首页> 外国专利> Classifying software modules based on comparisons using a neighborhood distance metric

Classifying software modules based on comparisons using a neighborhood distance metric

机译:使用邻域距离度量基于比较对软件模块进行分类

摘要

A method comprises obtaining at least a first software module not classified as benign or potentially malicious, extracting a set of features associated with the first software module, the set of features comprising static features, behavior features and context features, identifying a first cluster comprising one or more known software modules previously classified as benign, computing distance metrics between the extracted feature set of the first software module and feature sets of respective ones of the known software modules in the first cluster, classifying the first software module as one of benign and potentially malicious based on a comparison between the computed distance metrics and a neighborhood distance metric based on distances between feature sets of the known software modules in the first cluster, and modifying access by a given client device to the first software module responsive to classifying the first software module as potentially malicious.
机译:一种方法包括:至少获得未被分类为良性或潜在恶意的第一软件模块;提取与第一软件模块相关联的一组特征;该组特征包括静态特征,行为特征和上下文特征;识别包括一个特征的第一集群。一个或多个先前被分类为良性的已知软件模块,计算提取的第一软件模块的特征集与第一集群中各个已知软件模块的特征集之间的距离度量,将第一软件模块分类为良性和潜在基于所计算的距离度量与基于第一集群中已知软件模块的特征集之间的距离的邻域距离度量之间的比较而确定是否恶意,并且响应于对第一软件的分类,修改给定客户端设备对第一软件模块的访问模块为潜在恶意软件。

著录项

  • 公开/公告号US10122742B1

    专利类型

  • 公开/公告日2018-11-06

    原文格式PDF

  • 申请/专利权人 EMC CORPORATION;

    申请/专利号US201615191027

  • 发明设计人 ZHOU LI;AHMET BUYUKKAYHAN;ALINA M. OPREA;

    申请日2016-06-23

  • 分类号H04L29/06;H04L29/08;G06F17/30;

  • 国家 US

  • 入库时间 2022-08-21 13:04:00

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号