CN105488409B - 一种检测恶意代码家族变种及新家族的方法及系统 - Google Patents
一种检测恶意代码家族变种及新家族的方法及系统 Download PDFInfo
- Publication number
- CN105488409B CN105488409B CN201410845278.9A CN201410845278A CN105488409B CN 105488409 B CN105488409 B CN 105488409B CN 201410845278 A CN201410845278 A CN 201410845278A CN 105488409 B CN105488409 B CN 105488409B
- Authority
- CN
- China
- Prior art keywords
- malicious code
- api function
- detected
- sample
- function name
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims abstract description 34
- 230000035772 mutation Effects 0.000 title claims abstract description 30
- 238000001514 detection method Methods 0.000 claims abstract description 31
- 239000000284 extract Substances 0.000 claims abstract description 19
- 238000000605 extraction Methods 0.000 claims description 18
- 230000000052 comparative effect Effects 0.000 claims description 12
- 238000005516 engineering process Methods 0.000 claims description 9
- 230000003068 static effect Effects 0.000 claims description 6
- 230000007812 deficiency Effects 0.000 abstract description 3
- 238000010586 diagram Methods 0.000 description 3
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000010276 construction Methods 0.000 description 1
- 238000013075 data extraction Methods 0.000 description 1
- 235000013399 edible fruits Nutrition 0.000 description 1
- 230000000750 progressive effect Effects 0.000 description 1
Landscapes
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
- Measuring Or Testing Involving Enzymes Or Micro-Organisms (AREA)
Abstract
Description
Claims (8)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201410845278.9A CN105488409B (zh) | 2014-12-31 | 2014-12-31 | 一种检测恶意代码家族变种及新家族的方法及系统 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201410845278.9A CN105488409B (zh) | 2014-12-31 | 2014-12-31 | 一种检测恶意代码家族变种及新家族的方法及系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN105488409A CN105488409A (zh) | 2016-04-13 |
CN105488409B true CN105488409B (zh) | 2018-04-24 |
Family
ID=55675383
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201410845278.9A Active CN105488409B (zh) | 2014-12-31 | 2014-12-31 | 一种检测恶意代码家族变种及新家族的方法及系统 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN105488409B (zh) |
Families Citing this family (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN108256325A (zh) * | 2016-12-29 | 2018-07-06 | 中移(苏州)软件技术有限公司 | 一种恶意代码变种的检测的方法和装置 |
CN107392019A (zh) * | 2017-07-05 | 2017-11-24 | 北京金睛云华科技有限公司 | 一种恶意代码家族的训练和检测方法及装置 |
CN111881446B (zh) * | 2020-06-19 | 2023-10-27 | 中国科学院信息工程研究所 | 一种工业互联网恶意代码识别方法及装置 |
CN112434294A (zh) * | 2020-11-27 | 2021-03-02 | 厦门服云信息科技有限公司 | 一种恶意代码检测方法、终端设备及存储介质 |
CN113222079B (zh) * | 2021-03-31 | 2024-06-07 | 钉钉科技有限公司 | 基于家庭码或群体码的信息处理方法、装置及设备 |
CN117272303B (zh) * | 2023-09-27 | 2024-06-25 | 四川大学 | 一种基于遗传对抗的恶意代码样本变体生成方法及系统 |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101140611A (zh) * | 2007-09-18 | 2008-03-12 | 北京大学 | 一种恶意代码自动识别方法 |
CN102810142A (zh) * | 2011-12-20 | 2012-12-05 | 北京安天电子设备有限公司 | 基于可扩展模式的恶意代码查杀系统和方法 |
-
2014
- 2014-12-31 CN CN201410845278.9A patent/CN105488409B/zh active Active
Patent Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101140611A (zh) * | 2007-09-18 | 2008-03-12 | 北京大学 | 一种恶意代码自动识别方法 |
CN102810142A (zh) * | 2011-12-20 | 2012-12-05 | 北京安天电子设备有限公司 | 基于可扩展模式的恶意代码查杀系统和方法 |
Non-Patent Citations (3)
Title |
---|
一种针对Android平台恶意代码的;胡文君等;《西安交通大学学报》;20131031;第47卷(第10期);第37-43页 * |
基于特征聚类的海量恶意代码在线自动分析模型;徐小琳等;《通信学报》;20130831;第34卷(第8期);第146-153页 * |
恶意代码检测与分类技术研究;赵恒立;《中国优秀硕士学位论文全文数据库》;20120331;I139-346 * |
Also Published As
Publication number | Publication date |
---|---|
CN105488409A (zh) | 2016-04-13 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN105488409B (zh) | 一种检测恶意代码家族变种及新家族的方法及系统 | |
