首页> 外国专利> SYSTEM AND METHOD OF DETECTION OF MALICIOUS FILES USING A TRAINED MALWARE DETECTION PATTERN

SYSTEM AND METHOD OF DETECTION OF MALICIOUS FILES USING A TRAINED MALWARE DETECTION PATTERN

机译:使用经过训练的恶意软件检测模式检测恶意文件的系统和方法

摘要

FIELD: information technology.;SUBSTANCE: invention is intended for anti-virus scanning of files. Malicious file detection system contains a behavior log analysis tool designed to generate a behavior template based on commands and parameters selected from the log; calculation of convolution from all generated behavior patterns; detection pattern selection tool for retrieving from at least two detection patterns of malicious files based on commands and parameters selected from the behavior log; means for calculating the severity of harmfulness, designed to calculate the severity of an executable file based on the analysis of the resulting convolution using each obtained detection pattern; analysis tool designed to form a solution based on the received severity of the pattern; recognition of the executable file as malicious, when the degree of similarity between the generated decision pattern and at least one of the predetermined solution patterns from the decision pattern database exceeds a predetermined threshold value.;EFFECT: technical result consists in the detection of malicious files using a trained malware detection pattern.;20 cl, 7 dwg
机译:领域:信息技术;实体:本发明旨在对文件进行防病毒扫描。恶意文件检测系统包含一个行为日志分析工具,该工具旨在根据从日志中选择的命令和参数来生成行为模板;根据所有生成的行为模式计算卷积;检测模式选择工具,用于根据从行为日志中选择的命令和参数,从至少两个恶意文件的检测模式中进行检索;用于计算有害性严重性的装置,用于根据使用每个获得的检测模式对卷积进行的分析来计算可执行文件的严重性;分析工具,旨在根据收到的模式严重性来形成解决方案;当所生成的决策模式与决策模式数据库中至少一个预定解决方案模式之间的相似度超过预定阈值时,将可执行文件识别为恶意;效果:技术成果在于检测恶意文件使用受过训练的恶意软件检测模式; 20 cl,7 dwg

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号