ARM Linux嵌入式设备正遭受着日益严重的Bootkit威胁。针对传统检测技术对Bootkit检测的局限性,提出了一种基于JTAG的固件底层检测方法。该方法以基本块级跟踪和循环识别构成的系统跟踪优化算法为基础,利用跟踪系统的启动过程中记录到...ARM Linux嵌入式设备正遭受着日益严重的Bootkit威胁。针对传统检测技术对Bootkit检测的局限性,提出了一种基于JTAG的固件底层检测方法。该方法以基本块级跟踪和循环识别构成的系统跟踪优化算法为基础,利用跟踪系统的启动过程中记录到的信息,对Bootloader引导阶段和内核启动阶段进行监控,从而实现对ARM Linux嵌入式设备Bootkit的分阶段检测。实验结果表明,以跟踪优化算法为基础的Bootkit分段检测技术不仅极大地提高了跟踪效率,而有有效检测出了Bootkit的存在,达到了预期效果。展开更多
Quick and reliable identification of the traffic state is of critical importance to traffic control systems, especially when spillovers appear. Firstly, a calculation method for the occupancy per cycle under different...Quick and reliable identification of the traffic state is of critical importance to traffic control systems, especially when spillovers appear. Firstly, a calculation method for the occupancy per cycle under different traffic conditions were presented, based on the relationship between the three basic traffic flow parameters, speed, traffic flow and density. Secondly, the times at which the stopping and starting waves approach a loop detector were confirmed using the traffic wave models modified by a kinematic equation. Then, the threshold of occupancy, which characterizes the appearance of spillovers, was determined by the premise that the stopping and starting waves had the same speed. At last, the accuracy and usability of the new method were verified by VISSIM simulation, using the ratio of misjudgment as the evaluation index. The results show that the ratio of misjudgment of the new method is about 11.36% compared to 17.65% of the previous method.展开更多
基金Project(2011AA110304) supported by the National High Technology Research and Development Program of China
文摘Quick and reliable identification of the traffic state is of critical importance to traffic control systems, especially when spillovers appear. Firstly, a calculation method for the occupancy per cycle under different traffic conditions were presented, based on the relationship between the three basic traffic flow parameters, speed, traffic flow and density. Secondly, the times at which the stopping and starting waves approach a loop detector were confirmed using the traffic wave models modified by a kinematic equation. Then, the threshold of occupancy, which characterizes the appearance of spillovers, was determined by the premise that the stopping and starting waves had the same speed. At last, the accuracy and usability of the new method were verified by VISSIM simulation, using the ratio of misjudgment as the evaluation index. The results show that the ratio of misjudgment of the new method is about 11.36% compared to 17.65% of the previous method.