Method and system for searching for final virus parent
A virus and matrix technology, applied in the field of communication, can solve problems such as poor search results, inability to submit information, consume a lot of manpower, material resources, and time, and achieve the effect of improving search results, avoiding mistakes, and saving manpower, material resources, and time
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0032] In this embodiment, description will be made from the perspective of a virus final parent search system, and the virus final parent search system may specifically be integrated in a computer.
[0033] A method for finding the final parent of a virus, comprising: obtaining a pseudo-random system program; generating a hash value of the pseudo-random system program according to the pseudo-random system program, adding an index and a generation time to the hash value, and obtaining a processed hash value; filter the processed hash value to obtain the filtered hash value; establish a query table with index and time as the dimension according to the filtered hash value; obtain the hash value analysis sample according to the query table; run the Hash value analysis sample, and record the hash value information of all files released by the hash value analysis sample to generate a behavior log file; analyze the behavior log file to determine the final parent of the virus.
[003...
Embodiment 2
[0057] According to the method described in Embodiment 1, an example will be given below for further detailed description.
[0058] In this embodiment, the search system for the final parent of the virus specifically includes an information processing subsystem, a honeypot subsystem and an analysis subsystem, see Figure 2a , the details can be as follows:
[0059] 1. Information processing subsystem;
[0060] The information processing subsystem may include a sample behavior generation module, a whitelist filtering module and a data processing module, as follows:
[0061] The sample behavior generation module is mainly used to obtain the pseudo-random system program, generate the hash value of the pseudo-random system program according to the obtained pseudo-random system program, and add an index and generation time to the hash value to obtain the processed hash value, Output the processed hash value to the whitelist filtering module.
[0062] The whitelist filtering modu...
Embodiment 3
[0090] Correspondingly, the embodiment of the present invention also provides a search system for the final parent of the virus, such as image 3 As shown, the search system for the final parent of the virus includes a program acquisition unit 301, a generation unit 302, a filter unit 303, an establishment unit 304, a sample acquisition unit 305, an operation unit 306 and an analysis unit 307;
[0091] A program acquisition unit 301, configured to acquire a pseudo-random system program;
[0092] The generating unit 302 is configured to generate a hash value of the pseudo-random system program according to the obtained pseudo-random system program, and add an index and a generation time to the hash value to obtain a processed hash value;
[0093] A filtering unit 303, configured to filter the processed hash value to obtain a filtered hash value;
[0094] For example, the filtered hash value may specifically be a black hash value and / or a gray hash value, that is, the filtering...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


