FIELD: computing technology.
SUBSTANCE: server computer system comprises at least one hardware processor configured to: in response to a target event occurring in the target client system, determine whether the target client system contains malware; and perform a protection operation in order to protect the target client system; wherein determining whether the target client system contains malware includes: determining the event context of the target event; selecting a client profile from a set of predetermined client profiles; using a behaviour model specific to the selected client profile in order to define a set of prediction estimates in accordance with the event context; selecting an estimate defined for the type of event of the target event; and comparing the selected estimate with the predetermined threshold, wherein the composition of the selected cluster of client systems is determined by analysing the multiple events that have occurred in the set of client systems in order to determine which of the set of client systems exhibits similar behaviour.
EFFECT: increase in the level of security of a computing system.
21 cl, 20 dwg, 1 tbl
Title | Year | Author | Number |
---|---|---|---|
SYSTEMS AND METHODS FOR DETECTING BEHAVIOURAL THREATS | 2019 |
|
RU2803399C2 |
SYSTEMS AND METHODS FOR DETECTING BEHAVIOURAL THREATS | 2019 |
|
RU2772549C1 |
COMPUTER SYSTEM AND METHOD FOR DETECTING MALWARE USING MACHINE LEARNING | 2021 |
|
RU2802860C1 |
SYSTEMS AND METHODS FOR USING DNS MESSAGES FOR SELECTIVE COLLECTION OF COMPUTER FORENSIC DATA | 2020 |
|
RU2776349C1 |
DYNAMIC REPUTATION INDICATOR FOR OPTIMIZATION OF COMPUTER SECURITY OPERATIONS | 2017 |
|
RU2723665C1 |
SYSTEMS AND METHODS FOR REPORTING COMPUTER SECURITY INCIDENTS | 2019 |
|
RU2757597C1 |
SYSTEMS AND METHODS FOR AUTOMATIC DEVICE DETECTION, DEVICE CONTROL AND REMOTE ASSISTANCE | 2015 |
|
RU2694022C2 |
SYSTEM AND METHODS FOR DECRYPTING NETWORK TRAFFIC IN A VIRTUALIZED ENVIRONMENT | 2017 |
|
RU2738021C2 |
USER INTERFACE FOR PROVIDING SECURITY AND REMOTE CONTROL OF NETWORK ENDPOINTS | 2015 |
|
RU2697935C2 |
DOUBLE SELF-TEST OF MEMORY FOR PROTECTION OF MULTIPLE NETWORK ENDPOINTS | 2016 |
|
RU2714607C2 |
Authors
Dates
2022-08-22—Published
2019-12-10—Filed