论文部分内容阅读
据国外媒体报道,从今年2月开始,赛门铁克的诺顿网络安全产品的用户将拥有一个新的工具来帮助他们避免未打补丁的软件漏洞。被称作“赛门铁克高级响应在线网络(SONAR)”的安全软件将分析运行在用户计算机中的程序代码行为,以判断该程序是否是恶意的。与赛门铁克传统的以病毒码特征库的防病毒保护技术不同的是,该软件是将程序代码与一个存储了已知恶意软件行为的数据库进行匹配比较。零日(Zero-day)攻击通常基于未知的安全漏洞,或还没有被厂商修复的安全漏洞,通常此类攻击可以绕过基于病毒库特征的防病毒保护。而 SONAR 采用了一种算法,可以用来评测计算机中运行的软件的数百种相关属性,因此,不管一个攻击是否已经被人们所发现,只要它具有攻击的特征,就会被识别出来。
According to foreign media reports, from February this year, Symantec’s Norton Internet Security product users will have a new tool to help them avoid unpatched software vulnerabilities. Security software, known as “Symantec Advanced Response Online Network (SONAR)”, analyzes the behavior of program code running on the user’s computer to determine whether the program is malicious. Unlike Symantec’s traditional anti-virus protection technology that uses the signature database, the software compares the code to a database that stores known malware. Zero-day attacks are usually based on unknown security vulnerabilities or security vulnerabilities that have not been fixed by the vendor, and such attacks typically bypass antivirus protection based on the characteristics of the virus signature database. SONAR uses an algorithm that can be used to evaluate hundreds of related properties of software running on a computer so that whenever an attack has been discovered, it will be identified as long as it has the characteristics of an attack.