Abnormal process detection method and apparatus
A detection method and detection device technology, applied in the direction of platform integrity maintenance, etc., can solve problems such as unable to detect and kill unknown viruses
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0033] This embodiment provides an abnormal process detection method, please refer to figure 1 , figure 1 It is a schematic flow chart of the method, and the method comprises the steps:
[0034] Step S101: Determine the execution program corresponding to the running process in the system;
[0035] Step S102: Determine whether the path of the execution program belongs to the preset legal path, if not, mark the process corresponding to the execution program as abnormal.
[0036] At least one of the following methods can be used to determine the preset legal path before judging whether the path of executing the program belongs to the preset legal path: take a snapshot of the system process to obtain the legal path of the legal process when the terminal is virus-free; The path corresponding to the legal process is regarded as the legal path. The legal path generally includes a system folder path set and a custom legal program full path set. The system folder path set is a coll...
Embodiment 2
[0045] In order to describe an abnormal process detection method proposed in Embodiment 1 in more detail, this embodiment provides a more specific embodiment, please refer to figure 2 , figure 2 A schematic flowchart of an abnormal process detection method provided in this embodiment includes the following steps:
[0046] Step S201: start.
[0047] Step S202: The system schedules the detection program, and enters step S203.
[0048] Before this step, a whitelist of legitimate processes is generated first. The whitelist is a text file, and each line represents a record. In the white list, a system folder path set, a custom legal program full path set, and a data summary value of an application corresponding to the custom legal program full path set are recorded.
[0049] Step S203: Obtain a list of all processes in the current system and detailed information such as the execution program and start time of each process through means such as ps and accessing / proc. Then go t...
Embodiment 3
[0060] This embodiment provides an abnormal process detection device, please refer to image 3 , image 3 An abnormal process detection device provided for this embodiment, the device includes: a program determination module 301, a path judgment module 302, and a process marking module 303; the program determination module 301 is used to determine the execution program corresponding to the running process in the system; The path judging module 302 is used to judge whether the path of executing the program belongs to the preset legal path, if not, notify the process marking module 303 to mark the process corresponding to the executing program as abnormal.
[0061] In this embodiment, another abnormal process detection device is provided, please refer to Figure 4 , the device includes the above modules, wherein the path judging module 302 also includes a system judging submodule 3021 and a custom judging submodule 3022, the system judging submodule 3021 is used to judge whethe...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com