Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

31 results about "Software behavior" patented technology

Systems and methods for detecting malicious activity with a foundational language model

Disclosed herein are systems and method for detecting malicious activity. A method may receive a plurality of logs indicative of software behavior from an endpoint device and generate, based on the plurality of logs, a provenance graph that represents relationships between different types of data objects on the endpoint device. The method may detect a plurality of trigger actions in the provenance graph and generate, for each respective trigger action of the plurality of trigger actions, a sequence of events that contributed to an occurrence of the respective trigger action. The method may train, using sequences of events generated for the plurality of trigger actions, a foundational language model to predict resultant events for a sequence of lead up events and classify whether the resultant events indicate malicious activity. The method may detect the malicious activity by applying the foundational language model on an input sequence of events.
Owner:ACRONIS INTEMATIONAL GMBH

Detection of anomalies associated with interfering processes

Methods and systems for detecting anomalous software behavior by monitoring frequency spectrums emanating from an electronic device are provided. A method includes storing frequency spectrum profiles for software applications and operational modes on the device. During execution of a software application, the real-time emanating frequency spectrum is measured and compared to the stored spectrum profile for that application and operational mode. Deviations between the real-time and reference spectrums indicate anomalous behavior from unknown software executing. The device determines a deviation exists and performs remedial actions like alerting the user, disconnecting from the network, shutting down, or switching application execution to another device. Frequency profiles are measured for new applications installed and stored to keep the data updated. Monitoring real-time frequency spectrums emanating from a device provides a computationally lightweight technique for detecting malicious software behavior without requiring complex analysis of application code.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Systems and methods for detecting malicious activity using a machine learning model tuned to a specific endpoint device

Disclosed herein are systems and method for detecting malicious activity using a tuned machine learning model. In one aspect, a method includes receiving a plurality of logs indicative of software behavior from a plurality of endpoint devices and generating a plurality of event sequences from the plurality of logs. The method includes training a global machine learning model using the plurality of event sequences to predict resultant events for a sequence of lead up events and classify whether the resultant events indicate malicious activity. The method includes, for each respective endpoint device of the plurality of endpoint devices, generating a testing dataset comprising a plurality of benign event sequences that occurred on the respective endpoint device. The method includes generating a tuned machine learning model for the respective endpoint device by retraining the global machine learning model using the testing dataset. The method includes executing the tuned machine learning model.
Owner:ACRONIS INT

Domestic software and hardware compatibility intelligent evaluation system and method thereof

The invention relates to the technical field of software and hardware compatibility testing, in particular to a domestic software and hardware compatibility intelligent evaluation system and method, and the system comprises a compatibility analysis engine, a compatibility detection task execution engine, a software behavior analysis module, a fault positioning module, a knowledge graph module, a performance optimization suggestion module and a visual interface. The software behavior analysis module constructs a high-dimensional feature space of a software running state through deep learning, and extracts abnormal features based on a topological space mapping technology; the fault positioning module constructs a dynamic causal network based on a probability graph model, and identifies a root node through a chaos sensitivity analysis algorithm; the knowledge graph module constructs a software and hardware dependency relationship model and provides priori knowledge for fault location; and the performance optimization suggestion module generates an optimization scheme based on the root positioning result, so that the functions of automatically executing a compatibility test, accurately positioning the root of the compatibility problem and providing targeted optimization suggestions are realized, and the adaptation efficiency of domestic software and hardware is greatly improved.
Owner:BEIJING ZHIDAKE INFORMATION TECH CO LTD

Construction method of approximate specification mining model and software behavior verification system

