FIELD: computer equipment.
SUBSTANCE: method of determining membership of a software (SW) to a certain family of programs based on its machine code, in which a file is obtained, comprising a machine code SW; determining format of obtained file; retrieving and storing code of functions present in the obtained file; deleting from stored code functions, which are library; selecting in each function a command; selecting "action, argument" pair in each command; converting each pair "action, argument" to number; storing, separately for each selected function, the obtained sequence of numbers; accumulating a predetermined number of machine code analysis results and detecting repeated sequences of numbers (patterns); for each detected pattern, calculating a parameter characterizing its frequency; based on the calculated set of parameters, the classifier is trained to determine the SW membership by the "action, argument" pairs sequence; trained classifier is used for subsequent determination of membership of SW to a certain family of programs.
EFFECT: technical result consists in automatic identification of software (SW) according to the sequence of machine commands executed by it.
12 cl, 4 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD AND SYSTEM FOR DETERMINING SOFTWARE BELONGING BY ITS SOURCE CODE | 2019 |
|
RU2728498C1 |
METHOD AND SYSTEM FOR CLUSTERING EXECUTABLE FILES | 2021 |
|
RU2778979C1 |
METHOD AND SYSTEM FOR GENERATING THE LIST OF COMPROMISE INDICATORS | 2020 |
|
RU2743619C1 |
METHOD AND SYSTEM FOR SEARCHING FOR SIMILAR MALWARE BASED ON RESULTS OF THEIR DYNAMIC ANALYSIS | 2020 |
|
RU2738344C1 |
SYSTEM AND METHOD TO COMPARE FILES BASED ON FUNCTIONALITY TEMPLATES | 2009 |
|
RU2427890C2 |
METHOD AND SYSTEM FOR STATIC ANALYSIS OF EXECUTABLE FILES BASED ON PREDICTIVE MODELS | 2020 |
|
RU2759087C1 |
METHOD FOR COUNTERACTING MALICIOUS SOFTWARE (MALWARE) BY IMITATING TEST ENVIRONMENT | 2020 |
|
RU2748518C1 |
SYSTEM AND METHOD FOR DETECTING MALICIOUS FILES ON MOBILE DEVICES | 2015 |
|
RU2614557C2 |
SYSTEM AND METHOD OF DETECTING MALICIOUS CODE IN FILE | 2016 |
|
RU2637997C1 |
METHOD OF DETECTING MALICIOUS FILES USING LINK GRAPH | 2023 |
|
RU2823749C1 |
Authors
Dates
2020-07-29—Published
2019-12-05—Filed