左黎明, 刘二根, 徐保根, 汤鹏志. 未知恶意代码族群归属决策研究[J]. 微电子学与计算机, 2012, 29(2): 188-191,196.
引用本文: 左黎明, 刘二根, 徐保根, 汤鹏志. 未知恶意代码族群归属决策研究[J]. 微电子学与计算机, 2012, 29(2): 188-191,196.
ZUO Li-ming, LIU Er-gen, XU Bao-gen, TANG Peng-zhi. A Research on Decision-making of Unknown Malicious Code's Family[J]. Microelectronics & Computer, 2012, 29(2): 188-191,196.
Citation: ZUO Li-ming, LIU Er-gen, XU Bao-gen, TANG Peng-zhi. A Research on Decision-making of Unknown Malicious Code's Family[J]. Microelectronics & Computer, 2012, 29(2): 188-191,196.

未知恶意代码族群归属决策研究

A Research on Decision-making of Unknown Malicious Code's Family

  • 摘要: 提出了恶意代码API调用函数特征集的概念.根据不同恶意代码为实现相同功能调用相同API函数的特点, 给出了一种基于API调用函数集合的恶意代码特征提取方法.使用集合运算获取族群函数特征集, 通过模糊聚类与熵值法计算出未知恶意代码与已知恶意代码族群的正隶属度, 利用正隶属度极大原则来确定未知恶意代码归属族群, 最后给出算例.该方法不需要人工干预决策, 易于程序实现.

     

    Abstract: A new concept of system API calling characteristics set of malicious codes is given.According to the feature of same API calling of the different malicious codes for the same malicious functions, the new extraction and analysis methods of malicious code characteristics which based on the set of API calling is put forward.The method uses set operations to obtain function characteristics set, calculates the membership degree between unknown malicious code and known malicious code families by fuzzy clustering and entropy method, then judges the family of unknown malicious code by the principle of max membership degree, At last, an example is given to verify the method.The proposed method can be realized easily and automatically without any manual intervene.

     

/

返回文章
返回