Malicious file detection method and device

By converting the files to be detected into grayscale maps, extracting and matching the set of feature points, the problem of missing files detection caused by data loss and network fluctuations in the prior art is solved, and the effective detection and safe detection of incomplete malicious files are realized.

CN120068075APending Publication Date: 2025-05-30HANGZHOU DPTECH TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510231722.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing malicious file detection technology has limitations when facing problems such as data loss, anti-virtualization technology, and performance losses. Especially when files are truncated or incompleted due to network fluctuations during file transfer, it is difficult to effectively detect, resulting in frequent missed detection.

Method used

By converting the file to be detected into a grayscale graph, the feature point set is extracted, and the feature point set is initially matched with the malicious file, the wrong matching points are eliminated, the optimal matching point pair is extracted, and the matching ratio is calculated. If the ratio is greater than the threshold, it is determined to be a malicious file.

Benefits of technology

This method can better deal with the file truncation and incompleteness caused by network fluctuations, detect incomplete malicious files, and improve the security of the detection process, avoiding the risk of directly opening or executing files to be detected.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068075A_ABST
    Figure CN120068075A_ABST
Patent Text Reader

Abstract

The invention relates to a malicious file detection method and device. The method comprises the following steps: extracting a feature point set of a to-be-detected file in a grey-scale map mode; performing preliminary matching on the feature point set and a malicious file feature point set to generate preliminary matching point pairs; extracting an optimal matching point pair from the preliminary matching point pairs; generating a matching ratio of the to-be-detected file according to the number of the optimal matching point pairs; and when the matching ratio is greater than a threshold value, determining that the to-be-detected file is a malicious file. According to the malicious file detection method and device, the problems of file truncation and incompleteness caused by network fluctuation can be better solved, even incomplete malicious files can be detected through the technology, and due to the fact that the to-be-detected file does not need to be opened and executed through the technology, the safety of the detection process is also improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer information processing, and in particular, to a method and device for detecting malicious files. Background Art

[0002] Currently, malicious file detection technologies are mainly divided into two categories: static feature-based detection and dynamic feature-based detection.

[0003] Static feature-based detection: This method collects and analyzes the content and structure information of files (such as API call sequences, file hash values, etc.) using tool software, extracts the features of malicious software, and establishes a feature library for detection. However, when there is data loss in the file, the structural fragment hash value may be incorrect, resulting in the loss of content and structure features, and thus missed detections may occur.

[0004] Dynamic feature-based detection: One of the key technologies of this method is the sandbox. The sandbox system is usually implemented using virtual machines to simulate the real environment. The file is executed or opened in the sandbox, and its behavioral characteristics are observed to determine whether the file is malicious software. However, when there is data loss in the binary file, it may fail to execute in the sandbox, resulting in missed detections. Moreover, some malicious software has anti-virtualization technology and can escape sandbox detection. Even in a virtual environment, some malicious software may still pose a threat to the computer. The performance loss of the sandbox technology is relatively high, affecting the detection efficiency.

[0005] Existing malicious file detection technologies have obvious limitations when facing problems such as data loss, anti-virtualization technology, and performance loss. Especially when the file is truncated or incomplete due to network fluctuations during transmission, existing technologies are difficult to effectively detect, resulting in frequent missed detections. In addition, although the dynamic detection method based on the sandbox can observe the file behavior, its performance loss is relatively high, and some malicious software can escape detection.

[0006] Therefore, a new method and device for detecting malicious files are needed.

[0007] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present application, and therefore it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0008] In view of this, the present application provides a method and device for detecting malicious files, which can better handle the problems of file truncation and incompleteness caused by network fluctuations. Through the technology of the present application, even an incomplete malicious file can be detected. Since the technology of the present application does not require opening and executing the file to be detected, the security of the detection process is also improved.

[0009] Other features and advantages of the present application will become apparent from the following detailed description, or be learned in part through the practice of the present application.

[0010] According to one aspect of the present application, a method for detecting malicious files is provided. The method includes: extracting a set of feature points of a file to be detected in a grayscale image manner; preliminarily matching the set of feature points with a set of malicious file feature points to generate preliminary matching point pairs; extracting optimal matching point pairs from the preliminary matching point pairs; generating a matching ratio of the file to be detected according to the number of the optimal matching point pairs; and determining that the file to be detected is a malicious file when the matching ratio is greater than a threshold.

