首页> 外国专利> DETECTING MALICIOUS EXECUTABLE FILES BY PERFORMING STATIC ANALYSIS ON EXECUTABLE FILES' OVERLAY

DETECTING MALICIOUS EXECUTABLE FILES BY PERFORMING STATIC ANALYSIS ON EXECUTABLE FILES' OVERLAY

机译:通过对可执行文件的覆盖进行静态分析来检测恶意可执行文件

摘要

Embodiments of the present systems and methods may decide if a software file is malicious or benign, using properties of the file's overlay, if existing. For example, in an embodiment, a computer-implemented method for identifying malware in computer systems may comprise receiving a plurality of executable files labeled as being malicious or benign, training a machine learning model using properties extracted from overlays associated with each of the plurality of received labeled executable files, receiving an executable file that is not labeled, determining whether the received unlabeled executable file is malicious or benign using the trained machine learning model based on properties extracted from an overlay associated with the received unlabeled executable file, and transmitting information identifying the received unlabeled executable file as malicious when the received unlabeled executable file is determined to be malicious.
机译:本系统和方法的实施例可以使用文件覆盖的属性(如果存在)来确定软件文件是恶意的还是良性的。例如,在一个实施例中,一种用于在计算机系统中识别恶意软件的计算机实现的方法可以包括:接收多个被标记为恶意或良性的可执行文件,使用从与多个操作系统中的每一个相关联的覆盖物中提取的属性来训练机器学习模型。接收标记的可执行文件,接收未标记的可执行文件,基于从与接收到的未标记可执行文件相关联的覆盖层中提取的属性,使用训练有素的机器学习模型确定接收到的未标记可执行文件是恶意的还是良性的,并传输标识当确定接收到的未标记可执行文件是恶意的时,接收到的未标记可执行文件为恶意。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号