FIELD: computer engineering.
SUBSTANCE: technical result is achieved due to the fact that: a) obtaining data on computers in the network, wherein the data include information on software (SW) used on the computer; b) determining the presence of vulnerabilities in the SW on at least one computer in the network based on the obtained data; c) at least one patch is identified for each determined vulnerability; d) calculating, for each patch, a final score based on two or more of the following scores: estimation of SW usage frequency, for which presence of vulnerability has been determined; evaluation of use of computer hardware resources; assessment of risks of compromise by viral incidents; evaluation of the data transmission channel to the computer; e) determining the installation priority for at least two patches based on the calculated final score for each said patch; f) installing patches on computers depending on the determined installation priority.
EFFECT: higher degree of security due to prioritization of patches installation on computers in a network.
16 cl, 5 dwg, 3 tbl
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD FOR DETERMINING THE LEVEL OF DANGER OF INFORMATION SECURITY EVENTS | 2022 |
|
RU2800739C1 |
INTELLIGENT CONTROL SYSTEM FOR CYBERTHREATS | 2019 |
|
RU2702269C1 |
SYSTEM AND METHOD OF PROVIDING SAFETY OF ONLINE TRANSACTIONS | 2013 |
|
RU2587423C2 |
METHOD OF COMPUTER SECURITY DISTRIBUTED EVENTS INVESTIGATION | 2015 |
|
RU2610395C1 |
METHOD AND SYSTEM FOR PREVENTING UNAUTHORIZED ACCESS TO CORPORATE NETWORK OBJECTS | 2022 |
|
RU2799117C1 |
SYSTEM AND METHOD FOR PREVENTION SAFETY INCIDENTS BASED ON USER DANGER RATING | 2011 |
|
RU2477929C2 |
METHOD FOR ADJUSTING THE PARAMETERS OF A MACHINE LEARNING MODEL IN ORDER TO IDENTIFY FALSE TRIGGERING AND INFORMATION SECURITY INCIDENTS | 2020 |
|
RU2763115C1 |
INFORMATION SECURITY INCIDENT RESPONSE SYSTEM AND METHOD | 2023 |
|
RU2824732C1 |
METHOD FOR PROCESSING INFORMATION SECURITY EVENTS PRIOR TO TRANSMISSION FOR ANALYSIS | 2020 |
|
RU2762528C1 |
METHOD AND SYSTEM OF CYBER TRAINING | 2022 |
|
RU2808388C1 |
Authors
Dates
2024-02-12—Published
2023-06-07—Filed