| 注册
首页|期刊导航|计算机与现代化|基于序列比对的勒索病毒同源性分析

基于序列比对的勒索病毒同源性分析

龚琪 曹金璇 芦天亮

计算机与现代化Issue(2):1-5,5.
计算机与现代化Issue(2):1-5,5.DOI:10.3969/j.issn.1006-2475.2018.02.001

基于序列比对的勒索病毒同源性分析

Homology Analysis of Ransomware Based on Sequence Alignment

龚琪 1曹金璇 1芦天亮1

作者信息

  • 1. 中国人民公安大学信息技术和网络安全学院,北京100076
  • 折叠

摘要

Abstract

The number of ransomware is increasing rapidly while few belong to new family,most of them are mutations.A new homologous analysis approach based on API sequence of ransomware is proposed.The paper uses sandbox to extract ransomware's dynamic behavior for analyzing API category,and then encodes the feature as well as removes the repetition.Also,the sequence alignment algorithm is used to calculate the similarity between different ransomware.The dataset for the experiment contains 6 different families of ransomware and their variants.The result shows that proposed method performs well in analyzing the homology of ransomware which can be used to distinguish unknown software.

关键词

勒索软件/动态检测/沙箱/API序列/序列比对

Key words

ransomware/dynamic detection/sandbox/API sequence/sequence alignment

分类

信息技术与安全科学

引用本文复制引用

龚琪,曹金璇,芦天亮..基于序列比对的勒索病毒同源性分析[J].计算机与现代化,2018,(2):1-5,5.

基金项目

国家重点研发计划“网络空间安全”重点专项(2017YFB0802804) (2017YFB0802804)

国家自然科学基金资助项目(61602489) (61602489)

赛尔网络下一代互联网技术创新项目(NGII20160405) (NGII20160405)

计算机与现代化

OACSTPCD

1006-2475

访问量0
|
下载量0
段落导航相关论文