The invention belongs to a specification mining technology of software engineering, and relates to a construction method of an approximate specification mining model and a software behavior verification system. The construction method comprises the following steps: generating a group of linear temporal logic LTL formulas for describing positive example time sequence attributes according to a positive example set; using an LTL formula to generate a potential negative example for evaluation and training; designing and constructing a neural network for analyzing the finite state automaton from the parameter assignment so as to simulate an acceptance behavior of the finite state automaton; and iteratively searching the neural network through a gradient descent algorithm until the maximum number of iterations is reached, and mining to obtain the finite state automaton. The neural network can simulate acceptance of the finite state automaton in the reasoning process, the finite state automaton can be explained at low cost, and the problem of search space explosion is solved.
Owner:SUN YAT SEN UNIV

Malicious software analysis and identification method and device

The invention discloses a malicious software analysis and identification method and device. The method comprises the steps of performing data extraction on a to-be-detected code running in a sandbox, and determining an application program editing interface calling sequence; performing feature processing on the application program editing interface calling sequence through a pre-constructed multi-head attention map network, and determining a feature extraction map; performing feature extraction on the application program editing interface calling sequence through a preset multi-dimensional word embedding method, and determining a target semantic chain embedding vector; and malicious code identification is carried out according to the feature extraction graph and the target semantic chain embedding vector through a pre-constructed identification network, and a target identification result is determined. According to the method, the common features of the malicious behaviors can be captured by fusing the features of different levels, and accurate classification and detection of the malicious software behaviors are realized, so that the robustness and accuracy of malicious software detection are improved.
Owner:INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER +2

A multi-level protocol software dangerous behavior detection method

ActiveCN121859332BPlatform integrity maintainanceTemporal logicLinguistic model
The application belongs to the technical field of software dangerous behavior detection, and is a multi-level specification software dangerous behavior detection method, comprising the following steps: setting a positive and negative example set and a distance measurement function for quantifying the similarity degree of software behavior sequences, and dividing the positive example set into a plurality of positive example subsets; constructing a temporal logic specification weight tree as a triple consisting of a root node weight function, a left child formula depth weight function and a right child formula depth weight function; extracting positive examples from the positive example subsets to form a positive example reduced set; inquiring a large language model to obtain software dangerous behavior logic formulas and converting the software dangerous behavior logic formulas into equivalent finite state automata; sampling a negative example reduced set from the automata; inquiring the large language model based on the positive and negative example reduced sets multiple times to obtain formula fragments, dynamically updating the weight tree, and obtaining candidate formulas; and selecting the optimal candidate formula as a temporal logic specification to detect whether the software behavior sequence conforms to the temporal logic specification. The application alleviates the challenges of scarce dangerous behavior data and a too large dangerous behavior search space.
Owner:SUN YAT SEN UNIV

Software fault detection method based on software behavior analysis and intelligent reasoning

The invention discloses a software fault detection method based on software behavior analysis and intelligent reasoning, belongs to the technical field of computer system software, and aims to solve the technical problems of low efficiency and poor accuracy of a current traditional software fault detection mode and improve the troubleshooting efficiency. According to the technical scheme, the method comprises the steps that firstly, software behaviors are defined, file access, memory operation and other types are covered, software codes are scanned, the behaviors are recorded in detail, recording formats are defined, including recording time, code positions and other information, and then a software behavior fault model is established; secondly, defining fault log information including fault time, register values and the like, and constructing an analysis mechanism; when the log is analyzed, the log is read and analyzed, the fault position and the initial reason are judged, the final reason is determined in combination with the fault code, and finally the fault code position and condition are determined according to the model. The software fault can be efficiently detected and positioned, manual intervention is greatly reduced, the software stability and reliability are improved, and the method is suitable for various software fault detection scenes.
Owner:CHINA THREE GORGES UNIV

