CN109460386B - 基于多维模糊哈希匹配的恶意文件同源性分析方法及装置 - Google Patents
基于多维模糊哈希匹配的恶意文件同源性分析方法及装置 Download PDFInfo
- Publication number
- CN109460386B CN109460386B CN201811272132.4A CN201811272132A CN109460386B CN 109460386 B CN109460386 B CN 109460386B CN 201811272132 A CN201811272132 A CN 201811272132A CN 109460386 B CN109460386 B CN 109460386B
- Authority
- CN
- China
- Prior art keywords
- hash
- file
- matching
- fuzzy
- fuzzy hash
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000004458 analytical method Methods 0.000 title claims abstract description 20
- 238000000034 method Methods 0.000 claims abstract description 18
- 238000013467 fragmentation Methods 0.000 claims description 12
- 238000006062 fragmentation reaction Methods 0.000 claims description 12
- 238000003491 array Methods 0.000 claims description 7
- 238000006243 chemical reaction Methods 0.000 claims description 4
- 238000000605 extraction Methods 0.000 claims description 4
- 230000008676 import Effects 0.000 claims description 3
- 238000001514 detection method Methods 0.000 description 5
- 238000010586 diagram Methods 0.000 description 2
- 238000012986 modification Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 238000013459 approach Methods 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 230000007547 defect Effects 0.000 description 1
- 238000012217 deletion Methods 0.000 description 1
- 230000037430 deletion Effects 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000006870 function Effects 0.000 description 1
- 238000003780 insertion Methods 0.000 description 1
- 230000037431 insertion Effects 0.000 description 1
- 230000003287 optical effect Effects 0.000 description 1
- 230000008569 process Effects 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
- 238000006467 substitution reaction Methods 0.000 description 1
Images
Landscapes
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Abstract
Description
Claims (6)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201811272132.4A CN109460386B (zh) | 2018-10-29 | 2018-10-29 | 基于多维模糊哈希匹配的恶意文件同源性分析方法及装置 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201811272132.4A CN109460386B (zh) | 2018-10-29 | 2018-10-29 | 基于多维模糊哈希匹配的恶意文件同源性分析方法及装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN109460386A CN109460386A (zh) | 2019-03-12 |
CN109460386B true CN109460386B (zh) | 2021-01-22 |
Family
ID=65608807
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201811272132.4A Active CN109460386B (zh) | 2018-10-29 | 2018-10-29 | 基于多维模糊哈希匹配的恶意文件同源性分析方法及装置 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN109460386B (zh) |
Families Citing this family (9)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110363000B (zh) * | 2019-07-10 | 2023-11-17 | 深圳市腾讯网域计算机网络有限公司 | 识别恶意文件的方法、装置、电子设备及存储介质 |
CN112347477A (zh) * | 2019-08-07 | 2021-02-09 | 腾讯云计算(北京)有限责任公司 | 家族变种恶意文件挖掘方法和装置 |
US11449608B2 (en) * | 2019-10-14 | 2022-09-20 | Microsoft Technology Licensing, Llc | Computer security using context triggered piecewise hashing |
CN112084146A (zh) * | 2020-09-08 | 2020-12-15 | 国网上海市电力公司 | 基于多维特征的固件同源性检测方法 |
CN112487432A (zh) * | 2020-12-10 | 2021-03-12 | 杭州安恒信息技术股份有限公司 | 一种基于图标匹配的恶意文件检测的方法、系统及设备 |
CN112818347B (zh) * | 2021-02-22 | 2024-04-09 | 深信服科技股份有限公司 | 一种文件标签确定方法、装置、设备及存储介质 |
CN114021116B (zh) * | 2022-01-05 | 2022-03-29 | 北京微步在线科技有限公司 | 一种同源分析知识库的构建方法、同源分析方法及装置 |
CN114491539A (zh) * | 2022-02-16 | 2022-05-13 | 上海斗象信息科技有限公司 | 文件检测方法、装置、设备及计算机可读存储介质 |
CN116708008A (zh) * | 2023-07-18 | 2023-09-05 | 山东溯源安全科技有限公司 | 确定变电站系统中恶意文件的方法、电子设备及存储介质 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN105868305A (zh) * | 2016-03-25 | 2016-08-17 | 西安电子科技大学 | 一种支持模糊匹配的云存储数据去重复方法 |
