File detection method and device, electronic equipment, storage medium and program product

By employing a multi-branch tree structure and a detection queue management mechanism in the file system, only nodes in the detection state are detected, thus solving the problem of low file detection efficiency and achieving efficient and reliable file integrity detection.

CN120832692APending Publication Date: 2025-10-24CHINA MOBILE SHANGHAI ICT CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410495976.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-23
Publication Date
2025-10-24

AI Technical Summary

Technical Problem

Existing technologies lack effective methods to improve file detection efficiency, especially in the case of massive file changes, making it difficult to detect file change messages in a timely manner and take remedial measures.

Method used

The system uses a multi-branch tree structure to store file data and employs a detection queue management mechanism to detect only nodes that are in the pending detection state. The detection thread processes these nodes sequentially and updates the multi-branch tree structure to reflect the detection results.

Benefits of technology

It improves the efficiency of file detection, saves computing resources, ensures the reliability and timeliness of file integrity detection, and reduces the problem of duplicate file detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120832692A_ABST
    Figure CN120832692A_ABST
Patent Text Reader

Abstract

The invention provides a file detection method and device, electronic equipment, a storage medium and a program product. The method comprises the steps that file data of the vehicle-mounted system are obtained, the file data are stored in a multi-way tree structure, and the multi-way tree structure comprises a plurality of nodes; for each node of the multi-way tree structure, executing the following processing: marking the node state of the node as a to-be-detected state under the condition that the node in the file data meets a to-be-detected condition; adding the node in the to-be-detected state to the tail of a detection queue; according to a detection sequence in the detection queue, calling a detection thread to detect each node in the to-be-detected state in sequence to obtain a detection result; and under the condition that the detection result is data change, updating the multi-way tree structure based on the detection result. According to the invention, the file detection efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, and particularly relates to a file detection method and device, electronic equipment, storage medium and program product. BACKGROUND

[0002] A file system is a part of a computer operating system responsible for managing and organizing files and folders stored in a computer's hard disk or other media. The security of the file system is crucial because it involves the risk of file data being modified or damaged. Viruses and malicious software are one of the most common file system security threats, which can invade computer systems through various means, exploit vulnerabilities or weak passwords to access, modify or delete files.

[0003] In the digital age, the importance of file system security is increasingly prominent. In the face of massive file attacks, deleting important files, modifying important configuration files and other operations, it is necessary to timely detect file change messages and take the next step to remedy. In the file detection process, it is necessary to determine all file modification change messages. Therefore, in the case of massive file changes, comprehensive detection of file integrity is a necessary condition for the safe operation of the file system. In related technologies, there is no better way to improve the detection efficiency of files. SUMMARY

[0004] The embodiments of the present application provide a file detection method and device, electronic equipment, storage medium and program product, which can improve the detection efficiency of files.

[0005] The technical scheme of the embodiments of the present application is implemented as follows:

[0006] The embodiments of the present application provide a file detection method, which comprises the following steps:

[0007] Obtain file data of an in-vehicle system, wherein the file data is stored in a multi-way tree structure, the multi-way tree structure comprises a plurality of nodes, and types of the nodes comprise directory nodes and sub-file nodes;

[0008] For each node of the multi-way tree structure, the following processing is performed:

[0009] If the node in the file data meets a to-be-detected condition, mark a node state of the node as a to-be-detected state;

[0010] Add the node in the to-be-detected state to a tail of a detection queue, wherein the detection queue comprises a plurality of nodes in the to-be-detected state;

[0011] According to a detection sequence in the detection queue, the detection thread is invoked to perform detection processing on each node in the to-be-detected state in turn, and a detection result is obtained.

[0012] In a case where the detection result is data change, the multiway tree structure is updated based on the detection result.

[0013] Embodiments of the present application provide a file detection device, comprising:

[0014] A file acquisition module is configured to acquire file data of a vehicle-mounted system, wherein the file data is stored in a multiway tree structure, the multiway tree structure comprises a plurality of nodes, and types of the nodes comprise directory nodes and sub-file nodes; for each node in the multiway tree structure, the following processing is performed: in a case where the node in the file data satisfies a to-be-detected condition, a node state of the node is marked as a to-be-detected state;

[0015] A file detection module is configured to add the node in the to-be-detected state to a tail of a detection queue, wherein the detection queue comprises a plurality of nodes in the to-be-detected state; according to a detection sequence in the detection queue, a detection thread is invoked to perform detection processing on each node in the to-be-detected state in turn, and a detection result is obtained;

[0016] A result processing module is configured to, in a case where the detection result is data change, update the multiway tree structure based on the detection result.

