FIELD: computing.
SUBSTANCE: invention relates to the field of computing for the analysis of malicious software. The effect is achieved due to the fact that a set of decomposed elements, which are functionally related by the structure of the input program (message), are analyzed taking into account databases containing information about known malicious and safe elements, after which the safe elements are loaded into the places provided for them in the input structure. programs (messages), and potentially malicious elements are subjected to the next decomposition into many smaller, structurally related, decomposed elements, which, in turn, are analyzed taking into account the mentioned databases, and the smaller decomposed safe elements obtained at this stage are loaded into their designated places in the structure of the related many smaller decomposed elements, and potentially malicious smaller decomposed elements are subjected to the next decomposition into many even smaller, structurally related, decomposed elements, repeating the operation until a sub-element of the malware code is identified or a specified number of decompositions are performed.
EFFECT: increasing the likelihood of detecting malicious programs and elements without using the dynamic detection mode while simplifying the method.
3 cl, 1 dwg
Authors
Dates
2021-12-15—Published
2021-03-24—Filed