METHOD AND SYSTEM OF PROTOCOLS ANALYSIS OF HARMFUL PROGRAMS INTERACTION WITH CONTROL CENTERS AND DETECTION OF COMPUTER ATTACKS Russian patent published in 2017 - IPC G06F21/55 G06F21/53 H04L29/02 

Abstract RU 2634211 C1

FIELD: information technology.

SUBSTANCE: malicious program in a virtual environment is run; requests sent by malicious program to the malicious software control center are collected; the parameters in collected requests and their order are determined; requests with the same sets of parameters are grouped; for each group of requests a regular expression describing the parameters of this group of requests is formed; a request, described by the regular expression received in the previous step, is formed and sent to the malicious program cintrol center; a response from the control center is received, while if the response is encoded and/or encrypted, then it is decoded and/or decrypted; the response is analyzed to the presence of information, specific to conducting network attacks; the results are stored; computer attacks are identified using the results of analysis.

EFFECT: increasing the effectiveness of detecting computer attacks.

17 cl, 3 dwg

Similar patents RU2634211C1

Title Year Author Number
DOUBLE SELF-TEST OF MEMORY FOR PROTECTION OF MULTIPLE NETWORK ENDPOINTS 2016
  • Lutas Dan-Horea
  • Lukacs Sandor
  • Ticle Daniel-Ioan
  • Ciocas Radu-Ioan
  • Anichitei Ionel-Cristinel
RU2714607C2
SYSTEM AND METHOD OF CREATING ANTIVIRUS RECORD 2018
  • Gordejchik Sergej Vladimirovich
  • Soldatov Sergej Vladimirovich
  • Sapronov Konstantin Vladimirovich
RU2697954C2
SYSTEM AND METHODS FOR DECRYPTING NETWORK TRAFFIC IN A VIRTUALIZED ENVIRONMENT 2017
  • Caragea Radu
RU2738021C2
SYSTEMS AND METHODS FOR DETECTING MALICIOUS PROGRAMS WITH A DOMAIN GENERATION ALGORITHM (DGA) 2016
  • Minea Octavian Mihai
  • Vatamanu Cristina
  • Benchea Mihai-Razvan
  • Gavrilut Dragos-Teodor
RU2726032C2
SYSTEM AND METHOD OF AUTOGENERATION OF DECISION RULES FOR INTRUSION DETECTION SYSTEMS WITH FEEDBACK 2016
  • Kislitsin Nikita Igorevich
RU2634209C1
OBJECTS OF VIRTUAL NETWORK INTERFACE 2012
  • Schultze Eric W.
  • Thompson Aaron C.
  • Ganguly Arijit
  • Iyer Padmini C.
  • Holgers Tobias L.
  • Lefelhocz Christopher J.
  • Searle Ian R.
RU2646343C1
METHOD OF ANALYSING AND DETECTING MALICIOUS INTERMEDIATE NODES IN NETWORK 2012
  • Golovanov Sergej Jur'Evich
RU2495486C1
OBJECTS OF VIRTUAL NETWORK INTERFACE 2012
  • Shulttse Erik V.
  • Tompson Aaron S.
  • Ganguli Arijit
  • Ajer Padmini S.
  • Kholgers Tobias L.
  • Lefelkhoch Kristofer Dzh.
  • Sirl Ivan R.
RU2595517C2
ROBUST AND SECURE HARDWARE-COMPUTER SYSTEM IN CLOUD COMPUTING ENVIRONMENT 2013
  • Gavrilov Dmitrij Aleksandrovich
  • Shchelkunov Nikolaj Nikolaevich
RU2557476C2
SYSTEMS AND METHODS FOR REPORTING COMPUTER SECURITY INCIDENTS 2019
  • Warmenhoven Adrianus
  • Hofstede Richard J.
RU2757597C1

RU 2 634 211 C1

Authors

Volkov Dmitrij Aleksandrovich

Dates

2017-10-24Published

2016-07-06Filed