CN106682505A (zh) * | 2016-05-04 | 2017-05-17 | 腾讯科技(深圳)有限公司 | 一种病毒检测方法、终端、服务器及系统 |
CN107273746A (zh) * | 2017-05-18 | 2017-10-20 | 广东工业大学 | 一种基于apk字符串特征的变种恶意软件检测方法 |
CN108073815A (zh) * | 2017-12-29 | 2018-05-25 | 哈尔滨安天科技股份有限公司 | 基于代码切片的家族判定方法、系统及存储介质 |
Family Cites Families (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US9294501B2 (en) * | 2013-09-30 | 2016-03-22 | Fireeye, Inc. | Fuzzy hash of behavioral results |
CN103902910B (zh) * | 2013-12-30 | 2016-07-13 | 北京奇虎科技有限公司 | 检测智能终端中恶意代码的方法及装置 |
WO2018148591A1 (en) * | 2017-02-10 | 2018-08-16 | Secured FTP Hosting, LLC d/b/a SmartFile | System for describing and tracking the creation and evolution of digital files |
US10440051B2 (en) * | 2017-03-03 | 2019-10-08 | Bank Of America Corporation | Enhanced detection of polymorphic malicious content within an entity |
-
2018
- 2018-10-29 CN CN201811272132.4A patent/CN109460386B/zh active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN105868305A (zh) * | 2016-03-25 | 2016-08-17 | 西安电子科技大学 | 一种支持模糊匹配的云存储数据去重复方法 |
CN106682505A (zh) * | 2016-05-04 | 2017-05-17 | 腾讯科技(深圳)有限公司 | 一种病毒检测方法、终端、服务器及系统 |
CN107273746A (zh) * | 2017-05-18 | 2017-10-20 | 广东工业大学 | 一种基于apk字符串特征的变种恶意软件检测方法 |
CN108073815A (zh) * | 2017-12-29 | 2018-05-25 | 哈尔滨安天科技股份有限公司 | 基于代码切片的家族判定方法、系统及存储介质 |
Also Published As
Publication number | Publication date |
---|---|
CN109460386A (zh) | 2019-03-12 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN109460386B (zh) | 基于多维模糊哈希匹配的恶意文件同源性分析方法及装置 | |
US10621493B2 (en) | Multiple record linkage algorithm selector | |
Breitinger et al. | Approximate matching: definition and terminology | |
JP6893209B2 (ja) | 構造化されたマルチフィールドファイルのレイアウトの自動解釈 | |
CN110674360B (zh) | 一种用于数据的溯源方法和系统 | |
CN111723371A (zh) | 构建恶意文件的检测模型以及检测恶意文件的方法 | |
CN106844553B (zh) | 基于样本数据的数据探测和扩充方法及装置 | |
CN112364014A (zh) | 数据查询方法、装置、服务器及存储介质 | |
CN113688240A (zh) | 威胁要素提取方法、装置、设备及存储介质 | |
CN114816518A (zh) | 基于simhash的源代码中开源成分筛选识别方法及系统 | |
CN109064067B (zh) | 基于互联网的金融风险运营主体判定方法及装置 | |
WO2017080183A1 (zh) | 网络小说章节列表评估方法及装置 | |
CN112100670A (zh) | 一种基于大数据的隐私数据分级保护方法 | |
CN115905373B (zh) | 一种数据查询以及分析方法、装置、设备及存储介质 | |
CN114706899B (zh) | 快递数据的敏感度计算方法、装置、存储介质及设备 | |
CN114021116B (zh) | 一种同源分析知识库的构建方法、同源分析方法及装置 | |
CN114021138B (zh) | 一种同源分析知识库的构建方法、同源分析方法及装置 | |
CN108132941B (zh) | 法律文献的关联关系的处理方法和装置 | |
Moia et al. | A comparative analysis about similarity search strategies for digital forensics investigations | |
CN114995880A (zh) | 一种基于SimHash的二进制代码相似性比对方法 | |
Chen et al. | CGAP-align: a high performance DNA short read alignment tool | |
CN118467669B (zh) | 索引构建方法、字段搜索方法、装置、设备及介质 | |
CN115622818B (zh) | 一种网络攻击数据处理方法及装置 | |
KR102655234B1 (ko) | 고속 패킷 검색 방법 및 장치 | |
CN117313111B (zh) | 一种基于汽车信息安全测试用例的标注与索引方法和系统 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
CB02 | Change of applicant information |
Address after: No. 188, Lianhui street, Xixing street, Binjiang District, Hangzhou, Zhejiang Province, 310000 Applicant after: Dbappsecurity Co.,Ltd. Address before: 310000 15-storey Zhejiang Zhongcai Building, No. 68 Tonghe Road, Binjiang District, Hangzhou City, Zhejiang Province Applicant before: Dbappsecurity Co.,Ltd. |
|
CB02 | Change of applicant information | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20190312 Assignee: Hangzhou Anheng Information Security Technology Co.,Ltd. Assignor: Dbappsecurity Co.,Ltd. Contract record no.: X2024980043368 Denomination of invention: Method and device for malicious file homology analysis based on multidimensional fuzzy hash matching Granted publication date: 20210122 License type: Common License Record date: 20241231 |
|
EE01 | Entry into force of recordation of patent licensing contract |