首页> 外国专利> METHOD AND SYSTEM FOR DETECTING THE INFRASTRUCTURE OF A MALICIOUS SOFTWARE OR A CYBERCRIMINAL

METHOD AND SYSTEM FOR DETECTING THE INFRASTRUCTURE OF A MALICIOUS SOFTWARE OR A CYBERCRIMINAL

机译:检测恶意软件或网络犯罪工具基础结构的方法和系统

摘要

FIELD: computer equipment.;SUBSTANCE: disclosed is a computer-implemented method of identifying infrastructure of a malicious program or a cybercriminal, wherein: obtaining a request containing an infrastructure element and a tag on whether the item belongs to a malicious program or a cybercriminal; retrieving from the database a parameter of the received infrastructure element, an additional infrastructure element used by the same malware as the obtained infrastructure element, and an additional infrastructure element parameter; analyzing the obtained infrastructure element and the associated parameter and the additional infrastructure element and the parameter associated therewith; based on the analysis, statistical relationships between the parameter of the obtained infrastructure element and the parameter of the additional infrastructure element are determined; generating rules for searching for new infrastructure elements based on the detected statistical link and extracting new infrastructure elements from the database; assigning to new elements tags corresponding to certain malware or cybercriminals, and storing results in a database.;EFFECT: technical result is higher efficiency of detecting computer attacks.;10 cl, 2 dwg
机译:技术领域:公开了一种计算机实现的识别恶意程序或网络犯罪分子的基础结构的方法,其中:获得包含基础结构元素和关于该项目是否属于恶意程序或网络犯罪分子的标签的请求;从数据库中检索接收到的基础设施元素的参数,与获取的基础设施元素相同的恶意软件使用的附加基础设施元素以及附加基础设施元素参数;分析获得的基础设施要素和关联的参数以及附加基础设施要素和与其关联的参数;基于分析,确定获取的基础设施要素的参数与附加基础设施要素的参数之间的统计关系;生成规则,用于基于检测到的统计链接搜索新的基础架构元素,并从数据库中提取新的基础架构元素;为新元素分配与某些恶意软件或网络罪犯相对应的标签,并将结果存储在数据库中;效果:技术结果是检测计算机攻击的效率更高; 10 cl,2 dwg

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号