CN103902905B - 基于软件结构聚类的恶意代码生成器识别方法及系统 - Google Patents
基于软件结构聚类的恶意代码生成器识别方法及系统 Download PDFInfo
- Publication number
- CN103902905B CN103902905B CN201310691228.5A CN201310691228A CN103902905B CN 103902905 B CN103902905 B CN 103902905B CN 201310691228 A CN201310691228 A CN 201310691228A CN 103902905 B CN103902905 B CN 103902905B
- Authority
- CN
- China
- Prior art keywords
- sample
- information
- timestamp
- malicious code
- software structure
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims abstract description 25
- 239000013598 vector Substances 0.000 claims abstract description 13
- 239000000284 extract Substances 0.000 claims description 10
- 238000010276 construction Methods 0.000 claims description 8
- 230000000052 comparative effect Effects 0.000 claims description 6
- 238000000605 extraction Methods 0.000 claims description 5
- 238000013075 data extraction Methods 0.000 claims description 3
- 230000000694 effects Effects 0.000 description 2
- 238000005516 engineering process Methods 0.000 description 2
- 230000000644 propagated effect Effects 0.000 description 2
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
- G06F21/563—Static detection by source code analysis
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/03—Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
- G06F2221/033—Test or assess software
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2151—Time stamp
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Virology (AREA)
- Health & Medical Sciences (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- General Health & Medical Sciences (AREA)
- Stored Programmes (AREA)
- Debugging And Monitoring (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (4)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310691228.5A CN103902905B (zh) | 2013-12-17 | 2013-12-17 | 基于软件结构聚类的恶意代码生成器识别方法及系统 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310691228.5A CN103902905B (zh) | 2013-12-17 | 2013-12-17 | 基于软件结构聚类的恶意代码生成器识别方法及系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN103902905A CN103902905A (zh) | 2014-07-02 |
CN103902905B true CN103902905B (zh) | 2017-02-15 |
Family
ID=50994217
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201310691228.5A Active CN103902905B (zh) | 2013-12-17 | 2013-12-17 | 基于软件结构聚类的恶意代码生成器识别方法及系统 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN103902905B (zh) |
Families Citing this family (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN105512555B (zh) * | 2014-12-12 | 2018-05-25 | 哈尔滨安天科技股份有限公司 | 基于文件字符串聚类的划分同源家族和变种的方法及系统 |
Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US7257841B2 (en) * | 2001-03-26 | 2007-08-14 | Fujitsu Limited | Computer virus infection information providing method, computer virus infection information providing system, infection information providing apparatus, and computer memory product |
CN101162485A (zh) * | 2006-10-11 | 2008-04-16 | 飞塔信息科技(北京)有限公司 | 一种计算机恶意代码处理方法和系统 |
CN101470620A (zh) * | 2007-12-29 | 2009-07-01 | 珠海金山软件股份有限公司 | Pe文件源代码一致性的判定方法及装置 |
US8166544B2 (en) * | 2007-11-09 | 2012-04-24 | Polytechnic Institute Of New York University | Network-based infection detection using host slowdown |
CN103123618A (zh) * | 2011-11-21 | 2013-05-29 | 北京新媒传信科技有限公司 | 文本相似度获取方法和装置 |
CN103221960A (zh) * | 2012-12-10 | 2013-07-24 | 华为技术有限公司 | 恶意代码的检测方法及装置 |
-
2013
- 2013-12-17 CN CN201310691228.5A patent/CN103902905B/zh active Active
Patent Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US7257841B2 (en) * | 2001-03-26 | 2007-08-14 | Fujitsu Limited | Computer virus infection information providing method, computer virus infection information providing system, infection information providing apparatus, and computer memory product |
CN101162485A (zh) * | 2006-10-11 | 2008-04-16 | 飞塔信息科技(北京)有限公司 | 一种计算机恶意代码处理方法和系统 |
US8166544B2 (en) * | 2007-11-09 | 2012-04-24 | Polytechnic Institute Of New York University | Network-based infection detection using host slowdown |
CN101470620A (zh) * | 2007-12-29 | 2009-07-01 | 珠海金山软件股份有限公司 | Pe文件源代码一致性的判定方法及装置 |
CN103123618A (zh) * | 2011-11-21 | 2013-05-29 | 北京新媒传信科技有限公司 | 文本相似度获取方法和装置 |
CN103221960A (zh) * | 2012-12-10 | 2013-07-24 | 华为技术有限公司 | 恶意代码的检测方法及装置 |
Non-Patent Citations (1)
Title |
---|
基于特征聚类的海量恶意代码在线自动分析模型;徐小琳,等;《通信学报》;20130831;第34卷(第8期);论文第148-150页 * |
Also Published As
Publication number | Publication date |
