FIELD: physics, computer engineering.
SUBSTANCE: invention relates to computer engineering. The method of populating an antivirus rule database for rating threats involves obtaining, in a report processing means at the server side, application verification statistics on at least one user personal computer; comparing the application verification statistics with a storage list of safe objects; detecting known safe objects for which a high threat rating was calculated; analysing characteristic features of operation of the known safe objects and creating a new threat rating rule; the new threat rating rule has a higher priority that rules that were used when calculating the high rating of the safe object; populating the antivirus rule database with the new threat rating rule on the side of the user personal computer.
EFFECT: high quality of detecting malware.
18 cl, 6 dwg, 1 tbl
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD FOR CREATING APPLICATION BEHAVIOUR MODEL SCRIPTS | 2012 |
|
RU2535506C2 |
METHOD FOR AUTOMATIC ADJUSTMENT OF SECURITY MEANS | 2012 |
|
RU2514137C1 |
METHOD FOR AUTOMATIC GENERATION OF HEURISTIC ALGORITHMS FOR SEARCHING FOR MALICIOUS OBJECTS | 2012 |
|
RU2510530C1 |
SYSTEM AND METHOD OF PROTECTING CLOUD INFRASTRUCTURE FROM ILLEGAL USE | 2012 |
|
RU2536663C2 |
SYSTEM AND METHOD OF INCREASING EFFICIENCY OF DETECTING UNKNOWN HARMFUL OBJECTS | 2010 |
|
RU2454714C1 |
SYSTEM AND METHOD OF CREATING ANTIVIRUS RECORD | 2018 |
|
RU2697954C2 |
SYSTEM AND METHOD OF CREATING RULES FOR FILTERING INSIGNIFICANT EVENTS FOR EVENT LOG ANALYSIS | 2012 |
|
RU2514139C1 |
SYSTEM AND METHOD FOR FORMING RULE FOR CHECKING FILE FOR MALICIOUSNESS | 2020 |
|
RU2757408C1 |
SYSTEM AND METHOD OF DETECTING MALICIOUS FILES OF CERTAIN TYPE | 2014 |
|
RU2583712C2 |
SYSTEM AND METHOD FOR CHECKING WEB RESOURCES FOR PRESENCE OF MALICIOUS COMPONENTS | 2010 |
|
RU2446459C1 |
Authors
Dates
2014-04-27—Published
2012-09-28—Filed