FIELD: data processing.
SUBSTANCE: invention relates to the protection of a computer system from malicious programs. Client system contains a hardware processor configured to run the malware protection engine, configured to monitor the target process for malicious activity, the target process contains instances of the main executable module and the shared library; receiving from the server the first indicator of the reputation of the module of the main executable module and the second indicator of the reputation of the common library module, the first and second reputation indicators of the module contain respectively the first and second sets of monitoring rules; determining whether the target process is probably malicious, in accordance with the first and second indicators of the reputation of the module, and if the target process is probably not harmful, combining the first and second set of monitoring rules into a combined set of monitoring rules; and configuring the malware protection engine to monitor the target process in accordance with a combined set of monitoring rules.
EFFECT: technical result is to provide a fast, reliable and customizable solution to protect against malicious programs.
29 cl, 21 dwg, 2 tbl
Title | Year | Author | Number |
---|---|---|---|
DYNAMIC REPUTATION INDICATOR FOR OPTIMIZATION OF COMPUTER SECURITY OPERATIONS | 2017 |
|
RU2723665C1 |
FUZZY WHITELISTING ANTI-MALWARE SYSTEMS AND METHODS | 2012 |
|
RU2607231C2 |
ENDPOINT SECURITY SYSTEM AND METHOD | 2015 |
|
RU2693922C2 |
SYSTEM AND METHOD FOR AUTOMATIC DEVICE DETECTION, DEVICE CONTROL AND REMOTE ASSISTANCE | 2015 |
|
RU2691858C2 |
SYSTEM AND METHODS FOR AUDITING A VIRTUAL MACHINE | 2017 |
|
RU2691187C1 |
SYSTEMS AND METHODS FOR USING DNS MESSAGES FOR SELECTIVE COLLECTION OF COMPUTER FORENSIC DATA | 2020 |
|
RU2776349C1 |
COMPUTER SYSTEM AND METHOD FOR DETECTING MALWARE USING MACHINE LEARNING | 2021 |
|
RU2802860C1 |
SYSTEMS AND METHODS OF MONITORING MALWARE BEHAVIOR TO MULTIPLE OBJECTS OF SOFTWARE | 2016 |
|
RU2683152C1 |
DECLARATION-BASED CONTENT REPUTATION SERVICE | 2011 |
|
RU2573760C2 |
USER INTERFACE FOR PROVIDING SECURITY AND REMOTE CONTROL OF NETWORK ENDPOINTS | 2015 |
|
RU2697935C2 |
Authors
Dates
2018-03-02—Published
2014-09-25—Filed