FIELD: computer equipment.
SUBSTANCE: invention relates to methods for monitoring the execution of the investigated software in order to detect the behavior characteristic of malicious software. To do this, get a lot of scripts, get a list of activation events of malicious behavior from at least one script from the received set of scripts; collect all the events caused by the execution of the activation event of the malicious behavior from the list of events of the activation of the malicious behavior during the execution of the application being studied in the modified software and hardware of the computer device; and detect the activation of the malicious behavior of the application under study based on the analysis of all collected events by identifying events characteristic of the malicious behavior.
EFFECT: achieving the creation of a script of popular events by selecting from the event scenarios the activations of the event that activated the malicious behavior when executing the monitoring of the application being monitored, and recording it in the script of popular events.
1 cl, 7 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD AND SYSTEM FOR DETECTING MALICIOUS SOFTWARE BY CONTROL OF SOFTWARE IMPLEMENTATION RUNNING UNDER SCRIPT | 2013 |
|
RU2653985C2 |
SYSTEM AND METHOD FOR DETECTING MALWARE BY CREATING ISOLATED ENVIRONMENT | 2012 |
|
RU2535175C2 |
METHOD OF DETECTING MALICIOUS EXECUTABLES, CONTAINING INTERPRETER, BY COMBINING EMULATORS | 2015 |
|
RU2622627C2 |
SYSTEM AND METHOD OF DETECTING THREAT IN CODE EXECUTED BY VIRTUAL MACHINE | 2012 |
|
RU2522019C1 |
SYSTEM AND METHOD OF IMPROVING ORGANISATION DATA SECURITY BY CREATING ISOLATED ENVIRONMENT | 2012 |
|
RU2541895C2 |
METHOD OF DETECTING UNKNOWN PROGRAMS BY LOAD PROCESS EMULATION | 2011 |
|
RU2472215C1 |
SYSTEM AND METHOD FOR ANTIVIRUS SCANNING OF OBJECTS ON A MOBILE DEVICE | 2023 |
|
RU2818877C1 |
METHOD OF DETECTING MALICIOUS FILES USING LINK GRAPH | 2023 |
|
RU2823749C1 |
METHOD FOR AUTOMATIC ADJUSTMENT OF SECURITY MEANS | 2012 |
|
RU2514137C1 |
SYSTEM AND METHOD OF DETECTING LATENT BEHAVIOUR OF BROWSER EXTENSION | 2018 |
|
RU2697950C2 |
Authors
Dates
2019-02-12—Published
2015-12-18—Filed