CN101604364B - 基于文件指令序列的计算机恶意程序分类系统和分类方法 - Google Patents
基于文件指令序列的计算机恶意程序分类系统和分类方法 Download PDFInfo
- Publication number
- CN101604364B CN101604364B CN2009100409972A CN200910040997A CN101604364B CN 101604364 B CN101604364 B CN 101604364B CN 2009100409972 A CN2009100409972 A CN 2009100409972A CN 200910040997 A CN200910040997 A CN 200910040997A CN 101604364 B CN101604364 B CN 101604364B
- Authority
- CN
- China
- Prior art keywords
- family
- sample
- file
- dimension
- point
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Landscapes
- Stored Programmes (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Abstract
Description
Claims (6)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2009100409972A CN101604364B (zh) | 2009-07-10 | 2009-07-10 | 基于文件指令序列的计算机恶意程序分类系统和分类方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2009100409972A CN101604364B (zh) | 2009-07-10 | 2009-07-10 | 基于文件指令序列的计算机恶意程序分类系统和分类方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN101604364A CN101604364A (zh) | 2009-12-16 |
CN101604364B true CN101604364B (zh) | 2012-08-15 |
Family
ID=41470091
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN2009100409972A Active CN101604364B (zh) | 2009-07-10 | 2009-07-10 | 基于文件指令序列的计算机恶意程序分类系统和分类方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN101604364B (zh) |
Families Citing this family (14)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102622302B (zh) * | 2011-01-26 | 2014-10-29 | 中国科学院高能物理研究所 | 碎片数据类型的识别方法 |
CN102737186B (zh) * | 2012-06-26 | 2015-06-17 | 腾讯科技(深圳)有限公司 | 恶意文件识别方法、装置及存储介质 |
CN103632091B (zh) * | 2012-08-21 | 2017-08-25 | 腾讯科技(深圳)有限公司 | 恶意特征提取方法、装置及存储介质 |
CN103679012A (zh) * | 2012-09-03 | 2014-03-26 | 腾讯科技(深圳)有限公司 | 一种可移植可执行文件的聚类方法和装置 |
CN104008333B (zh) * | 2013-02-21 | 2017-12-01 | 腾讯科技(深圳)有限公司 | 一种安装包的检测方法和设备 |
CN103761476B (zh) * | 2013-12-30 | 2016-11-09 | 北京奇虎科技有限公司 | 特征提取的方法及装置 |
CN104318158A (zh) * | 2014-07-09 | 2015-01-28 | 北京邮电大学 | 基于挖掘的网络智能平台恶意数据检测方法和装置 |
CN106909839B (zh) * | 2015-12-22 | 2020-04-17 | 北京奇虎科技有限公司 | 一种提取样本代码特征的方法及装置 |
CN106127044A (zh) * | 2016-06-20 | 2016-11-16 | 武汉绿色网络信息服务有限责任公司 | 一种函数恶意程度的检测方法和装置 |
CN105975854B (zh) * | 2016-06-20 | 2019-06-28 | 武汉绿色网络信息服务有限责任公司 | 一种恶意文件的检测方法和装置 |
CN108694319B (zh) * | 2017-04-06 | 2021-04-16 | 武汉安天信息技术有限责任公司 | 一种恶意代码家族判定方法及装置 |
CN107657175A (zh) * | 2017-09-15 | 2018-02-02 | 北京理工大学 | 一种基于图像特征描述子的恶意样本同源检测方法 |
CN112084502B (zh) * | 2020-09-18 | 2024-06-21 | 珠海豹趣科技有限公司 | 一种软件识别方法、装置、电子设备及存储介质 |
CN114254317B (zh) * | 2021-11-29 | 2023-06-16 | 上海戎磐网络科技有限公司 | 基于软件基因的软件处理方法、装置以及存储介质 |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101213555A (zh) * | 2005-06-30 | 2008-07-02 | 普瑞维克斯有限公司 | 用于处理恶意软件的方法和装置 |
US7430308B1 (en) * | 2002-11-26 | 2008-09-30 | University Of South Florida | Computer aided diagnosis of mammographic microcalcification clusters |
-
2009
- 2009-07-10 CN CN2009100409972A patent/CN101604364B/zh active Active
Patent Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US7430308B1 (en) * | 2002-11-26 | 2008-09-30 | University Of South Florida | Computer aided diagnosis of mammographic microcalcification clusters |
CN101213555A (zh) * | 2005-06-30 | 2008-07-02 | 普瑞维克斯有限公司 | 用于处理恶意软件的方法和装置 |
Also Published As
Publication number | Publication date |
