首页> 外国专利> SYSTEMS AND METHODS FOR PROTECTION malicious software based on fuzzy Vaytlisting

SYSTEMS AND METHODS FOR PROTECTION malicious software based on fuzzy Vaytlisting

机译:基于模糊Vaytlisting的恶意软件防护系统和方法

摘要

1. A method comprising: running in a client computer system an initial set of targets scan client computer system for malware; ive response to a predetermined initial scan for malware suspicion target for malicious: the generation of the client computer system sets the target hashes targets, each target hash represents a single code block target, with each separate unit of code contains a sequence of processor instructions Trust object, sending the set of hashes with the target client computer system to server computer system connected to a client computer system of the global computer network; ipoluchenie client computer system from the server computer system server indicator indicating whether the target object is malicious, and server indicator generated server computer system by means of: obtaining a plurality of reference hash reference object for at least one target hash of the set target hashes, the reference object is selected according to the target hash of a set of objects listed in the vaytlist, and if the set targets are not identical to the set of hashes of hashes of reference, certain indicators of similarity according to the number of hashes that are common for a plurality of target hash and hash reference for the set; and if the similarity measure exceeds a predetermined threshold value, marking the object as a target nevredonosnogo.2. The method of claim. 1, wherein the generation with
机译:1。一种方法,包括:在客户端计算机系统中运行初始目标集合,以扫描客户端计算机系统中的恶意软件;以及对恶意软件可疑目标的预定初始扫描的积极响应:客户端计算机系统的生成设置了目标哈希目标,每个目标哈希表示单个代码块目标,每个单独的代码单元均包含一系列处理器指令Trust对象,将具有目标客户端计算机系统的哈希集发送到连接到全球计算机网络的客户端计算机系统的服务器计算机系统; ipoluchenie客户端计算机系统从服务器计算机系统的服务器指示符指示目标对象是否是恶意的,并且服务器指示符通过以下方式生成服务器计算机系统:通过为设置的目标哈希中的至少一个目标哈希获取多个参考哈希参考对象,根据vaytlist中列出的一组对象的目标哈希选择参考对象,如果设置的目标与参考哈希的集合不同,则根据哈希的数量确定某些相似性指标多个目标哈希和该集合的哈希参考共同;如果相似性度量超过预定阈值,则将该对象标记为目标nevredonosnogo。权利要求的方法。 1,其中代用

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号