首页> 外国专利> Systems and methods for executable code detection, automatic feature extraction and position independent code detection

Systems and methods for executable code detection, automatic feature extraction and position independent code detection

机译:可执行代码检测的系统和方法,自动特征提取和位置独立代码检测

摘要

Disclosed herein are systems and methods for enabling the automatic detection of executable code from a stream of bytes. In some embodiments, the stream of bytes can be sourced from the hidden areas of files that traditional malware detection solutions ignore. In some embodiments, a machine learning model is trained to detect whether a particular stream of bytes is executable code. Other embodiments described herein disclose systems and methods for automatic feature extraction using a neural network. Given a new file, the systems and methods may preprocess the code to be inputted into a trained neural network. The neural network may be used as a “feature generator” for a malware detection model. Other embodiments herein are directed to systems and methods for identifying, flagging, and/or detecting threat actors which attempt to obtain access to library functions independently.
机译:本文公开了用于使能够从字节流自动检测可执行代码的系统和方法。 在一些实施例中,字节流可以从传统恶意软件检测解决方案忽略的文件的隐藏区域中源。 在一些实施例中,训练机器学习模型以检测特定字节流是可执行的代码。 本文描述的其他实施例公开了使用神经网络的用于自动特征提取的系统和方法。 给定新文件,系统和方法可以预处理要输入的代码被输入到培训的神经网络中。 神经网络可以用作恶意软件检测模型的“特征生成器”。 这里的其他实施例涉及用于识别,标记和/或检测试图独立地获得对库功能的访问的威胁演员的系统和方法。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号