[0011] In an exemplary embodiment of the present application, it further includes: obtaining a plurality of malicious files and converting them into a plurality of grayscale images; respectively performing key point detection on the plurality of grayscale images to generate a plurality of sets of malicious file feature points.

[0012] In an exemplary embodiment of the present application, it further includes: preliminarily matching the set of feature points of the file to be detected with a plurality of sets of malicious file feature points one by one to generate a plurality of matching ratios; and determining that the file to be detected is a normal file when the plurality of matching ratios are all less than the threshold.

[0013] In an exemplary embodiment of the present application, extracting a set of feature points of a file to be detected in a grayscale image manner includes: converting the file to be detected into a grayscale image; and extracting the set of feature points in the grayscale image.

[0014] In an exemplary embodiment of the present application, converting the file to be detected into a grayscale image includes: converting the binary data of the file to be detected into the grayscale image through a B2M algorithm.

[0015] In an exemplary embodiment of the present application, extracting the set of feature points in the grayscale image includes: performing key point detection on the grayscale image by using a SURF algorithm to generate the set of feature points.

[0016] In an exemplary embodiment of the present application, extracting optimal matching point pairs from the preliminary matching point pairs includes: removing mismatched points in the preliminary matching point pairs according to a RANSAC algorithm; and obtaining the best matching point pairs according to an inlier ratio threshold and a maximum number of iterations.

[0017] In an exemplary embodiment of the present application, removing mismatched points in the preliminary matching point pairs according to a RANSAC algorithm includes: randomly sampling the preliminary matching point pairs through a RANSAC algorithm to generate initial matching inliers; performing iterations based on the initial matching inliers to obtain an optimal homography matrix; and screening the initial matching inliers through a projection error.

[0018] In an exemplary embodiment of the present application, generating a matching ratio of the file to be detected according to the number of the optimal matching point pairs includes: generating the matching ratio according to the number of the optimal matching point pairs and the number of feature points in the malicious file feature point set.

[0019] According to one aspect of the present application, there is provided a detection device for malicious files, the device including: a feature module for extracting a feature point set of a file to be detected in a grayscale image manner; a matching module for preliminarily matching the feature point set with a malicious file feature point set to generate preliminary matching point pairs; an extraction module for extracting optimal matching point pairs from the preliminary matching point pairs; a ratio module for generating a matching ratio of the file to be detected according to the number of the optimal matching point pairs; a determination module for determining that the file to be detected is a malicious file when the matching ratio is greater than a threshold.

[0020] According to one aspect of the present application, there is provided an electronic device, the electronic device including: one or more processors; a storage device for storing one or more programs; when the one or more programs are executed by the one or more processors, enabling the one or more processors to implement the method as described above.

[0021] According to one aspect of the present application, there is provided a computer-readable medium having a computer program stored thereon, and when the program is executed by a processor, the method as described above is implemented.

[0022] According to the malicious file detection method and device of the present application, by extracting a feature point set of a file to be detected in a grayscale image manner; preliminarily matching the feature point set with a malicious file feature point set to generate preliminary matching point pairs; extracting optimal matching point pairs from the preliminary matching point pairs; generating a matching ratio of the file to be detected according to the number of the optimal matching point pairs; and determining that the file to be detected is a malicious file when the matching ratio is greater than a threshold, it is possible to better cope with the problems of file truncation and mutilation caused by network fluctuations. Through the technology of the present application, even an incomplete malicious file can be detected. Since the technology of the present application does not require opening and executing the file to be detected, the security of the detection process is also improved.

[0023] It should be understood that the above general description and the following detailed description are merely exemplary and do not limit the present application. Description of the Drawings

[0024] By referring to the accompanying drawings and describing its exemplary embodiments in detail, the above and other objectives, features, and advantages of the present application will become more apparent. The following described drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0025] Figure 1 It is a flowchart of a method for detecting malicious files shown according to an exemplary embodiment.

[0026] Figure 2 It is a flowchart of a method for detecting malicious files shown according to another exemplary embodiment.

[0027] Figure 3 It is a flowchart of a method for detecting malicious files shown according to another exemplary embodiment.

[0028] Figure 4 It is a block diagram of a device for detecting malicious files shown according to an exemplary embodiment.

[0029] Figure 5 It is a block diagram of an electronic device shown according to an exemplary embodiment.

