Fine-grained RAT (remote administration tool) program detection method and system based on dynamic behaviors and corresponding APT (advanced persistent threat) attack detection method
A program detection, fine-grained technology, applied in the field of information security, can solve the problems of non-existence, expensive labor, and the detection system cannot provide semantics for detection results, and achieves the effect of ensuring accuracy and improving reliability.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Example Embodiment
[0052] The present invention will be described in detail below with reference to the drawings and specific embodiments.
[0053] A fine-grained RAT program detection method based on dynamic behavior, which obtains the dynamic data of the target program when it is running as the data to be checked, and matches the data to be checked with the signature of each fine-grained behavior. If there is a successful match Feature code, use the fine-grained behavior corresponding to the successfully matched feature code as the label of the target program, and determine whether the target program is a RAT program according to the label of the target program; the feature code of each fine-grained behavior described is obtained through the following steps :
[0054] Run different fine-grained behaviors through the RAT program, obtain the dynamic data of each fine-grained behavior runtime as training data, and record the fine-grained behavior corresponding to each dynamic data;
[0055] Feature mat...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap