首页> 外国专利> Locality-sensitive hash-based detection of malicious codes

Locality-sensitive hash-based detection of malicious codes

机译:基于位置的基于哈希的恶意代码检测

摘要

Malicious code is detected in binary data by disassembling machine language instructions of the binary data into assembly language instructions. Opcodes of the assembly language instructions are normalized and formed into groups, with each group being a subsequence of a sequence of machine language instructions of the binary data. The subsequence is delimited by a predetermined machine language instruction. Locality-sensitive hashes are calculated for each group and compared to locality-sensitive hashes of known malicious machine language instructions to detect malicious code in the binary data.
机译:通过将二进制数据的机器语言指令分解为汇编语言指令,可以检测二进制数据中的恶意代码。汇编语言指令的操作码被规范化并形成组,每个组是二进制数据的机器语言指令序列的子序列。子序列由预定的机器语言指令界定。为每个组计算局部敏感哈希,并将其与已知恶意机器语言指令的局部敏感哈希进行比较,以检测二进制数据中的恶意代码。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号