FIELD: computing technology.
SUBSTANCE: disclosed is a computer-implemented method for static analysis of executable files based on predictive, containing: a preparatory stage of: forming a sample of files containing at least one malicious executable file and at least one clean executable file; analysing each received file of the formed sample, wherein the data is extracted, and also converting and enriching said files; determining the features characteristic of clean files or, vice versa, of malicious files by constructing predictive models for each type of converted data; combining the resulting characteristic features for each type of data into feature vectors, wherein at least one classifier is trained based on said vectors; combining the classifiers into a classifier ensemble, wherein the priority is determined for each classifier in the classifier ensemble; a working stage of: obtaining at least one executable file for analysis; analysing the obtained file, wherein data is extracted therefrom and conversion thereof is executed; forming at least one vector based on the extracted data distributed by data types; launching the classifier ensemble trained at the preparatory stage and outputting the result of the analysis.
EFFECT: increase in the efficiency of static analysis of executable files based on predictive models.
13 cl, 5 dwg, 5 tbl
Title | Year | Author | Number |
---|---|---|---|
METHOD AND SYSTEM FOR DETECTING MALICIOUS FILES IN A NON-ISOLATED MEDIUM | 2020 |
|
RU2722692C1 |
METHOD AND SYSTEM FOR SEARCHING FOR SIMILAR MALWARE BASED ON RESULTS OF THEIR DYNAMIC ANALYSIS | 2020 |
|
RU2738344C1 |
SYSTEM AND METHOD OF DETECTING A MALICIOUS FILE | 2018 |
|
RU2739865C2 |
COMPUTER SYSTEM AND METHOD FOR DETECTING MALWARE USING MACHINE LEARNING | 2021 |
|
RU2802860C1 |
SYSTEM AND METHOD OF CLASSIFYING OBJECTS OF COMPUTER SYSTEM | 2018 |
|
RU2724710C1 |
SYSTEM AND METHOD OF MACHINE TRAINING MODEL OF DETECTING MALICIOUS FILES | 2017 |
|
RU2673708C1 |
SYSTEM AND METHOD OF CLASSIFICATION OF OBJECTS | 2017 |
|
RU2679785C1 |
MALWARE FILES IN NETWORK TRAFFIC DETECTION SERVER AND METHOD | 2018 |
|
RU2680736C1 |
SYSTEM AND METHOD OF DETECTION OF MALICIOUS FILES USING A TRAINED MALWARE DETECTION PATTERN | 2017 |
|
RU2654151C1 |
SYSTEM AND METHOD OF MANAGING COMPUTING RESOURCES FOR DETECTING MALICIOUS FILES | 2017 |
|
RU2659737C1 |
Authors
Dates
2021-11-09—Published
2020-12-07—Filed