FIELD: information technology.
SUBSTANCE: method is realised by isolating processes launched from those inspection objects which are trusted using a means of analysing objects. Then, using a means of creating contexts, contexts are created and stored in a means of storing contexts. These contexts are then analysed by a means of analysing contexts using rule bases from the means of storing rule bases in order to detect malicious objects. Based on results of analysing the created contexts, this invention enables to determine malicious objects from malicious processes launched from said objects and protect a computing device from actions of the malicious objects by ending these malicious processes.
EFFECT: high level of protecting computing devices from malicious objects owing to analysis of processes on the computing device and ending processes launched from the malicious objects.
34 cl, 5 dwg
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD TO PROTECT COMPUTER SYSTEM AGAINST ACTIVITY OF HARMFUL OBJECTS | 2011 |
|
RU2468427C1 |
SYSTEM AND METHOD OF REDUCING LOAD ON OPERATING SYSTEM WHEN EXECUTING ANTIVIRUS APPLICATION | 2013 |
|
RU2571723C2 |
METHOD OF SELECTIVE USE OF PATTERNS OF DANGEROUS PROGRAM BEHAVIOR | 2017 |
|
RU2665909C1 |
SYSTEM AND METHOD OF PROTECTING CLOUD INFRASTRUCTURE FROM ILLEGAL USE | 2012 |
|
RU2536663C2 |
SYSTEM AND METHOD FOR CATEGORIZATION OF .NET APPLICATIONS | 2018 |
|
RU2756186C2 |
METHOD FOR COUNTERACTING MALICIOUS SOFTWARE (MALWARE) BY IMITATING TEST ENVIRONMENT | 2020 |
|
RU2748518C1 |
METHOD OF CREATING ANTIVIRUS RECORD WHEN DETECTING MALICIOUS CODE IN RANDOM-ACCESS MEMORY | 2015 |
|
RU2592383C1 |
METHOD FOR AUTOMATIC ADJUSTMENT OF SECURITY MEANS | 2012 |
|
RU2514137C1 |
SYSTEM AND METHOD OF DETECTING MALICIOUS CODE IN FILE | 2016 |
|
RU2637997C1 |
SYSTEM AND METHOD OF DETECTING FRAUDULENT ONLINE TRANSACTIONS | 2014 |
|
RU2571721C2 |
Authors
Dates
2012-06-27—Published
2011-04-19—Filed