首页> 外文会议>The 12th world multi-conference on systemics, cybernetics and informatics : Proceedings >Using an Information Retrieval Technique to Discover Malicious Software
【24h】

Using an Information Retrieval Technique to Discover Malicious Software

机译:使用信息检索技术发现恶意软件

获取原文
获取原文并翻译 | 示例

摘要

This paper describes a research effort to detect unknown, known or variances of known malicious software using an information retrieval technique known as cosine similarity. Document similarity techniques, such as cosine similarity, have been used with great success in several document retrieval applications. By following the standard information retrieval methodology, software, in machine readable format, is regarded as documents in the corpus. These "documents" may or may not have a known malicious intent. The query is a piece of software, again in machine readable format, which contains a certain type of malicious software. This methodology provides an ability to search the corpus with a query and retrieve/identify potentially malicious software as well as other instances of the same type of vulnerability. This retrieval is based on the similarity of the query to a given document in the corpus. The subsequent use of an information visualization technique will allow for quickly and clearly finding the malicious software and will provide the ability for finding similar, potentially new types or variances of malicious behavior.
机译:本文介绍了一项研究工作,该研究工作使用称为余弦相似度的信息检索技术来检测已知恶意软件的未知,已知或变异。文档相似度技术(例如余弦相似度)已在几种文档检索应用程序中获得了巨大成功。通过遵循标准的信息检索方法,机器可读格式的软件被视为语料库中的文档。这些“文档”可能具有或没有已知的恶意意图。该查询是一种再次以机器可读格式显示的软件,其中包含某种类型的恶意软件。这种方法提供了使用查询来搜索语料库并检索/识别潜在恶意软件以及同类漏洞的其他实例的能力。该检索基于查询与语料库中给定文档的相似性。信息可视化技术的后续使用将允许快速而明确地查找恶意软件,并将提供查找相似,潜在的新类型或变种的恶意行为的能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号