SYSTEM AND METHOD OF FILE ANALYSIS FOR MALICIOUSNESS IN VIRTUAL MACHINE Russian patent published in 2018 - IPC G06F21/56 G06F21/53 

Abstract RU 2665911 C2

FIELD: information technology.

SUBSTANCE: invention relates to solutions for detecting malicious files. System for analyzing the maliciousness of a file opened in a virtual machine as an environment for safe execution of files, which intercepts the event that occurs during the execution of the process thread created when the file is opened in the virtual machine as a safe execution environment, and suspends the execution of the stream; read the context of the processor on which the thread is executing; save the intercepted event and the context in the log; compare the data stored in the log with the templates, at the same time, at least one of the decisions is taken based on the comparison: the decision to recognize the file as malicious, the decision to stop the execution of the file, the decision to change the context of the processor, the decision to wait for the next event; perform actions that are consistent with the decisions taken.

EFFECT: increased security of the computer system.

18 cl, 4 dwg

Similar patents RU2665911C2

Title Year Author Number
SYSTEM AND METHOD FOR LOG FORMING IN VIRTUAL MACHINE FOR ANTI-VIRUS FILE CHECKING 2017
  • Pintijskij Vladislav Valerevich
  • Anikin Denis Vyacheslavovich
  • Kobychev Denis Yurevich
  • Golovkin Maksim Yurevich
  • Butuzov Vitalij Vladimirovich
  • Karasovskij Dmitrij Valerievich
  • Kirsanov Dmitrij Aleksandrovich
RU2649794C1
METHOD OF DETECTING MALICIOUS FILES THAT COUNTERACT ANALYSIS IN ISOLATED ENVIRONMENT 2018
  • Karasovskij Dmitrij Valerievich
  • Shulmin Aleksej Sergeevich
  • Kobychev Denis Yurevich
RU2708355C1
SYSTEM AND METHOD OF GENERATING LOG WHEN EXECUTING FILE WITH VULNERABILITIES IN VIRTUAL MACHINE 2018
  • Monastyrskij Aleksej Vladimirovich
  • Pavlyushchik Mikhail Aleksandrovich
  • Pintijskij Vladislav Valerevich
  • Anikin Denis Vyacheslavovich
  • Kirsanov Dmitrij Aleksandrovich
RU2724790C1
SYSTEM AND METHOD FOR PERFORMING ANTI-VIRUS SCAN OF FILE ON VIRTUAL MACHINE 2016
  • Monastyrskij Aleksej Vladimirovich
  • Butuzov Vitalij Vladimirovich
  • Golovkin Maksim Yurevich
  • Karasovskij Dmitrij Valerievich
  • Pintijskij Vladislav Valerevich
  • Kobychev Denis Yurevich
RU2628921C1
SYSTEM AND METHOD OF DETECTING MALICIOUS CODE IN FILE 2016
  • Golovkin Maksim Yurevich
  • Monastyrskij Aleksej Vladimirovich
  • Pintijskij Vladislav Valerevich
  • Pavlyushchik Mikhail Aleksandrovich
  • Butuzov Vitalij Vladimirovich
  • Karasovskij Dmitrij Valerievich
RU2637997C1
SYSTEM AND METHOD FOR CATEGORIZATION OF .NET APPLICATIONS 2018
  • Kuskov Vladimir Anatolevich
  • Anikin Denis Vyacheslavovich
  • Kirsanov Dmitrij Aleksandrovich
RU2756186C2
EMULATOR AND METHOD FOR EMULATION 2020
  • Pintijskij Vladislav Valerevich
  • Anikin Denis Vyacheslavovich
  • Kirsanov Dmitrij Aleksandrovich
  • Trofimenko Sergej Vladimirovich
RU2757409C1
METHOD OF DETECTING MALICIOUS EXECUTABLES, CONTAINING INTERPRETER, BY COMBINING EMULATORS 2015
  • Zakorzhevskij Vyacheslav Vladimirovich
  • Vinogradov Dmitrij Valerevich
  • Pintijskij Vladislav Valerevich
  • Kirsanov Dmitrij Aleksandrovich
RU2622627C2
SYSTEM AND METHOD FOR DETECTING THE PRESENCE OF A VULNERABILITY IN THE OPERATING SYSTEM BASED ON DATA ON PROCESSES AND THREADS 2022
  • Monastyrskii Aleksei Vladimirovich
  • Kondratev Dmitrii Andreevich
RU2797716C1
SYSTEM AND METHOD OF DETECTING LATENT BEHAVIOUR OF BROWSER EXTENSION 2018
  • Vinogradov Dmitrij Valerevich
  • Davydov Vasilij Aleksandrovich
  • Parinov Denis Igorevich
RU2697950C2

RU 2 665 911 C2

Authors

Pintijskij Vladislav Valerevich

Anikin Denis Vyacheslavovich

Kobychev Denis Yurevich

Golovkin Maksim Yurevich

Butuzov Vitalij Vladimirovich

Karasovskij Dmitrij Valerievich

Kirsanov Dmitrij Aleksandrovich

Dates

2018-09-04Published

2017-02-08Filed