File enumeration method and device based on USN log, electronic equipment and storage medium
A log and enumeration technology, applied in the computer field, can solve the problems of time-consuming acquisition of the full path and low efficiency of file enumeration.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0035] Such as figure 1 As shown, the embodiment of the present invention provides a method for enumerating files based on USN logs, including:
[0036] S101. Obtain the USN log in the disk drive, each log information in the USN log records the number of a modified object in the disk and the parent directory number of the modified object, wherein the modified object Including: modified files or modified directories;
[0037] In this step, the USN Journal (USN Journal) is a feature of NTFS, the full name is Update SequenceNumber Journal (update sequence number journal), or change journal (Change Journal), which maintains a record of changes made to the volume. The change of a file or directory is random and unpredictable, so the information of the modified object obtained through the USN log is irregular, and the order of arrival of the modified object is unpredictable. Under this background, the present invention aims to It provides an accurate and fast algorithm scheme for ...
Embodiment 2
[0076] Such as Figure 5 As shown, the embodiment of the present invention provides a USN log-based file enumeration device, including: an acquisition unit 21, configured to acquire the USN log in the disk drive, and each log information in the USN log is recorded with the A number of a modified object and a parent directory number of the modified object, wherein the modified object includes: a modified file or a modified directory; the first judging unit 22 is configured to Each log information: judging whether the parent directory number of the modified object recorded in the log information exists in the parent directory number whitelist, and the parent directory number of the preset enumerated object is recorded in the parent directory number whitelist; The second judging unit 23 is configured to determine whether the modified object recorded in the log information satisfies the preset enumeration if the parent directory number of the modified object recorded in the log in...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


