FIELD: information technology.
SUBSTANCE: method for filtration of files for monitoring of applications, in which intercepted function calls recording in a file in order to determine data located inside part of file, which are used to determine characteristics of file; file is used to filter part of file; file filter represents a bit mask together with at least one characteristic of file; wherein using file filter understand calculation results of operation AND used to part of file and bit mask; determining a set of characteristics of file, if file was defined filter fired on part of file; if filter worked on part of file, file has characteristics described within file filter; excluded file of inspection, which is carried out within control application, if a plurality of determined characteristics file meets criterion of filtration; wherein filtration criterion is heuristic rule used to set characteristics of file.
EFFECT: reduction of time during which file analysis is performed by client within control applications.
4 cl, 3 dwg
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD FOR CHECKING WEB RESOURCES FOR PRESENCE OF MALICIOUS COMPONENTS | 2010 |
|
RU2446459C1 |
METHOD FOR AUTOMATIC ADJUSTMENT OF SECURITY MEANS | 2012 |
|
RU2514137C1 |
SYSTEM AND METHOD OF PROVIDING APPLICATION ACCESS RIGHTS TO COMPUTER FILES | 2013 |
|
RU2546585C2 |
SYSTEM AND METHOD FOR ELIMINATION OF CONSEQUENCES OF INFECTION OF VIRTUAL MACHINES | 2014 |
|
RU2583709C2 |
METHOD OF USING DEDICATED COMPUTER SECURITY SERVICE | 2015 |
|
RU2601162C1 |
SYSTEM AND METHOD FOR OPTIMISING EXECUTION OF ANTIVIRUS TASKS IN LOCAL AREA NETWORK | 2010 |
|
RU2453917C1 |
SYSTEM AND METHOD OF OPENING FILES CREATED BY VULNERABLE APPLICATIONS | 2015 |
|
RU2606883C2 |
METHOD OF CREATING ANTIVIRUS RECORD WHEN DETECTING MALICIOUS CODE IN RANDOM-ACCESS MEMORY | 2015 |
|
RU2592383C1 |
SYSTEM AND METHOD OF BLOCKING SCRIPT EXECUTION | 2015 |
|
RU2606564C1 |
SYSTEM AND METHOD OF PROVIDING SAFETY OF ONLINE TRANSACTIONS | 2013 |
|
RU2587423C2 |
Authors
Dates
2016-05-20—Published
2014-04-18—Filed