Netinfo Security ›› 2020, Vol. 20 ›› Issue (12): 83-90.doi: 10.3969/j.issn.1671-1122.2020.12.011

Previous Articles     Next Articles

A Threat Intelligence Generation Method for Malware Family

WANG Changjie, LI Zhihua(), ZHANG Ye   

  1. School of Artificial Intelligence and Computer, Jiangnan University, Wuxi 214122, China
  • Received:2020-10-14 Online:2020-12-10 Published:2021-01-12
  • Contact: LI Zhihua E-mail:jswxzhli@aliyun.com

Abstract:

In view of the current high redundancy of threat intelligence and the inability to quickly generate and share intelligence, a rapid threat intelligence generation method for malware families is proposed. Run the malware through the open source automated malware analysis platform and extract the malicious features, calculate the feature fuzzy hash value, use the improved CFSFDP algorithm to cluster the malware based on the fuzzy Hash value of the malicious code, and finally according to each type of malware family The characteristics of generate threat intelligence that meets the STIX1.2 standards. Experiments show that this method can effectively generate machine-readable and shareable threat intelligence, and significantly shorten the time for threat intelligence generation.

Key words: threat intelligence, malware, fuzzy Hash, clustering

CLC Number: