FIELD: information technologies.
SUBSTANCE: method to determine belonging of files to collections of available files on the basis of files comparison with the help of functionality templates includes stages, at which functionality templates are generated on the basis of information on the executed file. Then extracted noise information is deleted from functionality templates of the executed file. Then units of functionality templates of the executed file are reduced to normalised view. Then these units are compared to units of functionality templates of available files, and using comparison results, decision is made on belonging of the unit to one of functionality templates of available files. Creating functionality templates by available malicious software, newly arrived files may be compared with them, and automatic records may be added with condition of similarity; characteristic logical units are extracted from collections of malicious programs, and heuristic rules are created by these units; automatic descriptions are generated. Also the possibility appears to carry out clusterisation of objects, which helps to accelerate their further processing.
EFFECT: increased reliability and accuracy of malicious software detection, achieved by comparison of executed files by means of functionality templates.
14 cl, 16 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD OF ASSOCIATING PREVIOUSLY UNKNOWN FILE WITH COLLECTION OF FILES DEPENDING ON DEGREE OF SIMILARITY | 2009 |
|
RU2420791C1 |
SYSTEM AND METHOD OF INCREASING EFFICIENCY OF DETECTING UNKNOWN HARMFUL OBJECTS | 2010 |
|
RU2454714C1 |
FUZZY WHITELISTING ANTI-MALWARE SYSTEMS AND METHODS | 2012 |
|
RU2607231C2 |
SYSTEM AND METHOD FOR DETECTING MALICIOUS FILES ON MOBILE DEVICES | 2015 |
|
RU2614557C2 |
METHOD OF DETECTING MALICIOUS FILES USING LINK GRAPH | 2023 |
|
RU2823749C1 |
SYSTEM AND METHOD OF CREATING RULES FOR FILTERING INSIGNIFICANT EVENTS FOR EVENT LOG ANALYSIS | 2012 |
|
RU2514139C1 |
METHOD FOR DETECTING HARMFUL ASSEMBLIES | 2015 |
|
RU2628920C2 |
METHOD FOR DETERMINING SIMILARITY OF COMPOSITE FILES | 2016 |
|
RU2628922C1 |
SYSTEM AND METHOD OF SIMILAR FILES DETERMINING | 2015 |
|
RU2614561C1 |
SYSTEM AND METHOD OF MAKING FLEXIBLE CONVOLUTION FOR MALWARE DETECTION | 2013 |
|
RU2580036C2 |
Authors
Dates
2011-08-27—Published
2009-10-01—Filed