首页> 外国专利> System and method for .Net PE file malware detection

System and method for .Net PE file malware detection

机译:.Net PE文件恶意软件检测的系统和方法

摘要

A system and method for .Net PE files malware detection is provided. The method may include accessing two or more portable executable (PE) files and detecting at least one identical global user identifier (GUID) attribute. In response to finding identical GUID attributes, the method may include clustering a group of files into family clusters each having the same GUID attribute. The method may generate and release a signature for the family cluster. An exoneration criteria level may be set in accordance with matching characteristics associated with an acceptable software standard for the computing system or network, such that when the exoneration criteria level is reached, the PE file is exonerated from being associated with PUA or malware. Until this criterion is met, the PE file will be identified as PUA or malware. Additional GUID attributes may be identified as further proof that the PE file is polymorphic.
机译:提供了一种用于.Net PE文件恶意软件检测的系统和方法。该方法可以包括访问两个或更多个便携式可执行(PE)文件并检测至少一个相同的全局用户标识符(GUID)属性。响应于找到相同的GUID属性,该方法可以包括将一组文件聚类为每个具有相同的GUID属性的族簇。该方法可以生成和释放家庭集群的签名。可以根据与计算系统或网络的可接受软件标准相关联的匹配特征来设置免除标准级别,使得当达到免除标准级别时,PE文件被免除与PUA或恶意软件的关联。在满足此标准之前,PE文件将被标识为PUA或恶意软件。可以将其他GUID属性标识为PE文件是多态的进一步证明。

著录项

  • 公开/公告号US10181035B1

    专利类型

  • 公开/公告日2019-01-15

    原文格式PDF

  • 申请/专利权人 SYMANTEC CORPORATION;

    申请/专利号US201615184294

  • 发明设计人 KISHOR KUMAR;NITIN SHEKOKAR;

    申请日2016-06-16

  • 分类号G06F21/56;H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 12:12:32

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号