首页> 外国专利> SIMILAR MALICIOUS CODE RETRIEVAL APPARATUS AND METHOD BASED ON MALICIOUS CODE FEATURE INFORMATION

SIMILAR MALICIOUS CODE RETRIEVAL APPARATUS AND METHOD BASED ON MALICIOUS CODE FEATURE INFORMATION

机译:基于恶意代码特征信息的类似恶意代码检索装置和方法

摘要

The present invention provides a kind of similar malicious code retrieval devices and one kind to be based on malicious code characteristic information, these search for the similitude in malicious sample with highest similitude, malicious sample is based on existing, and by similar data, and the malicious sample of producer's group information is provided to analysis personnel, thus allow analyst to be used for detailed analysis. Provided device may include: a kind of which register new input queue malicious code of malicious code register cell completely such as new malicious code sample, especially and registers details and extracts new malicious code sample; A kind of malicious code sample that malicious code analysis unit analysis details are new; A kind of unit of malicious code, this DNA extracting solutions extract malicious code DNA information, the characteristic information including malicious code, based on the information of malicious code analysis malicious code resolution unit; A kind of which progress similarity-rough set of malicious code DNA comparing units, passes through between DNA types, the information and the previous malicious code sample of malicious code DNA information that malicious code DNA is extracted; And similar malicious code retrieval unit calculates the malicious code DNA comparing units of total similarity and pre-stored malicious code sample similarity calculation between new malicious code sample in this way, and extracts the certain amount of malicious code sample as similar malicious code search result. ;The 2016 of copyright KIPO submissions
机译:本发明提供了一种相似的恶意代码检索设备和一种基于恶意代码特征信息的设备,这些设备在具有最高相似度的恶意样本中搜索相似度,恶意样本基于现有的并通过相似数据,并且将生产者的团体信息的恶意样本提供给分析人员,从而使分析人员可以进行详细的分析。所提供的装置可以包括:一种将新的输入队列完全注册到新的恶意代码样本之类的恶意代码注册单元的新输入队列中的恶意代码,并详细注册并提取新的恶意代码样本;恶意代码分析单元分析详细信息的一种恶意代码样本;这种DNA提取解决方案是一种恶意代码单元,基于恶意代码分析信息,恶意代码解析单元提取出恶意代码DNA信息,包括恶意代码的特征信息;一种进行相似度的粗略的恶意代码DNA比较单元,在DNA类型,信息和先前提取的恶意代码DNA信息中的恶意代码DNA信息之间传递;相似恶意代码检索单元以此方式计算新恶意代码样本之间的总相似度和预先存储的恶意代码样本相似度计算的恶意代码DNA比较单元,并提取一定数量的恶意代码样本作为相似恶意代码搜索结果。 ; 2016年版权KIPO提交文件

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号