发明名称 SYSTEM AND METHOD OF MAKING FLEXIBLE CONVOLUTION FOR MALWARE DETECTION
摘要 FIELD: computer engineering.SUBSTANCE: method of detecting malicious files, where the plurality of variable and immutable signs files from the database files for training; plenty features at least one file; separated multiple selected attributes of file on at least two subsets, in one of which there is at least one variable feature, the other has at least one immutable attribute; obtaining convolution of each of the above subsets of file attributes; created convolution file as a combination of folds of each of the above subsets of file attributes; Comparing the convolution of at least one file with a set of previously created folds files; file is considered to be similar to files from multiple similar files, having the same convolution if during comparison convolution of the said file matches the convolution file from the specified multiple; considered file objects, if the file is similar to files from multiple similar files, wherein said plurality of similar files is multiple harmful files.EFFECT: technical result consists in computer safety.16 cl, 5 dwg
申请公布号 RU2580036(C2) 申请公布日期 2016.04.10
申请号 RU20130129552 申请日期 2013.06.28
申请人 ZAKRYTOE AKTSIONERNOE OBSHCHESTVO "LABORATORIJA KASPERSKOGO" 发明人 ANTONOV ALEKSEJ EVGENEVICH;ROMANENKO ALEKSEJ MIKHAJLOVICH
分类号 G06F21/14 主分类号 G06F21/14
代理机构 代理人
主权项
地址