项目名称: 计算机病毒应急响应关键技术研究
项目编号: No.61471169
项目类型: 面上项目
立项/批准年度: 2015
项目学科: 无线电电子学、电信技术
项目作者: 张波云
作者单位: 湖南警察学院
项目金额: 83万元
中文摘要: 当前计算机病毒泛滥成灾,突显反病毒技术滞后,本课题致力研究计算机病毒应急响应处置过程所涉及的关键技术问题。将程序恶意性判定问题抽象为对多个证据的合成问题,建立一种基于证据推理的程序恶意性判定模型。采用最优控制理论和网络分割方法构建计算机病毒传播抑制模型,降低病毒在疫情传播的过程中感染速率和传播速度。应用马尔可夫模型和随机博弈模型对病毒攻击情境下的网络进行实时评估,量化病毒危害,评估资产损失。建立计算机病毒传播溯源理论模型,寻找病毒的传播路径并进而求得病毒的源点,为病毒取证提供理论支持。设计高效的病毒免疫算法,采用适当的平衡机制来降低时间复杂度,为免疫方法在实际病毒防范系统中的应用提供理论指导。将计算机病毒应急响应全过程整合设计出原型系统,实现对计算机病毒的主动防御。
中文关键词: 信息安全;病毒防治;病毒传播;安全度量
英文摘要: Due to the lag of anti virus technology, virus spread widely in the network. The project is devoted to studying the key techniques of computer virus emergency response. Regarding the malicious behaviors of program abstract as synthesis of multiple evidences, a program maliciousness decision model based on evidence reasoning is present. By using the optimal control theory and segmentation method of network, we construct the computer virus propagation inhibition model. It reduces the virus infection rate and propagation velocity in the process of the spread of the epidemic. A computer virus spread tracing theory model is present. It obtains the propagation path of the virus and the virus source. This model provides the theory support for the virus forensics. A virus efficient immune algorithm is designed. In the method the balance mechanism appropriate to reduce the time complexity is discussed. It provides theoretical guidance to the immune method in practical application of virus prevention system. For realizing of active defense of computer virus, the computer virus emergency response integration prototype system is designed.
英文关键词: information security;computer virus defence;virus propagation;security assessment