FIELD: physics, computer technology.
SUBSTANCE: invention relates to computer technology. The method of assessment of harmfulness of the code executed in addressing space of confidential process, which defines the attributes of unreliable processes, critical functions and criteria of harmfulness of the executed code; the defined attributes of unreliable processes, critical functions and criteria of harmfulness of the executed code are kept; among the processes, started in operating system, unreliable process is identified by presence of defined attributes; the call of critical function is intercepted, that is carried out on behalf of unreliable process; an executed code initiated the call of critical function is identified using the analysis of the call stack; an executed code is recognised as harmful on the basis of the analysis of the defined criteria.
EFFECT: improvement of efficiency of assessment of harmfulness of the code executed in addressing space of confidential process.
14 cl, 7 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD FOR EXCLUDING PROCESSES OF ANTIVIRUS SCANNING ON THE BASIS OF DATA ON FILE | 2015 |
|
RU2595510C1 |
SYSTEM AND METHOD OF GENERATING LOG WHEN EXECUTING FILE WITH VULNERABILITIES IN VIRTUAL MACHINE | 2018 |
|
RU2724790C1 |
SYSTEM AND METHOD OF DETECTING THE HARMFUL CODE IN THE ADDRESS PROCESS SPACE | 2017 |
|
RU2665910C1 |
SYSTEM AND METHOD OF DETECTING MALICIOUS SCRIPT | 2017 |
|
RU2659738C1 |
METHOD OF CREATING ANTIVIRUS RECORD WHEN DETECTING MALICIOUS CODE IN RANDOM-ACCESS MEMORY | 2015 |
|
RU2592383C1 |
METHOD OF DETECTING MALICIOUS CODE IN RANDOM-ACCESS MEMORY | 2015 |
|
RU2589862C1 |
SYSTEM AND METHOD OF REDUCING LOAD ON OPERATING SYSTEM WHEN EXECUTING ANTIVIRUS APPLICATION | 2013 |
|
RU2571723C2 |
METHOD FOR AUTOMATIC ADJUSTMENT OF SECURITY MEANS | 2012 |
|
RU2514137C1 |
METHOD OF DETECTING MALICIOUS FILES THAT COUNTERACT ANALYSIS IN ISOLATED ENVIRONMENT | 2018 |
|
RU2708355C1 |
SYSTEM AND METHOD OF OPENING FILES CREATED BY VULNERABLE APPLICATIONS | 2015 |
|
RU2606883C2 |
Authors
Dates
2014-10-27—Published
2013-04-26—Filed