Sample homology analysis method based on dynamic behavior chain and dynamic characteristics
A technology of dynamic features and analysis methods, applied in the field of homologous analysis of malicious samples, can solve the problems of identification ability, response time and work efficiency that cannot meet the requirements, and achieve the effect of solving low efficiency and large investment
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0042] The present invention aims to solve the problems existing in common methods of homology analysis, and make up for the shortcomings of mainstream analysis methods, that is, the feature rules are aimed at a single sample, which cannot adapt to the rapid change process of APT samples, and the resources and time overhead are too large, and there is a lag problem. The present invention provides a sample homologous analysis method based on dynamic behavior chains and dynamic features, through chain modeling and analysis of behavioral features during sample execution and matching of file IOCs information exposed during dynamic execution, to realize the detection of malicious samples homology analysis.
[0043] In order to make the object of the present invention clearer and the technical solution clearer, detailed steps will be described below in conjunction with the accompanying drawings. The training method in the content of the above-mentioned "technical solution" is "step ...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com