首页> 外国专利> Generation of behavioral signatures using the clustering

Generation of behavioral signatures using the clustering

机译:使用聚类生成行为签名

摘要

Generating behavior signatures to detect malware. By using a computer, to collect the trace behavior of malware malware data set. Behavior trace describes the continuous behavior that was performed by the malware. Generating a malware behavior sequence by normalizing the behavior trace. Clustering together the malware behavior sequence similar. Malware behavior sequence in the cluster, I will describe the behavior of the malware family. To identify the behavior of sub-sequence common to malware family of clusters by analyzing the cluster. The behavior signature for malware family, is generated using the behavior subsequence. To match that of the existing cluster by normalizing if possible traces of new malware. The behavioral signature for that cluster, it is generated based on the sequence of the other behavior and sequence of new malware cluster.
机译:生成行为签名以检测恶意软件。通过使用计算机来收集恶意软件恶意软件数据集的跟踪行为。行为跟踪描述了恶意软件执行的连续行为。通过规范行为跟踪来生成恶意软件行为序列。将恶意软件的行为序列聚类在一起类似。群集中的恶意软件行为序列,我将描述恶意软件家族的行为。通过分析群集来确定恶意软件群集家族共有的子序列的行为。使用行为子序列生成恶意软件家族的行为签名。通过规范化新恶意软件的痕迹来匹配现有群集。该群集的行为签名是根据其他行为的顺序和新恶意软件群集的顺序生成的。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号