FIELD: information technology.
SUBSTANCE: invention relates to protection of a computer system from malicious software. Reputation manager operates in a computer system simultaneously with a malware protection mechanism. Reputation manager associates a dynamic reputation indicator with each executable entity, which is considered to be a unique combination of separate components (for example, a main executable file and a set of loaded libraries). Reputation indicator indicates the probability that the corresponding entity is malicious. Reputation of safe entities may increase with time. If the entity performs certain actions that may indicate malicious activity, the reputation of the corresponding entity may be reduced. Malware protection mechanism uses an entity-specific protocol to scan and/or track each target entity for malware, wherein this protocol varies depending on the reputation of the entity. Entities trusted as safe entities can be analysed using a softer protocol, unlike unknown or untrusted entities.
EFFECT: technical result is reduction of computational costs.
22 cl, 1 tbl, 19 dwg
Title | Year | Author | Number |
---|---|---|---|
SYSTEMS AND METHODS FOR USING A REPUTATION INDICATOR TO FACILITATE MALWARE SCANNING | 2014 |
|
RU2646352C2 |
SYSTEMS AND METHODS FOR REPORTING COMPUTER SECURITY INCIDENTS | 2019 |
|
RU2757597C1 |
SYSTEMS AND METHODS FOR AUTOMATIC DEVICE DETECTION, DEVICE CONTROL AND REMOTE ASSISTANCE | 2015 |
|
RU2694022C2 |
DECLARATION-BASED CONTENT REPUTATION SERVICE | 2011 |
|
RU2573760C2 |
SYSTEMS AND METHODS FOR USING DNS MESSAGES FOR SELECTIVE COLLECTION OF COMPUTER FORENSIC DATA | 2020 |
|
RU2776349C1 |
SYSTEMS AND METHODS FOR DETECTING BEHAVIOURAL THREATS | 2019 |
|
RU2778630C1 |
COMPLEX CLASSIFICATION FOR DETECTING MALWARE | 2014 |
|
RU2645268C2 |
USER INTERFACE FOR PROVIDING SECURITY AND REMOTE CONTROL OF NETWORK ENDPOINTS | 2015 |
|
RU2697935C2 |
SYSTEMS AND METHODS OF DEVICES AUTOMATIC DETECTION | 2017 |
|
RU2742824C2 |
SYSTEMS AND METHODS FOR DETECTING BEHAVIOURAL THREATS | 2019 |
|
RU2803399C2 |
Authors
Dates
2020-06-17—Published
2017-10-26—Filed