Abstract: A system, method and computer readable medium for detecting and diffusing malware on a computer. Malware is analyzed to generate signatures and determine a fixing moment. All of the system calls of the operating system of a client computer are hooked and processed without emulation or the need for unpackers or decrypters, and a multi-level filter removes all system calls that are not associated with malware. The resulting system calls are accumulated on a per-thread basis and scanned, and the relevant threads are compared with the signatures to match with malware. The threads associated with malware are addressed at the fixing moment before the malware can operate to cause undesirable effects on the client computer.
Type:
Grant
Filed:
February 13, 2014
Date of Patent:
June 21, 2016
Assignee:
SYSTEMS OF INFORMATION SECURITY 2012
Inventors:
Volodymyr Grystan, Evgeny Tumoyan, Ivan Romanenko, Anton Kukoba, Anatolii Sviridenkov, Rusin Dmitry Evgenyevich
Abstract: A system, method and computer readable medium for detecting and diffusing malware on a computer. Malware is analysed to generate signatures and determine a fixing moment. All of the system calls of the operating system of a client computer are hooked and processed without emulation or the need for unpackers or decrypters, and a multi-level filter removes all system calls that are not associated with malware. The resulting system calls are accumulated on a per-thread basis and scanned, and the relevant threads are compared with the signatures to match with malware. The threads associated with malware are addressed at the fixing moment before the malware can operate to cause undesirable effects on the client computer.
Type:
Application
Filed:
February 13, 2014
Publication date:
August 21, 2014
Applicant:
Systems of Information Security 2012
Inventors:
Volodymyr Grytsan, Evgeny Tumoyan, Ivan Romanenko, Anton Kukoba, Anatolii Sviridenkov