A malware feature extraction method and device, electronic equipment and storage medium

CN115766274BActive Publication Date: 2026-09-29HARBIN ANTIY TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211528893.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-30
Publication Date
2026-09-29
Estimated Expiration
2042-11-30

AI Technical Summary

Technical Problem

目前,现有技术通常不能有效地提取到模块化恶意软件的恶意行为特征,难以及时确定恶意软件的攻击行为

Benefits of technology

[0049]本发明实施例提供了一种恶意软件特征提取方法、装置、电子设备及存储介质,本发明通过静态行为特征识别,结合动态运行进行行为特征提取,获得多个代表恶意软件行为的特征项,基于所得的特征项与已有样本特征库进行比较,寻找出与当前的样本数据耦合度最高的已有样本,然后将当前的样本数据和已有样本一同按照耦合关系进行行为特征提取,从而提取到更多的行为特征;本发明能够基于耦合度关联模块化恶意软件,获取相应的关联行为特征,实现关联检测,可提高对模块化恶意软件上下游分析能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115766274B_ABST
    Figure CN115766274B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of network security, and particularly relates to a malware feature extraction method and device, electronic equipment and storage medium, wherein the method comprises: obtaining sample data; performing behavior feature recognition on the sample data to obtain a static feature set; performing behavior feature extraction on the sample data to obtain a dynamic feature set; obtaining a feature vector based on the static feature set and the dynamic feature set; calculating the coupling degree between the sample data and each existing sample in a sample feature library according to the feature vector and a coupling rule, determining the existing sample with the highest coupling degree with the sample data and the corresponding coupling relationship; performing behavior feature extraction on the sample data and the existing sample according to the coupling relationship to obtain a coupling relationship feature set; and updating the feature vectors corresponding to the sample data and the existing sample based on the coupling relationship feature set and storing them in the sample feature library. The present application can modularize malware based on a coupling degree correlation module, obtain corresponding correlation behavior features, and realize correlation detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, electronic device, and storage medium for extracting malicious software features. Background Technology

[0002] In cybersecurity protection, modular malware evades traditional antivirus software by distributing malicious behavior across multiple modules or steps. Currently, existing technologies are generally unable to effectively extract the malicious behavior characteristics of modular malware, making it difficult to promptly identify malware attack activities. Summary of the Invention

[0003] To address the problem that existing technologies struggle to extract malicious behavior features from modular malware in a timely manner, this invention provides a malware feature extraction method, apparatus, electronic device, and storage medium. These methods can associate modular malware based on coupling degree and obtain corresponding associated behavioral features, thereby achieving association detection and improving the upstream and downstream analysis capabilities of modular malware.

[0004] In a first aspect, embodiments of the present invention provide a method for extracting malicious software features, including:

[0005] Obtain sample data of malware;

[0006] The sample data is subjected to behavioral feature recognition to obtain a static feature set of the sample data; the behavioral features include behavioral type, object type, and object name.

[0007] Behavioral features are extracted from the sample data to obtain a dynamic feature set of the sample data;

[0008] Based on the static feature set and the dynamic feature set, the feature vector corresponding to the sample data is obtained;

[0009] Based on the corresponding feature vector and the preset coupling degree rule, calculate the coupling degree between the sample data and each existing sample in the sample feature library, and determine the existing sample with the highest coupling degree with the sample data and the corresponding coupling relationship.

[0010] The sample data and the existing sample with the highest coupling degree with the sample data are subjected to behavioral feature extraction according to the corresponding coupling relationship to obtain the coupling relationship feature set;

[0011] Based on the coupling relationship feature set, the feature vectors corresponding to the sample data and the existing samples with the highest coupling degree with the sample data are updated and stored in the sample feature library to obtain the updated sample feature library.

[0012] Optionally, the step of performing behavioral feature recognition on the sample data includes:

[0013] Data parsing is performed on the plaintext data in the sample data to determine all operation instructions involved in the plaintext data;

[0014] Behavioral feature identification is performed based on all operational instructions involved in the plaintext data;

[0015] By decrypting the encrypted data in the sample data, a decrypted string is obtained;

[0016] Based on the decrypted string, data is parsed to determine all operation instructions involved in the encrypted data;

[0017] Behavioral characteristics are identified based on all operational instructions involved in the encrypted data.

[0018] Optionally, obtaining the feature vector corresponding to the sample data based on the static feature set and the dynamic feature set includes:

[0019] Based on the filtering list, behavioral features in the static feature set and the dynamic feature set are filtered respectively, and behavioral features existing in the filtering list are removed; wherein, the filtering list includes a system benchmark list and a whitelist list;

[0020] Based on the filtered static feature set and the behavioral features in the dynamic feature set, the feature vector of the sample data is obtained.

[0021] Optionally, calculating the coupling degree between the sample data and each existing sample in the sample feature library based on the corresponding feature vector and a preset coupling degree rule includes:

[0022] Based on the feature vectors corresponding to the sample data, determine the feature terms and corresponding weights of all coupling values ​​to be calculated, and group them according to object type;

[0023] For each existing sample in the sample feature library, perform the following operation:

[0024] Based on the feature vectors corresponding to existing samples, determine all feature terms for which the coupling degree value is to be calculated, and group them according to object type;

[0025] The group corresponding to the sample data is matched with the group corresponding to the existing sample. If there is a group with the same object type, the coupling degree value is calculated one by one between each feature item in the group corresponding to the sample data and each feature item in the group corresponding to the existing sample, according to the preset coupling degree rule.

[0026] The coupling degree between the existing sample and the sample data is obtained by weighted summation of all the calculated coupling degree values.

[0027] Optionally, determining the feature terms and corresponding weights of all features whose coupling degree values ​​are to be calculated based on the feature vector corresponding to the sample data includes:

[0028] Based on the feature vectors corresponding to the sample data, determine all feature terms for which the coupling degree value is to be calculated.

[0029] Based on the feature terms for which the coupling degree value is to be calculated and the sample feature library, determine the number of times each feature term for which the coupling degree value is to be calculated appears in the sample feature library;

[0030] The weight of each feature is determined based on the number of times it appears in the sample feature library; the number of times a feature appears is inversely proportional to its corresponding weight.

