首页> 外国专利> MALWARE ANALYSIS AND VARIANTS DETECTION METHODS USING VISUALIZATION OF BINARY INFORMATION, APPARATUS FOR PROCESSING THE SAME METHOD

MALWARE ANALYSIS AND VARIANTS DETECTION METHODS USING VISUALIZATION OF BINARY INFORMATION, APPARATUS FOR PROCESSING THE SAME METHOD

机译:使用二进制信息可视化的恶意软件分析和变异检测方法,用于处理相同方法的设备

摘要

The present invention relates to a method for detecting and classifying a variant by analyzing features of a malignant code by extracting and visualizing binary information of the malignant code. The present invention includes a step of extracting multiple assembly code blocks formed of an assembly code by dissembling a binary file; a step of generating an operation command group from a command included in each of the assembly code blocks; a step of generating an image matrix by using the operation command group; a step of calculating the similarity of the image matrix; and a step of determining a variant relationship of malignant code binary based on the calculated similarity.
机译:本发明涉及一种通过提取和可视化恶性代码的二进制信息来分析恶性代码的特征以检测和分类变体的方法。本发明包括通过分解二进制文件提取由汇编代码形成的多个汇编代码块的步骤。从每个汇编代码块中包括的命令生成操作命令组的步骤;使用操作命令组生成图像矩阵的步骤;计算图像矩阵相似度的步骤;根据所计算的相似度确定恶性代码二进制的变体关系的步骤。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号