FIELD: information technology.
SUBSTANCE: method includes modifying a virtual machine code for monitoring exceptions within the virtual machine and controlling the virtual machine; monitoring exceptions inside the virtual machine; shutting down the virtual machine when an exception occurs; obtaining exception context information containing data on virtual machine events leading to said exception; analysing the exception context for presence of behaviour typical of a threat; identifying the threat based on the analysis.
EFFECT: higher virtual machine safety.
9 cl, 4 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD AND SYSTEM FOR DETECTING MALICIOUS SOFTWARE BY CONTROL OF SOFTWARE IMPLEMENTATION RUNNING UNDER SCRIPT | 2013 |
|
RU2653985C2 |
METHOD OF CREATING SCRIPT OF POPULAR ACTIVATION EVENTS | 2015 |
|
RU2679783C2 |
SYSTEM AND METHOD FOR DETECTING MALWARE BY CREATING ISOLATED ENVIRONMENT | 2012 |
|
RU2535175C2 |
SYSTEM AND METHOD OF GENERATING LOG WHEN EXECUTING FILE WITH VULNERABILITIES IN VIRTUAL MACHINE | 2018 |
|
RU2724790C1 |
INTELLIGENT CONTROL SYSTEM FOR CYBERTHREATS | 2019 |
|
RU2702269C1 |
SYSTEM AND METHOD OF PROTECTING COMPUTING DEVICE FROM MALICIOUS OBJECTS USING COMPLEX INFECTION SCHEMES | 2011 |
|
RU2454705C1 |
METHOD FOR ADJUSTING THE PARAMETERS OF A MACHINE LEARNING MODEL IN ORDER TO IDENTIFY FALSE TRIGGERING AND INFORMATION SECURITY INCIDENTS | 2020 |
|
RU2763115C1 |
METHOD OF MALICIOUS FILES DETECTING, EXECUTED BY MEANS OF THE STACK-BASED VIRTUAL MACHINE | 2015 |
|
RU2624552C2 |
METHOD FOR PROCESSING INFORMATION SECURITY EVENTS PRIOR TO TRANSMISSION FOR ANALYSIS | 2020 |
|
RU2762528C1 |
METHOD OF DETECTING UNKNOWN PROGRAMS BY LOAD PROCESS EMULATION | 2011 |
|
RU2472215C1 |
Authors
Dates
2014-07-10—Published
2012-12-25—Filed