METHOD AND SYSTEM FOR DETECTING THE INFRASTRUCTURE OF A MALICIOUS SOFTWARE OR A CYBERCRIMINAL Russian patent published in 2020 - IPC G06F21/56 

Abstract RU 2722693 C1

FIELD: computer equipment.

SUBSTANCE: disclosed is a computer-implemented method of identifying infrastructure of a malicious program or a cybercriminal, wherein: obtaining a request containing an infrastructure element and a tag on whether the item belongs to a malicious program or a cybercriminal; retrieving from the database a parameter of the received infrastructure element, an additional infrastructure element used by the same malware as the obtained infrastructure element, and an additional infrastructure element parameter; analyzing the obtained infrastructure element and the associated parameter and the additional infrastructure element and the parameter associated therewith; based on the analysis, statistical relationships between the parameter of the obtained infrastructure element and the parameter of the additional infrastructure element are determined; generating rules for searching for new infrastructure elements based on the detected statistical link and extracting new infrastructure elements from the database; assigning to new elements tags corresponding to certain malware or cybercriminals, and storing results in a database.

EFFECT: technical result is higher efficiency of detecting computer attacks.

10 cl, 2 dwg

Similar patents RU2722693C1

Title Year Author Number
SYSTEM AND METHOD FOR OUTSIDE CONTROL OF THE CYBERATTACK SURFACE 2021
  • Bobak Tim Dzhon Oskar
  • Volkov Dmitrij Aleksandrovich
RU2778635C1
SYSTEM AND METHOD FOR ACTIVE DETECTION OF MALICIOUS NETWORK RESOURCES 2021
  • Volkov Dmitrij Aleksandrovich
  • Prudkovskij Nikolaj Sergeevich
RU2769075C1
INTELLIGENT CONTROL SYSTEM FOR CYBERTHREATS 2019
  • Ryupichev Dmitrij Yurevich
  • Novikov Evgenij Aleksandrovich
  • Nichiporchuk Maksim Mikhajlovich
RU2702269C1
COMPUTING APPARATUS AND METHOD FOR IDENTIFYING COMPROMISED APPARATUSES BASED ON DNS TUNNELLING DETECTION 2021
  • Afonin Anton Viktorovich
RU2777348C1
METHOD FOR CLASSIFYING OBJECTS TO PREVENT SPREAD OF MALICIOUS ACTIVITY 2023
  • Parinov Denis Igorevich
  • Vlasova Viktoriia Vladimirovna
  • Romanenko Aleksei Mikhailovich
  • Antonov Aleksei Evgenevich
RU2808385C1
SYSTEM AND METHOD OF AUTOGENERATION OF DECISION RULES FOR INTRUSION DETECTION SYSTEMS WITH FEEDBACK 2016
  • Kislitsin Nikita Igorevich
RU2634209C1
METHOD AND SERVER FOR SEARCHING RELATED NETWORK RESOURCES 2018
  • Volkov Dmitry Aleksandrovich
  • Mileshin Philipp Alekseevich
RU2681699C1
METHOD OF ANALYSING MALICIOUS ACTIVITY ON INTERNET, DETECTING MALICIOUS NETWORK NODES AND NEIGHBOURING INTERMEDIATE NODES 2012
  • Golovanov Sergej Jur'Evich
RU2523114C2
SYSTEM AND METHOD OF PROTECTING CLOUD INFRASTRUCTURE FROM ILLEGAL USE 2012
  • Kononov Ehl'Dar Mikhajlovich
  • Lapushkin Anton Sergeevich
  • Efremov Andrej Anatol'Evich
RU2536663C2
METHOD OF ANALYSING AND DETECTING MALICIOUS INTERMEDIATE NODES IN NETWORK 2012
  • Golovanov Sergej Jur'Evich
RU2495486C1

RU 2 722 693 C1

Authors

Volkov Dmitrij Aleksandrovich

Mileshin Filipp Alekseevich

Dates

2020-06-03Published

2020-01-27Filed