[0030] Figure 6 It is a block diagram of a computer-readable medium shown according to an exemplary embodiment. Detailed implementation manners

[0031] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this application will be thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art. Identical reference numerals in the figures denote identical or similar parts, and thus their repetitive description will be omitted.

[0032] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of this application. However, those skilled in the art will realize that the technical solutions of this application can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of this application.

[0033] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0034] The flowcharts shown in the accompanying drawings are only illustrative descriptions and do not necessarily include all the contents and operations / steps, nor do they necessarily have to be executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined. Therefore, the actual execution order may change according to the actual situation.

[0035] It should be understood that although terms such as first, second, and third may be used herein to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another. Therefore, the first component discussed below can be referred to as the second component without departing from the teachings of the concept of the present application. As used herein, the term "and / or" includes any one of the associated listed items and all combinations of one or more of them.

[0036] Those skilled in the art can understand that the drawings are only schematic diagrams of exemplary embodiments, and the modules or processes in the drawings are not necessarily essential for implementing the present application, so they cannot be used to limit the protection scope of the present application.

[0037] The technical abbreviations related to the present application are explained as follows:

[0038] SURF (Speeded-Up Robust Features), a computer vision algorithm for feature point detection and description, has high computational efficiency and robustness, and is widely used in fields such as image matching and target recognition.

[0039] RANSAC (Random Sample Consensus), an iterative algorithm for parameter estimation, can find the best parameter model in a dataset containing a large number of outliers (mismatched points).

[0040] B2M (Binary-to-Image), a method for converting binary data into a grayscale image.

[0041] API (Application Programming Interface), an interface in software for communicating with other software components. Some malware detection methods are based on API call sequence analysis, and malicious files are identified by extracting and matching API call features.

[0042] Homography Matrix, in computer vision, a 3×3 matrix used to describe the projection relationship between two planes.

[0043] Grayscale Image, an image that only contains grayscale information. Each pixel is represented by a single-channel value and is commonly used for feature extraction and computer vision analysis.

[0044] Matching Ratio, which refers to the ratio of the number of effective matching feature points in the file to be detected to the number of sample feature points. It is usually used to determine whether a file is a malicious file.

[0045] Sandbox, a secure isolation environment, usually implemented based on virtual machine technology, used to run and observe the behavior of suspicious files in a controlled environment. Sandbox technology is widely used in malware detection to capture and analyze the behavioral characteristics of malware by simulating a real environment.

[0046] Key Points are local regions in an image or data that have significant features. In image processing, key points are usually used to describe the structural information of an image and are matched through feature descriptors. The key points extracted by the SURF algorithm have scale invariance and rotation invariance.

[0047] Feature Descriptor is a mathematical description of the information in the area around a key point, usually represented in the form of a vector. Feature descriptors are used to compare and match key points in different images or data.

[0048] Inliers, in the RANSAC algorithm, inliers are data points that conform to the current model parameters. The set of inliers is used to estimate the optimal model parameters, while outliers are noise or mis-matched points.

[0049] Outliers, in the RANSAC algorithm, outliers are data points that do not conform to the current model parameters. Outliers are usually regarded as noise or mis-matched points and need to be removed through algorithms.

[0050] Based on the high stability of the SURF algorithm and its robustness to local noise and data loss, this application aims to improve the accuracy of malicious file detection, especially the recognition ability for incomplete or damaged files.

[0051] Specifically, in this application, the binary data of the file to be detected is first converted into a grayscale image using the B2M algorithm, and then the SURF algorithm is applied to extract the global key-point features to form a set of key points. Next, the set of key points is preliminarily matched with the set of key points in the existing malicious file sample library. To improve the matching accuracy, this application uses the RANSAC algorithm to eliminate the mis-matched points and calculate the optimal homography matrix, and finally filters out the optimal matching point pairs. Subsequently, by calculating the ratio of the number of matching key points to the total number of sample key points and comparing it with the set threshold, it is determined whether the file to be detected is a malicious file.

[0052] The advantage of this application is that it can effectively make up for the deficiencies of existing detection methods. Especially in the case of incomplete files or missing data, it can still maintain a high detection accuracy. When traditional detection technologies face file truncation and mutilation caused by network fluctuations, they are prone to missed detections, unable to detect attack behaviors in a timely manner, and even difficult to record the attack source information, affecting the security defense capabilities. However, this solution extracts the global key points of the file through SURF. Its algorithm has strong robustness to noise and partial data loss, so that even if there is partial binary data loss in the file, a high matching accuracy can still be maintained.