[0031] Optionally, the coupling rule includes:

[0032] For two feature items, if the object names are the same but the behavior types are different, the coupling value is recorded as 1;

[0033] If objects have the same name and the same behavior type, the coupling value is recorded as 0.5;

[0034] If the object names and behavior types are different, the coupling value is recorded as 0.

[0035] Optionally, obtaining sample data of malware further includes:

[0036] Determine the environmental characteristics that include the source information of the sample data;

[0037] After obtaining the feature vector corresponding to the sample data based on the static feature set and the dynamic feature set, and before calculating the coupling degree between the sample data and each existing sample in the sample feature library according to the corresponding feature vector and a preset coupling degree rule, the method further includes:

[0038] Based on environmental characteristics, the dimensionality of the feature vector corresponding to the obtained sample data is expanded.

[0039] Secondly, embodiments of the present invention also provide a malware feature extraction device, comprising:

[0040] The sample acquisition module is used to acquire sample data of malware.

[0041] A static recognition module is used to perform behavioral feature recognition on the sample data to obtain a static feature set of the sample data; the behavioral features include behavioral type, object type, and object name.

[0042] The dynamic extraction module is used to extract behavioral features from the sample data to obtain a dynamic feature set of the sample data.

[0043] A vector construction module is used to obtain the feature vector corresponding to the sample data based on the static feature set and the dynamic feature set;

[0044] The coupling calculation module is used to calculate the coupling degree between the sample data and each existing sample in the sample feature library according to the corresponding feature vector and the preset coupling degree rule, and to determine the existing sample with the highest coupling degree with the sample data and the corresponding coupling relationship.

[0045] The coupling extraction module is used to extract behavioral features from the sample data and the existing samples with the highest coupling degree to the sample data according to the corresponding coupling relationship, so as to obtain a coupling relationship feature set.

[0046] The feature update module is used to update the feature vectors corresponding to the sample data and the existing samples with the highest coupling degree to the sample data based on the coupling relationship feature set, and store them in the sample feature library to obtain the updated sample feature library.

[0047] Thirdly, embodiments of the present invention also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the method described in any embodiment of this specification.

[0048] Fourthly, embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the methods described in any embodiment of this specification.

[0049] This invention provides a method, apparatus, electronic device, and storage medium for extracting malware features. The invention extracts behavioral features by combining static behavioral feature recognition with dynamic operation, obtaining multiple feature items representing malware behavior. Based on the obtained feature items, it compares them with an existing sample feature library to identify the existing sample with the highest coupling degree to the current sample data. Then, it extracts behavioral features from the current sample data and the existing sample together according to their coupling relationship, thereby extracting more behavioral features. This invention can associate modular malware based on coupling degree, obtain corresponding associated behavioral features, and achieve associated detection, thus improving the ability to analyze the upstream and downstream of modular malware. Attached Figure Description

[0050] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0051] Figure 1 This is a flowchart of a malware feature extraction method provided by an embodiment of the present invention;

[0052] Figure 2 This is a hardware architecture diagram of an electronic device provided in an embodiment of the present invention;

[0053] Figure 3 This is a structural diagram of a malware feature extraction device provided in an embodiment of the present invention. Detailed Implementation

[0054] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0055] Modular malware refers to malware that employs multi-stage payload deployment or distributes malicious behavior across multiple modules for on-demand invocation. As mentioned earlier, modular malware evades detection by distributing malicious behavior across multiple modules or steps. To detect and analyze modular malware, it is necessary to correlate the malware and promptly identify its attack behavior.

[0056] Currently, malware association technology primarily relies on endpoint antivirus engines and traffic monitoring devices to capture sample behavior and traffic, then compares and analyzes this data against an accumulated database. This method can identify general malware. However, for advanced threat actors, whose attack methods are diverse and who actively use new intrusion techniques, while matching against an accumulated database can certainly detect them, the discovery time is often after the attacker has already launched the attack, by which time the attacked organization has already suffered significant losses.

[0057] The common method for associating upstream and downstream process components involves forming a software execution chain (execution tree) based on records during software execution. This allows for the extension of associations based on discovered malicious behavior to all execution entities involved in the entire execution chain. This method has limitations: First, an execution chain cannot be constructed when the software is not executing; once constructed, it proves that malicious code has already gained execution privileges. Second, modular malware often employs anti-virus and obfuscation techniques to prevent detection, and many encryption and decryption operations are performed on non-persistent storage media, making them impossible to record in the software execution chain. Third, modular malware may generate numerous obfuscated behaviors or restart the machine to complete the next stage of behavior during execution, disrupting the integrity of the execution chain and thus evading association detection methods that use software execution behavior to discover malware.

[0058] In view of this, the present invention proposes a dynamic and static combined association technology, which can associate modular malware based on coupling degree and obtain corresponding association behavior features, so as to use association behavior features to achieve detection and improve the ability to analyze the upstream and downstream of modular malware.

[0059] The following describes the specific implementation of the above concept.

[0060] Please refer to Figure 1 This invention provides a method for extracting malicious software features (hereinafter referred to as the feature extraction method), comprising:

[0061] Step 100: Obtain sample data of malware;

[0062] Step 102: Perform behavioral feature recognition on the acquired sample data to obtain a static feature set of the sample data; the behavioral features include behavioral type, object type, and object name; the static feature set includes all behavioral features identified in step 102.

[0063] In step 102, when the sample data is not running, behavioral characteristics can be obtained by performing static data parsing on the sample data. The object type of the behavior may include the registry, file, event and window, which can be a modular process interface or a reusable interface. The object name is the corresponding registry name, file name, event name and window name, etc.

[0064] Step 104: Extract behavioral features from the sample data to obtain a dynamic feature set of the sample data; the dynamic feature set includes all the behavioral features extracted in step 104.