---|---|
CN101604364A (zh) | 2009-12-16 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN101604364B (zh) | 基于文件指令序列的计算机恶意程序分类系统和分类方法 | |
Liu et al. | Automatic malware classification and new malware detection using machine learning | |
CN102346829B (zh) | 基于集成分类的病毒检测方法 | |
Islam et al. | Classification of malware based on string and function feature selection | |
Tixier et al. | A graph degeneracy-based approach to keyword extraction | |
CN107315954B (zh) | 一种文件类型识别方法及服务器 | |
CN102779249B (zh) | 恶意程序检测方法及扫描引擎 | |
Chakrabarty et al. | Navo minority over-sampling technique (NMOTe): a consistent performance booster on imbalanced datasets | |
CN101604363A (zh) | 基于文件指令频度的计算机恶意程序分类系统及分类方法 | |
CN103257957B (zh) | 一种基于中文分词的文本相似性识别方法及装置 | |
Tuarob et al. | Automatic detection of pseudocodes in scholarly documents using machine learning | |
Dal Bianco et al. | A practical and effective sampling selection strategy for large scale deduplication | |
Tan et al. | Time series classification for varying length series | |
CN103886077B (zh) | 短文本的聚类方法和系统 | |
Mohan et al. | Data mining classification techniques for intrusion detection system | |
CN106685964A (zh) | 基于恶意网络流量词库的恶意软件检测方法及系统 | |
CN104504334A (zh) | 用于评估分类规则选择性的系统及方法 | |
Karampidis et al. | File type identification-computational intelligence for digital forensics | |
CN103744964A (zh) | 一种基于局部敏感Hash函数的网页分类方法 | |
KR102367859B1 (ko) | 특징 벡터를 이용하여 데이터를 분류하는 장치 및 방법 | |
CN114676431A (zh) | 一种基于api增强顺序的安卓恶意代码检测方法 | |
CN109716660A (zh) | 数据压缩装置和方法 | |
Patri et al. | Multivariate time series classification using inter-leaved shapelets | |
Seideman et al. | Identifying malware genera using the Jensen-Shannon distance between system call traces | |
KR102110523B1 (ko) | 문서 분석 기반 주요 요소 추출 시스템 및 방법 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
ASS | Succession or assignment of patent right |
Owner name: KINGSOFT CORPORATION LIMITED Free format text: FORMER OWNER: ZHUHAI KINGSOFT SOFTWARE CO., LTD. Effective date: 20140903 |
|
C41 | Transfer of patent application or patent right or utility model | ||
COR | Change of bibliographic data |
Free format text: CORRECT: ADDRESS; FROM: 519015 ZHUHAI, GUANGDONG PROVINCE TO: 100085 HAIDIAN, BEIJING |
|
TR01 | Transfer of patent right |
Effective date of registration: 20140903 Address after: Kingsoft No. 33 building, 100085 Beijing city Haidian District Xiaoying Road Patentee after: BEIJING KINGSOFT INTERNET SECURITY SOFTWARE Co.,Ltd. Address before: Jinshan computer Building No. 8 Jingshan Hill Road, Lane 519015 Zhuhai Jida Lianshan Guangdong city of Zhuhai Province Patentee before: Zhuhai Kingsoft Software Co.,Ltd. |
|
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20091216 Assignee: Zhuhai Kingsoft Software Co.,Ltd. Assignor: BEIJING KINGSOFT INTERNET SECURITY SOFTWARE Co.,Ltd. Contract record no.: 2014990000778 Denomination of invention: Classification system and classification method of computer rogue programs based on file instruction sequence Granted publication date: 20120815 License type: Common License Record date: 20140926 |
|
LICC | Enforcement, change and cancellation of record of contracts on the licence for exploitation of a patent or utility model |