[0053] In addition, this application adopts a method combining binary stream conversion and image matching, avoiding directly opening or executing the file to be detected, effectively reducing the security risks in the detection process, and improving the reliability and applicability of the detection.

[0054] Next, with the help of specific embodiments, the content of this application will be described in detail.

[0055] Figure 1 is a flowchart of a method for detecting malicious files shown according to an exemplary embodiment. The method 10 for detecting malicious files at least includes steps S102 to S110.

[0056] As Figure 1 shown, in S102, a set of key points of the file to be detected is extracted in the form of a grayscale image. For example, the file to be detected can be converted into a grayscale image; the set of key points in the grayscale image is extracted. The purpose of this step is to convert the file to be detected into a grayscale image suitable for computer vision analysis and extract its set of key points for subsequent matching.

[0057] More specifically, the binary data of the file to be detected can be converted into the grayscale image through the B2M algorithm. The B2M conversion algorithm can be used to map the binary data of the file to be detected into pixel values and convert it into a grayscale image. Through the numerical distribution of byte data, it can be mapped to grayscale values between 0 and 255.

[0058] More specifically, it may be based on an 8-bit data block or a specific hash function conversion, and the present application is not limited thereto.

[0059] More specifically, the SURF algorithm can also be used to detect key points in the grayscale image to generate the feature point set. The SURF (Speeded-Up Robust Features) algorithm is used for key point detection: for example, the Hessian matrix can be calculated to identify regions with high gradient changes, that is, key points. Calculate the key point directions and generate feature descriptors for subsequent matching.

[0060] In S104, the feature point set is initially matched with the malicious file feature point set to generate initial matching point pairs. For example, the Euclidean distance or KNN (K-Nearest Neighbors) can be used for matching: calculate the similarity between the feature point set of the file to be detected and each feature point in the malicious file sample library. The nearest neighbor ratio (NNR) can also be used to screen candidate matching points. Record the matching point pairs between the feature points of the file to be detected and the feature points of the malicious file samples as the initial matching pairs.

[0061] In one embodiment, it further includes: obtaining multiple malicious files and converting them into multiple grayscale images; performing key point detection on each of the multiple grayscale images to generate multiple malicious file feature point sets. A malicious file sample library can be established, multiple malicious files are obtained, and the grayscale image conversion method in the above steps is used to generate multiple malicious file grayscale images. Perform SURF key point detection on each malicious file grayscale image to generate multiple malicious file feature point sets and store them in the sample library.

[0062] In S106, the optimal matching point pairs are extracted from the initial matching point pairs. For example, according to the RANSAC algorithm, the mis-matching points in the initial matching point pairs are removed; the best matching point pairs are obtained according to the inlier ratio threshold and the maximum number of iterations. Since the initial matching result may contain mis-matching points, this step uses the RANSAC (Random Sample Consensus) algorithm for optimization to filter out the incorrect matching points and extract the optimal matching point pairs.

[0063] More specifically, the RANSAC algorithm can be used to randomly sample the initial matching point pairs to generate initial matching inliers; iterate based on the initial matching inliers to obtain the optimal homography matrix; screen the initial matching inliers through projection error.

[0064] In S108, the matching ratio of the file to be detected is generated according to the number of the optimal matching point pairs. The matching ratio can be generated according to the number of the optimal matching point pairs and the number of feature points in the malicious file feature point set.

[0065] The matching ratio calculation formula can be:

[0066] Matching ratio = the number of optimal matching point pairs / the total number of feature points in the malicious file sample feature point set;

[0067] If there are many matching points between the file to be detected and the malicious file sample, it indicates that their similarity is high.

[0068] In S110, when the matching ratio is greater than the threshold, it is determined that the file to be detected is a malicious file. In the field of images, the set value of this threshold is relatively high, such as 0.8. Considering that the application field of this application is malicious file recognition, the difference between the binary sequence conversion in malicious files and typical image matching, and the noise interference caused by incomplete files, in this application, this threshold can be set to 0.6.

