借鉴生物信息学中的物种系统发生树构建方法,提出了基于恶意代码函数调用图和非加权组平均法(UPGMA)的恶意代码系统发生树构建方法,并利用恶意代码函数调用图的相似性距离数据对本方法进行了实验。此方法能够为恶意代码的同源及演化特性分析研究与恶意代码的检测和防范提供有力的支撑和参考。
Using for reference on the methods that construct the phyIogenetic tree among genes or speces in bioinformatics, this paper presents a method that constructs the phyIogenetic tree of maIware based on function-caI graphs of maIware and UPGMA method, and do some experiments using vaIue of the simiIarity distance of marware’s function-caI graphs (caI ed SDMFG).This method provide a strong support and reference for anaIysis of the homoIogy and evoIution characteristics of maIware and maIware detection and prevention.