摘要 |
FIELD: physics, computer engineering.SUBSTANCE: invention relates to computer engineering. The method of populating an antivirus rule database for rating threats involves obtaining, in a report processing means at the server side, application verification statistics on at least one user personal computer; comparing the application verification statistics with a storage list of safe objects; detecting known safe objects for which a high threat rating was calculated; analysing characteristic features of operation of the known safe objects and creating a new threat rating rule; the new threat rating rule has a higher priority that rules that were used when calculating the high rating of the safe object; populating the antivirus rule database with the new threat rating rule on the side of the user personal computer.EFFECT: high quality of detecting malware.18 cl, 6 dwg, 1 tbl |