Method for constructing homology analysis knowledge base, method and device for homology analysis
A construction method and knowledge base technology, applied in the direction of file access structure, file/folder operation, platform integrity maintenance, etc., can solve problems such as large manpower constraints, inability to analyze network data, and existence of network threats
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0061] Please see figure 1 , figure 1 A schematic flowchart of a method for constructing a homology analysis knowledge base is provided for the embodiment of the present application. Wherein, the construction method of the homology analysis knowledge base includes:
[0062] S101. Collect seed sample files.
[0063] In this embodiment, the seed sample file is used to form a homology analysis knowledge base.
[0064] As an optional implementation manner, step S101 includes:
[0065] Collect original sample files;
[0066] The original samples are sorted to obtain seed sample files; wherein, the seed sample files include one or more of white sample files, Trojan horse family sample files, and APT organization sample files.
[0067] In this embodiment, the method can classify the collected original sample files, so that the original sample files are divided into white sample files, Trojan horse family sample files and APT organization sample files.
[0068] In this embodimen...
Embodiment 2
[0109] Please see figure 2 , figure 2 A schematic flowchart of a homology analysis method is provided for the embodiment of the present application. Wherein, the homology analysis method includes:
[0110] S201. Collect sample files to be analyzed.
[0111] In this embodiment, the method may accept a sample file input by a user for homology analysis.
[0112] S202. Collect intermediate files generated when the sample files to be analyzed are run in the sandbox.
[0113] In this embodiment, the method uses a sandbox to analyze the above-mentioned sample files to be analyzed to obtain intermediate files.
[0114] In this embodiment, this method can perform sample expansion on a sample file to be analyzed, so that the method can perform homologous analysis on two files, and obtain two homologous analysis results, so that it can finally be based on two homologous analysis results. The source analysis results determine the exact homology analysis results of the sample to be ...
Embodiment 3
[0138] Please see image 3 , image 3 It is a schematic structural diagram of an apparatus for constructing a homology analysis knowledge base provided in an embodiment of the present application. Such as image 3 As shown, the construction device of the homology analysis knowledge base includes:
[0139] A first collection unit 310, configured to collect seed sample files;
[0140] The first collecting unit 310 is also used to collect intermediate files generated when the seed sample files are running in the sandbox;
[0141] The first recognition unit 320 is configured to perform format recognition on the seed sample file and the intermediate file to obtain a format recognition result;
[0142] The first analysis unit 330 is configured to analyze the seed sample file and the intermediate file to obtain a fuzzy hash and / or a globally unique identifier matching the format recognition result;
[0143] The first acquiring unit 340 is configured to match the background infor...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


