首页> 外国专利> SYSTEMS AND METHODS FOR EXECUTABLE CODE DETECTION, AUTOMATIC FEATURE EXTRACTION AND POSITION INDEPENDENT CODE DETECTION

SYSTEMS AND METHODS FOR EXECUTABLE CODE DETECTION, AUTOMATIC FEATURE EXTRACTION AND POSITION INDEPENDENT CODE DETECTION

机译:可执行代码检测、自动特征提取和位置无关代码检测的系统和方法

摘要

Disclosed herein are systems and methods for enabling the automatic detection of executable code from a stream of bytes. In some embodiments, the stream of bytes can be sourced from the hidden areas of files that traditional malware detection solutions ignore. In some embodiments, a machine learning model is trained to detect whether a particular stream of bytes is executable code. Other embodiments described herein disclose systems and methods for automatic feature extraction using a neural network. Given a new file, the systems and methods may preprocess the code to be inputted into a trained neural network. The neural network may be used as a "feature generator" for a malware detection model. Other embodiments herein are directed to systems and methods for identifying, flagging, and/or detecting threat actors which attempt to obtain access to library functions independently.
机译:本文公开了用于从字节流中自动检测可执行代码的系统和方法。在一些实施例中,字节流可以来自传统恶意软件检测解决方案忽略的文件隐藏区域。在一些实施例中,训练机器学习模型以检测特定字节流是否为可执行代码。本文描述的其他实施例公开了使用神经网络进行自动特征提取的系统和方法。给定一个新文件,系统和方法可以预处理要输入到经过训练的神经网络中的代码。神经网络可以用作恶意软件检测模型的“特征生成器”。本文中的其他实施例针对用于识别、标记和/或检测试图独立地获得对库函数的访问的威胁参与者的系统和方法。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号