Virus monitoring method and virus monitoring device in large network
A monitoring device and virus technology, applied in the field of information security, can solve the problems of unmanageable clients, hidden dangers of computer system security, virus blind spots, etc.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Publication Date
- 2010-02-24
- Estimated Expiration
- Not applicable · inactive patent
Smart Images
Figure 1 Figure 2
Abstract
Description
technical field
[0001] The present invention relates to information security technology, more specifically, relates to a virus monitoring method and device in a large network. Background technique
[0002] Virus prevention is an important means to ensure the safe and stable operation of information systems, and is a major issue in the field of information security. Especially in the financial industry, the security of information systems is of paramount importance. At present, antivirus software manufacturers at home and abroad have launched many antivirus software products, such as Symantec, Kill, McAfee and so on. In addition to the stand-alone version, these antivirus software also have a server-based network version to monitor the virus alarm status of each computer in the network, manage the virus database upgrade, and other various management and monitoring functions. All virus prevention clients The information is forwarded to the database of the antivirus server. ...
Examples
Embodiment Construction
[0027] Definition of terms, in the present invention, the following English abbreviations are defined as,
[0028] AVMC: (Anti Virus Monitoring Center) anti-virus monitoring center;
[0029] KILL: "Safe Armor" anti-virus software developed by CA;
[0030] NMAP: Network Mapper, a network scanning and sniffing tool.
[0031] The virus monitoring device of the present invention is an AVMC, and according to the present invention, the AVMC uses NMAP technology. Currently, NMAP (Network Mapper) is a commonly used network scanning and sniffing tool. NMAP can help network administrators in-depth detection of UDP or TCP ports, down to the operating system used by the host; it can also record all detection results in logs of various formats to serve system security. It has three basic functions, one is to detect whether a group of hosts are online; the second is to scan host ports and sniff the network services provided; it can also infer the operating system used by the host. NMAP ...