標題: | MACHINE-IMPLEMENTED METHOD AND SYSTEM FOR DETERMINING WHETHER A TO-BE-ANALYZED SOFTWARE IS A KNOWN MALWARE OR A VARIANT OF THE KNOWN MALWARE |
作者: | Chiang Yi-Ta Lin Ying-Dar Wu Yu-Sung Lai Yuan-Cheng |
公開日期: | 17-五月-2012 |
摘要: | A machine-implemented method for determining whether a to-be-analyzed software is a known malware or a variant of the known malware includes the steps of: (A) configuring a processor to execute the to-be-analyzed software, and obtain a to-be-analyzed system call sequence that corresponds to the to-be-analyzed software with reference to a plurality of system calls made in sequence as a result of executing the to-be-analyzed software; (B) configuring the processor to determine a degree of similarity between the to-be-analyzed system call sequence and a reference system call sequence that corresponds to the known malware; and (C) configuring the processor to determine that the to-be-analyzed software is neither the known malware nor a variant of the known malware when the degree of similarity determined in step (B) is not greater than a predefined similarity threshold value. |
官方說明文件#: | G06F011/00 |
URI: | http://hdl.handle.net/11536/105178 |
專利國: | USA |
專利號碼: | 20120124667 |
顯示於類別: | 專利資料 |