Method for constructing homology analysis knowledge base, method and device for homology analysis
A construction method and technology of knowledge base, applied in knowledge expression, computer security device, other database retrieval, etc.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0063] Please see figure 1 , figure 1 A schematic flowchart of a method for constructing a homology analysis knowledge base is provided for the embodiment of the present application. Wherein, the construction method of the homology analysis knowledge base includes:
[0064] S101. Collect seed sample files.
[0065] In this embodiment, the method can collect various sample files and use them as seed sample files for homologous analysis knowledge base construction.
[0066] As an optional implementation manner, the step of collecting seed sample files includes:
[0067] Collect original sample files;
[0068] The original samples are sorted to obtain the seed sample files; wherein, the seed sample files include one or more of class library related files, shell related files, and application programs.
[0069] In this embodiment, the method can classify and organize the collected seed sample files to obtain three specific categories of files. Among them, the first category ...
Embodiment 2
[0099] Please see figure 2 , figure 2 A schematic flowchart of a homology analysis method is provided for the embodiment of the present application. Wherein, the homology analysis method includes:
[0100] S201. Obtain a sample file to be analyzed.
[0101] In this embodiment, the method receives a sample file to be analyzed for homologous analysis.
[0102] S202. Collect intermediate files generated when the sample files to be analyzed are run in the sandbox.
[0103] In this embodiment, the method uses the sandbox to analyze the input sample file to be analyzed to obtain the intermediate file.
[0104] S203. Perform format recognition on the sample file to be analyzed and the intermediate file, and obtain a format recognition result.
[0105] S204. Based on the format recognition result, extract the file character string contained in the sample file to be analyzed and the intermediate file.
[0106] In this embodiment, the method can statically analyze the sample fil...
Embodiment 3
[0123] Please see image 3 , image 3 It is a schematic structural diagram of an apparatus for constructing a homology analysis knowledge base provided in an embodiment of the present application. Such as image 3 As shown, the construction device of the homology analysis knowledge base includes:
[0124] A first collection unit 310, configured to collect seed sample files;
[0125] The first collecting unit 310 is also used to collect intermediate files generated when the seed sample files are running in the sandbox;
[0126] The first recognition unit 320 is configured to perform format recognition on the seed sample file and the intermediate file to obtain a format recognition result;
[0127] The first extracting unit 330 is used to extract the file string contained in the seed sample file and the intermediate file based on the format recognition result;
[0128] The first filtering unit 340 is configured to filter and classify file strings to obtain meaningful string...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


