发明名称 BEHAVIORAL SIGNATURE GENERATION USING CLUSTERING
摘要 <p>A behavioral signature for detecting malware is generated. A computer is used to collect behavior traces of malware in a malware dataset. The behavior traces describe sequential behaviors performed by the malware. The behavior traces are normalized to produce malware behavior sequences. Similar malware behavior sequences are clustered together. The malware behavior sequences in a cluster describe behaviors of a malware family. The cluster is analyzed to identify a behavior subsequence common to the cluster's malware family. A behavior signature for the malware family is generated using the behavior subsequence. A trace of new malware is normalized and aligned with an existing cluster, if possible. The behavioral signature for that cluster is generated based on the behavior sequence of the new malware and the other sequences in the cluster.</p>
申请公布号 WO2011137083(A1) 申请公布日期 2011.11.03
申请号 WO2011US33829 申请日期 2011.04.25
申请人 SYMANTEC CORPORATION;SATISH, SOURABH;PEREIRA, SHANE 发明人 SATISH, SOURABH;PEREIRA, SHANE
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址