发明名称 SYSTEM AND METHOD FOR AUTOMATIC GENERATION OF HEURISTIC ALGORITHMS FOR MALICIOUS OBJECT IDENTIFICATION
摘要 A server-based system for generation of heuristic scripts for malware detection includes an automatic heuristics generation system for generating heuristic scripts for curing malware infections; a log database containing logs of events from user computers, including detection of known malicious objects and detection of suspicious objects; a safe objects database accessible containing signatures of known safe objects; a malicious objects database containing signatures of known malicious objects. The system retrieves suspect object metadata from the log database and generates the heuristic script based on data from the safe and malicious objects databases. For multiple computers having the same configuration and having the same logs, only one log common to all the multiple computers is transmitted and only one heuristic script is distributed to the multiple computers. A different and specific heuristic script is distributed to those computers that have a different log than the common log.
申请公布号 US2014223566(A1) 申请公布日期 2014.08.07
申请号 US201313756685 申请日期 2013.02.01
申请人 ZAITSEV Oleg V. 发明人 ZAITSEV Oleg V.
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项 1. A computer-implemented system for automatic generation of a heuristic script for malware detection, the system comprising: a server-based automatic heuristics generation system for generating heuristic scripts for curing malware infections on a user computer; a log database connected to the automatic heuristics generation system and containing logs of events that occurred on user computers, the events including detection of known malicious objects and detection of suspicious objects; a safe objects database accessible by the automatic heuristics generation system and containing properties of known safe objects; and a malicious objects database accessible by the automatic heuristics generation system and containing signatures of known malicious objects, wherein the automatic heuristics generation system retrieves suspect object metadata from the log database and generates the heuristic script based on data from the safe objects database and the malicious objects database, wherein, for multiple computers having the same configuration and connected to the same network and having the same logs, only one log that is common to all the multiple computers is transmitted to the log database and only one heuristic script is generated and distributed to the multiple computers, and a different and specific heuristic script is distributed to those computers that have a different log than the common log.
地址 Smolensk RU