Large Scale Malicious Process Detection
    2.
    发明申请
    Large Scale Malicious Process Detection 有权
    大规模恶意流程检测

    公开(公告)号:US20160269424A1

    公开(公告)日:2016-09-15

    申请号:US14657215

    申请日:2015-03-13

    IPC分类号: H04L29/06 G06F17/30

    摘要: Identify a set or session of processes as having certain characteristics. A method obtains a known set or session of processes, wherein the known set or session of processes has the certain characteristics. A set or session of processes to be evaluated is obtained. A weighted similarity measure is performed between the known set or session of processes and the set or session of processes to be evaluated. The weighted similarity measure is performed element wise, where a comparison is performed for each defined element in the set or session of processes to be evaluated against elements in the known set or session of processes.

    摘要翻译: 将一组或多个进程识别为具有某些特征。 一种方法获得已知的一组或多个进程会话,其中已知的一组或多个进程具有一定的特征。 获得要评估的过程的集合或会话。 在已知的一组或多个进程与待评估的进程的集合或会话之间执行加权相似性度量。 加权相似性度量是以元素方式执行的,其中针对要被评估的过程的集合或会话中的每个定义的元素进行比较,所述过程的对象或者会话被处理已知的过程集合或会话中的元素。