FIELD: information technology.
SUBSTANCE: invention is intended for anti-virus scanning of files. Malicious file detection system contains a behavior log analysis tool designed to generate a behavior template based on commands and parameters selected from the log; calculation of convolution from all generated behavior patterns; detection pattern selection tool for retrieving from at least two detection patterns of malicious files based on commands and parameters selected from the behavior log; means for calculating the severity of harmfulness, designed to calculate the severity of an executable file based on the analysis of the resulting convolution using each obtained detection pattern; analysis tool designed to form a solution based on the received severity of the pattern; recognition of the executable file as malicious, when the degree of similarity between the generated decision pattern and at least one of the predetermined solution patterns from the decision pattern database exceeds a predetermined threshold value.
EFFECT: technical result consists in the detection of malicious files using a trained malware detection pattern.
20 cl, 7 dwg
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD OF DETECTING A MALICIOUS FILE | 2018 |
|
RU2739865C2 |
SYSTEM AND METHOD OF MANAGING COMPUTING RESOURCES FOR DETECTING MALICIOUS FILES | 2017 |
|
RU2659737C1 |
SYSTEM AND METHOD OF MACHINE TRAINING MODEL OF DETECTING MALICIOUS FILES | 2017 |
|
RU2673708C1 |
SYSTEM AND METHOD OF CLASSIFYING OBJECTS OF COMPUTER SYSTEM | 2018 |
|
RU2724710C1 |
SYSTEM AND METHOD OF CLASSIFICATION OF OBJECTS | 2017 |
|
RU2679785C1 |
SYSTEM AND METHOD OF SELECTING MEANS OF DETECTING MALICIOUS FILES | 2019 |
|
RU2739830C1 |
SYSTEM AND METHOD FOR TRAINING HARMFUL CONTAINER DETECTION MODEL | 2018 |
|
RU2697955C2 |
METHOD OF DETECTING MALICIOUS FILES THAT COUNTERACT ANALYSIS IN ISOLATED ENVIRONMENT | 2018 |
|
RU2708355C1 |
SYSTEM AND METHOD OF DETECTING MALICIOUS FILES ACCOMPANIED WITH USING THE STATIC ANALYSIS ELEMENTS | 2017 |
|
RU2654146C1 |
SYSTEM AND METHOD FOR DETECTING MALICIOUS ACTIVITY ON A COMPUTER SYSTEM | 2018 |
|
RU2697958C1 |
Authors
Dates
2018-05-16—Published
2017-08-10—Filed