CN108256329A - 基于动态行为的细粒度rat程序检测方法、系统及相应的apt攻击检测方法 - Google Patents
基于动态行为的细粒度rat程序检测方法、系统及相应的apt攻击检测方法 Download PDFInfo
- Publication number
- CN108256329A CN108256329A CN201810131880.4A CN201810131880A CN108256329A CN 108256329 A CN108256329 A CN 108256329A CN 201810131880 A CN201810131880 A CN 201810131880A CN 108256329 A CN108256329 A CN 108256329A
- Authority
- CN
- China
- Prior art keywords
- fine granularity
- rat
- data
- behavior
- programs
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/566—Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/03—Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
- G06F2221/033—Test or assess software
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
Claims (10)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810131880.4A CN108256329B (zh) | 2018-02-09 | 2018-02-09 | 基于动态行为的细粒度rat程序检测方法、系统及相应的apt攻击检测方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810131880.4A CN108256329B (zh) | 2018-02-09 | 2018-02-09 | 基于动态行为的细粒度rat程序检测方法、系统及相应的apt攻击检测方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN108256329A true CN108256329A (zh) | 2018-07-06 |
CN108256329B CN108256329B (zh) | 2022-06-17 |
Family
ID=62744051
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201810131880.4A Active CN108256329B (zh) | 2018-02-09 | 2018-02-09 | 基于动态行为的细粒度rat程序检测方法、系统及相应的apt攻击检测方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN108256329B (zh) |
Cited By (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110414228A (zh) * | 2018-12-20 | 2019-11-05 | 腾讯科技(深圳)有限公司 | 计算机病毒的检测方法、装置、存储介质和计算机设备 |
CN110837640A (zh) * | 2019-11-08 | 2020-02-25 | 深信服科技股份有限公司 | 恶意文件的查杀方法、查杀设备、存储介质及装置 |
CN111797394A (zh) * | 2020-06-24 | 2020-10-20 | 广州大学 | 基于stacking集成的APT组织识别方法、系统及存储介质 |
CN112671741A (zh) * | 2020-12-16 | 2021-04-16 | 平安普惠企业管理有限公司 | 一种网络防护的方法、装置、终端及存储介质 |
RU2769651C2 (ru) * | 2020-08-24 | 2022-04-04 | Акционерное общество "Лаборатория Касперского" | Способ формирования сигнатуры для обнаружения неправомерного доступа к компьютеру, получаемого с помощью средств удаленного администрирования, и реализующая его система |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101183414A (zh) * | 2007-12-07 | 2008-05-21 | 白杰 | 一种程序检测的方法、装置及程序分析的方法 |
CN103136471A (zh) * | 2011-11-25 | 2013-06-05 | 中国科学院软件研究所 | 一种恶意Android应用程序检测方法和系统 |
CN106682515A (zh) * | 2016-12-15 | 2017-05-17 | 中国人民解放军国防科学技术大学 | 恶意代码分析中行为能力的度量方法 |
CN106997367A (zh) * | 2016-01-26 | 2017-08-01 | 华为技术有限公司 | 程序文件的分类方法、分类装置和分类系统 |
-
2018
- 2018-02-09 CN CN201810131880.4A patent/CN108256329B/zh active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101183414A (zh) * | 2007-12-07 | 2008-05-21 | 白杰 | 一种程序检测的方法、装置及程序分析的方法 |
CN103136471A (zh) * | 2011-11-25 | 2013-06-05 | 中国科学院软件研究所 | 一种恶意Android应用程序检测方法和系统 |
CN106997367A (zh) * | 2016-01-26 | 2017-08-01 | 华为技术有限公司 | 程序文件的分类方法、分类装置和分类系统 |
CN106682515A (zh) * | 2016-12-15 | 2017-05-17 | 中国人民解放军国防科学技术大学 | 恶意代码分析中行为能力的度量方法 |
Cited By (9)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110414228A (zh) * | 2018-12-20 | 2019-11-05 | 腾讯科技(深圳)有限公司 | 计算机病毒的检测方法、装置、存储介质和计算机设备 |
CN110414228B (zh) * | 2018-12-20 | 2023-01-03 | 腾讯科技(深圳)有限公司 | 计算机病毒的检测方法、装置、存储介质和计算机设备 |
CN110837640A (zh) * | 2019-11-08 | 2020-02-25 | 深信服科技股份有限公司 | 恶意文件的查杀方法、查杀设备、存储介质及装置 |
CN110837640B (zh) * | 2019-11-08 | 2022-02-22 | 深信服科技股份有限公司 | 恶意文件的查杀方法、查杀设备、存储介质及装置 |
CN111797394A (zh) * | 2020-06-24 | 2020-10-20 | 广州大学 | 基于stacking集成的APT组织识别方法、系统及存储介质 |
CN111797394B (zh) * | 2020-06-24 | 2021-06-08 | 广州大学 | 基于stacking集成的APT组织识别方法、系统及存储介质 |
RU2769651C2 (ru) * | 2020-08-24 | 2022-04-04 | Акционерное общество "Лаборатория Касперского" | Способ формирования сигнатуры для обнаружения неправомерного доступа к компьютеру, получаемого с помощью средств удаленного администрирования, и реализующая его система |
CN112671741A (zh) * | 2020-12-16 | 2021-04-16 | 平安普惠企业管理有限公司 | 一种网络防护的方法、装置、终端及存储介质 |
