FIELD: information technology.
SUBSTANCE: method of scanning for detecting the malicious software presence is proposed, in which a directory access table is kept for tracking the access to the files contained in the general directory by the application, wherein the directory access table includes the path to the directory that contains the name or the logical location of the general directory, the number of operations, indicating the number of events of the access to the files in the general directory, and the state of the record, indicating whether the directory is in the state before scanning, the scanning state, or the state of the performed scanning; the events of the applications access to the files contained in the general directory are detected; the detected access events are used for the identification of one or more groups of files contained in the general directory, the access to which the application may want to implement in the future, while running the application; the specified one or more groups of files are scanned for detecting the malicious software presence while running the application and before the application tries to perform the access to the files of the group or groups.
EFFECT: minimization of delays while running the applications caused by scanning.
21 cl, 7 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD OF MAINTAINING DATABASE AND CORRESPONDING SERVER | 2015 |
|
RU2698776C2 |
METHOD OF PROTECTING COMPUTER SYSTEM FROM MALWARE | 2011 |
|
RU2566329C2 |
METHOD OF SELECTIVE USE OF PATTERNS OF DANGEROUS PROGRAM BEHAVIOR | 2017 |
|
RU2665909C1 |
METHOD AND APPARATUS FOR DETECTING VIRUSES IN FILE SYSTEM | 2010 |
|
RU2551820C2 |
SECURITY AGENT, OPERATING AT EMBEDDED SOFTWARE LEVEL WITH SUPPORT OF OPERATING SYSTEM SECURITY LEVEL | 2013 |
|
RU2583714C2 |
SYSTEM AND METHOD OF ADAPTING PATTERNS OF DANGEROUS PROGRAM BEHAVIOR TO USERS' COMPUTER SYSTEMS | 2017 |
|
RU2652448C1 |
SYSTEM AND METHOD OF DETECTING MALICIOUS ENTITIES DISTRIBUTED OVER PEER-TO-PEER NETWORKS | 2011 |
|
RU2487406C1 |
SYSTEM AND METHOD OF SPEEDING UP PROBLEM SOLVING BY ACCUMULATING STATISTICAL INFORMATION | 2010 |
|
RU2444056C1 |
SYSTEM AND METHOD OF PROTECTING CLOUD INFRASTRUCTURE FROM ILLEGAL USE | 2012 |
|
RU2536663C2 |
SYSTEM AND METHOD OF CREATING RULES FOR FILTERING INSIGNIFICANT EVENTS FOR EVENT LOG ANALYSIS | 2012 |
|
RU2514139C1 |
Authors
Dates
2017-06-06—Published
2012-03-29—Filed