Software verification method and device, equipment, medium and program product

The invention provides a software verification method and device, equipment, a medium and a program product, and can be applied to the technical field of software management and artificial intelligence. The method comprises the steps that in response to obtained information of to-be-verified software, identity information and behavior information of the to-be-verified software are extracted, and the identity information comprises at least one of a program name, a version number, an installation date, a digital signature or a file hash value; the behavior information comprises at least one of resource occupation, a network connection behavior, a file operation behavior or a running time period; whether the identity information of the to-be-verified software is matched with a pre-configured software standard information base white list or not is verified, whether the behavior information accords with a predetermined software behavior baseline or not is verified, and the baseline is established according to historical behavior information of normal software identical to the to-be-verified software; and if both the identity information and the behavior information pass verification, determining that the to-be-verified software is normal software.
Owner:CHINA CONSTRUCTION BANK +1

Power chip security protection method and device

The invention relates to a power chip security protection method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the steps that in response to a data access request sent by an access device for a chip, a first entropy value, a second entropy value and a third entropy value of the chip are obtained, the first entropy value is used for representing hardware physical characteristics of the chip, the second entropy value is used for representing software behavior characteristics of the chip in the data processing process, and the third entropy value is used for representing software behavior characteristics of the chip in the data processing process; the third entropy value is used for representing environment information of the chip; generating a target entropy according to the first entropy, the second entropy and the third entropy; and generating a challenge packet according to the target entropy and the anti-quantum attack root key, sending the challenge packet to the access device, and sending a data access token to the access device when a response factor returned by the access device for the challenge packet is effective. By adopting the method, the security of the chip can be improved.
Owner:CHINA SOUTHERN POWER GRID NEW POWER SYSTEM (BEIJING) RESEARCH INSTITUTE CO LTD

Domestic chip and CAE (Computer Aided Engineering) software collaborative optimization method and system combined with AI (Artificial Intelligence) technology

The invention discloses a domestic chip and CAE software collaborative optimization method and system combined with an AI technology, and belongs to the technical field of collaborative optimization, and the method comprises the steps: obtaining, preprocessing and marking original data, and obtaining training data; the initialized AI model is trained, and a trained AI model is obtained; acquiring real-time state data and real-time load characteristics, inputting the real-time state data and the real-time load characteristics into the trained AI model to obtain an optimization decision, performing instruction translation on the optimization decision to obtain a specific control instruction, sending the specific control instruction to chip hardware, automatically adjusting hardware behaviors and / or operating an interface through software. And automatically adjusting software behaviors. According to the method, dynamic and systematic software and hardware collaborative optimization is realized through an AI-driven optimization closed loop, and meanwhile, relevant parameter indexes can be adjusted and optimized.
Owner:NEOLITHIC COBALT BLUE INFORMATION TECHNOLOGY CO LTD

APT detection method and device in smart power plant and storage medium

The invention discloses an APT detection method and device in a smart power plant and a storage medium. The method comprises the steps that a program behavior model is adopted, and a low-layer system call API and a high-layer call stack API are fused to construct a feature generation module so as to accurately describe software behaviors; a noise problem is solved by using an optimal local graph matching algorithm based on dynamic programming, so that behaviors of malicious software are accurately identified. In the application, the feature generation module is constructed by combining the program behavior model with the low-level system call API and the high-level call stack API, so as to accurately describe software behaviors; and the noise problem is solved by using an optimal local graph matching algorithm of dynamic planning, and malicious software behaviors are accurately identified. According to the method, the detection accuracy and reliability are improved through multi-level and multi-dimensional feature description, noise is effectively filtered out, and the power plant network security protection capability, adaptability and expandability are improved.
Owner:GUODIAN ZHEJIANG BEILUN FIRST POWER GENERATION CO LTD

Processor system structure state extraction method based on instruction injection

The invention provides a processor system structure state extraction method based on instruction injection, which comprises the following steps of: S1, acquiring a written debugging program, and implanting the debugging program into an illegal instruction exception handling function of software to be tested, the debugging program is triggered by a specified illegal instruction word injected by a user to read the system structure state of the simulation processor, and the system structure state comprises state information of a register and a memory; s2, embedding a microstructure mark in hardware of a simulation processor running on the software behavior simulator so as to provide a controllable operation point for injecting a specified illegal instruction word for the simulator; s3, when the system structure state of the simulation processor needs to be extracted, specified illegal instruction words are injected into the simulation processor through the microstructure marks, the simulation processor enters an exception handling process under the condition that the simulator determines that the specified illegal instruction words are received, and the system structure state of the simulation processor is extracted. And automatically skipping to the debugging program by executing the exception handling function to extract and output the extracted architecture state.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