[0069] According to the malicious file detection method of this application, by extracting the feature point set of the file to be detected in the form of a grayscale image; preliminarily matching the feature point set with the malicious file feature point set to generate preliminary matching point pairs; extracting the optimal matching point pairs from the preliminary matching point pairs; generating the matching ratio of the file to be detected according to the number of the optimal matching point pairs; and when the matching ratio is greater than the threshold, determining that the file to be detected is a malicious file, it can better handle the problems of file truncation and mutilation caused by network fluctuations. Through the technology of this application, even incomplete malicious files can be detected. Since the technology of this application does not need to open and execute the file to be detected, it also improves the security of the detection process.

[0070] It should be clearly understood that this application describes how to form and use specific examples, but the principles of this application are not limited to any details of these examples. On the contrary, based on the teachings of the content disclosed in this application, these principles can be applied to many other embodiments.

[0071] Figure 2 It is a flowchart of a malicious file detection method shown according to another exemplary embodiment. Figure 2 The shown process 20 is a supplementary description of Figure 1 the shown process.

[0072] Such as Figure 2 shown, in S202, the feature point set of the file to be detected and the malicious file feature point set are preliminarily matched. Calculate the feature similarity between the file to be detected and a certain malicious file in the malicious file sample library, and judge the relevance between the two through feature point matching.

[0073] In S204, a matching ratio for the malicious file feature point set is generated. The matching ratio is used to measure the similarity between the file to be detected and a certain malicious file, and it is a key indicator for determining whether a file is a malicious file.

[0074] In S206, when the matching ratio is less than the threshold, continue to compare with other malicious file feature point sets. If the current matching ratio does not reach the set threshold, it is necessary to continue to match with the next malicious file in the sample library to ensure the comprehensiveness of the detection.

[0075] In S208, when the matching ratio is greater than the threshold, determine that the file to be detected is a malicious file. For example, if the matching ratio of the file to be detected and the malicious file ≥ 0.6 (i.e., more than 60% of the feature points match), it is determined to be highly similar, and the file is a malicious file.

[0076] Figure 3 It is a flowchart of a method for detecting malicious files shown according to another exemplary embodiment. Figure 3 The shown process 30 is for Figure 1 a detailed description of S106 "extracting the optimal matching point pairs from the preliminary matching point pairs" in the shown process.

[0077] As Figure 3 shown, in S302, randomly sample the preliminary matching point pairs through the RANSAC algorithm to generate initial matching inliers. Among the preliminary matching point pairs, randomly select 4 - 8 pairs of matching points to construct an initial hypothesized inlier set. These points are hypothesized to be correctly matched points and will be used to calculate the projective transformation relationship between the files.

[0078] Calculate the projective transformation relationship, i.e., the homography matrix, between the file to be detected and the malicious file sample through the selected matching points. This matrix describes the geometric correspondence between the files. Since the matching point pairs may contain false matches, subsequent steps will screen and optimize them.

[0079] In S304, iterate based on the initial matching inliers to obtain the optimal homography matrix. After calculating the homography matrix, check whether other matching points conform to this transformation relationship. If the transformation error of some points is small, add them to the inlier set to make it more stable.

[0080] Re - select new random matching points, repeat calculating the homography matrix, and optimize the inlier set. After multiple rounds of iteration, find the homography matrix with the largest number of inliers as the final result.

[0081] In S306, screen the initial matching inliers through the projection error. Calculate the transformation results of all matching points under the homography matrix, compare with the actual matching point positions, and judge whether their deviations are within the allowable range.

[0082] If the error of a certain matching point is lower than the set threshold (such as the pixel offset is less than a certain range), it is determined to be a valid inlier. If the error is large, eliminate this point to avoid false matches affecting the final judgment.

[0083] In S308, the optimal matching point pairs are obtained according to the inlier ratio threshold and the maximum number of iterations.

[0084] For example, a minimum matching ratio can be set to ensure that the number of final matching point pairs is large enough to guarantee the reliability of the judgment. If the ratio of the number of inliers exceeds the set threshold (such as 60%), the homography matrix is considered valid, and the final matching point pairs are determined.

[0085] For another example, the maximum number of iterations can be set to prevent the algorithm from falling into an infinite loop. If no set of inliers that meets the matching ratio is found within the maximum number of iterations, the calculation is terminated to avoid the influence of invalid matching on the detection efficiency.

[0086] Those skilled in the art can understand that all or part of the steps of implementing the above embodiments are realized as a computer program executed by a CPU. When the computer program is executed by the CPU, the above functions defined by the above method provided in this application are executed. The program can be stored in a computer-readable storage medium, which can be a read-only memory, a magnetic disk, an optical disk, etc.

