基于云服务的恶意内容检测方法研究
2023-08-21魏先燕卢加奇冯燕茹吕广旭王小英
魏先燕 卢加奇 冯燕茹 吕广旭 王小英



摘 要:云服务的文件存储存在“后门”攻击,以混淆用户视听,窃取用户隐私。现有的检测方法单一且需要更多的运行内存,因此文章提出通过使用AC自动机算法和朴素贝叶斯算法,快速精准地识别文本内容,利用scikit-learn机器学习库对图片内容进行甄别,且调用VirusTotal的API检测恶意文件,实验结果表明该检测方法在识别恶意内容的准确率上达到96.2%、可对海量数据进行实时检测,优于其他检测方法。
关键词:恶意文件;图片内容检测;AC自动机算法;朴素贝叶斯算法
中图分类号:TP309 文献标识码:A 文章编号:2096-4706(2023)12-0155-04
Research on Malicious Content Detection Methods Based on Cloud Services
WEI Xianyan, LU Jiaqi, FENG Yanru, LYU Guangxu, WANG Xiaoying
(Institute of Disaster Prevention, Langfang 065201, China)
Abstract: There are “backdoor” attacks on the file storage of cloud services to confuse visual and auditory sense of users and steal their privacy. The existing detection methods are single and require more running memory. Therefore, this paper proposes to use AC automaton algorithm and Naive Bayesian algorithm to identify text content quickly and accurately. It uses scikit-learn machine learning library to screen image content, and calls API of VirusTotal to detect malicious files. The experimental results show that the detection method achieves 96.2% accuracy in identifying malicious content and can detect massive data in real time, which is better than other detection methods.
Keywords: malicious file; image content detection; AC automaton algorithm; Naive Bayesian algorithm
0 引 言
云服務平台[1]是运营商为提升通信服务质量所搭建的系统平台,可以分配网络资源供用户使用。用户则根据自己的需求随时随地在云服务平台上进行数据存取。而云存储存在“后门”攻击[2],攻击的方式主要以“网络钓鱼”“网页挂马”、漏洞为主,主要通过发送用户感兴趣的文件,引导用户下载,当用户打开并运行包含攻击代码的文件后,黑客就可以在用户不知情的情况下将攻击程序安装到用户系统,然后攻击者可以进行查看用户文件,更改电脑权限等操作。
黑客们将攻击代码植入上传的文本文件、图片、程序等中,以此混淆用户的视听,造成的损失小到搜索注册表信息并更改,或使系统发生故障,大到窃取用户的隐私,给用户带来严重的经济损失。
1 研究概述
基于前者的研究经验,恶意软件检测技术[3]得到快速发展,检测的准确率越来越高效,但仍有提升空间,防御恶意攻击的能力仍有不足。……