CN112671741B (zh) * | 2020-12-16 | 2022-10-18 | 平安普惠企业管理有限公司 | 一种网络防护的方法、装置、终端及存储介质 |
Also Published As
Publication number | Publication date |
---|---|
CN108256329B (zh) | 2022-06-17 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN108256329A (zh) | 基于动态行为的细粒度rat程序检测方法、系统及相应的apt攻击检测方法 | |
Aslan et al. | A new malware classification framework based on deep learning algorithms | |
Sun et al. | Detecting anomalous user behavior using an extended isolation forest algorithm: an enterprise case study | |
CN103839003B (zh) | 恶意文件检测方法及装置 | |
CN108920954B (zh) | 一种恶意代码自动化检测平台及方法 | |
CN112866023B (zh) | 网络检测、模型训练方法、装置、设备及存储介质 | |
Ma et al. | Active semi-supervised approach for checking app behavior against its description | |
Agrawal et al. | Neural sequential malware detection with parameters | |
Zhu et al. | Android malware detection based on multi-head squeeze-and-excitation residual network | |
Qin et al. | API call based ransomware dynamic detection approach using textCNN | |
CN107688743A (zh) | 一种恶意程序的检测分析方法及系统 | |
CN110704841A (zh) | 一种基于卷积神经网络的大规模安卓恶意应用检测系统及方法 | |
Shrivastava et al. | Forensic computing models: Technical overview | |
Paranthaman et al. | Malware collection and analysis | |
Carney et al. | The Trojan made me do it: A first step in statistical based computer forensics event reconstruction | |
Dubey et al. | Digital forensics techniques and trends: a review. | |
Memon et al. | Harvesting covert networks: a case study of the iMiner database | |
KR20130074224A (ko) | 악성코드의 행동 패턴 수집장치 및 방법 | |
Sali et al. | Ram forensics: The analysis and extraction of malicious processes from memory image using gui based memory forensic toolkit | |
Chen et al. | A survey on threat hunting: Approaches and applications | |
Chen | Contextual binding and intelligent targeting | |
Zhang | Application of Artificial Intelligence Technology in Computer Network Security. | |
Pierdomenico | Applied Feature Extraction for Novel Malicious Software Identification Using Convolutional Neural Networks | |
Jemal et al. | Detection of Ransomware Attack Using Deep Learning | |
Rao et al. | Digital forensics and digital investigation to form a suspension bridge flanked by law enforcement, prosecution, and examination of computer frauds and cybercrime |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
TA01 | Transfer of patent application right | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20190621 Address after: Room 431, Building 7, No. 5, No. 3 Road, Genshan Branch, Jianggan District, Hangzhou City, Zhejiang Province, 310004 Applicant after: Hangzhou Yidun Information Technology Co., Ltd. Address before: Room 411, Building 7, No. 5, No. 3 Road, Genshan Branch, Jianggan District, Hangzhou City, Zhejiang Province, 310004 Applicant before: Hangzhou Qi shield Information Technology Co., Ltd. |
|
CB03 | Change of inventor or designer information | ||
CB03 | Change of inventor or designer information |
Inventor after: Yang Runqing Inventor after: Xiong Chunlin Inventor after: Li Zhenyuan Inventor after: Song Zhe Inventor before: Yang Runqing Inventor before: Xiong Chunlin Inventor before: Li Zhenyuan Inventor before: Chen Yan Inventor before: Song Zhe |
|
TA01 | Transfer of patent application right | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20210804 Address after: 310000 room 431, building 7, No. 5, Genshan Zhisan Road, Jianggan District, Hangzhou City, Zhejiang Province Applicant after: Hangzhou Yidun Information Technology Co.,Ltd. Applicant after: HANGZHOU QIDUN INFORMATION TECHNOLOGY Co.,Ltd. Address before: Room 431, Building 7, No. 5, No. 3 Road, Genshan Branch, Jianggan District, Hangzhou City, Zhejiang Province, 310004 Applicant before: Hangzhou Yidun Information Technology Co.,Ltd. |
|
GR01 | Patent grant | ||
GR01 | Patent grant |