[0087] In addition, it should be noted that the above drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of this application, rather than for limiting purposes. It is easy to understand that the processes shown in the above drawings do not indicate or limit the time sequence of these processes. Additionally, it is also easy to understand that these processes can be executed synchronously or asynchronously in, for example, multiple modules.

[0088] The following is an embodiment of the device of this application, which can be used to execute the method embodiment of this application. For details not disclosed in the device embodiment of this application, please refer to the method embodiment of this application.

[0089] Figure 4 is a block diagram of a malicious file detection device shown according to an exemplary embodiment. As Figure 4 shown, the malicious file detection device 40 includes: a feature module 402, a matching module 404, an extraction module 406, a ratio module 408, and a judgment module 410.

[0090] The feature module 402 is used to extract a set of feature points of the file to be detected in the form of a grayscale image; the feature module 402 is also used to convert the file to be detected into a grayscale image; and extract the set of feature points in the grayscale image.

[0091] The matching module 404 is used to perform a preliminary match between the set of feature points and the set of malicious file feature points to generate preliminary matching point pairs;

[0092] The extraction module 406 is used to extract the optimal matching point pairs from the preliminary matching point pairs; the extraction module 406 is further used to eliminate the mismatched points in the preliminary matching point pairs according to the RANSAC algorithm; the best matching point pairs are obtained according to the inlier ratio threshold and the maximum number of iterations.

[0093] The ratio module 408 is used to generate the matching ratio of the file to be detected according to the number of the optimal matching point pairs; the ratio module 408 is further used to generate the matching ratio according to the number of the optimal matching point pairs and the number of feature points in the malicious file feature point set.

[0094] The determination module 410 is used to determine that the file to be detected is a malicious file when the matching ratio is greater than the threshold.

[0095] According to the malicious file detection device of the present application, the feature point set of the file to be detected is extracted by means of a grayscale image; the feature point set is preliminarily matched with the malicious file feature point set to generate preliminary matching point pairs; the optimal matching point pairs are extracted from the preliminary matching point pairs; the matching ratio of the file to be detected is generated according to the number of the optimal matching point pairs; when the matching ratio is greater than the threshold, the way of determining that the file to be detected is a malicious file can better cope with the problems of file truncation and mutilation caused by network fluctuations. Through the technology of the present application, even an incomplete malicious file can be detected. Since the technology of the present application does not need to open and execute the file to be detected, the security of the detection process is also improved.

[0096] Figure 5 It is a block diagram of an electronic device shown according to an exemplary embodiment.

[0097] Next, refer to Figure 5 to describe the electronic device 500 according to this embodiment of the present application. Figure 5 The shown electronic device 500 is only an example and should not bring any limitation to the functions and the scope of use of the embodiments of the present application.

[0098] As Figure 5 shown, the electronic device 500 is presented in the form of a general-purpose computing device. The components of the electronic device 500 may include but are not limited to: at least one processing unit 510, at least one storage unit 520, a bus 530 connecting different system components (including the storage unit 520 and the processing unit 510), a display unit 540, etc.

[0099] Among them, the storage unit stores program codes, and the program codes can be executed by the processing unit 510, so that the processing unit 510 executes the steps according to various exemplary embodiments of the present application described in this specification. For example, the processing unit 510 can execute as Figure 1 ,Figure 2 , Figure 3 the steps shown in

[0100] The storage unit 520 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 5201 and / or a cache storage unit 5202, and may further include a read-only storage unit (ROM) 5203.

[0101] The storage unit 520 may also include a program / utilities 5204 having a set (at least one) of program modules 5205. Such program modules 5205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.

[0102] The bus 530 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus structures.

[0103] The electronic device 500 may also communicate with one or more external devices 500' (such as a keyboard, a pointing device, a Bluetooth device, etc.), a device that enables a user to interact with the electronic device 500, and / or any device with which the electronic device 500 can communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication may be through an input / output (I / O) interface 550. Also, the electronic device 500 may communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 560. The network adapter 560 may communicate with other modules of the electronic device 500 through the bus 530. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 500, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0104] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, as Figure 6As shown, the technical solution according to the embodiment of the present application can be embodied in the form of a software product. This software product can be stored in a non-volatile storage medium (which can be a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, server, or network device, etc.) to execute the above method according to the embodiment of the present application.

