Computer Science ›› 2015, Vol. 42 ›› Issue (1): 187-192.doi: 10.11896/j.issn.1002-137X.2015.01.042

Previous Articles     Next Articles

Detection of Malware Code Based on Acquaintance Degree

DU Nan, HAN Lan-sheng, FU Cai, ZHANG Zhong-ke and LIU Ming   

  • Online:2018-11-14 Published:2018-11-14

Abstract: Signature recognition method can only identify the known malicious code,did not solve the problem of the discrimination of the malicious code.The current method based on behavior and heuristic scanning only pays attention to the single danger action point of malicious code,and has a high rate of false positives.The paper focused on the relationship between behaviors,described and tested behaviors and the relationship between behaviors by matrix,then gave a malicious code detection method based on acquaintance degree.Acquaintance degree is the familiarity degree of the system to under-test code.According to the size of the acquaintance degree,whether the under-test code is malicious code can be judged,the greater the acquaintance degree,the smaller the possibility of being malicious code.An algorithm of detecting malware behavior was given and its feasibility was justified through real example test.

Key words: Acquaintance degree,Similarity,Behavior characteristics,Malware code,Matrix

