会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 3. 发明授权
    • Encoding machine code instructions for static feature based malware clustering
    • 编码基于静态功能的恶意软件集群的机器代码说明
    • US08826439B1
    • 2014-09-02
    • US13014552
    • 2011-01-26
    • Xin HuKent E. GriffinSandeep B. Bhatkar
    • Xin HuKent E. GriffinSandeep B. Bhatkar
    • G06F11/00G06F21/56
    • G06F21/56G06F21/563
    • Machine language instruction sequences of computer files are extracted and encoded into standardized opcode sequences. The standardized opcodes in the sequences are of the same length and do not include operands. A multi-dimension vector is generated as a static feature for each computer file, where each element in the vector corresponds to the number of occurrences of a unique N-gram (i.e., unique sequence of N consecutive standardized opcodes) in the standardized opcode sequence for that computer file. The computer files are clustered into clusters of similarly classified files based on similarities of their static features. An unknown computer file can be classified by first grouping the file into a cluster of files with similar static features (e.g., into the cluster with the shortest average distance), and then determining the classification of that file based on the classifications of other files that belong to the same cluster.
    • 计算机文件的机器语言指令序列被提取并编码成标准化的操作码序列。 序列中的标准化操作码具有相同的长度,不包括操作数。 生成多维向量作为每个计算机文件的静态特征,其中向量中的每个元素对应于标准化操作码序列中唯一N-gram(即,N个连续标准化操作码的唯一序列)的出现次数 为该计算机文件。 基于其静态特征的相似性,将计算机文件聚类成类似分类文件的群集。 可以通过首先将文件分组成具有相似静态特征的文件集(例如,到具有最短平均距离的集群),然后基于其他文件的分类来确定该文件的分类,来分类未知的计算机文件 属于同一个集群。
    • 5. 发明申请
    • APPARATUS AND METHOD FOR DETECTION OF MALICIOUS PROGRAM USING PROGRAM BEHAVIOR
    • 使用程序行为检测恶意程序的装置和方法
    • US20090049549A1
    • 2009-02-19
    • US12099649
    • 2008-04-08
    • Taejoon ParkKang Geun ShinXin HuAbhijit Bose
    • Taejoon ParkKang Geun ShinXin HuAbhijit Bose
    • G06F11/30G06F7/04
    • G06F21/552G06F21/55G06F21/56
    • An apparatus and method of diagnosing whether a computer program executed in a computer system is a malicious program and more particularly, an apparatus and method of diagnosing whether a computer program is a malicious program using a behavior of a computer program, and an apparatus and method of generating malicious code diagnostic data is provided. The apparatus for diagnosing a malicious code may include a behavior vector generation unit which generates a first behavior vector based on a behavior signature extracted from a diagnostic target program; a diagnostic data storage unit which stores a plurality of second behavior vectors for a plurality of sample programs predetermined to be malicious or normal; and a code diagnostic unit which diagnoses whether the diagnostic target program is a malicious code by comparing the first behavior vector with the plurality of second behavior vectors.
    • 一种用于诊断在计算机系统中执行的计算机程序是否是恶意程序的装置和方法,更具体地,涉及使用计算机程序的行为来诊断计算机程序是恶意程序的装置和方法,以及装置和方法 提供了生成恶意代码诊断数据。 用于诊断恶意代码的装置可以包括行为向量生成单元,其基于从诊断目标程序提取的行为签名来生成第一行为向量; 诊断数据存储单元,其存储预定为恶意或正常的多个样本程序的多个第二行为向量; 以及代码诊断单元,其通过将所述第一行为向量与所述多个第二行为向量进行比较来诊断所述诊断对象程序是否是恶意代码。
    • 10. 发明授权
    • Apparatus and method for repairing computer system infected by malware
    • 用于修复受恶意软件感染的计算机系统的装置和方法
    • US08448248B2
    • 2013-05-21
    • US12056236
    • 2008-03-26
    • Abhijit BoseTaejoon ParkKang Geun ShinXin Hu
    • Abhijit BoseTaejoon ParkKang Geun ShinXin Hu
    • G06F11/00
    • G06F21/568G06F21/566
    • An apparatus and method of diagnosing whether a program executed in a computer system is malware and repairing the computer system infected by malware. The apparatus includes a receiving unit which receives a first behavior vector for the malware from a malware control server; a determination unit which determines whether a diagnostic target program corresponds to malware based on the received first behavior vector and a second behavior vector for the diagnostic target program; and a repair unit which repairs the computer system based on a result of the determination.A behavior of a computer program executed in the computer system may be modeled in real time.
    • 诊断在计算机系统中执行的程序是否是恶意软件并修复被恶意软件感染的计算机系统的装置和方法。 该装置包括从恶意软件控制服务器接收恶意软件的第一行为向量的接收单元; 确定单元,其基于所接收的第一行为向量和用于诊断目标程序的第二行为向量来确定诊断目标程序是否对应​​于恶意软件; 以及基于确定结果修复计算机系统的修理单元。 计算机系统中执行的计算机程序的行为可以被实时建模。