首页> 外国专利> Malware Detection System and Method based on API Function Extraction

Malware Detection System and Method based on API Function Extraction

机译:基于API函数提取的恶意软件检测系统和方法

摘要

The present invention relates to an API function extraction-based malware detection system and method, and more particularly, to a first API call list database including API call lists generated by static analysis of a plurality of malware and a plurality of normal files included in a data set. Generating (DB), generating a second API call list DB including API call lists generated by dynamically analyzing a plurality of malware and a plurality of normal files included in a data set, a first API call list DB and a plurality of API feature vectors corresponding to each of the plurality of malware and the plurality of normal files based on the second API call list DB. The API feature vector is the frequency of each API function included in the API call list of the corresponding malware or normal file. It includes the steps of generating - as training data, and training a machine learning algorithm to classify malware and normal files using the generated training data.
机译:本发明涉及基于API函数提取的恶意软件检测系统和方法,更具体地,涉及一种包括由多个恶意软件的静态分析生成的API呼叫列表的第一API呼叫列表数据库和包括在A中的多个正常文件生成的API呼叫列表 数据集。 生成(DB),生成包括通过动态分析多个恶意软件和包括在数据集中的多个正常文件,第一API呼叫列表DB和对应的多个API特征向量生成的第二API呼叫列表DB。 基于第二API呼叫列表DB的多个恶意软件和多个正常文件中的每一个。 API特征向量是相应恶意软件或普通文件的API调用列表中包含的每个API函数的频率。 它包括生成 - 作为培训数据的步骤,以及培训机器学习算法,使用生成的训练数据对恶意软件和正常文件进行分类。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号