FIELD: safety of computer systems.
SUBSTANCE: technical result is achieved by implementing a method of detecting and countering the distribution of malicious programs in a computer network, in which a topology of a computer network is formed, malware is distributed over n-assets of the computer network, a directed graph of the trajectories of the implementation of the malicious program with respect to the n-th asset is formed, generating malware detection conditions, detecting malware using detection conditions, making a decision on isolating a fragment of a computer network from n-assets infected with a known malware, setting up a z-th antivirus program, comparing the malware detection conditions with the z-th antivirus program settings, adjusting the z-th antivirus program settings, determining the level of information security risk from unknown malicious programs for n-assets of a computer network, comparing the level of information security risk with the required value, computer network information security incidents are investigated.
EFFECT: reduced level of damage to a computer network.
1 cl, 1 dwg
| Title | Year | Author | Number | 
|---|---|---|---|
| METHOD FOR IDENTIFYING INFORMATION SECURITY THREATS (OPTIONS) | 2023 | 
 | RU2802539C1 | 
| METHOD FOR ADJUSTING THE PARAMETERS OF A MACHINE LEARNING MODEL IN ORDER TO IDENTIFY FALSE TRIGGERING AND INFORMATION SECURITY INCIDENTS | 2020 | 
 | RU2763115C1 | 
| METHOD FOR PROCESSING INFORMATION SECURITY EVENTS PRIOR TO TRANSMISSION FOR ANALYSIS | 2020 | 
 | RU2762528C1 | 
| SYSTEM AND METHOD FOR PREVENTION SAFETY INCIDENTS BASED ON USER DANGER RATING | 2011 | 
 | RU2477929C2 | 
| INFORMATION SECURITY INCIDENT RESPONSE SYSTEM AND METHOD | 2023 | 
 | RU2824732C1 | 
| METHOD OF COMPUTER SECURITY DISTRIBUTED EVENTS INVESTIGATION | 2015 | 
 | RU2610395C1 | 
| SYSTEM AND METHOD OF CORRELATING EVENTS FOR DETECTING INFORMATION SECURITY INCIDENT | 2019 | 
 | RU2739864C1 | 
| METHOD FOR AUTOMATIC ADJUSTMENT OF SECURITY MEANS | 2012 | 
 | RU2514137C1 | 
| METHOD FOR FILTERING EVENTS FOR TRANSMISSION TO REMOTE DEVICE | 2022 | 
 | RU2813239C1 | 
| METHOD FOR EARLY DETECTION OF DESTRUCTIVE EFFECTS OF BOTNET ON A COMMUNICATION NETWORK | 2019 | 
 | RU2731467C1 | 
Authors
Dates
2024-04-23—Published
2023-05-11—Filed