首页> 外国专利> SYSTEMS AND METHODS FOR AUTOMATED GENERATION OF GENERIC SIGNATURES USED TO DETECT POLYMORPHIC MALWARE

SYSTEMS AND METHODS FOR AUTOMATED GENERATION OF GENERIC SIGNATURES USED TO DETECT POLYMORPHIC MALWARE

机译:自动生成用于检测多态恶意软件的通用签名的系统和方法

摘要

The disclosed computer-implemented method for automated generation of generic signatures used to detect polymorphic malware may include (1) clustering a set of polymorphic file samples that share a set of static attributes in common with one another, (2) computing a distance of the polymorphic file samples from a centroid that represents a reference data point with respect to the set of polymorphic file samples, (3) determining that the distance of the polymorphic file samples from the centroid is below a certain threshold, and then upon determining that the distance is below the certain threshold, (4) identifying, within the set of static attributes shared in common by the polymorphic file samples, a subset of static attributes whose values are identical across all of the polymorphic file samples and (5) generating a generic file-classification signature from the subset of static attributes. Various other methods, systems, and computer-readable media are also disclosed.
机译:所公开的用于自动生成用于检测多态恶意软件的通用签名的计算机实现的方法可以包括:(1)聚类一组多态文件样本,这些样本彼此共享一组静态属性,(2)计算来自质心的多态文件样本,该质心表示相对于多态文件样本集合的参考数据点,(3)确定多态文件样本距质心的距离低于某个阈值,然后确定该距离低于某个阈值,(4)在由多态文件样本共同共享的一组静态属性中,标识其所有多态文件样本的值都相同的静态属性子集,以及(5)生成通用文件静态属性的子集进行分类签名。还公开了各种其他方法,系统和计算机可读介质。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号