首页> 外国专利> Malware clustering based on analysis of execution-behavior reports

Malware clustering based on analysis of execution-behavior reports

机译:基于执行行为报告分析的恶意软件群集

摘要

Techniques are disclosed relating to malware clustering based on execution-behavior reports. In some embodiments, a computer system may access malware information that includes a plurality of reports corresponding to a plurality of malware samples. In some embodiments, each of the malware reports specifies a set of features relating to execution behavior of a corresponding malware sample. The computer system may, in various embodiments, process the plurality of reports to generate a plurality of vectors that includes, for each of the malware samples, a corresponding vector indicative of the execution behavior of the corresponding malware sample. Based on the plurality of vectors, the computer system may generate similarity values indicative of a similarity between ones of the plurality of vectors. Further, based on the similarity values, the computer system may assign each of the plurality of malware samples to one of a plurality of clusters of related malware samples.
机译:公开了基于执行行为报告的恶意软件群集的技术。在一些实施例中,计算机系统可以访问包括对应于多个恶意软件样本的多个报告的恶意软件信息。在一些实施例中,每个恶意软件报告指定与相应恶意软件示例的执行行为有关的一组特征。在各种实施例中,计算机系统可以处理多个报告以生成多个向量,该向量包括用于每个恶意软件样本,指示相应恶意软件样本的执行行为的对应矢量。基于多个矢量,计算机系统可以生成指示多个向量中的相似性的相似性值。此外,基于相似性值,计算机系统可以将多个恶意软件样本中的每一个分配给多个相关恶意软件样本的多个集群之一。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号