发明名称 SYSTEM AND METHOD TO COMPARE FILES BASED ON FUNCTIONALITY TEMPLATES
摘要 FIELD: information technologies. ^ SUBSTANCE: method to determine belonging of files to collections of available files on the basis of files comparison with the help of functionality templates includes stages, at which functionality templates are generated on the basis of information on the executed file. Then extracted noise information is deleted from functionality templates of the executed file. Then units of functionality templates of the executed file are reduced to normalised view. Then these units are compared to units of functionality templates of available files, and using comparison results, decision is made on belonging of the unit to one of functionality templates of available files. Creating functionality templates by available malicious software, newly arrived files may be compared with them, and automatic records may be added with condition of similarity; characteristic logical units are extracted from collections of malicious programs, and heuristic rules are created by these units; automatic descriptions are generated. Also the possibility appears to carry out clusterisation of objects, which helps to accelerate their further processing. ^ EFFECT: increased reliability and accuracy of malicious software detection, achieved by comparison of executed files by means of functionality templates. ^ 14 cl, 16 dwg
申请公布号 RU2427890(C2) 申请公布日期 2011.08.27
申请号 RU20090136238 申请日期 2009.10.01
申请人 ZAO "LABORATORIJA KASPERSKOGO" 发明人 VASILENKO ROMAN SERGEEVICH
分类号 G06F7/02;G06F9/44;G06F21/00 主分类号 G06F7/02
代理机构 代理人
主权项
地址