[0017] Embodiments of the present application provide an electronic device, comprising:

[0018] A memory is configured to store computer executable instructions or computer programs;

[0019] A processor is configured to execute the computer executable instructions or computer programs stored in the memory, and implement the file detection method provided by embodiments of the present application.

[0020] Embodiments of the present application provide a computer readable storage medium, which stores computer executable instructions or computer programs, and is configured to be executed by a processor to implement the file detection method provided by embodiments of the present application.

[0021] Embodiments of the present application provide a computer program product, comprising computer executable instructions or computer programs, and the computer executable instructions or computer programs are executed by a processor to implement the file detection method provided by embodiments of the present application.

[0022] Embodiments of the present application have the following beneficial effects:

[0023] The file data is stored as nodes on a multi-branch tree structure, and the detection state of the nodes is set, and only the files in the to-be-detected state are detected, so as to solve the file repeated detection problem and save the computing resources; by adding the nodes in the to-be-detected state to the tail of the detection queue, according to the detection order in the detection queue, the detection thread is called to detect each node in the to-be-detected state in turn, the detection resources are reasonably allocated, and the detection efficiency of the file is improved; the multi-branch tree structure is updated according to the detection result, the files or subdirectories under the directory can be updated and modified in time, and the reliability of the file integrity detection is improved. BRIEF DESCRIPTION OF DRAWINGS

[0024] Figure 1 is an application mode schematic diagram of the file detection method provided by the embodiment of the application;

[0025] Figure 2 is a structural schematic diagram of an electronic device provided by the embodiment of the application;

[0026] Figure 3A is a first flow schematic diagram of the file detection method provided by the embodiment of the application;

[0027] Figure 3B is a second flow schematic diagram of the file detection method provided by the embodiment of the application;

[0028] Figure 3C is a third flow schematic diagram of the file detection method provided by the embodiment of the application;

[0029] Figure 3D is a fourth flow schematic diagram of the file detection method provided by the embodiment of the application;

[0030] Figure 3E is a fifth flow schematic diagram of the file detection method provided by the embodiment of the application;

[0031] Figure 3F is a sixth flow schematic diagram of the file detection method provided by the embodiment of the application;

[0032] Figure 3G is a seventh flow schematic diagram of the file detection method provided by the embodiment of the application;

[0033] Figure 4 is a vehicle-mounted file integrity detection architecture schematic diagram provided by the embodiment of the application;

[0034] Figure 5 is a detection data tree management structure schematic diagram provided by the embodiment of the application;

[0035] Figure 6 is a detection task state machine migration schematic diagram provided by the embodiment of the application;

[0036] Figure 7 is a detection scheduling management structure schematic diagram provided by an embodiment of the present application;

[0037] Figure 8 is a total structure schematic diagram provided by an embodiment of the present application;

[0038] Figure 9 is a file detection processing flowchart in a real-time monitoring mode provided by an embodiment of the present application;

[0039] Figure 10 is a file detection processing flowchart in a timing monitoring mode provided by an embodiment of the present application. DETAILED DESCRIPTION

[0040] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be described in further detail below with reference to the drawings, and the described embodiments should not be regarded as limiting the present application, and all other embodiments obtained by those skilled in the art without making creative efforts fall within the scope of protection of the present application.

[0041] In the following description, "some embodiments" are related to a subset of all possible embodiments, but it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.

[0042] In the following description, the terms "first\second\third" are only to distinguish similar objects, and do not represent a specific order of the objects, and it can be understood that "first\second\third" can be interchanged in a specific order or sequence as allowed, so that the embodiments of the present application described here can be implemented in an order other than that illustrated or described here.

[0043] It should be noted that the related data collection and processing (for example: obtaining file data to be detected) in the present application should strictly comply with the requirements of relevant national laws and regulations, obtain the informed consent or separate consent of the personal information subject, and carry out subsequent data use and processing behavior within the scope of authorization of laws and regulations and the personal information subject.

[0044] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works with other related parts to achieve a predetermined target, and can be implemented entirely or partially by using software, hardware (such as a processing circuit or a memory) or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an overall module or unit that includes the functions of the module or unit.

[0045] Unless otherwise defined, all technical and scientific terms used in the embodiments of the present application have the same meanings as those commonly understood by one of ordinary skill in the art. The terms used in the embodiments of the present application are merely used to describe the embodiments of the present application, and are not intended to limit the present application.

[0046] Before the embodiments of the present application are further described, the terms and phrases involved in the embodiments of the present application are explained, and the terms and phrases involved in the embodiments of the present application are applicable to the following explanations.

