首页>
外国专利>
BEHAVIORAL SIGNATURE GENERATION USING CLUSTERING
BEHAVIORAL SIGNATURE GENERATION USING CLUSTERING
展开▼
机译:使用聚类生成行为签名
展开▼
页面导航
摘要
著录项
相似文献
摘要
A behavioral signature for detecting malware is generated. A computer is used to collect behavior traces of malware in a malware dataset. The behavior traces describe sequential behaviors performed by the malware. The behavior traces are normalized to produce malware behavior sequences. Similar malware behavior sequences are clustered together. The malware behavior sequences in a cluster describe behaviors of a malware family. The cluster is analyzed to identify a behavior subsequence common to the cluster's malware family. A behavior signature for the malware family is generated using the behavior subsequence. A trace of new malware is normalized and aligned with an existing cluster, if possible. The behavioral signature for that cluster is generated based on the behavior sequence of the new malware and the other sequences in the cluster.
展开▼