SYSTEM AND METHOD OF ASSESSMENT OF HARMFULLNESS OF CODE EXECUTED IN ADDRESSING SPACE OF CONFIDENTIAL PROCESS Russian patent published in 2014 - IPC G06F21/55 

Abstract RU 2531861 C1

FIELD: physics, computer technology.

SUBSTANCE: invention relates to computer technology. The method of assessment of harmfulness of the code executed in addressing space of confidential process, which defines the attributes of unreliable processes, critical functions and criteria of harmfulness of the executed code; the defined attributes of unreliable processes, critical functions and criteria of harmfulness of the executed code are kept; among the processes, started in operating system, unreliable process is identified by presence of defined attributes; the call of critical function is intercepted, that is carried out on behalf of unreliable process; an executed code initiated the call of critical function is identified using the analysis of the call stack; an executed code is recognised as harmful on the basis of the analysis of the defined criteria.

EFFECT: improvement of efficiency of assessment of harmfulness of the code executed in addressing space of confidential process.

14 cl, 7 dwg

Similar patents RU2531861C1

Title Year Author Number
METHOD FOR EXCLUDING PROCESSES OF ANTIVIRUS SCANNING ON THE BASIS OF DATA ON FILE 2015
  • Levchenko Vyacheslav Ivanovich
  • Yudin Maksim Vitalevich
RU2595510C1
SYSTEM AND METHOD OF GENERATING LOG WHEN EXECUTING FILE WITH VULNERABILITIES IN VIRTUAL MACHINE 2018
  • Monastyrskij Aleksej Vladimirovich
  • Pavlyushchik Mikhail Aleksandrovich
  • Pintijskij Vladislav Valerevich
  • Anikin Denis Vyacheslavovich
  • Kirsanov Dmitrij Aleksandrovich
RU2724790C1
SYSTEM AND METHOD OF DETECTING THE HARMFUL CODE IN THE ADDRESS PROCESS SPACE 2017
  • Pavlyushchik Mikhail Aleksandrovich
RU2665910C1
SYSTEM AND METHOD OF DETECTING MALICIOUS SCRIPT 2017
  • Pavlyushchik Mikhail Aleksandrovich
RU2659738C1
METHOD OF CREATING ANTIVIRUS RECORD WHEN DETECTING MALICIOUS CODE IN RANDOM-ACCESS MEMORY 2015
  • Pavlyushshik Mikhail Aleksandrovich
  • Monastyrskij Aleksej Vladimirovich
  • Nazarov Denis Aleksandrovich
RU2592383C1
METHOD OF DETECTING MALICIOUS CODE IN RANDOM-ACCESS MEMORY 2015
  • Pavlyushshik Mikhail Aleksandrovich
  • Monastyrskij Aleksej Vladimirovich
  • Nazarov Denis Aleksandrovich
RU2589862C1
SYSTEM AND METHOD OF REDUCING LOAD ON OPERATING SYSTEM WHEN EXECUTING ANTIVIRUS APPLICATION 2013
  • Sobko Andrej Vladimirovich
  • Judin Maksim Vital'Evich
  • Mezhuev Pavel Nikolaevich
  • Godunov Il'Ja Borisovich
  • Shirokij Maksim Aleksandrovich
RU2571723C2
METHOD FOR AUTOMATIC ADJUSTMENT OF SECURITY MEANS 2012
  • Zajtsev Oleg Vladimirovich
RU2514137C1
METHOD OF DETECTING MALICIOUS FILES THAT COUNTERACT ANALYSIS IN ISOLATED ENVIRONMENT 2018
  • Karasovskij Dmitrij Valerievich
  • Shulmin Aleksej Sergeevich
  • Kobychev Denis Yurevich
RU2708355C1
SYSTEM AND METHOD OF OPENING FILES CREATED BY VULNERABLE APPLICATIONS 2015
  • Efremov Andrej Anatolevich
  • Ladikov Andrej Vladimirovich
  • Solodovnikov Andrej Yurevich
  • Monastyrskij Aleksej Vladimirovich
RU2606883C2

RU 2 531 861 C1

Authors

Pavljushchik Mikhail Aleksandrovich

Dates

2014-10-27Published

2013-04-26Filed