[0047] 1) Linux operating system command line framework (Linux inotify): a framework in Linux for monitoring file system changes, which can efficiently track changes in the Linux file system in real time and send notifications to related applications.

[0048] 2) Linux operating system audit component (Linux auditd): a component in the user space of the Linux audit system, responsible for writing audit records to disk and monitoring changes to files and directories.

[0049] 3) Polling: a way for a central processing unit (CPU) to decide how to provide services to peripheral devices.

[0050] 4) Message-Digest Algorithm 5 (MD5): a widely used hash algorithm. Hereinafter referred to as MD5, a hash algorithm can convert data of any length into a fixed length hash value, usually represented as a 32-bit hexadecimal string. Hash algorithms are mainly used to ensure the integrity of information transmission, commonly used in data integrity verification, password storage and digital signature fields. The output of MD5 is a fixed length hash value of 128 bits, i.e. 16 bytes, usually represented as a 32-bit hexadecimal string.

[0051] The embodiments of the present application provide a file detection method and device, electronic equipment, storage medium and program product, which can improve the detection efficiency of the file.

[0052] The following describes an exemplary application of the electronic device provided by the embodiments of the present application. The electronic device provided by the embodiments of the present application can implement terminal devices such as notebook computers, tablet computers, desktop computers, set-top boxes, mobile devices (e.g. mobile phones, portable music players, personal digital assistants, dedicated messaging devices, portable game devices), smart phones, smart speakers, smart watches, smart televisions, vehicle-mounted terminals, etc. various types of terminals, and can also be implemented as a server. In the following, an exemplary application when the electronic device is implemented as a server will be described.

[0053] Referring to Figure 1 , Figure 1 is an application mode schematic diagram of the file detection method provided by the embodiment of the present application, and the file detection method is used for detecting the file data in the database 500. Figure 1 The server 200, the network 300, the terminal device 400, and the database 500 are involved in the embodiment. The terminal device 400 is connected to the server 200 through the network 300. The network 300 can be a wide area network or a local area network, or a combination of the two.

[0054] In some embodiments, the server 200 can be a stand-alone physical server, a server cluster composed of multiple physical servers, or a distributed system. The server 200 can also be a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and basic cloud computing services such as big data and artificial intelligence platforms. The terminal device and the server can be directly or indirectly connected through wired or wireless communication, which is not limited in the embodiment of the present application.

[0055] In some embodiments, the database 500 stores a large amount of vehicle-mounted file data to be detected. The server 200 is configured to detect each file data to be detected according to a detection order in a detection queue. The terminal device 400 can be a vehicle-mounted terminal of a user.

[0056] For example, when receiving a file detection request uploaded by the user through the terminal device 400, the server 200 obtains file data to be detected from the database 500, and loads the file data to be detected according to a detection condition of the file data. The file detection request carries the detection order and the detection condition of the file data. The server 200 calls a detection thread to detect each file data to be detected in turn according to the detection order, sends the detection result to the terminal device 400 through the network 300, and the user can view the detection result in a computer application program on the terminal device 400.

[0057] In some embodiments, the file detection method of the present application can also be applied to the detection of other types of file data in the following scenarios: in an enterprise office scenario, the file detection method of the present application is used to detect important core file data, to timely find abnormal file data, and to replace lost or tampered file data to ensure the integrity of the file; in a teaching scenario, when the teaching system file data is updated, the file detection method of the present application is used to timely receive the update message of the file data and perform real-time detection to ensure the integrity of the teaching file data.

[0058] The embodiment of the present application can be implemented through database technology. A database is an electronic file cabinet that stores electronic files. Users can add, query, update, delete, and perform other operations on the data in the files. A "database" is a collection of data stored together in a certain way, shared by multiple users, with as little redundancy as possible, and independent of application programs.

[0059] A database management system (DBMS) is a computer software system designed to manage databases, generally with basic functions such as storage, interception, security, backup, etc. Database management systems can be classified according to the database model they support, such as relational, XML (Extensible Markup Language); or according to the type of computer they support, such as server cluster, mobile phone; or according to the query language they use, such as structured query language (SQL), XQuery; or according to the performance focus, such as maximum size, maximum speed; or other classification methods. Regardless of the classification method used, some DBMSs can cross categories, such as supporting multiple query languages at the same time.

[0060] The embodiment of the present application can also be implemented through cloud technology. Cloud technology is a general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on cloud computing business model applications, which can form a resource pool, be used on demand, and be flexible and convenient. A wide area network or local area network unifies a series of resources such as hardware, software, and network to realize a kind of hosting technology for data calculation, storage, processing and sharing.