[0065] In step 104, the sample data can be put into a sandbox. While the sample data is running, behavioral features are dynamically extracted through the sandbox. The extracted behavioral features also include behavior type, object type, and object name. The sandbox can refer to existing technology, which will not be described in detail here. By actually running the sample data in the sandbox, behavioral features that were not identified by static data parsing may be obtained.

[0066] Step 106: Based on the static feature set and the dynamic feature set, obtain the feature vector corresponding to the sample data;

[0067] In step 106, a corresponding feature vector is constructed for the sample data. The feature vector can be considered to include two parts: one part is the behavioral features identified from static data parsing, and the other part is the behavioral features dynamically extracted from the sandbox.

[0068] Step 108: Calculate the coupling degree between the sample data and each existing sample in the sample feature library according to the corresponding feature vector and the preset coupling degree rule, and determine the existing sample with the highest coupling degree with the sample data and the corresponding coupling relationship.

[0069] This step 108 aims to determine whether there is a coupling relationship between the existing sample feature library and the current sample data, so as to analyze whether there is an existing sample and the current sample data belonging to the same modular malware. For example, if the current sample data has a behavior of creating a registry with the name A, and there is a corresponding existing sample in the sample feature library with a behavior of reading a registry with the name A, then it can be considered that there is a coupling relationship between the two, and they may both belong to the same modular malware, so it is necessary to associate them.

[0070] Step 110: Extract behavioral features from the sample data and the existing samples with the highest coupling degree to the sample data according to the corresponding coupling relationship to obtain a coupling relationship feature set; the coupling relationship feature set includes all the behavioral features extracted in step 110.

[0071] In step 110, the sample data and the existing sample with the highest coupling degree to the sample data can be put into a sandbox according to the corresponding coupling relationship. Under the association of the two, actual operation and behavioral feature extraction are performed. For example, if the current sample data has a behavior of creating a registry with the name A, and the existing sample with the highest coupling degree has a behavior of reading the registry with the name A, then the current sample data is run first to create registry A in the sandbox, and then the existing sample is run to read registry A, so as to extract the behavioral features that appear under the association operation through the sandbox.

[0072] Step 112: Based on the coupling relationship feature set, update the feature vectors corresponding to the sample data and the existing samples with the highest coupling degree with the sample data, and store them in the sample feature library to obtain the updated sample feature library.

[0073] Step 112 adds the behavioral characteristics that occur during associated operation to the sample feature library, so that subsequent malware analysis and detection can be performed based on the behavioral characteristics in the feature vectors. The sample feature library preferably stores the data of existing samples themselves and their corresponding feature vectors, so that users can search for and obtain the feature vectors and the data of existing samples themselves. Alternatively, it can only store the feature vectors corresponding to existing samples, while storing the data of existing samples themselves in another sample database. When the data of existing samples themselves is needed, it can be retrieved from the other sample database.

[0074] The malware feature extraction method provided by this invention uses a combination of static and dynamic methods to obtain behavioral features. Then, it associates different samples based on the degree of coupling. According to the coupling relationship, the associated samples are put into a sandbox to extract new features, thereby obtaining more coupling features and realizing correlation detection to improve the upstream and downstream analysis capabilities of modular malware.

[0075] Currently, modular malware delivery methods often use non-executable software to lure users into execution during the initial access phase, such as through .lnk shortcuts, .vbs, or .jse scripts. Subsequently, the command execution capability is used to remotely download and execute a second-stage payload to complete more complex intrusions. The second-stage payload can be a dynamic link library (DLL), such as a .NET DLL, which cannot be executed independently in a sandbox to evade detection. In this case, the first-stage payload must contain explicit payload execution commands, such as exported functions called by the DLL and the parameters used. In this scenario, the URL (i.e., object name) where the second-stage payload is stored serves as a marker of coupling between the first and second stages, and the exported functions (i.e., object names) called by the library file also serve as markers of this coupling.

[0076] In the above scenarios, the second-stage payload is mostly executed in memory and does not have a physical file. Therefore, the second-stage payload cannot be obtained on the host side, and its behavior cannot be accurately determined by the traffic side due to its unknown execution method. In this case, the feature extraction method provided by this invention can determine the coupling relationship between the two stages based on dynamic and static detection. Then, based on this coupling relationship, the first and second-stage payloads are placed together in a sandbox to detect and extract new behavioral features, which are then used to couple any potential third-stage payloads.

[0077] Optionally, the behavioral feature recognition in step 102 further includes:

[0078] Data parsing is performed on the plaintext data in the acquired sample data to determine all operation instructions involved in the plaintext data; operation instructions correspond to actions, and the information in the operation instructions includes action type, object type, and object name;

[0079] Based on all the operation instructions involved in the plaintext data, perform behavioral feature identification, that is, determine the corresponding behavior type, object type and object name;

[0080] By decrypting the encrypted data in the acquired sample data, a decrypted string is obtained;

[0081] Based on the obtained decryption string, data is parsed to determine all operation instructions involved in the encrypted data;

[0082] Behavioral characteristics are identified based on all operational instructions involved in the encrypted data.

[0083] Using the above embodiments, not only can the behavioral characteristics involved in plaintext data in the sample be identified, but also the behavioral characteristics involved in encrypted data can be identified, enabling the acquisition of more behavioral characteristics that malicious software attempts to hide. Specifically, by decrypting the encrypted data in the sample data to obtain the decrypted string, existing technologies can be referenced, or the following information detection method can be used to decrypt and extract behavioral characteristics. The information detection method includes:

[0084] Based on a pre-defined algorithm feature library, the target algorithm in the sample file is identified;

[0085] Based on the algorithm address of the target algorithm in the sample file, the algorithm parameters and parameter addresses of the target algorithm are obtained at the algorithm address using the disassembly engine;

[0086] Based on the algorithm type, algorithm parameters, and parameter addresses of the target algorithm, the target algorithm is simulated and run to obtain simulation results;

[0087] The simulation results are checked for abnormality using a predetermined detection method corresponding to the data type of the simulation results.

