CN105205397A - 恶意程序样本分类方法及装置 - Google Patents
恶意程序样本分类方法及装置 Download PDFInfo
- Publication number
- CN105205397A CN105205397A CN201510669982.8A CN201510669982A CN105205397A CN 105205397 A CN105205397 A CN 105205397A CN 201510669982 A CN201510669982 A CN 201510669982A CN 105205397 A CN105205397 A CN 105205397A
- Authority
- CN
- China
- Prior art keywords
- rogue program
- program sample
- sample
- dynamic clustering
- static
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000000034 method Methods 0.000 title claims abstract description 62
- 230000003068 static effect Effects 0.000 claims abstract description 139
- 238000012216 screening Methods 0.000 claims abstract description 24
- 230000006399 behavior Effects 0.000 claims description 55
- 239000000284 extract Substances 0.000 claims description 18
- 244000035744 Hura crepitans Species 0.000 claims description 8
- 230000006870 function Effects 0.000 description 34
- 238000012360 testing method Methods 0.000 description 13
- 238000010586 diagram Methods 0.000 description 9
- 238000004590 computer program Methods 0.000 description 7
- 238000012545 processing Methods 0.000 description 4
- 230000000052 comparative effect Effects 0.000 description 2
- 238000011161 development Methods 0.000 description 2
- 241000700605 Viruses Species 0.000 description 1
- 238000004458 analytical method Methods 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000007621 cluster analysis Methods 0.000 description 1
- 230000008030 elimination Effects 0.000 description 1
- 238000003379 elimination reaction Methods 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 230000003203 everyday effect Effects 0.000 description 1
- 238000004519 manufacturing process Methods 0.000 description 1
- 230000035772 mutation Effects 0.000 description 1
- 230000003287 optical effect Effects 0.000 description 1
- 230000002265 prevention Effects 0.000 description 1
- 230000035945 sensitivity Effects 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
- G06F21/563—Static detection by source code analysis
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Abstract
Description
Claims (10)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201510669982.8A CN105205397B (zh) | 2015-10-13 | 2015-10-13 | 恶意程序样本分类方法及装置 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201510669982.8A CN105205397B (zh) | 2015-10-13 | 2015-10-13 | 恶意程序样本分类方法及装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN105205397A true CN105205397A (zh) | 2015-12-30 |
CN105205397B CN105205397B (zh) | 2018-10-16 |
Family
ID=54953071
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201510669982.8A Active CN105205397B (zh) | 2015-10-13 | 2015-10-13 | 恶意程序样本分类方法及装置 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN105205397B (zh) |
Cited By (12)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN106372508A (zh) * | 2016-08-30 | 2017-02-01 | 北京奇虎科技有限公司 | 恶意文档的处理方法及装置 |
CN106570394A (zh) * | 2016-11-10 | 2017-04-19 | 厦门安胜网络科技有限公司 | 一种检测恶意程序的方法 |
CN106599688A (zh) * | 2016-12-08 | 2017-04-26 | 西安电子科技大学 | 一种基于应用类别的安卓恶意软件检测方法 |
CN106599686A (zh) * | 2016-10-12 | 2017-04-26 | 四川大学 | 一种基于tlsh特征表示的恶意软件聚类方法 |
CN106709326A (zh) * | 2016-11-24 | 2017-05-24 | 北京奇虎科技有限公司 | 一种可疑样本的处理方法和装置 |
CN106815521A (zh) * | 2015-12-31 | 2017-06-09 | 武汉安天信息技术有限责任公司 | 一种样本关联性检测方法、系统及电子设备 |
CN107247902A (zh) * | 2017-05-10 | 2017-10-13 | 深信服科技股份有限公司 | 恶意软件分类系统及方法 |
CN108985086A (zh) * | 2018-07-18 | 2018-12-11 | 中软信息系统工程有限公司 | 应用程序权限控制方法、装置及电子设备 |
CN111160021A (zh) * | 2019-10-12 | 2020-05-15 | 华为技术有限公司 | 日志模板提取方法及装置 |
