METHOD OF DETECTING MALICIOUS FILES USING LINK GRAPH Russian patent published in 2024 - IPC G06F21/56 

Abstract RU 2823749 C1

FIELD: computer engineering.

SUBSTANCE: method of detecting malicious files includes steps of: collecting telemetry based on events associated with execution of files on user computers for two user computers; constructing a link graph based on the collected telemetry, where the vertices are files and the associated metadata from the telemetry, and the edges connecting them relate to the same event from the telemetry; marking is performed for at least one file, where objects are also marked, information on which has been collected within telemetry and which relate to both one file and several; detecting at least one unknown malicious file using a trained classifier based on the constructed link graph.

EFFECT: high level of detection of unknown malicious files.

7 cl, 9 dwg

Similar patents RU2823749C1

Title Year Author Number
SYSTEM AND METHOD FOR TWO-STAGE CLASSIFICATION OF FILES 2018
  • Romanenko Aleksej Mikhajlovich
  • Prokudin Sergej Viktorovich
  • Liskin Aleksandr Viktorovich
RU2708356C1
METHOD FOR CLASSIFYING OBJECTS TO PREVENT SPREAD OF MALICIOUS ACTIVITY 2023
  • Parinov Denis Igorevich
  • Vlasova Viktoriia Vladimirovna
  • Romanenko Aleksei Mikhailovich
  • Antonov Aleksei Evgenevich
RU2808385C1
SYSTEM AND METHOD OF INCREASING EFFICIENCY OF DETECTING UNKNOWN HARMFUL OBJECTS 2010
  • Mashevskij Jurij Vjacheslavovich
  • Vasilenko Roman Sergeevich
RU2454714C1
METHOD OF SELECTIVE USE OF PATTERNS OF DANGEROUS PROGRAM BEHAVIOR 2017
  • Pavlyushchik Mikhail Aleksandrovich
  • Slobodyanyuk Yurij Gennadevich
  • Monastyrskij Aleksej Vladimirovich
  • Martynenko Vladislav Valerevich
RU2665909C1
SYSTEM AND METHOD FOR ANALYSING FILE LAUNCH EVENTS FOR DETERMINING SAFETY RANKING THEREOF 2012
  • Pavljushchik Mikhail Aleksandrovich
  • Monastyrskij Aleksej Vladimirovich
RU2531565C2
SYSTEM AND METHOD OF ADAPTING PATTERNS OF DANGEROUS PROGRAM BEHAVIOR TO USERS' COMPUTER SYSTEMS 2017
  • Pavlyushchik Mikhail Aleksandrovich
  • Slobodyanyuk Yurij Gennadevich
  • Monastyrskij Aleksej Vladimirovich
  • Martynenko Vladislav Valerevich
RU2652448C1
ELIMINATION OF FALSE ACTIVATION OF ANTI-VIRUS RECORDS 2016
  • Parinov Denis Igorevich
  • Sviridov Konstantin Yurevich
  • Ulasen Sergej Ivanovich
RU2625053C1
METHOD FOR FASTER FULL ANTIVIRUS SCANNING OF FILES ON MOBILE DEVICE 2019
  • Chebyshev Viktor Vladimirovich
  • Glavatskikh Dmitrij Nikolaevich
  • Filatov Konstantin Mikhajlovich
  • Kuskov Vladimir Anatolevich
RU2726878C1
SYSTEM AND METHOD OF REDUCING NUMBER OF FALSE TRIGGERING OF CLASSIFICATION ALGORITHMS 2018
  • Prokudin Sergej Viktorovich
  • Chistyakov Aleksandr Sergeevich
  • Romanenko Aleksej Mikhajlovich
RU2706883C1
METHOD FOR SELECTIVE REPEATED ANTIVIRUS SCANNING OF FILES ON MOBILE DEVICE 2019
  • Chebyshev Viktor Vladimirovich
  • Glavatskikh Dmitrij Nikolaevich
  • Filatov Konstantin Mikhajlovich
  • Kuskov Vladimir Anatolevich
RU2726877C1

RU 2 823 749 C1

Authors

Kogtenkov Aleksei Aleksandrovich

Romanenko Aleksei Mikhailovich

Antonov Aleksei Evgenevich

Dates

2024-07-29Published

2023-07-28Filed