[0088] For algorithms that are easily exploited by malicious code and difficult to identify using conventional malware detection methods, especially encryption algorithms, the aforementioned information detection methods can identify them from sample files. Simulation runs can then be performed outside the sample file to obtain simulation results. These results can then be used in subsequent steps to determine whether the sample file is abnormal and contains malicious code. In this way, regardless of whether the algorithm and its related data in the sample file are encrypted or how they are encrypted, their security can be tested by externally calling and simulating them. This avoids situations where the limitations of the sample file itself prevent effective detection of malicious code, enabling quick and effective security detection of sample files, facilitating accurate identification of malicious code, and protecting computer network security.

[0089] Optionally, step 106 further includes:

[0090] Based on the filtering list, behavioral features in the static feature set and the dynamic feature set are filtered separately, and behavioral features existing in the filtering list are removed; wherein, the filtering list includes a system benchmark list and a whitelist list; the system benchmark list is determined based on the system; the whitelist list is determined based on user instructions;

[0091] Based on the filtered static feature set and the behavioral features in the dynamic feature set, the feature vector of the sample data is obtained.

[0092] Using the above embodiments, routine behavioral features that lack discriminative value can be filtered out using the system benchmark list and whitelist list. This removes some behavioral features that are not of reference value. On the one hand, it allows for targeted extraction of malicious software behavioral features, reducing computational and analytical workload. On the other hand, it avoids some routine behaviors affecting the coupling between judgment samples. The resulting feature vector can be directly concatenated with feature items from the filtered static feature set and feature items from the filtered dynamic feature set, or it can store only non-repeating feature items and label them as coming from the static feature set and / or the dynamic feature set.

[0093] Optionally, prior to step 108, the feature extraction method further includes:

[0094] Determine whether the sample data is a duplicate of an existing sample in the sample feature library. If so, discard the current sample data and return to the step of obtaining sample data of malware, that is, return to step 100 and obtain new sample data again.

[0095] By employing the above embodiments, duplicate sample data can be removed before calculating the coupling degree, avoiding redundant calculations of the same samples. Furthermore, calculating the coupling degree between two identical samples may interfere with the search for correlations between samples. In other embodiments, duplicate samples can also be removed by calculating the coupling degree or similar methods.

[0096] Optionally, calculating the coupling degree between the sample data and each existing sample in the sample feature library in step 108 further includes:

[0097] Based on the feature vectors corresponding to the sample data, the feature terms and corresponding weights of all coupling degree values ​​to be calculated are determined and grouped according to object type; wherein, a feature term represents a behavioral feature, which may come only from static behavioral feature recognition or only from dynamic behavioral feature extraction, or may come from both static behavioral feature recognition and dynamic behavioral feature extraction (i.e., the behavioral feature can be detected by both static and dynamic methods).

[0098] For each existing sample in the sample feature library, perform the following operation:

[0099] Based on the feature vector corresponding to the existing sample, determine all feature terms for which the coupling degree value is to be calculated, and group them according to object type; in the feature vector corresponding to the existing sample, the feature terms may come from the static feature set, the dynamic feature set, or the coupling relationship feature set;

[0100] The sample data is grouped with existing sample groups. If there are groups with the same object type, then according to a preset coupling rule, the coupling degree of each feature item in the sample data group is calculated with each feature item in the existing sample group. That is, the coupling degree of one feature item in the sample data group is calculated with each feature item in the existing sample group, and then the next feature item in the sample data group is calculated with each feature item in the existing sample group, and so on. If there are no groups with the same object type between the sample data group and the existing sample group, then it can be considered that there is no coupling between the sample data and the existing sample.

[0101] The coupling degree between the existing sample and the sample data is obtained by weighted summation of all the calculated coupling degree values.

[0102] The above embodiments calculate coupling degree based on behavioral features of the same object type, so as to quickly discover the coupling relationship between the current sample data and existing samples, avoiding comparison of behaviors of different object types and reducing the amount of computation. In other embodiments, step 108 can also use other methods to calculate coupling degree. For example, it can also skip grouping and directly search and calculate coupling degree based on object name, that is, only consider that there may be a coupling relationship between behavioral features with the same object name, and directly not match cases with different object names.

[0103] Further, determining the feature terms and corresponding weights of all the coupling values ​​to be calculated based on the feature vector corresponding to the sample data includes:

[0104] Based on the feature vectors corresponding to the sample data, determine all feature terms for which the coupling degree value is to be calculated.

[0105] Based on the feature terms of the coupling degree value to be calculated and the sample feature library, determine the number of times each feature term of the coupling degree value to be calculated appears in the sample feature library, that is, the number of corresponding feature terms in the feature vector of the existing sample.

[0106] The weight of each feature term is determined based on the number of times it appears in the sample feature library. The number of times a feature term appears is inversely proportional to its corresponding weight, so that features terms that appear less frequently are assigned a larger weight.

[0107] The above embodiments use dynamic weighting to increase the weight of behavioral features that appear less frequently and newly, in order to enhance the matching of behavioral features that appear less frequently and newly, which is beneficial to realizing the interrelation between modular malware.

[0108] Preferably, based on the feature vector corresponding to the sample data, all feature terms for which the coupling degree value to be calculated are determined. If the determined feature term exists only in the dynamic feature set, the weight corresponding to the feature term is increased.

[0109] The above embodiments focus on behavioral characteristics obtained only in a dynamic manner in order to detect malicious software attack behavior in a timely manner.

[0110] Furthermore, based on the frequency of occurrence of each feature term in the sample feature library for which the coupling degree value to be calculated, the weight corresponding to each feature term is determined, including:

[0111] A mapping relationship is established based on the frequency of each feature item in the sample feature library, with the base value of the weight corresponding to the feature item with the most occurrences being 0.5 and the base value of the weight corresponding to the feature item with the fewest occurrences being 1.

[0112] If a feature term comes from static behavioral feature recognition, that is, it only exists in the static feature set and has no corresponding behavioral feature in the dynamic feature set, or it has a corresponding behavioral feature in both the static and dynamic feature sets, then the base value of the weight corresponding to the feature term is set to 1.

[0113] If a feature term comes only from dynamic behavioral feature recognition, that is, it only exists in the dynamic feature set and has no corresponding behavioral feature in the static feature set, then the base value of the weight corresponding to the feature term is set to 2.

