File exception identification method, apparatus and device, and computer readable storage medium

An abnormal identification and file technology, applied in computer security devices, computing, instruments, etc., can solve the problems of slow virus feature extraction and upgrade speed, ineffective detection of feature code scanning technology, and inflexible detection engine configuration. High performance, strong coping ability, comprehensive detection effect

CN111753298APending Publication Date: 2020-10-09ZHUHAI BAOQU TECH CO LTD
0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Publication Date
2020-10-09

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention provides a file exception identification method, apparatus and device, and a computer readable storage medium. The method comprises the steps of obtaining a to-be-identified file; determining whether the to-be-identified file contains file features stored in a yara engine feature library or not through a yara engine; if the to-be-identified file contains the file features stored in the yara engine feature library, determining that the to-be-identified file is an abnormal file; and if the to-be-identified file does not contain the file features stored in the yara engine feature library, determining that the to-be-identified file is a non-abnormal file. By adopting the method and the device, the file exception identification efficiency can be improved, the file exception handling capacity is high, and the applicability is high.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The present invention relates to the technical field of network detection, in particular to a method, device, equipment and computer-readable storage medium for identifying abnormal files. Background technique

[0002] With the development of computer network technology, while the computer and its network technology bring great convenience to people's life, threats on the network also emerge in endlessly. One of the most harmful and most influential is the increasing proliferation of computer viruses. Portable Executable (PE) files are the most widely used file format in the Windows operating system, and the impact of malicious PE files is particularly great. For file anomalies caused by computer viruses, virus signature scanning technology is currently the most widely used file anomaly detection technology. However, when a new virus or virus variant is generated, the extraction speed and upgrade speed of virus signatures are slow, resulting in signat...

Examples

Embodiment Construction

[0051] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiment of the application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiment of the application. Obviously, the described embodiment is only It is an embodiment of a part of the application, but not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by persons of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application.

[0052] Each will be described in detail below.

[0053] It should be understood that the terms "first", "second", "third" and "fourth" in the specification and claims of the present application and the above drawings are used to distinguish different objects, rather than to describe specific order. Furthermore, the terms "include" and "have", as well...