Signature Extraction and Detection Method of Computer Viruses Based on Immunity and Code Relocation

Yu ZHANG,Qing-zhong LIU,Li-ping SONG,Zi-qiang LUO,Jun-kuo CAO
DOI: https://doi.org/10.15918/j.tbit1001-0645.2017.10.009
2017-01-01
Abstract:A novel signature extraction and detection method of computer viruses based on immunity and code relocation was proposed to solve the current infection and threat of computer viruses.Referencing the biology immunity mechanism,some definitions such as self,nonself,antibody,viruses' detectors,and viruses' gene were established.Making use of the code relocation to extract viruses' gene in the computer viruses,a viruses' gene pool was constructed.And the dynamic evolution equations of self and nonself,viruses' gene pool,and viruses' detectors were established.The theoretical analysis and experimental results show that the proposed method can effectively overcome the problem of the self maturity and the integrity of viruses' detectors.Compared with tradition method,the proposed method shows better efficiency and adaptability.
What problem does this paper attempt to address?