[0061] The embodiment of the present application can also be implemented through artificial intelligence. Artificial intelligence (AI) is a new technical science that studies and develops theories, methods, technologies and application systems for simulating, extending and expanding human intelligence. Artificial intelligence is an important part of intelligent disciplines. It aims to understand the essence of intelligence and produce a new intelligent machine that can react in a similar way to human intelligence. The field of research includes robots, language recognition, image recognition, natural language processing and expert systems. Combining the method of the embodiment of the present application with artificial intelligence can improve the efficiency of vehicle-mounted file integrity detection.

[0062] Referring to Figure 2 , Figure 2 is a structural schematic diagram of an electronic device provided by the embodiment of the present application. The electronic device can beFigure 1 server 200, Figure 2 The server 200 shown in FIG. 10 includes at least one processor 410, a memory 450, and at least one network interface 420. The various components of the server 200 are coupled together by a bus system 440, which can include a data bus, a power bus, a control bus, and a state signal bus. For the sake of clarity, the various buses are illustrated in FIG. 10 as the bus system 440. The server 200 can also include a user input interface 430, a display 460, and a communication interface 470, all of which are coupled together by the bus system 440. Figure 2 The various buses are illustrated as the bus system 440 in FIG. 10 for the sake of clarity.

[0063] The processor 410 can be an integrated circuit chip with signal processing capabilities, such as a general purpose processor, a Digital Signal Processor (DSP), or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or the like. The general purpose processor can be a microprocessor, or any conventional processor, etc.

[0064] The memory 450 can be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard drives, optical disc drives, etc. The memory 450 optionally includes one or more storage devices remotely located from the processor 410.

[0065] The memory 450 includes volatile memory or non-volatile memory, or both. Non-volatile memory can be read only memory (ROM), volatile memory can be random access memory (RAM). The memory 450 described in the embodiments of the present application is intended to include any suitable type of memory.

[0066] In some embodiments, the memory 450 is capable of storing data to support various operations, examples of which include programs, modules, and data structures or a subset or superset thereof, which are described below.

[0067] The operating system 451 includes a system program for processing various basic system services and performing hardware-related tasks, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks.

[0068] The network communication module 452 is used to communicate with other electronic devices via one or more (wired or wireless) network interfaces 420, examples of which include Bluetooth, Wireless Fidelity (WiFi), and Universal Serial Bus (USB), etc.

[0069] In some embodiments, the device provided by the embodiments of the present application can be implemented in software, Figure 2 The detection device 455 of the file stored in the memory 450 is shown, which can be software in the form of programs and plug-ins, including the following software modules: a file acquisition module 4551, a file detection module 4552, and a result processing module 4553. These modules are logical, and thus can be combined or further split according to the implemented functions. The functions of each module will be described below.

[0070] In some embodiments, the terminal or server can implement the file detection method provided by the embodiments of the present application by running various computer-executable instructions or computer programs. For example, the computer-executable instructions can be microprogram-level commands, machine instructions, or software instructions. The computer program can be a native program in the operating system or a software module; can be a native application (APP), i.e., a program that needs to be installed in the operating system to run, such as a car navigation APP or an instant messaging APP; or can be a small program that can be embedded into any APP, i.e., a program that only needs to be downloaded into a browser environment to run. In summary, the above computer-executable instructions can be any form of instructions, and the above computer programs can be any form of application programs, modules, or plug-ins.

[0071] The file detection method provided by the embodiments of the present application will be described in conjunction with an exemplary application and implementation of the server device provided by the embodiments of the present application.

[0072] Next, the file detection method provided by the embodiments of the present application will be described. As described above, the electronic device implementing the file detection method of the embodiments of the present application can be a terminal, a server, or a combination of the two. Therefore, the execution subject of each step will not be repeated in the following description.

[0073] In some embodiments, referring to Figure 3A , Figure 3A is a first flowchart of the file detection method provided by the embodiments of the present application. Taking the server as the execution subject, the steps shown will be described in conjunction with Figure 3A .

[0074] In step 301, file data of a vehicle-mounted system is acquired.

[0075] Here, the file data is stored in a multiway tree structure, and the multiway tree structure includes multiple nodes. The types of the nodes include directory nodes and sub-file nodes.

[0076] The in-vehicle system includes audio and video data, running state data, and file data. The in-vehicle file system is a log file system suitable for a Linux system and is a simple and lightweight file system. The multi-way tree is a special tree data structure, in which there are multiple nodes, and each node can have 0, 1, or multiple child nodes. The in-vehicle file data is stored in each node in the multi-way tree structure, and the file data stored in the node is detected and processed. The directory node is a node for storing directory data in the file data, and the child file node is a node for storing child file data under the directory. The child node of the directory node can be a directory node or a child file node.

