发明名称 METHOD AND APPARATUS FOR CLUSTERING PORTABLE EXECUTABLE FILES
摘要 The present invention relates to Internet and communication technologies, and discloses a method and apparatus for clustering portable executable (PE) files. The method comprises: extracting PE file characteristics from a PE file; generating a PE file identifier for the PE file based on the PE file characteristics; and clustering the PE file base on the PE file identifier. The apparatus comprises an extraction module, a generation module, and a clustering module. In accordance with embodiments of the present invention, a PE file identifier is generated for the PE file based on PE file characteristics extracted from the PE file, and the PE files are clustered based on the PE file identifier. Thus, random PE files are clustered into ordered classes, and the number of PE files to be processed by the antivirus clients and servers are reduced, which reduces storage costs, improves matching efficiency and the ability to detect and combat PE virus variants.
申请公布号 US2015178306(A1) 申请公布日期 2015.06.25
申请号 US201514637343 申请日期 2015.03.03
申请人 TENCENT TECHNOLOGY (SHENZHEN) COMPANY LIMITED 发明人 Yang Yi;Yu Tao;Bai Zi Pan;Cui Jing Bing;Wu Jia Xu
分类号 G06F17/30 主分类号 G06F17/30
代理机构 代理人
主权项 1. A method for clustering portable executable (PE) files, the method comprising: extracting PE file characteristics from a PE file; generating a PE file identifier for the PE file based on the PE file characteristics; and clustering the PE file base on the PE file identifier.
地址 Shenzhen CN