FIELD: physics, computer engineering.
SUBSTANCE: present invention relates to antiviruses and specifically to methods of detecting malicious infrastructure. A method of detecting intermediate nodes in a computer network through which malware is distributed, wherein the intermediate nodes are connected to the Internet, to which malicious nodes are also connected. The present method employs a system of computer tools, services for detecting a traffic route in a network, a WHOIS service for accessing login information about an owner of a domain or IP address, followed by constructing flow chart of distribution of malware from a malicious site over data link channels, evaluating the usage rate of the link channel for distributing malware, detecting and blocking an intermediate node used illegally; the method further allows the unblocking of the intermediate node if the intensity of distribution of malware considerably drops over time or ceases to pose a threat to the site which directly contained the malware.
EFFECT: detecting malicious infrastructure by analysing links between network nodes, constructing a flow chart of communication between network nodes and automatic analysis of the strength of the link between nodes.
17 cl, 9 dwg, 3 tbl
Title | Year | Author | Number |
---|---|---|---|
METHOD OF ANALYSING AND DETECTING MALICIOUS INTERMEDIATE NODES IN NETWORK | 2012 |
|
RU2495486C1 |
METHOD AND SYSTEM FOR DETECTING THE INFRASTRUCTURE OF A MALICIOUS SOFTWARE OR A CYBERCRIMINAL | 2020 |
|
RU2722693C1 |
METHOD FOR CLASSIFYING OBJECTS TO PREVENT SPREAD OF MALICIOUS ACTIVITY | 2023 |
|
RU2808385C1 |
METHOD AND COMPUTING DEVICE FOR DETECTING TARGET MALICIOUS WEB RESOURCE | 2022 |
|
RU2791824C1 |
METHOD OF INCREASING RELIABILITY OF DETECTING MALICIOUS SOFTWARE | 2012 |
|
RU2485577C1 |
METHOD FOR SEARCHING FOR SAMPLES OF MALICIOUS MESSAGES | 2019 |
|
RU2750627C2 |
METHOD AND A COMPUTER FOR INFORMING ON MALICIOUS WEB RESOURCES | 2018 |
|
RU2701040C1 |
METHOD OF DETECTING MALICIOUS FILES USING LINK GRAPH | 2023 |
|
RU2823749C1 |
METHOD FOR DISTRIBUTED PERFORMANCE OF COMPUTER SECURITY TASKS | 2011 |
|
RU2494453C2 |
METHOD OF SELECTING SAFE ROUTE IN COMMUNICATION NETWORK OF GENERAL USE | 2016 |
|
RU2640627C1 |
Authors
Dates
2014-07-20—Published
2012-04-06—Filed