FIELD: information technology.
SUBSTANCE: invention relates to solutions for detecting malicious files. System for analyzing the maliciousness of a file opened in a virtual machine as an environment for safe execution of files, which intercepts the event that occurs during the execution of the process thread created when the file is opened in the virtual machine as a safe execution environment, and suspends the execution of the stream; read the context of the processor on which the thread is executing; save the intercepted event and the context in the log; compare the data stored in the log with the templates, at the same time, at least one of the decisions is taken based on the comparison: the decision to recognize the file as malicious, the decision to stop the execution of the file, the decision to change the context of the processor, the decision to wait for the next event; perform actions that are consistent with the decisions taken.
EFFECT: increased security of the computer system.
18 cl, 4 dwg
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD FOR LOG FORMING IN VIRTUAL MACHINE FOR ANTI-VIRUS FILE CHECKING | 2017 |
|
RU2649794C1 |
METHOD OF DETECTING MALICIOUS FILES THAT COUNTERACT ANALYSIS IN ISOLATED ENVIRONMENT | 2018 |
|
RU2708355C1 |
SYSTEM AND METHOD OF GENERATING LOG WHEN EXECUTING FILE WITH VULNERABILITIES IN VIRTUAL MACHINE | 2018 |
|
RU2724790C1 |
SYSTEM AND METHOD FOR PERFORMING ANTI-VIRUS SCAN OF FILE ON VIRTUAL MACHINE | 2016 |
|
RU2628921C1 |
SYSTEM AND METHOD OF DETECTING MALICIOUS CODE IN FILE | 2016 |
|
RU2637997C1 |
SYSTEM AND METHOD FOR CATEGORIZATION OF .NET APPLICATIONS | 2018 |
|
RU2756186C2 |
EMULATOR AND METHOD FOR EMULATION | 2020 |
|
RU2757409C1 |
METHOD OF DETECTING MALICIOUS EXECUTABLES, CONTAINING INTERPRETER, BY COMBINING EMULATORS | 2015 |
|
RU2622627C2 |
SYSTEM AND METHOD FOR DETECTING THE PRESENCE OF A VULNERABILITY IN THE OPERATING SYSTEM BASED ON DATA ON PROCESSES AND THREADS | 2022 |
|
RU2797716C1 |
SYSTEM AND METHOD OF DETECTING LATENT BEHAVIOUR OF BROWSER EXTENSION | 2018 |
|
RU2697950C2 |
Authors
Dates
2018-09-04—Published
2017-02-08—Filed