首页> 外国专利> Classification of malware using clustering that orders events in accordance with the time of occurance

Classification of malware using clustering that orders events in accordance with the time of occurance

机译:使用根据事件发生时间对事件进行排序的群集对恶意软件进行分类

摘要

The present invention is directed to a method and system for automatically classifying an application into an application group which is previously classified in a knowledge base. More specifically, a runtime behavior of an application is captured as a series of events which are monitored and recorded during the execution of the application. The series of events are analyzed to find a proper application group which shares common runtime behavior patterns with the application. The knowledge base of application groups is previously constructed based on a large number of sample applications. The construction of the knowledge base is done in such a manner that each sample application can be classified into application groups based on a set of classification rules in the knowledge base. The set of classification rules are applied to a new application in order to classify the new application into one of the application groups.
机译:本发明针对一种用于将应用自动分类到先前在知识库中分类的应用组的方法和系统。更具体地说,将应用程序的运行时行为捕获为一系列事件,这些事件在应用程序执行期间受到监视和记录。对一系列事件进行分析,以找到合适的应用程序组,该组与应用程序共享常见的运行时行为模式。应用程序组的知识库是以前基于大量示例应用程序构建的。知识库的构建以如下方式完成:可以将每个样本应用程序根据知识库中的一组分类规则分类为应用程序组。将分类规则集应用于新应用程序,以便将新应用程序分类为应用程序组之一。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号