首页>
外国专利>
EMULATOR-BASED MALWARE LEARNING AND DETECTION
EMULATOR-BASED MALWARE LEARNING AND DETECTION
展开▼
机译:基于仿真器的恶意软件学习与检测
展开▼
页面导航
摘要
著录项
相似文献
摘要
Methods and systems are described for malware learning and detection. According to one embodiment, an antivirus (AV) engine includes a training mode for internal lab use, for example, and a detection mode for use in commercial deployments. In training mode, an original set of suspicious patterns is generated by scanning malware samples. A set of clean patterns is generated by scanning clean samples. A revised set of suspicious patterns is created by removing the clean patterns from the original set. A further revised set of suspicious patterns is created by: (i) applying a statistical filter to the first revised set; and (ii) removing any suspicious patterns therefrom that do not meet a predefined frequency of occurrence. A detection model, based on the further revised set, can then be used in detection mode to flag executables as malware when the presence of one or more of the suspicious patterns is identified.
展开▼