[0114] Based on the frequency of the feature item in the sample feature library and the established mapping relationship, a corresponding value not exceeding 1 is added to the base value of the feature item's weight to obtain the final weight corresponding to the feature item.

[0115] The above embodiments provide a way to determine dynamic weights, and assign greater weights to behavioral features that exist only in the dynamic feature set but have no corresponding counterparts in the static feature set. This helps to focus on matching behaviors that occur infrequently and are difficult to detect through data parsing, so as to quickly establish associations between modular malware.

[0116] Furthermore, according to a preset coupling rule, the coupling degree value is calculated for each feature item in the corresponding group of the sample data and each feature item in the corresponding group of the existing samples. The coupling degree rule includes:

[0117] For two feature items, one from the corresponding group of the sample data and the other from the corresponding group of existing samples, if the object names are the same but the behavior types are different, the coupling degree is recorded as 1.

[0118] If objects have the same name and the same behavior type, the coupling value is recorded as 0.5;

[0119] If the object names and behavior types are different, the coupling value is recorded as 0.

[0120] The above embodiments provide a method for calculating coupling degree, which can be used in conjunction with preset fixed weights or dynamic weights. Since the focus of this invention is to utilize coupling degree to associate modular malware, for groups of the same object type, behaviors with different object names and behavior types can be considered to have no matching coupling relationship. Behaviors with the same object name and behavior type may be related or identical, and can be considered to have a weak coupling relationship. However, behaviors with the same object name but different behavior types, such as one creating file T and the other reading file T, are considered to be modular malware, indicating a coupling relationship, as the malware executing these two behaviors may be performing a coupling relationship. Coupling relationships typically have a sequential order, such as creation first, then reading / writing, and finally deletion.

[0121] Optionally, step 110 includes behavioral feature extraction, which further includes:

[0122] Based on the sample data and the corresponding coupling relationships of the existing samples with the highest coupling degree to the sample data, the execution order is determined; for example, the order of creating an object should be earlier than the order of reading and writing the object, etc.

[0123] According to the determined running order, the sample data and the existing samples with the highest coupling degree with the sample data are put into the sandbox for running and behavioral feature extraction.

[0124] Furthermore, the following sandbox-based malicious sample detection method can be used for behavioral feature extraction. The malicious sample detection method includes:

[0125] Step A: Receive suspicious samples submitted by users.

[0126] This step involves placing the suspicious samples to be analyzed into a sandbox, which can be a virtual machine running on the host machine.

[0127] Step B involves performing static detection on the suspicious sample to determine the file configuration information required for the suspicious sample to run; and obtaining the client configuration information.

[0128] This embodiment allows for static analysis of the program code using a wealth of static analysis tools within the sandbox, even when the suspicious sample program is not running. This analysis reveals the necessary environment for the sample's operation, such as file configuration information, for example, specific directories and files. In some embodiments, the file configuration information may include: dependent filenames, dependent file directories, dependent dynamic link libraries, and / or dependent software loading information required for the suspicious sample to run.

[0129] The acquisition of client configuration information can be achieved by the sandbox automatically linking with the target client serving a specific production environment to acquire the target client configuration information, such as application software information like files, directories, paths, and software on the target client, or hardware information of the target client.

[0130] Step C: Based on the file configuration information and client configuration information, build the runtime environment configuration required for the suspicious sample to run, so as to simulate the real runtime environment of the suspicious sample.

[0131] In this embodiment, after obtaining the file configuration information and target client configuration information required by the suspicious sample, the runtime environment configuration required for the suspicious sample to run is built in the sandbox, thereby effectively simulating the real runtime environment of the suspicious sample, which facilitates the effective analysis of malicious samples based on their behavioral information after the suspicious sample runs.

[0132] Step D: Run the suspicious sample and monitor its behavior during operation.

[0133] After setting up a sandbox environment to simulate the real running environment of the suspicious sample based on the target client configuration information, the suspicious sample is run to monitor its behavior information during operation.

[0134] Step E: Generate the detection result of the suspicious sample based on the behavioral information.

[0135] In this embodiment, a corresponding suspicious sample detection report can also be generated based on the detected behavioral information, so that users can view and further analyze it.

[0136] By utilizing a sandbox-based malicious sample detection method, when it is necessary to detect malicious software developed for a specific production environment system, static detection is performed on suspicious samples placed in the sandbox by users to determine the file configuration information required for the suspicious samples to run; and client configuration information is obtained; and the runtime environment configuration required for the suspicious samples to run is built based on the file configuration information and client configuration information. In this way, the real runtime environment of the suspicious samples can be simulated, thereby facilitating the effective detection of malicious software developed for a specific production environment system and obtaining corresponding behavioral characteristics.

[0137] Optionally, step 112 further includes:

[0138] The dimension of the sample data and the feature vectors corresponding to the existing samples with the highest coupling degree to the sample data are both expanded.

[0139] The coupled relationship feature set includes various behavioral features and the mapping between the sample data and the existing samples are recorded in the expanded feature vector. That is, the coupled relationship feature set includes various behavioral features and the mapping with the sample data are recorded in the feature vector corresponding to the existing sample, and the coupled relationship feature set includes various behavioral features and the mapping with the existing sample are recorded in the feature vector corresponding to the sample data, so that each coupled relationship feature and the coupled sample can be determined according to the feature vector corresponding to the sample.

[0140] The above embodiments add the features obtained after coupling and sandboxing to the feature vectors corresponding to the samples, resulting in more feature items that characterize the behavior of sample data, so as to analyze the correlation between samples and provide technical support for correlation of modular malware and attack detection.

[0141] Optionally, in some embodiments, step 100 further includes:

[0142] Determine the environmental characteristics that include the source information of the sample data;

[0143] Environmental characteristics may include the host from which the sample data is sourced, and can be determined in conjunction with EDR;

[0144] Accordingly, after step 106 and before step 108, the following steps are also included:

[0145] Based on the environmental features containing the source information of the sample data, the dimensionality of the feature vector corresponding to the obtained sample data is expanded to obtain a feature vector containing environmental features.

