首页> 外国专利> System and method for automatically generating malware detection rule recommendations

System and method for automatically generating malware detection rule recommendations

机译:自动生成恶意软件检测规则建议的系统和方法

摘要

A method for generating rule recommendation utilized in a creation of malware detection rules is described. Meta-information associated with a plurality of events collected during a malware detection analysis of an object by a cybersecurity system is received and a first plurality of features is selected from the received meta-information. Machine learning (ML) models are applied to each of the first plurality of features to generate a score that represents a level of maliciousness for the feature and thereby a degree of usefulness of the feature in classifying the object as malicious or benign. Thereafter, a second plurality of features is selected as the salient features, which are used in creation of the malware detection rules in controlling subsequent operations of the cybersecurity system. The second plurality of features being lesser in number that the first plurality of features.
机译:描述了一种用于在创建恶意软件检测规则中使用的规则建议的方法。接收到由网络安全系统的恶意软件检测分析期间收集的多个事件相关联的元信息,并且从接收的元信息中选择第一多个特征。机器学习(ML)模型应用于第一多个特征中的每一个,以生成表示特征的恶意程度的分数,从而一定程度的特征在将物体分类为恶意或良性的特征。此后,选择第二多个特征作为突出特征,其用于在控制网络安全系统的后续操作时使用的恶意软件检测规则。第二多个特征在第一多个特征中的数量较小。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号