Method and device for program identification based on machine learning
    1.
    发明授权
    Method and device for program identification based on machine learning 有权
    基于机器学习的程序识别方法和设备

    公开(公告)号:US09349006B2

    公开(公告)日:2016-05-24

    申请号:US13990146

    申请日:2011-11-18

    IPC分类号: G06F11/00 G06F21/56 G06N99/00

    摘要: A method and device perform program identification based on machine learning. The method includes: analyzing an inputted unknown program, and extracting a feature of the unknown program; coarsely classifying the unknown program according to the extracted feature; judging by inputting the unknown program into a corresponding decision-making machine generated by training according to a result of the coarse classification; and outputting an identification result of the unknown program. The identification result is a malicious program or a non-malicious program. The method can save a lot of manpower and improve the identification efficiency for a malicious program by using the decision-making machine.

    摘要翻译: 方法和设备基于机器学习执行程序识别。 该方法包括:分析输入的未知程序,提取未知程序的特征; 根据提取的特征粗略地分类未知程序; 通过将未知程序输入到根据粗分类的结果通过训练产生的相应的决策机器中; 并输出未知程序的识别结果。 识别结果是恶意程序或非恶意程序。 该方法可以通过决策机器节省大量人力,提高恶意程序的识别效率。

    Method and Device for Program Identification Based on Machine Learning
    2.
    发明申请
    Method and Device for Program Identification Based on Machine Learning 有权
    基于机器学习的程序识别方法与设备

    公开(公告)号:US20130291111A1

    公开(公告)日:2013-10-31

    申请号:US13990146

    申请日:2011-11-18

    IPC分类号: G06F21/56 G06N99/00

    摘要: The invention discloses a method and device for programidentification based on machine learning. The method comprises: analyzing an inputted unknown program, and extracting a feature of the unknown program; coarsely classifying the unknown program according to the extracted feature; judging by inputting the unknown program into a corresponding decision-making machine generated by training according to a result of the coarse classification; and outputting an identification result of the unknown program, wherein the identification result is a malicious program or a non-malicious program. The embodiments of the invention adopt the machine learning technology, achieve the decision-making machine for identifying a malicious program by analyzing a large number of program samples, and can save a lot of manpower and improve the identification efficiency for a malicious program by using the decision-making machine; and furthermore, can find an inherent law of programs based on data mining for massive programs, prevent a malicious program that has not happened and make it difficult for a malicious program to avoid killing.

    摘要翻译: 本发明公开了一种基于机器学习的程序识别方法和装置。 该方法包括:分析输入的未知节目,提取未知节目的特征; 根据提取的特征粗略地分类未知程序; 通过将未知程序输入到根据粗分类的结果通过训练产生的相应的决策机器中; 并输出未知程序的识别结果,其中识别结果是恶意程序或非恶意程序。 本发明的实施例采用机器学习技术,通过分析大量程序样本来实现用于识别恶意程序的决策机,并且可以通过使用程序样本来节省大量的人力并提高恶意程序的识别效率 决策机; 此外,可以根据大规模程序的数据挖掘找到程序的内在规律,防止没有发生的恶意程序,使恶意程序难以避免杀死。

    WHITELIST-BASED INSPECTION METHOD FOR MALICIOUS PROCESS
    4.
    发明申请
    WHITELIST-BASED INSPECTION METHOD FOR MALICIOUS PROCESS 有权
    用于恶意程序的基于WHITELIST的检查方法

    公开(公告)号:US20130185797A1

    公开(公告)日:2013-07-18

    申请号:US13817563

    申请日:2011-08-16

    IPC分类号: G06F21/56

    摘要: A method of detecting a malware based on a white list comprises: receiving on a server side a program feature and/or a program behavior of a program to be detected sent from a client side; comparing the program feature and/or the program behavior of the detected program with legitimate program features and/or legitimate program behaviors stored in a white list; obtaining a legitimacy information of the unknown program based on the comparison result and feeding this back to the client side. In the invention, a legitimate program is determined by using a white list, thereby determining an illegitimate program excluded from the white list as a malware, which performs a determination and detecting and removing of a malware from another perspective.

    摘要翻译: 一种基于白名单检测恶意软件的方法包括:在服务器端接收从客户端发送的要检测的程序的程序特征和/或程序行为; 将检测到的程序的程序特征和/或程序行为与存储在白名单中的合法程序特征和/或合法程序行为进行比较; 根据比较结果获得未知程序的合法性信息,并将其反馈给客户端。 在本发明中,通过使用白名单来确定合法程序,由此确定从白名单中排除的非法程序作为恶意软件,其从另一角度执行恶意软件的确定和检测和删除。

    Active Defense Method on The Basis of Cloud Security
    5.
    发明申请
    Active Defense Method on The Basis of Cloud Security 有权
    基于云安全的主动防御方法

    公开(公告)号:US20130174257A1

    公开(公告)日:2013-07-04

    申请号:US13817577

    申请日:2011-08-08

    IPC分类号: G06F21/56

    摘要: The present invention relates to an active defense method based on cloud security comprising: a client collecting and sending a program behavior launched by a program thereon and/or a program feature of the program launching the program behavior to a server; with respect to the program feature and/or the program behavior sent by the client, the server performing an analysis and comparison in its database, making a determination on the program based on the comparison result, and feeding back to the client; based on the feedback determination result, the client deciding whether to intercept the program behavior, terminate execution of the program and/or clean up the program, and restore the system environment. The invention introduces a cloud security architecture, and employs a behavior feature based on active defense to search and kill a malicious program, thereby ensuring network security.

    摘要翻译: 本发明涉及一种基于云安全的主动防御方法,包括:客户端收集和发送由其上的程序启动的程序行为和/或将程序行为发送到服务器的程序特征; 对于客户端发送的程序特征和/或程序行为,服务器在其数据库中执行分析和比较,基于比较结果确定程序,并反馈给客户端; 基于反馈确定结果,客户端决定是否拦截程序行为,终止程序的执行和/或清理程序,并恢复系统环境。 本发明引入云安全架构,采用基于主动防御的行为特征来搜索和杀死恶意程序,从而确保网络安全。

    PARTICLE-TEMPLATED MEMBRANES, AND RELATED PROCESSES FOR THEIR PREPARATION
    8.
    发明申请
    PARTICLE-TEMPLATED MEMBRANES, AND RELATED PROCESSES FOR THEIR PREPARATION 审中-公开
    颗粒模板及其相关制备方法

    公开(公告)号:US20100155325A1

    公开(公告)日:2010-06-24

    申请号:US12343522

    申请日:2008-12-24

    IPC分类号: B01D39/14 C08J9/26

    摘要: A method for the formation of a membrane is described. A collection of substantially spherical particles formed from a selected material is contacted with at least one reactive material. The reactive material is cured or otherwise polymerized by various techniques, so that it forms a matrix that substantially surrounds and contains the particles. A portion of the particle material is then removed, so that the matrix contains a pattern of pores that are permeable to selected substances in solution. In some instances, the matrix is formed by an interfacial reaction between at least two reactive materials. Related filtration membranes are also described.

    摘要翻译: 描述了形成膜的方法。 从所选择的材料形成的基本上球形的颗粒的集合与至少一种反应性材料接触。 活性材料通过各种技术固化或以其它方式聚合,使得其形成基本上包围和包含颗粒的基质。 然后去除一部分颗粒材料,使得基质含有对溶液中选定物质可渗透的孔的图案。 在一些情况下,基质由至少两种反应性材料之间的界面反应形成。 还描述了相关的过滤膜。