[0077] In some embodiments, referring to Figure 3B , Figure 3B is a second flowchart of a file detection method provided by the embodiments of the present application. Before step 301 shown in Figure 3A , steps 3001 to 3002 shown in Figure 3B may also be performed, which are described in detail below.

[0078] In step 3001, the directory file structure and configuration information of the in-vehicle system are obtained.

[0079] Here, the configuration information includes information of the child files and directories to be detected, and the type of the directory file structure is a multi-way tree structure. Each node of the multi-way tree structure stores data of the corresponding child file or directory.

[0080] For example, the directory file structure of the in-vehicle system is a multi-way tree structure, and the configuration information of the child files or directories to be detected in whole or in part is stored in the configuration file of the in-vehicle system. For ease of understanding, the directory file structure is explained below in conjunction with the accompanying drawings, for example, referring to Figure 5 , Figure 5 is a schematic diagram of a detection data tree management structure provided by the embodiments of the present application. The detection data tree management structure is also the directory file structure of the in-vehicle system. In the detection data tree management structure, the circular node represents the directory node, and the square node represents the file node. The next level of each directory node further includes the child directory node or the child file node. For example, the next level of the configuration directory node 502 includes the system directory node 505, the text editing directory node 506, and the shell text file node 507.

[0081] In step 3002, each node in the multi-way tree structure is configured according to the configuration information, and the file data of the in-vehicle system is obtained.

[0082] According to the directory file structure and the configuration file of the vehicle-mounted system, a detection data tree management structure is generated. The detection data tree management structure is a multi-way tree structure for storing file data of the vehicle-mounted system. According to the configuration information in the configuration file, file nodes or directory nodes that need to be detected, partially detected or not detected are set in the detection data tree management structure. When each directory node in the detection data tree management structure is scanned and detected, whether the child files or child directories under the directory node are added or deleted is detected.

[0083] For example, continuing to refer to Figure 5 In the detection data tree management structure, the types of nodes include nodes that need to be detected, nodes that need to be partially detected and nodes that do not need to be detected. The nodes that need to be detected indicate that all files and directories under the node need to be detected. The nodes that need to be partially detected indicate that only the nodes existing in the tree management structure need to be detected, and the next level of files and directories do not need to be detected. The nodes that do not need to be detected indicate that the files or directories do not need to be detected. For example, the configuration directory node 502, the system directory node 505 and the text editing directory node 506 are nodes that need to be detected, and the shell text file node 507 is a node that does not need to be detected.

[0084] In some embodiments, the file data of the vehicle-mounted system can be obtained by the server from a local vehicle-mounted terminal, or obtained by the server from a cloud database, or obtained by the server by calling an external database interface of the vehicle-mounted system.

[0085] In the embodiments of the present application, based on the directory file structure and the configuration information of the vehicle-mounted system, a multi-way tree structure for storing file data of the vehicle-mounted system is generated, and each node in the multi-way tree structure is configured with detection requirements, so as to facilitate management and detection of the file data of the vehicle-mounted system.

[0086] For example, continuing to refer to Figure 3A In step 302, for each node of the multi-way tree structure, the following processing is performed: if the node in the file data meets the to-be-detected condition, the node state of the node is marked as a to-be-detected state.

[0087] For example, the file data is stored in multiple nodes of the multi-way tree structure, and whether the corresponding child files or directories on the node need to be detected is determined according to the to-be-detected condition. The node state of the node that needs to be detected is set as a to-be-detected state.

[0088] In some embodiments, the to-be-detected condition includes a first condition, as shown in Figure 3C , Figure 3C FIG. 3 is a third flowchart of a file detection method according to an embodiment of the present application. Figure 3AThe step 302 shown can be implemented by Figure 3C Steps 3021A to 3022A of FIG. 2B, which are specifically explained as follows.

[0089] In step 3021A, if the node in the file data satisfies the first condition, the type of the node is acquired.

[0090] Here, the first condition includes that the data of the node in the file data is changed.

[0091] For example, a change message of the node data is received, and the type of the data change node is acquired through the multi-branch tree structure of the stored file data. The type of the node includes a directory node and a child file node.

[0092] For example, when the file or the directory corresponding to the data change node is not stored in the configuration file, or the detection state of the file or the directory has been marked as the to-be-detected state, the change message of the data change node does not need to be processed; when the file or the directory corresponding to the data change node is stored in the configuration file, the change message of the data change node needs to be processed, and the type of the data change node is acquired based on the multi-branch tree structure.

[0093] In step 3022A, if the node is a child file node or a directory node to be detected, the node state of the node is marked as the to-be-detected state.