[0146] After expanding the dimension of the feature vector obtained in step 106 in the above embodiment, the feature terms in the feature vector corresponding to the sample not only have behavioral features from the static feature set and the dynamic feature set, but also environmental features, so that matching can be performed based on environmental features in step 108, and coupling can be established between samples with similar environmental features.

[0147] Further, in step 108, determining the feature terms and corresponding weights of all the coupling values ​​to be calculated based on the feature vector corresponding to the sample data further includes:

[0148] If the feature is an environmental feature, it is grouped separately and weighted according to similarity, so that features with high similarity are assigned greater weights.

[0149] The step of determining all feature terms for calculating coupling degree values ​​based on the feature vectors corresponding to existing samples and grouping them according to object type also includes:

[0150] If the feature is an environmental feature, it is grouped separately.

[0151] The coupling rule also includes:

[0152] If the feature is an environmental feature, then the similarity between the two feature items is calculated as the coupling degree value.

[0153] In the above embodiments, feature items corresponding to environmental characteristics are grouped and compared separately. For feature items with high similarity, such as two samples coming from the same host environment, it is considered that there may be coupling between them. The strength of this coupling is related to the degree of similarity of environmental features. This method is also beneficial for establishing associations between modular malware.

[0154] In one scenario, modular malware is delivered using a "white-and-black" approach. It often exists as a compressed package containing a white executable file. This white executable file uses side-loading technology to load a malicious dynamic link library (DLL), which then loads encrypted shellcode for execution. In this scenario, the white executable loads the library file without specifying an absolute path. Based on environmental characteristics, the library file and the white executable file, located in the same path, can be considered weakly coupled. The library file acquires the name of the encrypted shellcode, making the shellcode file name a weakly coupled feature (or strongly coupled if the samples originate from the same host). When the white executable and the malicious library file enter the associated coupled system, based on the weak coupling relationship, both are simultaneously placed in a sandbox to extract new features, namely the encrypted shellcode file name. Sandbox behavior detection is then performed again based on the file name association, yielding more coupled features for inclusion in the database.

[0155] The technical solution provided by this invention can link upstream and downstream modules of the same attack chain in sample analysis scenarios to form a relatively complete sample feature set, enabling analysts to conduct in-depth analysis of attack events. In production environments, it can work in conjunction with EDR to detect modular malware present in the environment. This solution can integrate endpoint-side protection and traffic-side protection results to achieve complete modular malware correlation analysis.

[0156] like Figure 2 , Figure 3 As shown, this embodiment of the invention provides a malware feature extraction device (hereinafter referred to as a feature extraction device). The device embodiment can be implemented by software, hardware, or a combination of both. From a hardware perspective, such as... Figure 2 The diagram shown is a hardware architecture diagram of an electronic device containing a malware feature extraction device according to an embodiment of the present invention. (Except for...) Figure 2 In addition to the processor, memory, network interface, and non-volatile memory shown, the electronic device in the embodiment may also include other hardware, such as a forwarding chip responsible for processing packets. Taking software implementation as an example, such as... Figure 3 As shown, a device in a logical sense is formed by the CPU of its host electronic device reading the corresponding computer program from non-volatile memory into memory for execution. This embodiment provides a malware feature extraction device, including:

[0157] The sample acquisition module 301 is used to acquire sample data of malware;

[0158] The static recognition module 302 is used to perform behavioral feature recognition on the sample data to obtain a static feature set of the sample data; the behavioral features include behavioral type, object type and object name; the static feature set includes all recognized behavioral features;

[0159] The dynamic extraction module 303 is used to extract behavioral features from the sample data to obtain a dynamic feature set of the sample data; the dynamic feature set includes all extracted behavioral features.

[0160] The vector construction module 304 is used to obtain the feature vector corresponding to the sample data based on the static feature set and the dynamic feature set;

[0161] The coupling calculation module 305 is used to calculate the coupling degree between the sample data and each existing sample in the sample feature library according to the corresponding feature vector and the preset coupling degree rule, and to determine the existing sample with the highest coupling degree with the sample data and the corresponding coupling relationship.

[0162] The coupling extraction module 306 is used to extract behavioral features from the sample data and the existing samples with the highest coupling degree to the sample data according to the corresponding coupling relationship, so as to obtain a coupling relationship feature set; the coupling relationship feature set includes all extracted behavioral features.

[0163] The feature update module 307 is used to update the feature vectors corresponding to the sample data and the existing samples with the highest coupling degree to the sample data based on the coupling relationship feature set, and store them in the sample feature library to obtain the updated sample feature library.

[0164] In this embodiment of the invention, the sample acquisition module 301 can be used to execute step 100 in the above method embodiment, the static recognition module 302 can be used to execute step 102 in the above method embodiment, the dynamic extraction module 303 can be used to execute step 104 in the above method embodiment, the vector construction module 304 can be used to execute step 106 in the above method embodiment, the coupling calculation module 305 can be used to execute step 108 in the above method embodiment, the coupling extraction module 306 can be used to execute step 110 in the above method embodiment, and the feature update module 307 can be used to execute step 112 in the above method embodiment.

[0165] Optionally, the static recognition module 302 performs behavioral feature recognition on the sample data, including executing:

[0166] Data parsing is performed on the plaintext data in the sample data to determine all operation instructions involved in the plaintext data;

[0167] Behavioral feature identification is performed based on all operational instructions involved in the plaintext data;

[0168] By decrypting the encrypted data in the sample data, a decrypted string is obtained;

[0169] Based on the decrypted string, data is parsed to determine all operation instructions involved in the encrypted data;

[0170] Behavioral characteristics are identified based on all operational instructions involved in the encrypted data.

[0171] Optionally, the vector construction module 304 obtains the feature vector corresponding to the sample data based on the static feature set and the dynamic feature set, including performing:

[0172] Based on the filtering list, behavioral features in the static feature set and the dynamic feature set are filtered separately, and behavioral features existing in the filtering list are removed; wherein, the filtering list includes a system benchmark list and a whitelist list; the system benchmark list is determined based on the system; the whitelist list is determined based on user instructions;

[0173] Based on the filtered static feature set and the behavioral features in the dynamic feature set, the feature vector of the sample data is obtained.

