首页> 外国专利> PORTABLE EXECUTIVE FILE PROCESSING METHOD AND APPARATUS, AND PORTABLE EXECUTIVE FILE DETECTING METHOD AND APPARATUS

PORTABLE EXECUTIVE FILE PROCESSING METHOD AND APPARATUS, AND PORTABLE EXECUTIVE FILE DETECTING METHOD AND APPARATUS

机译:便携式执行文件处理方法和装置,以及便携式执行文件检测方法和装置

摘要

A PE file processing method and apparatus, and a PE file detecting method and apparatus, for improving the detection hit rate of malicious PE files. The PE file detecting method comprises: obtaining an unknown PE file (S201); disassembling codes of the unknown PE file to obtain a second instruction sequence, instructions in the second instruction sequence comprising operators and an operand (S202); sequentially extracting the operator of each instruction in the second instruction sequence to generate a second operator sequence (S203); extracting at least one N-gram feature from the second operator sequence (S204); querying the corresponding number of hits in an N-gram feature list with regard to each N-gram feature in the at least one N-gram feature in the second operator sequence (S205); generating a number of hits list of the unknown PE file, the number of hits list of the unknown PE file comprising each N-gram feature extracted from the unknown PE file and the corresponding queried number of hits (S206); obtaining the number of hits list of each target PE file in a plurality of target PE files (S207); clustering the unknown PE file and the plurality of target PE files according to the number of hits list of the unknown PE file and the number of hits list of each target PE file in the plurality of target PE files (S208); and in the clustering result, if the unknown PE file alone forms one category, determining the unknown PE file as a malicious PE file (S209).
机译:一种PE文件处理方法和装置,以及PE文件检测方法和装置,用于提高恶意PE文件的检测命中率。 PE文件检测方法包括:获取未知的PE文件(S201);拆卸所述未知PE文件的代码,以获得第二指令序列,所述第二指令序列中的指令包括运算符和操作数(S202);依次提取第二指令序列中每条指令的运算符,以生成第二运算符序列(S203);从第二算子序列中提取至少一个N元语法特征(S204);针对第二算子序列中的至少一个N-gram特征中的每个N-gram特征,查询N-gram特征列表中的命中次数(S205);生成所述未知PE文件的点击数列表,所述未知PE文件的点击数列表包括从所述未知PE文件中提取的每个N-gram特征以及对应的查询到的点击数(S206);获取多个目标PE文件中的每个目标PE文件的点击次数列表(S207);根据未知PE文件的命中列表数和多个目标PE文件中每个目标PE文件的命中列表数,对未知PE文件和多个目标PE文件进行聚类(S208);并且在聚类结果中,如果仅未知PE文件构成一类,则将该未知PE文件确定为恶意PE文件(S209)。

著录项

  • 公开/公告号WO2020119771A1

    专利类型

  • 公开/公告日2020-06-18

    原文格式PDF

  • 申请/专利权人 HUAWEI TECHNOLOGIES CO. LTD.;

    申请/专利号WO2019CN124963

  • 发明设计人 SHEN TAO;

    申请日2019-12-13

  • 分类号G06F21/56;

  • 国家 WO

  • 入库时间 2022-08-21 11:10:44

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号