FIELD: information technology.
SUBSTANCE: invention relates to the field of detection of malicious files. System for recognizing the file as malicious is disclosed, which contains the following: a) the resource extraction tool, which is designed in order to: extract resources from the analyzed file; transfer the extracted resources to the rule formation and rule searching tools; b) the rule formation tool, which is designed in order to: generate at least one rule establishing the functional relationship between the resources received (hereinafter – the rule), in this case, the rule is formed by means of creating from the acquired resources the artificial neural network, where the nodes of the artificial neural network are the tools of analyzing the received resources, and the links between nodes, which were formed during the creation of the neural network, indicate the functional relationship between the resources received; of transfer of each formed rule to the rule comparison tool; c) the rule searching tool, which is designed in order to: search for at least one rule in the database of malicious file resources based on the received resources; transfer of each found rule to the rule comparison tool; d) the rule comparison tool, which is intended for: calculating the degree of similarity between the rules obtained from the rule formation tools and the rule searching tools; of transfer of the calculated degree of similarity to the decision making tool; e) the decision making tool is intended for: recognizing the file being analyzed as malicious, in the case where the obtained degree of similarity exceeds the predetermined threshold value.
EFFECT: technical result is the detection of malicious files based on the analysis of functional dependencies between the resources of the analyzed files.
16 cl, 3 dwg
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD FOR DETECTING MALICIOUS EXECUTABLE FILES BASED ON SIMILARITY OF EXECUTABLE FILE RESOURCES | 2013 |
|
RU2541120C2 |
SYSTEM AND METHOD OF CLASSIFYING OBJECTS OF COMPUTER SYSTEM | 2018 |
|
RU2724710C1 |
SYSTEM AND METHOD OF MACHINE TRAINING MODEL OF DETECTING MALICIOUS FILES | 2017 |
|
RU2673708C1 |
SYSTEM AND METHOD OF CLASSIFICATION OF OBJECTS | 2017 |
|
RU2679785C1 |
SYSTEM AND METHOD OF DETECTION OF MALICIOUS FILES USING A TRAINED MALWARE DETECTION PATTERN | 2017 |
|
RU2654151C1 |
SYSTEM AND METHOD OF DETECTING A MALICIOUS FILE | 2018 |
|
RU2739865C2 |
SYSTEM AND METHOD OF MANAGING COMPUTING RESOURCES FOR DETECTING MALICIOUS FILES | 2017 |
|
RU2659737C1 |
SYSTEM AND METHOD OF SELECTING MEANS OF DETECTING MALICIOUS FILES | 2019 |
|
RU2739830C1 |
SYSTEM AND METHOD OF BLOCKING SCRIPT EXECUTION | 2015 |
|
RU2606564C1 |
SYSTEM AND METHOD FOR TRAINING HARMFUL CONTAINER DETECTION MODEL | 2018 |
|
RU2697955C2 |
Authors
Dates
2018-05-16—Published
2017-06-16—Filed