[0094] For example, when the data change node is a child file node or a directory node that needs to be detected in whole or in part, the node state of the data change node is set as the to-be-detected state, and the to-be-detected state node is added to the detection task queue. For details, refer to Figure 6 , Figure 6 FIG. 6 is a schematic diagram of migration of a detection task state machine provided in an embodiment of the present application. In state 601, the file or the directory is set as the to-be-detected state, and the to-be-detected state indicates that the file or the directory can be detected.

[0095] In some embodiments, the to-be-detected condition includes a second condition, for details, refer to Figure 3G , Figure 3G FIG. 7 is a seventh flowchart of a file detection method provided in an embodiment of the present application. Figure 3A The step 302 shown can be implemented by Figure 3G Step 3021B of FIG. 2B, which is specifically explained as follows.

[0096] In step 3021B, if the node in the file data satisfies the second condition, the node state of the node is marked as the to-be-detected state.

[0097] Here, the second condition includes that the current time reaches the periodic detection time corresponding to the node, and the node is a child file node or a directory node to be detected.

[0098] For example, when a sub-file node or a directory node that needs to be detected reaches a periodic detection time, the node state of the corresponding node is set to a to-be-detected state.

[0099] In the embodiments of the present application, the file data of the vehicle-mounted system is stored in the nodes on the multi-branch tree structure, and the detection state of the nodes in the file data is set, and only the nodes in the to-be-detected state are detected, thereby solving the problem of repeated detection of files and saving computing resources.

[0100] With reference to the foregoing description Figure 3A In step 303, the node in the to-be-detected state is added to the tail of the detection queue.

[0101] Here, the detection queue includes a plurality of nodes in the to-be-detected state.

[0102] For example, the node in the to-be-detected state is a sub-file node or a directory node that needs to be detected, and the detection queue is a queue for detecting all nodes in the to-be-detected state. After determining the node in the to-be-detected state, the corresponding node is added to the tail of the detection queue and queued for detection.

[0103] In some embodiments, the to-be-detected condition includes a first condition and a second condition, and the detection queue includes a first detection queue and a second detection queue.

[0104] For example, the first condition is that the data of a node in the file data is changed, the second condition is that a to-be-detected sub-file node or a directory node reaches a corresponding periodic detection time, the first detection queue is a queue for real-time detection processing of the node in the to-be-detected state, and the second detection queue is a queue for timed detection processing of the node in the to-be-detected state. Figure 7 , Figure 7 FIG. 7 is a schematic diagram of a detection scheduling management structure provided by an embodiment of the present application. The detection scheduling management structure includes a plurality of detection queues, such as a real-time detection processing queue 701, a real-time detection processing queue 702, a real-time detection processing queue 703, and a timed detection processing queue 704.

[0105] In some embodiments, referring to Figure 3D , Figure 3D FIG. 8 is a fourth flowchart of a file detection method provided by an embodiment of the present application. Figure 3A The step 303 shown in FIG. 8 can be implemented by Figure 3D the steps 3031 to 3032 of FIG. 8, which are described in detail as follows.

[0106] In step 3031, when the node meets the first condition, the node in the to-be-detected state is added to the tail of the first detection queue.

[0107] Here, the first detection queue includes a plurality of sub-detection queues, each of the sub-detection queues has a priority order, and the nodes in each of the sub-detection queues in a to-be-detected state are detected in turn according to the priority order.

[0108] For example, when the node data in the file data is changed, the node in a to-be-detected state is determined through the multi-ary tree structure, and is added to the tail of the queue of the real-time detection processing and is queued for detection. If the node in a to-be-detected state is already in the queue of the real-time detection processing, it does not need to be added repeatedly.

[0109] For example, the priority order of the plurality of sub-detection queues in the first detection queue includes: detecting the nodes in a to-be-detected state in each of the sub-detection queues in turn according to the priority of the plurality of sub-detection queues in the detection scheduling management structure. Continue to refer to Figure 7 When the nodes in a to-be-detected state in the sub-detection queue 701 are all detected, the nodes in a to-be-detected state in the sub-detection queue 702 can be detected; and when the nodes in a to-be-detected state in the sub-detection queue 702 are all detected, the nodes in a to-be-detected state in the sub-detection queue 703 can be detected.

[0110] For example, in the sub-detection queues of the same level in the first detection queue, the nodes in a to-be-detected state are detected in turn from the head of each sub-detection queue.