CN113076537A (zh) * | 2021-03-04 | 2021-07-06 | 珠海城市职业技术学院 | 一种恶意文件识别方法、装置、电子设备及可读存储介质 |
CN113761912A (zh) * | 2021-08-09 | 2021-12-07 | 国家计算机网络与信息安全管理中心 | 一种对恶意软件归属攻击组织的可解释判定方法及装置 |
CN113987502A (zh) * | 2021-12-29 | 2022-01-28 | 阿里云计算有限公司 | 目标程序检测方法、设备及存储介质 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101604365A (zh) * | 2009-07-10 | 2009-12-16 | 珠海金山软件股份有限公司 | 确定计算机恶意程序样本家族数的系统和方法 |
CN102542190A (zh) * | 2010-12-31 | 2012-07-04 | 北京奇虎科技有限公司 | 基于机器学习的程序识别方法及装置 |
US20140150105A1 (en) * | 2011-08-09 | 2014-05-29 | Tencent Technology (Shenzhen) Company Limited | Clustering processing method and device for virus files |
CN104331436A (zh) * | 2014-10-23 | 2015-02-04 | 西安交通大学 | 基于家族基因码的恶意代码快速归类方法 |
-
2015
- 2015-10-13 CN CN201510669982.8A patent/CN105205397B/zh active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101604365A (zh) * | 2009-07-10 | 2009-12-16 | 珠海金山软件股份有限公司 | 确定计算机恶意程序样本家族数的系统和方法 |
CN102542190A (zh) * | 2010-12-31 | 2012-07-04 | 北京奇虎科技有限公司 | 基于机器学习的程序识别方法及装置 |
US20140150105A1 (en) * | 2011-08-09 | 2014-05-29 | Tencent Technology (Shenzhen) Company Limited | Clustering processing method and device for virus files |
CN104331436A (zh) * | 2014-10-23 | 2015-02-04 | 西安交通大学 | 基于家族基因码的恶意代码快速归类方法 |
Non-Patent Citations (1)
Title |
---|
林聚伟: "基于行为分析的病毒家族聚类系统设计与实现", 《万方数据知识服务平台》 * |
Cited By (20)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN106815521A (zh) * | 2015-12-31 | 2017-06-09 | 武汉安天信息技术有限责任公司 | 一种样本关联性检测方法、系统及电子设备 |
CN106815521B (zh) * | 2015-12-31 | 2019-07-23 | 武汉安天信息技术有限责任公司 | 一种样本关联性检测方法、系统及电子设备 |
CN106372508B (zh) * | 2016-08-30 | 2020-05-12 | 北京奇虎科技有限公司 | 恶意文档的处理方法及装置 |
CN106372508A (zh) * | 2016-08-30 | 2017-02-01 | 北京奇虎科技有限公司 | 恶意文档的处理方法及装置 |
CN106599686B (zh) * | 2016-10-12 | 2019-06-21 | 四川大学 | 一种基于tlsh特征表示的恶意软件聚类方法 |
CN106599686A (zh) * | 2016-10-12 | 2017-04-26 | 四川大学 | 一种基于tlsh特征表示的恶意软件聚类方法 |
CN106570394A (zh) * | 2016-11-10 | 2017-04-19 | 厦门安胜网络科技有限公司 | 一种检测恶意程序的方法 |
CN106709326A (zh) * | 2016-11-24 | 2017-05-24 | 北京奇虎科技有限公司 | 一种可疑样本的处理方法和装置 |
WO2018095099A1 (zh) * | 2016-11-24 | 2018-05-31 | 北京奇虎科技有限公司 | 一种可疑样本的处理方法和装置 |
CN106599688B (zh) * | 2016-12-08 | 2019-07-12 | 西安电子科技大学 | 一种基于应用类别的安卓恶意软件检测方法 |
CN106599688A (zh) * | 2016-12-08 | 2017-04-26 | 西安电子科技大学 | 一种基于应用类别的安卓恶意软件检测方法 |
CN107247902A (zh) * | 2017-05-10 | 2017-10-13 | 深信服科技股份有限公司 | 恶意软件分类系统及方法 |
CN107247902B (zh) * | 2017-05-10 | 2021-07-06 | 深信服科技股份有限公司 | 恶意软件分类系统及方法 |
CN108985086A (zh) * | 2018-07-18 | 2018-12-11 | 中软信息系统工程有限公司 | 应用程序权限控制方法、装置及电子设备 |
CN108985086B (zh) * | 2018-07-18 | 2022-04-19 | 中软信息系统工程有限公司 | 应用程序权限控制方法、装置及电子设备 |
CN111160021A (zh) * | 2019-10-12 | 2020-05-15 | 华为技术有限公司 | 日志模板提取方法及装置 |
CN113076537A (zh) * | 2021-03-04 | 2021-07-06 | 珠海城市职业技术学院 | 一种恶意文件识别方法、装置、电子设备及可读存储介质 |
CN113761912A (zh) * | 2021-08-09 | 2021-12-07 | 国家计算机网络与信息安全管理中心 | 一种对恶意软件归属攻击组织的可解释判定方法及装置 |
CN113761912B (zh) * | 2021-08-09 | 2024-04-16 | 国家计算机网络与信息安全管理中心 | 一种对恶意软件归属攻击组织的可解释判定方法及装置 |
CN113987502A (zh) * | 2021-12-29 | 2022-01-28 | 阿里云计算有限公司 | 目标程序检测方法、设备及存储介质 |
Also Published As
Publication number | Publication date |
---|---|
CN105205397B (zh) | 2018-10-16 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN105205397A (zh) | 恶意程序样本分类方法及装置 | |
US20210256127A1 (en) | System and method for automated machine-learning, zero-day malware detection | |
Kumar et al. | Malicious code detection based on image processing using deep learning | |
US11620471B2 (en) | Clustering analysis for deduplication of training set samples for machine learning based computer threat analysis | |