---|---|
CN103902905A (zh) | 2014-07-02 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
TWI729472B (zh) | 特徵詞的確定方法、裝置和伺服器 | |
CN111563509B (zh) | 一种基于tesseract的变电站端子排识别方法及系统 | |
MY195917A (en) | Blockchain-Based Data Processing Method And Device | |
CN105205397B (zh) | 恶意程序样本分类方法及装置 | |
CN103679012A (zh) | 一种可移植可执行文件的聚类方法和装置 | |
CN110110075A (zh) | 网页分类方法、装置以及计算机可读存储介质 | |
CN102243699A (zh) | 一种恶意代码检测方法及系统 | |
CN104834717A (zh) | 一种基于网页聚类的Web信息自动抽取方法 | |
NZ757969A (en) | Quantifying robustness by analyzing a property graph data model | |
CN105183742A (zh) | 一种简历识别方法 | |
CN103914657A (zh) | 一种基于函数特征的恶意程序检测方法 | |
CN110321142A (zh) | 一种接口文档更新方法、装置、电子设备及存储介质 | |
CN105183476A (zh) | 一种跨平台应用程序的构建方法和装置 | |
CN105404757A (zh) | 一种智能变电站scd文件标准化程度的校验方法 | |
CN113204465A (zh) | 一种基于执行跟踪的微服务提取方法 | |
CN105426305A (zh) | 一种控件属性解析系统及方法 | |
CN113407495A (zh) | 一种基于simhash的文件相似度判定方法及系统 | |
CN110399485B (zh) | 基于词向量和机器学习的数据溯源方法和系统 | |
CN103440197B (zh) | 一种基于对比测试自动生成差异测试报告的方法 | |
CN111104159A (zh) | 一种基于程序分析和神经网络的注释定位方法 | |
CN106802958A (zh) | Cad数据到gis数据的转换方法及系统 | |
CN104636324B (zh) | 话题溯源方法和系统 | |
CN103902905B (zh) | 基于软件结构聚类的恶意代码生成器识别方法及系统 | |
CN103729197A (zh) | 一种基于lda模型的多粒度层次软件聚类方法 | |
CN104750812A (zh) | 一种基于网页标签分析的数据自动采集方法 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
PE01 | Entry into force of the registration of the contract for pledge of patent right | ||
PE01 | Entry into force of the registration of the contract for pledge of patent right |
Denomination of invention: Malicious code generator identification method and system based on software structure cluster Effective date of registration: 20170621 Granted publication date: 20170215 Pledgee: Bank of Longjiang, Limited by Share Ltd, Harbin Limin branch Pledgor: Harbin Antiy Technology Co., Ltd. Registration number: 2017110000004 |
|
PC01 | Cancellation of the registration of the contract for pledge of patent right |
Date of cancellation: 20190614 Granted publication date: 20170215 Pledgee: Bank of Longjiang, Limited by Share Ltd, Harbin Limin branch Pledgor: Harbin Antiy Technology Co., Ltd. Registration number: 2017110000004 |
|
PC01 | Cancellation of the registration of the contract for pledge of patent right | ||
CP03 | Change of name, title or address | ||
CP03 | Change of name, title or address |
Address after: 150028 Building 7, Innovation Plaza, Science and Technology Innovation City, Harbin Hi-tech Industrial Development Zone, Heilongjiang Province (838 Shikun Road) Patentee after: Harbin antiy Technology Group Limited by Share Ltd Address before: 150090 room 506, Hongqi Street, Nangang District, Harbin Development Zone, Heilongjiang, China, 162 Patentee before: Harbin Antiy Technology Co., Ltd. |
|
PE01 | Entry into force of the registration of the contract for pledge of patent right | ||
PE01 | Entry into force of the registration of the contract for pledge of patent right |
Denomination of invention: Malicious code generator identification method and system based on software structure cluster Effective date of registration: 20190828 Granted publication date: 20170215 Pledgee: Bank of Longjiang, Limited by Share Ltd, Harbin Limin branch Pledgor: Harbin antiy Technology Group Limited by Share Ltd Registration number: Y2019230000002 |
|
CP01 | Change in the name or title of a patent holder | ||
CP01 | Change in the name or title of a patent holder |
Address after: 150028 building 7, innovation and entrepreneurship square, science and technology innovation city, Harbin high tech Industrial Development Zone, Heilongjiang Province (No. 838, Shikun Road) Patentee after: Antan Technology Group Co.,Ltd. Address before: 150028 building 7, innovation and entrepreneurship square, science and technology innovation city, Harbin high tech Industrial Development Zone, Heilongjiang Province (No. 838, Shikun Road) Patentee before: Harbin Antian Science and Technology Group Co.,Ltd. |
|
PC01 | Cancellation of the registration of the contract for pledge of patent right | ||
PC01 | Cancellation of the registration of the contract for pledge of patent right |
Date of cancellation: 20211119 Granted publication date: 20170215 Pledgee: Bank of Longjiang Limited by Share Ltd. Harbin Limin branch Pledgor: Harbin Antian Science and Technology Group Co.,Ltd. Registration number: Y2019230000002 |