[0111] For example, the priority order of the sub-file nodes or directory nodes in the sub-detection queue can be determined according to the frequency of use, the length of use, etc. of the user, or the priority order of the sub-file nodes or directory nodes can be determined according to the importance and type of the system file. For example: the priority of the startup file of the system and the core service is the highest, the priority of the system configuration file is the second, and the priority of the log file and the text file is the lowest. If the detection priority of a certain directory node is high, the files or sub-directories under the directory node are added to the sub-detection queue with high priority.

[0112] For example, when scanning and detecting the directory nodes in the detection data tree management structure, if there is a newly added sub-directory node under a certain directory node, the newly added sub-directory node is added to the detection data tree management structure, and the original sub-directory node and the newly added sub-directory node under the directory node are both added to the tail of the detection task queue with the highest priority and are queued for detection. Continue to refer to Figure 5 When the configuration directory node 502 is scanned and detected, in response to the existence of the newly added system directory node 505, the system directory node 505 is added to the detection data tree management structure, and the configuration directory node 502, the text editing directory node 506, and the shell text file node 507 are added to the tail of the detection task queue with the highest priority in the detection scheduling management structure and are queued for detection.

[0113] In step 3032, in the case where the node meets the second condition, the node in the to-be-detected state is added to the tail of the second detection queue.

[0114] Here, each node in the to-be-detected state in the second detection queue has a time sequence, each node in the to-be-detected state in the second detection queue is detected in turn according to the time sequence, and the time sequence is pre-configured for each node in the to-be-detected state. There is no order between step 3032 and step 3031, and when the node meets the corresponding condition, the corresponding step is executed.

[0115] For example, through the multi-way tree structure, the node in the to-be-detected state is determined, and the node reaching the periodic detection time is obtained from the node in the to-be-detected state, and the node reaching the periodic detection time is added to the tail of the queue of the timing detection processing and queued for detection. If the node reaching the periodic detection time is already in the queue of the timing detection processing, it does not need to be added repeatedly. Referring to Figure 7 , the queue 704 of the timing detection processing includes the configuration directory node, the text editing node, the system directory node, and the binary node, and each node in the to-be-detected state is queued for detection in the order of the periodic detection time.

[0116] For example, the second detection queue is periodically triggered, and the detection time sequence of each node in the to-be-detected state is pre-set, and the detection time sequence of each node in the to-be-detected state can be the same or different. In the second detection queue, each node in the to-be-detected state is detected in turn according to the time sequence. The second detection queue includes a sub-file node or a directory node reaching the periodic detection time, and when the second detection queue executes the corresponding node detection task, the timing detection processing of the corresponding node is triggered.

[0117] For example, the detection scheduling management structure is initialized to generate the first detection queue and the second detection queue. The first detection queue includes the queue heads of a plurality of sub-detection queues, and the second detection queue includes the queue head of the timing detection processing. According to the priority order of the plurality of detection queues, the node in the to-be-detected state is added to each detection queue. For the node in the first detection queue that has completed detection, it can be deleted from the first detection queue. For the node in the second detection queue that has completed detection, the node that has completed detection can be re-added to the second detection queue for detection at the next periodic detection time.

[0118] For example, the first detection queue and the second detection queue manage the nodes in the to-be-detected state through a double-linked list, and the detection data tree management structure and the detection queue with the double-linked list are fused together. Each node in the detection data tree management structure carries a double-linked list pointer, and the detection data tree management structure is as shown in Figure 8 ,Figure 8 is a total structure schematic diagram provided by the embodiment of the application. Figure 8 comprises Figure 5 a detection data tree management structure and Figure 7 a multi-priority detection task queue, which combines the detection data tree management structure 520 and the multi-detection queue 720, and the bidirectional arrow in the figure is a bidirectional linked list structure, in which a preceding node and a following node can be found, and by dynamically adjusting the bidirectional linked list pointers of each node, a sub-file node or a directory node can be added to the corresponding detection queue.

[0119] For example, the key-value pair data of each node is stored in the detection data tree management structure (i.e., a multi-way tree structure), and when a directory node is detected, all sub-directory nodes and sub-file nodes under the directory node can be detected, and the existence of node changes under the directory node can be detected.

[0120] In the embodiment of the application, by using the multi-way tree structure for storing the on-board file data, a queue for real-time detection processing and a queue for timing detection processing are established, and a combination of real-time detection and timing detection is adopted to realize integrity detection on the file data nodes.

[0121] With reference to Figure 3A , in step 304, according to the detection order in the detection queue, detection threads are called to detect each node in a detection state in turn to obtain a detection result.

[0122] For example, the detection queue has a detection order, which is an order of detecting nodes in a detection state in turn according to a preset priority detection rule. A thread is a basic unit of computer program running, which is responsible for executing instructions in the program and realizes concurrent execution of multiple threads through scheduling of an operating system. Detection threads can be used to detect each node in a detection state.

