发明名称 METHOD FOR AUTOMATIC DETECTING MALWARE CODE
摘要 PURPOSE: An automatic malicious code detecting method is provided to improve the performance of a malicious code classification device by classifying similar programs as the same kind. CONSTITUTION: An event set is generated by extracting an event in a range set by a program (910). An unnecessary event to determine the similarity of the program is removed from the event set (920). An event included in the event set is generalized (930). An event indicated as the same order is extracted by analyzing the event set (940). The similarity of the program is calculated based on event order (950). A malicious code of the program is classified based on the similarity (960). [Reference numerals] (910) Event set is generated by extracting an event in a range set by a program; (920) Unnecessary event to determine the similarity of the program is removed from the event set; (930) Event included in the event set is generalized; (940) Event indicated as the same order is extracted by analyzing the event set; (950) Similarity of the program is calculated based on event order; (960) Malicious code of the program is classified based on the similarity; (AA) Start; (BB) End
申请公布号 KR101308228(B1) 申请公布日期 2013.09.13
申请号 KR20110144786 申请日期 2011.12.28
申请人 发明人
分类号 G06F17/00;G06F21/00 主分类号 G06F17/00
代理机构 代理人
主权项
地址