FIELD: computer equipment.
SUBSTANCE: computer system for detecting malicious programs, comprising memory and associated microprocessor and configured to implement, outside the host with a potential malware domain generation algorithm (DGA), following steps: interception of the initial response to the first external access request; determining, according to address, included in the first external access request and the initial response, whether the external site is a time server; in response, if external site is time server, sending a modified response to a host with a potential DGA malware; interception, in response to a second external access request sent by a host with a potential malware DGA response, indicating that second access request was not successful; and in response to interception of response indicating that second access request was not successful, determining that a host comprises a malicious program which executes domain generation algorithm.
EFFECT: technical result consists in isolation of host with potential malware of domain generation algorithm from tool software for analysis.
15 cl, 12 dwg
Title | Year | Author | Number |
---|---|---|---|
INTELLIGENT BOTS DETECTION AND PROTECTION SYSTEM AND METHOD | 2020 |
|
RU2738337C1 |
SYSTEMS AND METHODS FOR USING DNS MESSAGES FOR SELECTIVE COLLECTION OF COMPUTER FORENSIC DATA | 2020 |
|
RU2776349C1 |
SYSTEMS AND METHODS OF DEVICES AUTOMATIC DETECTION | 2017 |
|
RU2742824C2 |
SYSTEMS AND METHODS FOR PROTECTING NETWORK DEVICES THROUGH FIREWALL | 2016 |
|
RU2714367C1 |
SYSTEM AND METHOD FOR AUTOMATIC DEVICE DETECTION, DEVICE CONTROL AND REMOTE ASSISTANCE | 2015 |
|
RU2691858C2 |
SYSTEM AND METHODS FOR DETECTING NETWORK FRAUD | 2017 |
|
RU2744671C2 |
ENDPOINT SECURITY SYSTEM AND METHOD | 2015 |
|
RU2693922C2 |
METHOD AND SYSTEM FOR CREATING PERSONALIZED USER PARAMETER OF INTEREST FOR IDENTIFYING PERSONALIZED TARGET CONTENT ELEMENT | 2017 |
|
RU2757546C2 |
COMPUTER SYSTEM AND METHOD FOR DETECTING MALWARE USING MACHINE LEARNING | 2021 |
|
RU2802860C1 |
DOUBLE SELF-TEST OF MEMORY FOR PROTECTION OF MULTIPLE NETWORK ENDPOINTS | 2016 |
|
RU2714607C2 |
Authors
Dates
2020-07-08—Published
2016-11-02—Filed