Malicious code family classification method based on fuzzy assembly instruction sequence
The invention relates to a malicious code family classification method based on a fuzzy assembly instruction sequence, and belongs to the technical field of computer network malicious code detection. According to the method, fuzzy assembly instruction sequence features after immediate operands and c...
Saved in:
Main Authors | , , , , , , |
---|---|
Format | Patent |
Language | Chinese English |
Published |
02.11.2021
|
Subjects | |
Online Access | Get full text |
Cover
Loading…
Summary: | The invention relates to a malicious code family classification method based on a fuzzy assembly instruction sequence, and belongs to the technical field of computer network malicious code detection. According to the method, fuzzy assembly instruction sequence features after immediate operands and constant address operands are filtered are extracted from malicious codes of different families, and a long-short-term memory network model used for malicious code family classification is trained. Compared with an existing byte code sequence and an existing operation code sequence, the adopted fuzzy assembly instruction sequence has higher accuracy in PE malicious code family classification tasks. A fuzzy assembly instruction sequence is adopted, a written instruction mask is used for shielding part of types of operands, compared with existing bytecode sequence features, the length of an input sequence is reduced, and the method has lower time cost in LSTM model training and family detection links. Compared with th |
---|---|
Bibliography: | Application Number: CN202110805548 |