전영역적일개중요연구시각。침대현유계통보편존재적망락행위분석불전면、불심입적문제,귀납료악의대마적공능모괴,제출료교위전면적망락행위분석내용。통과대비이유계통적망락행위분석공능,선취합괄적계통CUCKOO 작위기출평태。통과실례대기망락행위분석공능진행상세분석,병제출료우화、확전방안。
The analysis of malicious code’s network behavior is an important research field of network security. This function of existed systems is incomplete and not deep. The functions of malicious code are summarized and a compre-hensive content is presented. Moreover the network behavior analysis function of existed analysis systems is introduced and CUCKOO which is able to satisfy the requirements of involved study is found. Finally the advantage and points of this application platform were summarized, and an expansion of the system was proposed.