发明名称 SYSTEM AND METHOD FOR DETECTING MALWARE PREVENTING STANDARD USER INTERACTION WITH OPERATING SYSTEM INTERFACE
摘要 FIELD: physics, computer engineering.SUBSTANCE: invention relates systems and methods of detecting presence of malware in an operating system preventing the user from working with the operating system. To detect presence of malware in an operating system, the method includes: (a) detecting the occurrence of an event characterised by disruption of user interaction with the operating system interface; (b) comparing the current state of the operating system with patterns of states characterising operation of the of operating system with malware which prevents user interaction with the operating system interface; and (c) upon detecting said event characterised by disruption of user interaction with the operating system interface, and upon match of the current state of the operating system with said patterns of states characterising operation of the operating system with said malware, determining the presence of said malware in the operating system.EFFECT: detecting the presence of malware preventing user interaction with an operating system interface.11 cl, 6 dwg
申请公布号 RU2530210(C2) 申请公布日期 2014.10.10
申请号 RU20120156439 申请日期 2012.12.25
申请人 ZAKRYTOE AKTSIONERNOE OBSHCHESTVO "LABORATORIJA KASPERSKOGO" 发明人 TATARINOV IVAN IVANOVICH;MARTYNENKO VLADISLAV VALER'EVICH;MONASTYRSKIJ ALEKSEJ VLADIMIROVICH;PAVLJUSHCHIK MIKHAIL ALEKSANDROVICH;SAPRONOV KONSTANTIN VLADIMIROVICH;SLOBODJANJUK JURIJ GENNAD'EVICH
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址