[0174] Optionally, the coupling calculation module 305 is further configured to perform the following before calculating the coupling degree between the sample data and each existing sample in the sample feature library based on the corresponding feature vector and a preset coupling degree rule:

[0175] Determine whether the sample data is a duplicate of an existing sample in the sample feature library. If so, discard the current sample data and call the sample acquisition module 301.

[0176] Optionally, the coupling calculation module 305 calculates the coupling degree between the sample data and each existing sample in the sample feature library according to the corresponding feature vector and a preset coupling degree rule, including performing:

[0177] Based on the feature vectors corresponding to the sample data, determine the feature terms and corresponding weights of all coupling values ​​to be calculated, and group them according to object type;

[0178] For each existing sample in the sample feature library, perform the following operation:

[0179] Based on the feature vectors corresponding to existing samples, determine all feature terms for which the coupling degree value is to be calculated, and group them according to object type;

[0180] The group corresponding to the sample data is matched with the group corresponding to the existing sample. If there is a group with the same object type, the coupling degree value is calculated one by one between each feature item in the group corresponding to the sample data and each feature item in the group corresponding to the existing sample, according to the preset coupling degree rule.

[0181] The coupling degree between the existing sample and the sample data is obtained by weighted summation of all the calculated coupling degree values.

[0182] Optionally, the coupling calculation module 305 determines the feature terms and corresponding weights of all coupling values ​​to be calculated based on the feature vectors corresponding to the sample data, including performing:

[0183] Based on the feature vectors corresponding to the sample data, determine all feature terms for which the coupling degree value is to be calculated.

[0184] Based on the feature terms for which the coupling degree value is to be calculated and the sample feature library, determine the number of times each feature term for which the coupling degree value is to be calculated appears in the sample feature library;

[0185] The weight of each feature is determined based on the number of times it appears in the sample feature library; the number of times a feature appears is inversely proportional to its corresponding weight.

[0186] Optionally, the coupling rule includes:

[0187] For two feature items, if the object names are the same but the behavior types are different, the coupling value is recorded as 1;

[0188] If objects have the same name and the same behavior type, the coupling value is recorded as 0.5;

[0189] If the object names and behavior types are different, the coupling value is recorded as 0.

[0190] It is understood that the structures illustrated in the embodiments of the present invention do not constitute a specific limitation on a malware signature extraction device. In other embodiments of the present invention, a malware signature extraction device may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0191] The information interaction and execution process between the modules in the above-mentioned device are based on the same concept as the method embodiment of the present invention, and the specific details can be found in the description in the method embodiment of the present invention, and will not be repeated here.

[0192] This invention also provides an electronic device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements a malware feature extraction method according to any embodiment of this invention.

[0193] This invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform a malware feature extraction method according to any embodiment of this invention.

[0194] Specifically, a system or apparatus equipped with a storage medium may be provided, on which software program code implementing the functions of any of the embodiments described above is stored, and the computer (or CPU or MPU) of the system or apparatus may read and execute the program code stored in the storage medium.

[0195] In this case, the program code read from the storage medium can itself implement the function of any of the above embodiments, and therefore the program code and the storage medium storing the program code constitute part of the present invention.

[0196] Examples of storage media used to provide program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Alternatively, program code can be downloaded from a server computer via a communication network.

[0197] Furthermore, it should be clear that not only can the program code read by the computer be executed, but also the operating system or other components operating on the computer can be instructed based on the program code to perform some or all of the actual operations, thereby realizing the function of any of the embodiments described above.

[0198] Furthermore, it is understood that the program code read from the storage medium is written to the memory set in the expansion board inserted into the computer or to the memory set in the expansion module connected to the computer. Then, based on the instructions of the program code, the CPU or other components installed on the expansion board or expansion module execute some and all of the actual operations, thereby realizing the function of any of the above embodiments.

[0199] The embodiments of the present invention have at least the following beneficial effects:

[0200] 1. In one embodiment of the present invention, a method and apparatus for extracting malware features are provided. The method uses a combination of static and dynamic approaches to obtain behavioral features. Then, different samples are associated based on the degree of coupling. According to the coupling relationship, the associated samples are dynamically run together to extract new features. In other words, multi-module collaborative sandbox behavioral feature parsing can be performed to obtain more coupled features and realize associated detection, thereby improving the upstream and downstream analysis capabilities of modular malware.

[0201] 2. In one embodiment of the present invention, a method and apparatus for extracting malware features are provided. Static parsing includes plaintext behavioral feature parsing and decrypted string behavioral feature parsing. It can not only identify the behavioral features involved in plaintext data in the sample, but also identify the behavioral features involved in encrypted data, and can obtain more behavioral features that malware attempts to hide.

[0202] 3. In one embodiment of the present invention, a method and apparatus for extracting malicious software features are provided. The method uses a system benchmark list and a whitelist list to filter out conventional behavioral features that do not have discriminative value. On the one hand, it can extract malicious software behavioral features in a targeted manner, reducing the amount of computation and analysis. On the other hand, it can also avoid some conventional behaviors from affecting the coupling degree between judgment samples.

[0203] 4. In one embodiment of the present invention, a method and apparatus for extracting malware features are provided. Before calculating the coupling degree, sample data that is duplicated with existing samples are removed to avoid duplicate calculation of the same samples and interference with finding the correlation between samples.

[0204] 5. In one embodiment of the present invention, a method and apparatus for extracting malware features are provided, which calculates the coupling degree based on behavioral features of the same object type, so as to quickly discover the coupling relationship between the current sample data and existing samples, avoid comparing behaviors of different object types, and reduce the amount of computation;

[0205] 6. In one embodiment of the present invention, a method and apparatus for extracting malware features are provided. When calculating the coupling degree, a dynamic weighting method is used to increase the weights corresponding to behavioral features that appear less frequently and newly appear. When the dynamic and static parsing features are inconsistent, the features obtained by dynamic parsing are added to enhance the behavioral features that appear less frequently and newly appear in the matching samples. This enhances the dynamic parsing features, which is beneficial for associating upstream and downstream components in the network attack chain and clearly and completely understanding the relationships between the modules of multi-module malware.