US10621349B2 (en) | Detection of malware using feature hashing | |
US9237161B2 (en) | Malware detection and identification | |
Tian et al. | Function length as a tool for malware classification | |
US9516055B1 (en) | Automatic malware signature extraction from runtime information | |
Kirat et al. | Sigmal: A static signal processing based malware triage | |
US11373065B2 (en) | Dictionary based deduplication of training set samples for machine learning based computer threat analysis | |
US20200380125A1 (en) | Method for Detecting Libraries in Program Binaries | |
EP3346664B1 (en) | Binary search of byte sequences using inverted indices | |
Palahan et al. | Extraction of statistically significant malware behaviors | |
KR20200039912A (ko) | Ai 기반 안드로이드 악성코드 자동화 분석 시스템 및 방법 | |
CN105512555A (zh) | 基于文件字符串聚类的划分同源家族和变种的方法及系统 | |
CN110674360B (zh) | 一种用于数据的溯源方法和系统 | |
CN107273746A (zh) | 一种基于apk字符串特征的变种恶意软件检测方法 | |
CN115827895A (zh) | 一种漏洞知识图谱处理方法、装置、设备及介质 | |
Nguyen et al. | Detecting repackaged android applications using perceptual hashing | |
Chandramohan et al. | Scalable malware clustering through coarse-grained behavior modeling | |
CN113407495A (zh) | 一种基于simhash的文件相似度判定方法及系统 | |
WO2016093839A1 (en) | Structuring of semi-structured log messages | |
KR102031592B1 (ko) | 악성코드를 탐지하기 위한 방법 및 장치 | |
US10248789B2 (en) | File clustering using filters working over file attributes | |
CN105279434A (zh) | 恶意程序样本家族命名方法及装置 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C41 | Transfer of patent application or patent right or utility model | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20161122 Address after: 100015 Chaoyang District Road, Jiuxianqiao, No. 10, building No. 3, floor 15, floor 17, 1701-26, Applicant after: BEIJING QIANXIN TECHNOLOGY Co.,Ltd. Address before: 100088 Beijing city Xicheng District xinjiekouwai Street 28, block D room 112 (Desheng Park) Applicant before: BEIJING QIHOO TECHNOLOGY Co.,Ltd. Applicant before: Qizhi software (Beijing) Co.,Ltd. |
|
CI01 | Publication of corrected invention patent application | ||
CI01 | Publication of corrected invention patent application |
Correction item: Applicant|Address|Co-applicant Correct: BEIJING QIHOO TECHNOLOGY Co.,Ltd.|100088 Beijing city Xicheng District xinjiekouwai Street 28, block D room 112 (Desheng Park)|Qizhi software (Beijing) Co.,Ltd. False: BEIJING QIANXIN TECHNOLOGY Co.,Ltd.|100015 Chaoyang District Road, Jiuxianqiao, No. 10, building No. 3, floor 15, floor 17, 1701-26, Number: 50 Volume: 32 |
|
TA01 | Transfer of patent application right |
Effective date of registration: 20170523 Address after: 100015 Chaoyang District Road, Jiuxianqiao, No. 10, building No. 3, floor 15, floor 17, 1701-26, Applicant after: BEIJING QIANXIN TECHNOLOGY Co.,Ltd. Address before: 100088 Beijing city Xicheng District xinjiekouwai Street 28, block D room 112 (Desheng Park) Applicant before: BEIJING QIHOO TECHNOLOGY Co.,Ltd. Applicant before: Qizhi software (Beijing) Co.,Ltd. |
|
TA01 | Transfer of patent application right | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
CP03 | Change of name, title or address |
Address after: 100032 NO.332, 3rd floor, Building 102, 28 xinjiekouwai street, Xicheng District, Beijing Patentee after: QAX Technology Group Inc. Address before: 100015 15, 17 floor 1701-26, 3 building, 10 Jiuxianqiao Road, Chaoyang District, Beijing. Patentee before: BEIJING QIANXIN TECHNOLOGY Co.,Ltd. |
|
CP03 | Change of name, title or address |