发明名称 DEVICE AND METHOD FOR ELIMINATING SELF-CHANGING MALWARE
摘要 <p>PROBLEM TO BE SOLVED: To effectively and accurately eliminate self-changing malware that alters a data structure of a file by performing encryption and obfuscation whenever creating an own copy.SOLUTION: A fuzzy hash value (hereinafter, FH value) of a file determined as malware is found with a server device, by using a fuzzy hash algorithm for generating a coincident or similar value to data with a similar structure, and is distributed to a client device. Then, files with the same FH value are enumerated in the client device, a white list DB storing the Exact hash value of a regular file is referred, a decision is made that the file is self-changing malware when the received file is not present in the DB, and the file is eliminated from the client device. When the received file is present in the DB, a decision is made that collision is generated between the malware and the FH value of the regular file, and a threshold value of the FH algorithm is improved.</p>
申请公布号 JP2015011626(A) 申请公布日期 2015.01.19
申请号 JP20130138240 申请日期 2013.07.01
申请人 HITACHI ADVANCED SYSTEMS CORP 发明人 OTAWARA CHIAKI;KAWAGUCHI NOBUTAKA;TANIGAWA YOSHINOBU;KAJI TADASHI
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址
您可能感兴趣的专利