首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
外语
Letting computer viruses loose on a quarantined computer and recording their pattern of activity could lead to a better way of s
Letting computer viruses loose on a quarantined computer and recording their pattern of activity could lead to a better way of s
admin
2009-06-24
42
问题
Letting computer viruses loose on a quarantined computer and recording their pattern of activity could lead to a better way of spotting them in the "wild".
A prototype system developed at the University of Michigan uses the "fingerprint" of virus activity to identify them more effectively than existing anti-virus software.
The designers of programs that damage, take over or steal data from computers—called malware—are locked in an arms race with companies that make anti-virus (AV) software to prevent and fix malware damage.
Conventional AV software looks for suspicious behavior and then tries to determine what’s causing it. It does this by looking for virus "signatures"—chunks of computer code from known viruses.
But identifying previously unknown malware is difficult, and keeping track of different variants of existing viruses makes it harder. For example, a virus called Agobot has split into more than 580 variants since its release in 2002.
In tests, Michael Bailey and colleagues at the University of Michigan, U.S., showed that five leading AV programs could identify only between 50 and 80 percent of a large sample of malware. And the programs struggled to agree on what they had found—the identifications often did not match.
Bailey and his team say their approach is superior and have used it to develop a prototype AV system that is significantly better at identifying viruses once they are detected.
The team set loose the malicious software on a quarantined computer, recording all the files and strings of instructions (processes) created and modified by the malware.
They then created software that uses a database of these "fingerprints" to identify malware. It can also define clusters of malware that operate in similar ways, and generate a kind of family tree showing how superficially different programs have similar modi operandi.
In tests on the same malware, the new software could identify at least 10 percent more of the sample than any of the other AV software. It also always correctly linked different pieces of malware that behave in the same way—the best AV program spotted only 68 percent of such doubles.
"What they’re doing here is quite viable", says Richard Overill, a researcher at Kings College London, UK. "In principle this should work very well at identifying different viruses, and grouping those that may appear different but work in the same way".
The new approach could reduce the number of updates needed for conventional AV systems, suggests Overill. "Instead of having separate patches for each virus, this could be more efficient and reduce the size of updates that must be downloaded".
Grant Malcom researches computer security at Liverpool University, U.K. He says that recording activities like files created and modified is a novel approach to the problem and that it would be interesting to see whether this approach to categorizing malware could work without giving false positives.
选项
A、There is competition between virus designers and AV companies.
B、The definition of "malware".
C、Malware designers are locked up by AV companies.
D、A metaphoric explanation of how the new AV software is developed.
答案
D
解析
转载请注明原文地址:https://kaotiyun.com/show/hbTd777K
本试题收录于:
公共英语五级笔试题库公共英语(PETS)分类
0
公共英语五级笔试
公共英语(PETS)
相关试题推荐
Sandrecameacrossanimportantletteryesterdaywhilecleaningthedesk.
EatingMeat—LessorMore?EverysecondintheUnitedStatesalone,morethan250animalsareslaughteredforfood,adding
TheG8countriesincludeChina,India,Mexico,SouthAfricaandBrazil.Accordingtomedia,BushwillsigntheKyotoProtocola
Whereisthenapkinnormallyplacedduringthemeal?Allofthefollowingarefingerfoodsexcept
Accordingtothepassage,inbuyingasecond-handvehicleitismostimportanttoknowfair______.Accordingtothepassage,fr
Hespokesoquicklythatitwasdifficulttotakedownwhathewassaying.
RuthBenedict’shighlypopularbookPatternsofCulturestressedtheroleofcultureinpersonalityformation.
Anoldfriendcalledonmethedaybeforeyesterday.
A.toloseyourhouseB.tomanageyouremployeesC.tokeepindependentD.tolendyoumoneyE.totaketheresponsibilityforitF.
Howdidthestudyevaluateeveryparticipant’ssenseofresponsibility?Previousstudiessuggest______.
随机试题
甲汽车租赁公司拟购置一批新车用于出租。现有两种投资方案,相关信息如下:方案一:购买中档轿车100辆,每辆车价格10万元,另需支付车辆价格10%的购置相关税费。每年平均出租300天,日均租金150元/辆。车辆可使用年限8年,8年后变现价值为0。前5年每年维
64岁,男性患者。反复咳嗽、咳痰,痰中带血2周。体温38.3℃。WBC12×109/L,胸片示右肺门肿块影,伴远端大片状阴影,抗炎治疗阴影不吸收。首先考虑的治疗方案是
有关前列腺的超声扫查途径,不正确的是
下列不计入宗地面积的范围有()。
某储户2002年5月14存入银行定期存款1000元,存期1年,假设存入时该档次存款年利率为3%,该储户于2003年6月14才支取这笔存款,若支取日挂牌公告的活期储蓄存款年利率为1.89%(不考虑利息税)。根据以上资料,回答下列问题:该储户一年到期的
在《中国IT月刊》上刊登广告,比较适用的情况有()。
被西方称为“物理学之父”,并提出了“只要给我一个支点,我就能撬动整个地球”的名言的物理学家是()。
脱分化
我虽然不认识你,但第一眼就知道你是个军医,很简单,因为你具有医生的风度,但却是一副军人气概。上述推理要补充以下哪项前提?
今天,剪纸(paper—cutting)和古代一样是一项技术性很高的艺术形式,它需要创造力、技巧和经验。无论是简单的还是复杂的形式,每一个设计必须形成一个连续的、完整的(integral)剪纸。仔细研究你会发现中国人形成的那种巧妙的剪法既连接了内部的各个部
最新回复
(
0
)