Computer terminal user and software exception identification method

A computer terminal user and software exception identification method belongs to the field of computer science. The method aims at solving the problems that existing computer terminal security detection excessively depends on static rules and priori knowledge, and unknown threats cannot be accurately recognized. Static and dynamic user and software behavior feature vectors of a terminal are captured; the captured feature vectors are integrated and standardized; establishing a supervised learning model, and training the supervised learning model by using the historical user and software behavior feature vectors and the corresponding fault data to obtain a feature anomaly recognition model; and identifying the integrated and standardized feature vectors by using the anomaly identification model, and judging whether the computer terminal user and the software are abnormal or not. The method is mainly used for computer terminal user and software exception identification.
Owner:HARBIN FINANCE UNIV

User interrupt processing method and system

The invention discloses a user interrupt processing method and system, and belongs to the technical field of data transmission. The method comprises the following steps: when a user logic end of the FPGA requests to generate user interruption, notifying an upper computer through an XDMA IP (Extensible Direct Memory Access Internet Protocol); the upper computer receives the notification of generating the user interrupt, processes the user interrupt generated this time, and updates the state of a preset first register after processing is completed; the user logic end determines whether the upper computer completes processing of the user interruption generated this time or not according to the state of the first register, updates the state of a preset second register after determining that the processing is completed, and executes subsequent logic; and the upper computer determines whether the user interruption can be enabled again according to the state of the second register. Through bidirectional confirmation of the first register and the second register, software and hardware behaviors are strictly synchronized, and hardware time sequence requirements of XDMA IP are perfectly met, so that each interruption can be completely and correctly processed.
Owner:BEIJING INST OF ENVIRONMENTAL FEATURES

A vulnerability lossless detection method based on patch correlation behavior exploration

This invention relates to a non-destructive vulnerability detection method based on patch-related behavior exploration, belonging to the field of network security technology. This invention compares and analyzes the vulnerable versions and patch versions of binary software to explore the differences in software behavior introduced by the vulnerability patches, thereby generating non-destructive detection samples. This method can accurately detect the existence of known vulnerabilities while ensuring the normal operation of the software system.
Owner:BEIJING INST OF COMP TECH & APPL

Systems and methods for detecting malicious activity using a machine learning model tuned to a specific endpoint device

Disclosed herein are systems and method for detecting malicious activity using a tuned machine learning model. In one aspect, a method includes receiving a plurality of logs indicative of software behavior from a plurality of endpoint devices and generating a plurality of event sequences from the plurality of logs. The method includes training a global machine learning model using the plurality of event sequences to predict resultant events for a sequence of lead up events and classify whether the resultant events indicate malicious activity. The method includes, for each respective endpoint device of the plurality of endpoint devices, generating a testing dataset comprising a plurality of benign event sequences that occurred on the respective endpoint device. The method includes generating a tuned machine learning model for the respective endpoint device by retraining the global machine learning model using the testing dataset. The method includes executing the tuned machine learning model.
Owner:ACRONIS INT

Domestic chip and CAE (Computer Aided Engineering) software collaborative optimization method and system combined with AI (Artificial Intelligence) technology

