Cloud-based sample database dynamic maintaining method

A database and sample technology, applied in the field of information security, can solve problems such as slowness, troubles, and occupation of system resources on client computers

Active Publication Date: 2010-12-22
BEIJING QIHOO TECH CO LTD
View PDF5 Cites 42 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Due to the infectivity, replicability and destructiveness of these malicious programs, they have become a major problem that plagues computer use. Therefore, in today's soaring network threats, updating virus signatures has become a daily must for enterprises and Internet users. From once a week to once a day, until it is updated all the time, while the traditional antivirus software puts the virus database on the client computer, analyzes the files on the client, and repeatedly compares it with the local virus database during the scanning process. It takes up a lot of system resources, and with the continuous upgrade of the virus database, the capacity of the virus database is getting larger and larger, and the time spent analyzing files is also getting longer and longer, making the client computer slower and slower. Therefore, the anti-virus industry New technological breakthroughs must be found

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Cloud-based sample database dynamic maintaining method
  • Cloud-based sample database dynamic maintaining method
  • Cloud-based sample database dynamic maintaining method

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0037] The present invention will be further described below with reference to the accompanying drawings.

[0038] A cloud fabric is a large client / server (CS) architecture such as figure 1 Shown is a schematic diagram of the implementation mode of the present invention. The core idea of ​​the present invention is to collect the behaviors of various programs (which can be a single behavior or a combination of a group of behaviors) through a large number of client computers 102, especially the behaviors of suspicious programs, and associate the behaviors of the programs with the behaviors of the programs. characteristics, while the database 104 on the server side can record the characteristics of a program and its corresponding behavior records. In this way, on the server side, it can be summarized and analyzed in the database according to the program behavior or program characteristics or a group of program behavior and program characteristics, thus helping to classify softwa...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention provides a cloud-based sample database dynamic maintaining method comprising the following steps of: firstly, collecting program characteristics and program behaviors corresponding to the program characteristics and transmitting the program characteristics and the program behaviors corresponding to the program characteristics to a server end by a client computer; secondly, recordingdifferent program characteristics and the program behaviors corresponding to the program characteristics in a server end database and a black / white list; and finally analyzing unknown program characteristics and the program behaviors by combining with the program characteristics and the program behaviors corresponding to the program characteristics in the existing black / white list so as to updatethe black / white list. By collecting the program behaviors and linking to the program characteristics through a client, the invention can be used for recording the program characteristics and the program behaviors corresponding to the program characteristics in the database, analyzing and inducting a sample in the database according to the linking relationship between the collected program behaviors and the program characteristics, thereby being beneficial to classifying and discriminating black software or programs from white software or programs. In addition, the invention can be used for formulating corresponding clearing or restoring measures aiming at malicious software in a blacklist.

Description

technical field [0001] The invention relates to the technical field of information security, in particular to a method for dynamically maintaining a sample database based on cloud security. Background technique [0002] With the widespread use of computer technology in various fields of social life, malicious programs (Malwar, malicious software, refers to any software program deliberately created to perform unauthorized and usually harmful behaviors) have also followed one after another like its appendages. . Due to the infectivity, replicability and destructiveness of these malicious programs, they have become a major problem that plagues computer use. Therefore, in today's soaring network threats, updating virus signatures has become a must-have job for enterprises and Internet users every day. From once a week to once a day, until it is updated all the time, while the traditional anti-virus software puts the virus database on the client computer, analyzes the files on t...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): G06F21/00G06F21/50
Inventor 齐向东徐贵斌范纪锽
Owner BEIJING QIHOO TECH CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products