首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
外语
Letting computer viruses loose on a quarantined computer and recording their pattern of activity could lead to a better way of s
Letting computer viruses loose on a quarantined computer and recording their pattern of activity could lead to a better way of s
admin
2009-06-24
32
问题
Letting computer viruses loose on a quarantined computer and recording their pattern of activity could lead to a better way of spotting them in the "wild".
A prototype system developed at the University of Michigan uses the "fingerprint" of virus activity to identify them more effectively than existing anti-virus software.
The designers of programs that damage, take over or steal data from computers—called malware—are locked in an arms race with companies that make anti-virus (AV) software to prevent and fix malware damage.
Conventional AV software looks for suspicious behavior and then tries to determine what’s causing it. It does this by looking for virus "signatures"—chunks of computer code from known viruses.
But identifying previously unknown malware is difficult, and keeping track of different variants of existing viruses makes it harder. For example, a virus called Agobot has split into more than 580 variants since its release in 2002.
In tests, Michael Bailey and colleagues at the University of Michigan, U.S., showed that five leading AV programs could identify only between 50 and 80 percent of a large sample of malware. And the programs struggled to agree on what they had found—the identifications often did not match.
Bailey and his team say their approach is superior and have used it to develop a prototype AV system that is significantly better at identifying viruses once they are detected.
The team set loose the malicious software on a quarantined computer, recording all the files and strings of instructions (processes) created and modified by the malware.
They then created software that uses a database of these "fingerprints" to identify malware. It can also define clusters of malware that operate in similar ways, and generate a kind of family tree showing how superficially different programs have similar modi operandi.
In tests on the same malware, the new software could identify at least 10 percent more of the sample than any of the other AV software. It also always correctly linked different pieces of malware that behave in the same way—the best AV program spotted only 68 percent of such doubles.
"What they’re doing here is quite viable", says Richard Overill, a researcher at Kings College London, UK. "In principle this should work very well at identifying different viruses, and grouping those that may appear different but work in the same way".
The new approach could reduce the number of updates needed for conventional AV systems, suggests Overill. "Instead of having separate patches for each virus, this could be more efficient and reduce the size of updates that must be downloaded".
Grant Malcom researches computer security at Liverpool University, U.K. He says that recording activities like files created and modified is a novel approach to the problem and that it would be interesting to see whether this approach to categorizing malware could work without giving false positives.
选项
A、There is competition between virus designers and AV companies.
B、The definition of "malware".
C、Malware designers are locked up by AV companies.
D、A metaphoric explanation of how the new AV software is developed.
答案
D
解析
转载请注明原文地址:https://kaotiyun.com/show/hbTd777K
本试题收录于:
公共英语五级笔试题库公共英语(PETS)分类
0
公共英语五级笔试
公共英语(PETS)
相关试题推荐
GenerationGapAfewyearsago,itwasfashionabletospeakofagenerationgap,adivisionbetweenyoungpeopleandtheir
Weshouldbecautiousincrossingacrowdedstreet.
WhentoTakeMedicineIsImportantOurbodiesarewonderfullyskillfulatmaintainingbalance.Whenthetemperaturejumps,
EatingMeat—LessorMore?EverysecondintheUnitedStatesalone,morethan250animalsareslaughteredforfood,adding
WorkandHappinessWhetherworkshouldbeplacedamongthecausesofhappinessoramongthecausesofunhappinessmayperha
A)late18thcenturyB)equaleducationandemploymentwithmenC)weakerandlowerinsocialpositionD)early20th
Scotlandistherightplacetoreceiveafirst-classeducation.AccordingtoArthurHerman,theScotsdevelopedmanyimportant
Accordingtothepassage,inbuyingasecond-handvehicleitismostimportanttoknowfair______."Anindependenttechnician"
"Othercountrieshaveaclimate;inEnglandwehaveweather".ThisstatementsuggeststhatTheword"lands"inthelastsentenc
Anoldfriendcalledonmethedaybeforeyesterday.
随机试题
患者,男,35岁。左上腹外伤后出现面色苍白,四肢冰冷,血压下降,全腹轻度压痛、反跳痛,伴肌紧张,腹部叩诊有移动性浊音。该患者最可能发生了
应用后能在体内骨及关节中分布较多的抗菌药物是
下列哪项不可以判断皮肤的活力
M公司向J银行贷款30万元,由N公司出面作为担保人,但是合同里面并未明确约定保证责任的类别。期满之后M公司无力还债,J银行明知M公司濒临破产无力还钱,所以直接向法院起诉N公司,希望N公司偿还全部借款。关于此案,法院的下列做法正确的是()
建设工程采用施工总承包模式的特点是()。
手动火灾报警按钮的连接导线,应留有不小于()mm的余量,且在其端部应有明显标志。
某生产企业系增值税一般纳税人。为调整产业结构和产品升级换代,2010年4月,该企业对一批资产进行了处置。处置资产情况如下表:分别计算上述资产处置应缴纳的增值税或营业税。
某股份公司2007年有关资料如下表3.2:要求根据以上资料:(1)计算流动资产的平均余额(假定流动资产由速动资产与存货组成);(2)计算本年营业收入和总资产周转率;(3)计算营业净利率、净资产收益率;(4)计算每股利润和平均
设有以下定义和程序:#includeclassA1{public:voidshowl(){cout
Concernwithmoney,andthenmoremoney,inordertobuytheconveniencesandluxuriesofmodernlife,hasbroughtgreatchanges
最新回复
(
0
)