发明名称 CLUSTERING PROCESSING METHOD AND DEVICE FOR VIRUS FILES
摘要 A method and device for clustering virus files is provided. The method involves statically analyzing binary data of virus files to be clustered, so as to obtain PE structure data of the virus files. Further, based on a comparison of the PE structure data, those virus files with PE structure data meeting a specific similarity may be categorized into the same category. The device may include a first data analyzing module configured to extract PE structure data of virus files to be clustered by static analysis of binary data of the virus files. A first clustering module of the device may compare the PE structure data and cluster the virus files having the PE structure data meeting a specific similarity into the same category. The solution may improve efficiency of clustering computer virus files, reduce resource consumption, and avoid the risk of virus infection caused by dynamically running the virus files.
申请公布号 US2014150105(A1) 申请公布日期 2014.05.29
申请号 US201214125042 申请日期 2012.07.03
申请人 YU TAO;TENCENT TECHNOLOGY (SHENZHEN) COMPANY LIMITED 发明人 YU TAO
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址