METHOD FOR EXCLUDING PROCESSES OF ANTIVIRUS SCANNING ON THE BASIS OF DATA ON FILE Russian patent published in 2016 - IPC G06F21/00 

Abstract RU 2595510 C1

FIELD: information technology.

SUBSTANCE: invention relates to antivirus technologies. According to one version of implementation proposed method for excluding the process of antivirus scanning comprises the following steps: a) determining request for access to a file on the side of the process by the processes monitoring mean; b) file format is determined to be accessed from the side of said process, using event processing means; c) determining data on said process, data on said process include a list of libraries loaded to the virtual memory of the process, with the help of event processing means; d) determining stack call of file access, stack call comprises monitoring send of a request for access to file on the side of the process through other processes using event processing means; e) determining danger level of request for access to file on the side of the process on the basis of certain file format, data on said process, stack call of access to file by means of monitoring processes; f) excluding process of antivirus scanning through antivirus protection mean providing that certain danger level does not exceed a preset threshold.

EFFECT: technical result is faster antivirus scanning of the operating system due to excluding processes of antivirus scanning.

7 cl, 4 dwg

Similar patents RU2595510C1

Title Year Author Number
SYSTEM AND METHOD OF REDUCING LOAD ON OPERATING SYSTEM WHEN EXECUTING ANTIVIRUS APPLICATION 2013
  • Sobko Andrej Vladimirovich
  • Judin Maksim Vital'Evich
  • Mezhuev Pavel Nikolaevich
  • Godunov Il'Ja Borisovich
  • Shirokij Maksim Aleksandrovich
RU2571723C2
SYSTEM AND METHOD OF OPENING FILES CREATED BY VULNERABLE APPLICATIONS 2015
  • Efremov Andrej Anatolevich
  • Ladikov Andrej Vladimirovich
  • Solodovnikov Andrej Yurevich
  • Monastyrskij Aleksej Vladimirovich
RU2606883C2
SYSTEM AND METHOD OF DETECTING MALICIOUS SCRIPT 2017
  • Pavlyushchik Mikhail Aleksandrovich
RU2659738C1
SYSTEM AND METHOD OF DETECTING THE HARMFUL CODE IN THE ADDRESS PROCESS SPACE 2017
  • Pavlyushchik Mikhail Aleksandrovich
RU2665910C1
SYSTEM AND METHOD OF DETERMINING THE CATEGORY OF PROXY APPLICATION 2014
  • Filatov Konstantin Mikhajlovich
  • Inozemtseva Olga Olegovna
  • Jablokov Viktor Vladimirovich
RU2580032C2
SYSTEM AND METHOD OF ASSESSMENT OF HARMFULLNESS OF CODE EXECUTED IN ADDRESSING SPACE OF CONFIDENTIAL PROCESS 2013
  • Pavljushchik Mikhail Aleksandrovich
RU2531861C1
METHOD OF CREATING ANTIVIRUS RECORD WHEN DETECTING MALICIOUS CODE IN RANDOM-ACCESS MEMORY 2015
  • Pavlyushshik Mikhail Aleksandrovich
  • Monastyrskij Aleksej Vladimirovich
  • Nazarov Denis Aleksandrovich
RU2592383C1
SYSTEM AND METHOD OF ADAPTING PATTERNS OF DANGEROUS PROGRAM BEHAVIOR TO USERS' COMPUTER SYSTEMS 2017
  • Pavlyushchik Mikhail Aleksandrovich
  • Slobodyanyuk Yurij Gennadevich
  • Monastyrskij Aleksej Vladimirovich
  • Martynenko Vladislav Valerevich
RU2652448C1
METHOD FOR ANTI-VIRUS SCANNING OF COMPUTER SYSTEM 2015
  • Solodovnikov Andrej Yurevich
  • Ladikov Andrej Vladimirovich
  • Tsvetkov Sergej Valerevich
RU2617925C2
MACHINE CODE ACCESS LIMITATION METHOD TO THE OPERATING SYSTEM RESOURCES 2016
  • Ivanov Dmitrij Gennadevich
  • Pavlov Nikita Alekseevich
  • Shvetsov Dmitrij Vladimirovich
  • Gorshenin Mikhail Aleksandrovich
RU2625052C1

RU 2 595 510 C1

Authors

Levchenko Vyacheslav Ivanovich

Yudin Maksim Vitalevich

Dates

2016-08-27Published

2015-09-30Filed