CN106709345B (zh) | 基于深度学习方法推断恶意代码规则的方法、系统及设备 | |
CN104601556A (zh) | 一种面向web的攻击检测方法及系统 | |
CN103559235B (zh) | 一种在线社交网络恶意网页检测识别方法 | |
CN105224600B (zh) | 一种样本相似度的检测方法及装置 | |
US20120159625A1 (en) | Malicious code detection and classification system using string comparison and method thereof | |
JP6174520B2 (ja) | 悪性通信パターン検知装置、悪性通信パターン検知方法、および、悪性通信パターン検知プログラム | |
US10440035B2 (en) | Identifying malicious communication channels in network traffic by generating data based on adaptive sampling | |
CN109194677A (zh) | 一种sql注入攻击检测方法、装置及设备 | |
CN108833437A (zh) | 一种基于流量指纹和通信特征匹配的apt检测方法 | |
US20200012784A1 (en) | Profile generation device, attack detection device, profile generation method, and profile generation computer program | |
CN111835777B (zh) | 一种异常流量检测方法、装置、设备及介质 | |
JP2019110513A (ja) | 異常検知方法、学習方法、異常検知装置、および、学習装置 | |
CN105718795B (zh) | Linux下基于特征码的恶意代码取证方法及系统 | |
Coskun et al. | Mitigating sms spam by online detection of repetitive near-duplicate messages | |
CN105100023B (zh) | 数据包特征提取方法及装置 | |
EP2977928B1 (en) | Malicious code detection | |
US20230092159A1 (en) | Label guided unsupervised learning based network-level application signature generation | |
CN104765882B (zh) | 一种基于网页特征字符串的互联网网站统计方法 | |
Zhang et al. | Toward unsupervised protocol feature word extraction | |
Allodi | The heavy tails of vulnerability exploitation | |
CN109660517B (zh) | 异常行为检测方法、装置及设备 | |
CN105407096A (zh) | 基于流管理的报文数据检测方法 | |
CN107209834A (zh) | 恶意通信模式提取装置、恶意通信模式提取系统、恶意通信模式提取方法及恶意通信模式提取程序 | |
CN106301979B (zh) | 检测异常渠道的方法和系统 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
CP03 | Change of name, title or address | ||
CP03 | Change of name, title or address |
Address after: 150010 Heilongjiang science and technology innovation city, Harbin new and high tech Industrial Development Zone, No. 7 building, innovation and entrepreneurship Plaza, 838 Patentee after: Harbin antiy Technology Group Limited by Share Ltd Address before: 150090 room 506, Hongqi Street, Nangang District, Harbin Development Zone, Heilongjiang, China, 162 Patentee before: Harbin Antiy Technology Co., Ltd. |
|
PE01 | Entry into force of the registration of the contract for pledge of patent right |
Denomination of invention: Method and system for detecting malicious code family variety and new family Effective date of registration: 20190718 Granted publication date: 20180424 Pledgee: Bank of Longjiang, Limited by Share Ltd, Harbin Limin branch Pledgor: Harbin antiy Technology Group Limited by Share Ltd Registration number: 2019230000007 |
|
PE01 | Entry into force of the registration of the contract for pledge of patent right | ||
CP01 | Change in the name or title of a patent holder |
Address after: 150010 Heilongjiang science and technology innovation city, Harbin new and high tech Industrial Development Zone, No. 7 building, innovation and entrepreneurship Plaza, 838 Patentee after: Antan Technology Group Co.,Ltd. Address before: 150010 Heilongjiang science and technology innovation city, Harbin new and high tech Industrial Development Zone, No. 7 building, innovation and entrepreneurship Plaza, 838 Patentee before: Harbin Antian Science and Technology Group Co.,Ltd. |
|
CP01 | Change in the name or title of a patent holder | ||
PC01 | Cancellation of the registration of the contract for pledge of patent right |
Date of cancellation: 20211119 Granted publication date: 20180424 Pledgee: Bank of Longjiang Limited by Share Ltd. Harbin Limin branch Pledgor: Harbin Antian Science and Technology Group Co.,Ltd. Registration number: 2019230000007 |
|
PC01 | Cancellation of the registration of the contract for pledge of patent right |