FIELD: data processing.
SUBSTANCE: invention relates to the field of detection of malicious files. Classification system of the analyzed objects is disclosed, which contains: a) means of sampling a data block, intended for: sampling at least one data block contained in the analyzed object, using the analysis model, while the analysis model is a set of rules for searching data blocks, so that each found data block increases the probability of classifying the object being analyzed as malicious; transferring the selected data blocks to the static analysis tool; b) means of static analysis of the object, intended for: forming for each received data block a set of attributes describing the said data block; calculating the convolution of the generated feature sets; transferring the generated convolution to the means of calculating the degree of harmfulness; c) means of calculating the degree of harmfulness, designed to: calculate the degree of harmfulness of the object being analyzed based on the analysis of the resulting convolution using the model of detecting malicious objects; transferring the calculated degree of harmfulness to the classification tool; d) classification tool designed to: recognize the object being analyzed to be safe, in the case when the obtained degree of harmfulness does not exceed a predetermined threshold value and the mentioned degree of harmfulness is calculated on the basis of all the data blocks contained in the analyzed object; recognition of the object being analyzed as malicious, in the case when the obtained degree of harmfulness exceeds a predetermined threshold value.
EFFECT: technical result consists in the classification of objects using the detection model of malicious objects.
24 cl, 7 dwg
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD OF CLASSIFYING OBJECTS OF COMPUTER SYSTEM | 2018 |
|
RU2724710C1 |
SYSTEM AND METHOD OF DETECTION OF MALICIOUS FILES USING A TRAINED MALWARE DETECTION PATTERN | 2017 |
|
RU2654151C1 |
SYSTEM AND METHOD OF DETECTING A MALICIOUS FILE | 2018 |
|
RU2739865C2 |
SYSTEM AND METHOD OF MANAGING COMPUTING RESOURCES FOR DETECTING MALICIOUS FILES | 2017 |
|
RU2659737C1 |
SYSTEM AND METHOD OF MACHINE TRAINING MODEL OF DETECTING MALICIOUS FILES | 2017 |
|
RU2673708C1 |
SYSTEM AND METHOD FOR TRAINING HARMFUL CONTAINER DETECTION MODEL | 2018 |
|
RU2697955C2 |
SYSTEM AND METHOD OF DETECTING MALICIOUS FILES ACCOMPANIED WITH USING THE STATIC ANALYSIS ELEMENTS | 2017 |
|
RU2654146C1 |
WEB PROPERTY MODIFICATION DETECTION SYSTEM AND METHOD | 2018 |
|
RU2702081C2 |
SYSTEM AND METHOD OF SELECTING MEANS OF DETECTING MALICIOUS FILES | 2019 |
|
RU2739830C1 |
SYSTEM AND METHOD OF MAKING FLEXIBLE CONVOLUTION FOR MALWARE DETECTION | 2013 |
|
RU2580036C2 |
Authors
Dates
2019-02-12—Published
2017-10-18—Filed