[0105] The software product can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0106] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable storage medium can also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium can be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination of the above.

[0107] The program code for executing the operations of the present application can be written in any combination of one or more programming languages. The programming languages include object-oriented programming languages - such as Java, C++, etc., and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as an independent software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, by using an Internet service provider to connect through the Internet).

[0108] The above computer-readable medium carries one or more programs, which, when executed by the device, cause the computer-readable medium to implement the following functions: extracting a feature point set of a file to be detected in a grayscale image manner; preliminarily matching the feature point set with a malicious file feature point set to generate preliminary matching point pairs; extracting optimal matching point pairs from the preliminary matching point pairs; generating a matching ratio of the file to be detected according to the number of the optimal matching point pairs; and determining that the file to be detected is a malicious file when the matching ratio is greater than a threshold value.

[0109] Those skilled in the art can understand that the above-mentioned modules can be distributed in the device according to the description of the embodiments, or can be correspondingly changed and distributed in one or more devices that are different from the embodiments. The modules of the above embodiments can be combined into one module, or can be further split into multiple sub-modules.

[0110] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described here can be implemented by software, or can be implemented by a combination of software and necessary hardware. Therefore, the technical solution according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to cause a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.

[0111] The above specifically shows and describes the exemplary embodiments of the present application. It should be understood that the present application is not limited to the detailed structure, setting mode or implementation method described here; on the contrary, the present application is intended to cover various modifications and equivalent settings included in the spirit and scope of the appended claims.

Claims

1. A method for detecting malicious files, characterized in that: include: Extract the feature point set of the file to be detected by grayscale image; Preliminarily matching the feature point set with the malicious file feature point set to generate preliminary matching point pairs; Extracting the best matching point pair from the preliminary matching point pairs; Generating a matching ratio of the file to be detected according to the number of the optimal matching point pairs; When the matching ratio is greater than a threshold, it is determined that the file to be detected is a malicious file.

2. The method according to claim 1, characterized in that Also includes: Obtain multiple malicious files and convert them into multiple grayscale images; Key point detection is performed on the plurality of features to generate a plurality of malicious file feature point sets.

3. The method according to claim 1, characterized in that Also includes: Preliminarily matching the feature point set of the file to be detected with multiple feature point sets of malicious files one by one to generate multiple matching ratios; When the multiple matching ratios are all smaller than a threshold, it is determined that the file to be detected is a normal file.

4. The method according to claim 1, characterized in that The feature point set of the file to be detected is extracted by grayscale image, including: Convert the file to be detected into a grayscale image; A feature point set in the grayscale image is extracted.

5. The method according to claim 4, characterized in that Convert the file to be detected into a grayscale image, including: The binary data of the file to be detected is converted into the grayscale image through the B2M algorithm.

6. The method according to claim 4, characterized in that Extracting a feature point set in the grayscale image includes: The SURF algorithm is used to detect key points of the grayscale image to generate the feature point set.

7. The method according to claim 1, characterized in that Extracting the best matching point pair from the preliminary matching point pairs includes: Eliminate mismatched points in the preliminary matching point pairs according to the RANSAC algorithm; The best matching point pair is obtained according to the internal point ratio threshold and the maximum number of iterations.

8. The method according to claim 7, characterized in that Eliminating mismatched points in the preliminary matching point pairs according to the RANSAC algorithm includes: Randomly sampling the preliminary matching point pairs to generate initial matching inliers using the RANSAC algorithm; Iterate based on the initial matching interior points to obtain an optimal homography matrix; The initial matching inliers are screened by projection errors.

9. The method according to claim 1, characterized in that Generating a matching ratio of the file to be detected according to the number of the optimal matching point pairs includes: The matching ratio is generated according to the number of the optimal matching point pairs and the number of feature points in the malicious file feature point set.

10. A malicious file detection device, characterized in that: include: A feature module is used to extract a feature point set of the file to be detected by means of a grayscale image; A matching module, used for preliminarily matching the feature point set with the malicious file feature point set to generate a preliminary matching point pair; An extraction module, used for extracting the best matching point pair from the preliminary matching point pairs; A ratio module, used for generating a matching ratio of the file to be detected according to the number of the optimal matching point pairs; The judgment module is used to determine that the file to be detected is a malicious file when the matching ratio is greater than a threshold.