The invention discloses a domestic chip and CAE software collaborative optimization method and system combined with an AI technology, and belongs to the technical field of collaborative optimization, and the method comprises the steps: obtaining, preprocessing and marking original data, and obtaining training data; the initialized AI model is trained, and a trained AI model is obtained; acquiring real-time state data and real-time load characteristics, inputting the real-time state data and the real-time load characteristics into the trained AI model to obtain an optimization decision, performing instruction translation on the optimization decision to obtain a specific control instruction, sending the specific control instruction to chip hardware, automatically adjusting hardware behaviors and / or operating an interface through software. And automatically adjusting software behaviors. According to the method, dynamic and systematic software and hardware collaborative optimization is realized through an AI-driven optimization closed loop, and meanwhile, relevant parameter indexes can be adjusted and optimized.
Owner:NEOLITHIC COBALT BLUE INFORMATION TECHNOLOGY CO LTD

Method and system for constructing digital twin interphone

The invention discloses a method and a system for constructing a digital twin interphone. The method comprises the following steps of: 1, realizing hardware state data acquisition, software behavior data acquisition and communication environment data acquisition in a mode of combining hardware circuit transformation and software code instrumentation; 2, constructing a structured twinborn database through data preprocessing, feature engineering processing and database structure and storage by using the massive and heterogeneous original data with timestamps collected in the step 1, and training by using a machine learning technology to obtain a digital twinborn model of the interphone; 3, loading the digital twinborn model generated in the step 2, providing a virtual CPU, peripheral and radio frequency environment, executing unmodified actual interphone software codes or binary files, integrating a reinforcement learning AI algorithm in the digital twinborn model, performing automatic search and optimization on software parameters in a simulation environment, and obtaining a simulation result; and by taking power consumption and performance as optimization targets, displaying a simulation result in the form of a time sequence curve and / or a thermodynamic diagram.
Owner:SAMHOO SCI & TECH CO LTD

System and method of software behavior analysis

There are provided a method and a system of software behavior analysis. The method comprises: retrieving data sources related to a software program and mapping a list of behaviors characterizing the software program. Additionally, the method can comprise analyzing the list of behaviors to obtain at least one trait of at least one of the behaviors, and / or transcoding the list of behaviors to corresponding natural language descriptions and presenting the natural language descriptions of the list of behaviors to a user on a Graphical user interface (GUI). There are further provided a method and a system of testing changes between different versions of a software program based on the software behavior mapping and analysis.
Owner:CODIUN

Software behavior anomaly detection system and method based on deep learning

The application discloses a software behavior anomaly detection system and method based on deep learning, which comprises a behavior monitoring module, an anomaly detection module, an adaptive protection module and a model evolution module.The behavior monitoring module is used for capturing the calling sequence and context semantic information of a process and extracting a multi-dimensional feature vector.The anomaly detection module is used for analyzing the multi-dimensional feature vector through a hierarchical neural symbolic network, outputting a fusion feature through dynamic weighting of a gated symbolic attention mechanism, triggering a causal inference engine and a dynamic response framework based on a reinforcement decision tree.The adaptive protection module comprises the causal inference engine and the dynamic response framework based on the reinforcement decision tree, adjusts the protection strength according to an environmental risk index, and feeds back a feedback signal to the anomaly detection module to optimize a threshold.The model evolution module is used for integrating an adversarial sample generator and an online incremental learning mechanism to realize self-evolution capability.The application effectively solves the problem of missed detection of periodic attacks and hidden vulnerabilities, and significantly suppresses false positives caused by feature misjudgment.
Owner:HANGZHOU DIANZI UNIV

Deep learning malicious software detection method based on API sequence

According to the deep learning malicious software detection method based on the API sequence, the defects of a traditional malicious software detection method are improved, and the deep learning malicious software detection method based on the API sequence has the advantages that the accuracy rate is high, the anti-interference capacity is high, unknown novel and unknown malicious software can be recognized, and the malicious software subjected to shell adding and mixing processing can be detected. The basic idea of the method is as follows: simultaneously considering the structural characteristics of an API call sequence and the context dependency relationship between API calls, and obtaining the API call sequence during software running through a sandbox; then extracting feature structures of the sequences by using a depth auto-encoder, and extracting a hyponymy dependency relationship between the sequences by using a gated convolutional network and a bidirectional long-short time memory network; and finally, learning malicious software behavior characteristics by using a multi-layer perceptron, and performing detection. According to the method, malicious software detection can be accurately and efficiently carried out, and the model updating and maintaining cost is low.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Software behavior anomaly detection system and method based on deep learning

