FIELD: information technology.
SUBSTANCE: invention relates to computer security. In the method for detecting signs of a computer attack, information about the object on the computer is collected, transmit a security notification to the detection means, including information about the security means and the collected information about the object, while retaining the received security notification in the object database, finding the object contained in the received security notification in the threat database, and add a label corresponding to the object in the threat database to the object database to the object in question, search for suspicious activity signs contained in the database of suspicious activity, based on the received security notification and the added object labels contained in said security notification, when a sign of suspicious activity is found, a label in the database of suspicious activity is added to the database of objects to the security notification, perform detection of signs of computer attack by detecting at least one signature of computer attacks from the database of computer attacks among the received objects, and security notifications, and labels of the mentioned objects, and notifications of security notifications from the object database.
EFFECT: improving the quality of identifying signs of computer attacks on the information system.
32 cl, 8 dwg, 1 tbl
Title | Year | Author | Number |
---|---|---|---|
METHOD FOR ADJUSTING THE PARAMETERS OF A MACHINE LEARNING MODEL IN ORDER TO IDENTIFY FALSE TRIGGERING AND INFORMATION SECURITY INCIDENTS | 2020 |
|
RU2763115C1 |
METHOD FOR PROCESSING INFORMATION SECURITY EVENTS PRIOR TO TRANSMISSION FOR ANALYSIS | 2020 |
|
RU2762528C1 |
SYSTEM AND METHOD FOR IDENTIFYING MALICIOUS FILES | 2017 |
|
RU2673407C1 |
SYSTEM AND METHOD OF CREATING ANTIVIRUS RECORD | 2018 |
|
RU2697954C2 |
SYSTEM AND METHOD OF CORRELATING EVENTS FOR DETECTING INFORMATION SECURITY INCIDENT | 2019 |
|
RU2739864C1 |
METHOD FOR EARLY DETECTION OF DESTRUCTIVE EFFECTS OF BOTNET ON A COMMUNICATION NETWORK | 2019 |
|
RU2731467C1 |
SYSTEM AND METHOD FOR DETERMINING THE FILE TRUST LEVEL | 2019 |
|
RU2750628C2 |
METHOD FOR IDENTIFYING INFORMATION SECURITY THREATS (OPTIONS) | 2023 |
|
RU2802539C1 |
ADAPTIVE INFORMATION AND TECHNICAL MONITORING SYSTEM | 2019 |
|
RU2728763C1 |
SYSTEM AND METHOD FOR EVALUATING MALICIOUS WEBSITES | 2015 |
|
RU2622870C2 |
Authors
Dates
2018-07-17—Published
2017-09-29—Filed