The invention discloses a malicious-code family determination method and device. According to the method, features of all malicious-code families are extracted and merged on the basis of analysis on all the existing malicious code families to generate a malicious-code family feature
library, all extracted features of a to-be-tested sample are used to generate a
feature vector according to a structure of the malicious-code family feature
library, similarity calculation is carried out on the
feature vector of the to-be-tested sample and all preset malicious-code family feature vectors, and whensimilarity meets a preset value, it is judged that the to-be-tested sample belongs to a corresponding malicious-code family. According to the method, various feature scalars are quantificationally combined into the
feature vector, the sample is represented through the feature vector, operations of going deep into specific code
layers and methods are not needed, computational resources are greatlysaved, and judgment accuracy is high; and calculation on the sample features is streamlined through calculation on the feature vector, and a
processing rate is greatly improved.