The invention discloses a software behavior anomaly detection system and method based on deep learning, and the system comprises a behavior monitoring module which is used for capturing a call sequence and context semantic information of a process, and extracting a multi-dimensional feature vector; the anomaly detection module is used for analyzing the multi-dimensional feature vectors through a hierarchical neural symbol network, outputting fusion features, dynamically weighting the fusion features through a gating symbol attention mechanism, and triggering a causal inference engine and a dynamic response framework based on an enhanced decision tree; the self-adaptive protection module comprises a causal inference engine and a dynamic response framework based on an enhanced decision tree, adjusts the protection intensity according to the environmental risk index, and transmits a feedback signal back to the anomaly detection module to optimize a threshold value; and the model evolution module is used for integrating an adversarial sample generator and an online incremental learning mechanism to realize the self-evolution capability. According to the method, the problem of leak detection of periodic attacks and hidden vulnerabilities is effectively solved, and meanwhile, false alarms caused by feature misjudgment are remarkably inhibited.
Owner:HANGZHOU DIANZI UNIV

A method for rapid detection of malware based on power sandbox

The present application relates to the technical field of information security, and more particularly to a method for rapidly detecting malicious software based on a power sandbox, comprising monitoring target software, marking suspicious software, determining abnormal states and screening out abnormal software, evaluating attack strength, isolating and adjusting, wherein the present application significantly improves the detection accuracy of malicious software by monitoring the behavior of target software in real time in a virtual power system and combining multiple detection mechanisms, detailed analysis is performed using preset standard values and parameter ranges, abnormal software can be effectively distinguished, false positives are reduced, further evaluation is performed by setting different power load environments in the sandbox environment, comprehensive detection of malicious software behavior is ensured, and the security and stability of the system are improved by dynamically adjusting the evaluation duration to adapt to different attack modes and system states, thereby effectively solving the problems of untimely detection and high false positive rate caused by the complex and variable behavior of malicious software and long detection response time.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD NINGBO POWER SUPPLY CO

Machine learning-based system for sandboxing and malware detection

A system for detecting and containing malicious software behavior using machine learning in a secure sandbox environment, consisting of: a sandbox controller configured to instantiate at least one virtualized execution environment (VEE) for executing an observed target software example; a behavioral feature extraction processing unit operatively coupled to the sandbox controller, the behavioral feature extraction processing unit configured to monitor and record system-level events, including system calls, file system interactions, memory allocation patterns, interprocess communication events, and network activity generated by the target software sample within the VEE; a machine learning inference engine operatively connected to the behavioral feature extraction processing unit, the inference engine comprising a plurality of trained models, including at least one deep neural network (DNN), a long short-term memory network (LSTM), and a gradient boosting decision tree (GBDT), each configured to generate a classification output based on an input behavior vector derived from the monitored system-level events; a meta-classification arbitration processing unit configured to combine the classification outputs of the plurality of trained models and generate a threat classification score indicating the maliciousness of the target software sample; a federated learning interface configured to securely transmit anonymized behavior vectors and receive global model updates from a distributed group of peer systems participating in a federated threat intelligence network; and An automated remediation control unit configured to initiate containment and response actions based on the threat classification assessment. These actions include file quarantine, virtual environment rollback, execution blocking, and forensic logging.
Owner:RAJAGOPAL SMITHA DR BENGALURU

Abnormal software behavior remote identification method and system for multi-player game terminal