[0206] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus.

[0207] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as ROM, RAM, magnetic disk, or optical disk.

[0208] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for extracting malicious software features, characterized in that, include: Obtain sample data of malware; Behavioral feature recognition is performed on the sample data to obtain a static feature set of the sample data; The behavioral characteristics include behavioral type, object type, and object name; Behavioral features are extracted from the sample data to obtain a dynamic feature set of the sample data; Based on the static feature set and the dynamic feature set, the feature vector corresponding to the sample data is obtained; Based on the corresponding feature vector and the preset coupling degree rule, the coupling degree between the sample data and each existing sample in the sample feature library is calculated, and the existing sample with the highest coupling degree with the sample data and the corresponding coupling relationship are determined, so as to analyze whether there are existing samples and the current sample data belonging to the same modular malware based on the coupling degree relationship. The sample data and the existing sample with the highest coupling degree with the sample data are extracted according to the corresponding coupling relationship to obtain the coupling relationship feature set; Based on the coupling relationship feature set, the feature vectors corresponding to the sample data and the existing samples with the highest coupling degree with the sample data are updated and stored in the sample feature library to obtain the updated sample feature library. The step of calculating the coupling degree between the sample data and each existing sample in the sample feature library based on the corresponding feature vector and a preset coupling degree rule includes: Based on the feature vectors corresponding to the sample data, determine the feature terms and corresponding weights of all coupling values ​​to be calculated, and group them according to object type; For each existing sample in the sample feature library, the following operations are performed: Based on the feature vector corresponding to the existing sample, all feature items whose coupling degree value is to be calculated are determined and grouped according to object type; The group corresponding to the sample data is matched with the group corresponding to the existing sample. If there is a group with the same object type, then according to the preset coupling degree rule, the coupling degree value of each feature item in the group corresponding to the sample data is calculated one by one with the feature items in the group corresponding to the existing sample; The coupling degree rule includes: For two feature items, if the object name is the same but the behavior type is different, the coupling degree value is recorded as 1; if the object name is the same and the behavior type is the same, the coupling degree value is recorded as 0.5; if the object name and behavior type are different, the coupling degree value is recorded as 0; The coupling degree between the existing sample and the sample data is obtained by weighted summation of all the calculated coupling degree values.

2. The method according to claim 1, characterized in that, The behavioral feature recognition of the sample data includes: Data parsing is performed on the plaintext data in the sample data to determine all operation instructions involved in the plaintext data; Behavioral feature identification is performed based on all operational instructions involved in the plaintext data; By decrypting the encrypted data in the sample data, a decrypted string is obtained; Based on the decrypted string, data is parsed to determine all operation instructions involved in the encrypted data; Behavioral characteristics are identified based on all operational instructions involved in the encrypted data.

3. The method according to claim 1, characterized in that, The step of obtaining the feature vector corresponding to the sample data based on the static feature set and the dynamic feature set includes: Based on the filtering list, behavioral features in the static feature set and the dynamic feature set are filtered respectively, and behavioral features existing in the filtering list are removed; wherein, the filtering list includes a system benchmark list and a whitelist list; Based on the filtered static feature set and the behavioral features in the dynamic feature set, the feature vector of the sample data is obtained.

4. The method according to claim 1, characterized in that, The step of determining all feature terms and corresponding weights of the coupling degree value to be calculated based on the feature vector corresponding to the sample data includes: Based on the feature vectors corresponding to the sample data, determine all feature terms for which the coupling degree value is to be calculated. Based on the feature terms for which the coupling degree value is to be calculated and the sample feature library, determine the number of times each feature term for which the coupling degree value is to be calculated appears in the sample feature library; The weight of each feature is determined based on the number of times it appears in the sample feature library; the number of times a feature appears is inversely proportional to its corresponding weight.

5. The method according to claim 1, characterized in that, The acquisition of malware sample data also includes: Determine the environmental characteristics that include the source information of the sample data; After obtaining the feature vector corresponding to the sample data based on the static feature set and the dynamic feature set, and before calculating the coupling degree between the sample data and each existing sample in the sample feature library according to the corresponding feature vector and a preset coupling degree rule, the method further includes: Based on environmental characteristics, the dimensionality of the feature vector corresponding to the obtained sample data is expanded.

6. A malware signature extraction device, characterized in that, For performing the method as described in any one of claims 1-5 above, comprising: The sample acquisition module is used to acquire sample data of malware. A static recognition module is used to perform behavioral feature recognition on the sample data to obtain a static feature set of the sample data; the behavioral features include behavioral type, object type, and object name. The dynamic extraction module is used to extract behavioral features from the sample data to obtain a dynamic feature set of the sample data. A vector construction module is used to obtain the feature vector corresponding to the sample data based on the static feature set and the dynamic feature set; The coupling calculation module is used to calculate the coupling degree between the sample data and each existing sample in the sample feature library according to the corresponding feature vector and the preset coupling degree rule, and to determine the existing sample with the highest coupling degree with the sample data and the corresponding coupling relationship. The coupling extraction module is used to extract behavioral features from the sample data and the existing samples with the highest coupling degree to the sample data according to the corresponding coupling relationship, so as to obtain a coupling relationship feature set. The feature update module is used to update the feature vectors corresponding to the sample data and the existing samples with the highest coupling degree to the sample data based on the coupling relationship feature set, and store them in the sample feature library to obtain the updated sample feature library.

7. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1-5.

8. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed in the computer, it causes the computer to perform the method of any one of claims 1-5.

Citation Information

Patent Citations

  • Similar malicious sample file matching method and system based on feature vector

    CN105488406A

  • Malicious software detection method and system and storage medium

    CN110647746A

  • Malicious code detection method and device, electronic equipment and storage medium

    CN114168953A