Malicious software family classification model generation method and device

The invention provides a malicious software family classification model generation method and device, and the method comprises the steps: training a classification model through feature vectors of all samples in an original malicious software family, and determining representative samples in the ori...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: HWANG GO-JUN, YUAN WEI, GAO CUIYING, LI HENG, LIU MINGYUE
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:The invention provides a malicious software family classification model generation method and device, and the method comprises the steps: training a classification model through feature vectors of all samples in an original malicious software family, and determining representative samples in the original malicious software family, and constructing a new training sample by utilizing the representative sample and a new malicious software sample, and updating the classification model by utilizing the training sample to obtain a new malicious software family classification model. According to the method, classification knowledge of an original malicious software family is reserved by using the representative sample, and then knowledge of a new malicious software family is absorbed, so that the number of samples of the malicious software family is reduced, the calculation overhead is reduced, and a new malicious software family classification model does not forget the classification knowledge of the original famil