首页> 外国专利> Machine-implemented method and system for determining whether a to-be-analyzed software is a known malware or a variant of the known malware

Machine-implemented method and system for determining whether a to-be-analyzed software is a known malware or a variant of the known malware

机译:用于确定要分析的软件是已知恶意软件还是已知恶意软件的变体的机器实现的方法和系统

摘要

A machine-implemented method for determining whether a to-be-analyzed software is a known malware or a variant of the known malware includes the steps of: (A) configuring a processor to execute the to-be-analyzed software, and obtain a to-be-analyzed system call sequence that corresponds to the to-be-analyzed software with reference to a plurality of system calls made in sequence as a result of executing the to-be-analyzed software; (B) configuring the processor to determine a degree of similarity between the to-be-analyzed system call sequence and a reference system call sequence that corresponds to the known malware; and (C) configuring the processor to determine that the to-be-analyzed software is neither the known malware nor a variant of the known malware when the degree of similarity determined in step (B) is not greater than a predefined similarity threshold value.
机译:一种用于确定待分析软件是已知恶意软件还是已知恶意软件的变体的机器实现的方法,包括以下步骤:(A)配置处理器以执行待分析软件,并获得处理器。参照由于执行待分析软件而依次进行的多个系统调用,对应待分析软件的待分析系统调用序列; (B)配置处理器,以确定待分析的系统调用序列与对应于已知恶意软件的参考系统调用序列之间的相似度; (C)当步骤(B)中确定的相似度不大于预定的相似度阈值时,配置处理器确定待分析软件既不是已知恶意软件也不是已知恶意软件的变体。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号