EP2584484A1

System and method for protecting a computer system from the activity of malicious objects

Abstract

Disclosed are systems and methods for protecting a computer from activities of malicious objects. The method comprises: monitoring events of execution of one or more processes on the computer; identifying auditable events among the monitored events, including events of creation, alteration or deletion of files, events of alteration of system registry, and events of network access by processes executed on the computer; recording the identified auditable events in separate file, registry and network event logs; performing a malware check of one or more software objects on the computer; if an object is determined to be malicious, identifying from the file, registry and network event logs the events associated with the malicious object; performing rollback of file events associated with the malicious object; performing rollback of registry events associated with the malicious object; terminating network connections associated with the malicious object.

EP2584484A1, drawing sheet 1
Sheet 1 of 9

Term

5.1 yearsto projected expiry

Projected expiry 17 October 2031, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

14 claims: 2 independent, 12 dependent

  1. 1
    A method for malware protection of a computer, the method comprising:monitoring events of execution of one or more processes on the computer;identifying auditable events among the monitored events, wherein the auditable events include at least events of creation, alteration or deletion on of files, events of creation, alteration or deletion parameters and values of system registry, and events of network access by processes executed on the computer;recording the identified auditable events in separate file, registry and network event logs;performing a malware check of one or more software objects on the computer;if an object is determined to be malicious, identifying from the file, registry and network event logs one or more of file, registry and network events associated with the malicious object;performing rollback of one or more file events associated with the malicious object;performing rollback of one or more registry events associated with the malicious object;terminating one or more network connections associated with the malicious object.
  2. 8
    A system for malware protection of a computer having a processor and a memory, the system comprising at least the following software modules loaded into the memory of the computer and executable by the processor of the computer:an antivirus database containing information about known malicious objects;an auditable event database containing a list of auditable events including at least events of creation, alteration or deletion of files, events of creation, alteration or deletion parameters and values of system registry, and events of network access by processes executed on the computer;a data collection module configured to: monitor events of execution of one or more processes on the computer;identify auditable events among the monitored events based on the list of auditable events contained in the auditable event database;and record the identified auditable events in separate file, registry and network event logs contained in the memory;an antivirus module configured to: perform a malware check of one or more software objects on the computer using the information about known malicious objects contained in the antivirus database;if an object is determined to be malicious, identify from the network event log one or more of network events associated with said malicious object;and terminate one or more network connections established by said malicious object;a recovery module configured to: if the object is determined to be malicious, identify from the file and registry event logs one or more file and registry events associated with said malicious object;perform rollback of one or more file events associated with the malicious object;perform rollback of one or more registry events associated with the malicious object.