PendingCN121997236Aensure authenticityEnsure standardizationVideo gamesData setLocal outlier factor
The invention discloses an abnormal software behavior remote identification method and system oriented to a multi-player game terminal, particularly relates to the technical field of chess and card game terminal safety protection, and is used for solving the problem that in the prior art, due to terminal isomerism, behavior characteristic data collection granularity is not uniform, and then remote identification effectiveness is reduced. Collection granularity information is synchronously bound when behavior characteristic data are collected at a terminal side, a server side verifies the integrity and granularity marking validity of the data after receiving the data, then cluster classification is carried out according to terminal types, collection granularity marking probability distribution is fitted, local outlier factors are calculated accordingly, a data set conforming to a non-outlier threshold value is screened out, and the data set is subjected to data collection. Then, prior distribution is constructed based on probability distribution, correlation confidence is calculated, a data set with the confidence reaching the standard is screened out, then, a same-granularity feature data set is obtained through merging according to granularity marks, finally, quantitative calibration and correlation analysis are conducted on the data set, and therefore accurate recognition of abnormal software behaviors is achieved.
Owner:CHENGDU QUEYOUQUAN CULTURAL COMMUNICATION CO LTD

Malware behavior characteristic visualization method based on characteristic types and medium

The invention discloses a malicious software behavior feature visualization method based on feature types. The method comprises the following steps: extracting various features of malicious software; performing feature processing on each feature of the malicious software by adopting a corresponding processing mode; and carrying out visualization on each type of processed features. The method has the advantages that researchers can be helped to quickly identify similarity and difference between samples in the malicious software analysis process by integrating visualization modes of different types of features, so that the accuracy and efficiency of malicious software analysis are improved.
Owner:XUANCHENG VOCATIONAL & TECH COLLEGE

Multi-level protocol software dangerous behavior detection method

ActiveCN121859332APlatform integrity maintainanceTemporal logicLinguistic model
The invention belongs to a software dangerous behavior detection technology, and relates to a multilevel protocol software dangerous behavior detection method, which comprises the following steps of: setting a positive and negative example set and a distance measurement function for quantifying the similarity degree of software behavior sequences, and dividing the positive example set into positive example subsets; constructing a tense logic specification weight tree which is a triple composed of a root node weight function and left and right child formula depth weight functions; extracting positive examples from the positive example subsets to form a positive example simplified set; inquiring the large language model to obtain a software dangerous behavior logic formula, and converting the software dangerous behavior logic formula into an equivalent finite state automaton; sampling a counter-example simplified set from the automaton; inquiring the large language model for multiple times based on a positive and negative example simplified set to obtain a formula fragment so as to dynamically update the weight tree and obtain a candidate formula; and selecting the optimal candidate formula as a tense logic specification, and detecting whether the software behavior sequence conforms to the tense logic specification or not. According to the method, the challenges of scarcity of dangerous behavior data and overlarge dangerous behavior search space are relieved.
Owner:SUN YAT SEN UNIV

A malware detection method using dynamic graph attention network

The application discloses a malware detection method using a dynamic graph attention network. The application segments API sequences, constructs API graph snapshot sequences, and uses multiple snapshots to record the change process of software API call graphs, so as to indirectly represent the order and process of software behavior actions, and enable the model to better understand software behavior. The application updates the attention coefficient through the graph attention neural network module, and updates the hidden state through the gated recurrent neural network module, so that the model can capture the local malicious behavior information of the call graph and the evolution process of the call graph structure, and is more suitable for atypical malware detection.
Owner:HANGZHOU DIANZI UNIV

Software trusted measurement method, device and equipment and computer readable storage medium

The invention discloses a software trusted measurement method, device and equipment and a computer readable storage medium. According to the method, an expected behavior state machine is directly constructed based on a non-interference model, the problems of dependence of dynamic modeling on training data and feasibility of static modeling are fundamentally avoided, and a universal and feasible new software behavior credibility measurement normal form is provided.
Owner:FIBERHOME TELECOMMUNICATION TECHNOLOGIES CO LTD