FIELD: computer technology.
SUBSTANCE: disclosed is the method of categorizing an application created using the platform .NET (hereinafter application), implemented using a computer system in which: the CLR profiler is launched using the CLR security tool by loading the CLR execution environment into RAM when the application is launched in order to process events that occur during application execution, while the security tool sets the necessary values of environment variables for loading the CLR profiler into the address space of the application process; the application execution log is generated using a running CLR profiler based on the information collected; at the same time, information about events that occur during application execution that are processed by the CLR profiler is added to the execution log, while the events are at least function calls made by a process launched from an application where the functions are methods of the software platform .NET, which calls are made from the program code of the application during its execution; with the help of the security tool, the application is assigned to one of the predefined categories of applications based on the analysis of the generated application execution log, using heuristic rules, while the predefined categories of applications are: the category of trusted applications, the category of untrusted applications, the category of malicious applications, while if the security tool classifies the application as malicious applications, it also recognizes as malicious all assemblies loaded into RAM during application execution and are not trusted.
EFFECT: provided is categorization of an application created using the .NET platform.
10 cl, 3 dwg
Title | Year | Author | Number |
---|---|---|---|
MACHINE CODE ACCESS LIMITATION METHOD TO THE OPERATING SYSTEM RESOURCES | 2016 |
|
RU2625052C1 |
METHOD OF CATEGORIZING ASSEMBLIES AND DEPENDENT IMAGES | 2015 |
|
RU2635271C2 |
METHOD FOR DETECTING HARMFUL ASSEMBLIES | 2015 |
|
RU2628920C2 |
METHOD FOR ANTI-VIRUS SCANNING OF COMPUTER SYSTEM | 2015 |
|
RU2617925C2 |
METHOD FOR EXCLUDING PROCESSES OF ANTIVIRUS SCANNING ON THE BASIS OF DATA ON FILE | 2015 |
|
RU2595510C1 |
METHOD OF CONTROLLING APPLICATIONS | 2015 |
|
RU2587424C1 |
SYSTEM AND METHOD OF REDUCING LOAD ON OPERATING SYSTEM WHEN EXECUTING ANTIVIRUS APPLICATION | 2013 |
|
RU2571723C2 |
METHOD OF CREATING ANTIVIRUS RECORD WHEN DETECTING MALICIOUS CODE IN RANDOM-ACCESS MEMORY | 2015 |
|
RU2592383C1 |
METHOD OF DETECTING MALICIOUS CODE IN RANDOM-ACCESS MEMORY | 2015 |
|
RU2589862C1 |
SYSTEM AND METHOD FOR REDUCING LOAD ON MALWARE DETECTION SERVICE | 2019 |
|
RU2739833C1 |
Authors
Dates
2021-09-28—Published
2018-02-06—Filed