首页> 外国专利> FEATURE ENGINEERING APPARATUS AND METHOD FOR EVASIVE RANSOMWARE DETECTION

FEATURE ENGINEERING APPARATUS AND METHOD FOR EVASIVE RANSOMWARE DETECTION

机译:特征工程设备和方法,用于逃避勒索软件检测

摘要

The present invention relates to a feature processing apparatus and method for detecting evasive ransomware, an input/output request collection unit that periodically collects a header of an input/output request at a specific time interval, and a read request is detected from the header of the input/output request. In case, a first hash table construction unit that creates a first entry including block information related to the read request and stores it in the first hash table through window-based search, the same as the block of the read request in the header of the input/output request When an overwrite request for a memory block having a start address is detected, a second hash table construction unit that generates a second entry including block information related to the overwrite request and stores it in a second hash table through the search; and And a feature generator that calculates a plurality of features for detecting ransomware based on the first and second hash tables.
机译:本发明涉及一种用于检测Ethave ransomware的特征处理装置和方法,输入/输出请求收集单元以特定时间间隔周期地收集输入/输出请求的报头,并且从标题中检测到读取请求输入/输出请求。在情况下,第一哈希表构造单元,其创建第一条目,包括与读取请求相关的块信息,并通过基于窗口的搜索将其存储在第一哈希表中,与标题中的标题中的读取请求的块相同当检测到具有开始地址的存储块的覆盖请求时输入/输出请求,第二散列表构造单元生成第二条目,包括与覆盖请求相关的块信息,并通过搜索将其存储在第二哈希表中;并且和一个特征发生器,用于基于第一和第二哈希表来计算用于检测勒索软件的多个特征。

著录项

  • 公开/公告号KR20210045140A

    专利类型

  • 公开/公告日2021-04-26

    原文格式PDF

  • 申请/专利权人 국민대학교산학협력단;

    申请/专利号KR1020190128528

  • 发明设计人 윤명근;명준우;조영훈;

    申请日2019-10-16

  • 分类号G06F21/56;

  • 国家 KR

  • 入库时间 2024-06-14 21:29:14

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号