[0123] Referring to Figure 3E , Figure 3E is a fifth flowchart of a file detection method provided by the embodiment of the application. Figure 3A The step 304 shown in the figure can be implemented by steps 3041A to 3044A of the step 304 of Figure 3E , which are described in detail as follows.

[0124] In step 3041A, according to the detection order in the detection queue, detection threads are called to traverse each node in a detection state in the detection queue in turn.

[0125] For example, according to the detection sequence of the first detection queue and the second detection queue, the idle thread resource in the thread pool is taken as a detection thread, a corresponding detection thread is invoked, and the nodes in the multiple detection queues in the to-be-detected state are sequentially traversed and detected. The thread pool is used for managing the pre-allocated detection thread resources, and a conventional dynamic adjustment method can be used to add or delete the allocated detection thread resources, or a fixed allocation detection thread resource method can be used.

[0126] In step 3042A, when the node in the to-be-detected state traversed is a directory node, the detection thread is invoked to recursively detect the subdirectory nodes and each subfile node associated with the target node.

[0127] Here, the subdirectory node is a lower-level node of the directory node.

[0128] For example, the directory node currently traversed is taken as a target node to be detected, a detection thread is obtained from the thread pool, the detection thread is invoked to perform directory scanning detection on the target node, and the subdirectory nodes and subfile nodes associated with the target node are recursively detected.

[0129] For example, the second detection queue can recursively detect from the root node of the multi-ary tree, and scan and detect all directory nodes under the root node, or can be adjusted to start detection from an arbitrary directory node. Starting from the root node, all subfile nodes or directory nodes are detected, which can be used to perform periodic detection processing on important files such as system execution files and configuration files. For example, the second detection queue can recursively detect from the root node of the multi-ary tree, and scan and detect all directory nodes under the root node, or can be adjusted to start detection from an arbitrary directory node. Starting from the root node, all subfile nodes or directory nodes are detected, which can be used to perform periodic detection processing on important files such as system execution files and configuration files. Figure 6 In state 602, the file or directory is set to the detection-in-progress state, and the file or directory is detected.

[0130] In step 3043A, when the second association relationship between the target node and the subdirectory node is different from the first association relationship, it is determined that the detection result of the subdirectory node is that there is data change.

[0131] Here, the first association relationship is the association relationship between the target node and the subdirectory node in the multi-ary tree structure, and the second association relationship is the association relationship between the target node and the subdirectory node detected.

[0132] For example, the association relationship refers to the superior-inferior relationship between the upper-level directory and the subdirectory included in the directory. The target node is the directory node currently performing directory scanning detection, and the multi-ary tree structure is a detection data tree management structure. The original association relationship between the target node and the subdirectory node in the multi-ary tree structure is taken as the first association relationship, and the actual detected association relationship between the target node and the subdirectory node is taken as the second association relationship. When the second association relationship is different from the first association relationship, it is determined that the subdirectory node associated with the target node has data change.

[0133] In step 3044A, when the second hash value of the sub-file node is different from the first hash value, it is determined that the detection result of the sub-file node is that there is data change.

[0134] Here, the first hash value is the original hash value of the sub-file node stored in the multi-ary tree structure, and the second hash value is the hash value of the sub-file node detected.

[0135] For example, the hash value of the file node is a set of binary values obtained by performing an encryption operation on the file content. Since it is calculated according to the size, time, type and other information of the file, the hash value of each file node is different even if the contents of each file are the same.

[0136] For example, the multi-ary tree structure is a detection data tree management structure, and the original hash value of the sub-file node associated with the target node stored in the multi-ary tree structure is the first hash value. When performing directory scanning detection on the target node, the hash value of the sub-file node associated with the target node actually detected is taken as the second hash value. When the second hash value is different from the first hash value, it is determined that there is data change in the sub-file node associated with the target node.

[0137] Referring to Figure 3F , Figure 3F is a sixth flowchart of a file detection method provided by an embodiment of the present application. Figure 3A The step 304 shown can also be implemented by the steps 3041B to 3043B of the step 304 of the method 3000, which will be described in detail below. Figure 3F

[0138] In step 3041B, according to the detection order in the detection queue, the detection thread is called to traverse each node in the detection queue in the detection order.

[0139] For example, for the specific implementation of the detection thread traversing the detection node, please refer to the description of step 3041A above, which will not be repeated here.

[0140] In step 3042B, when the node in the detection state to be traversed is a sub-file node, the detection thread detects the second hash value of the sub-file node.

[0141] For example, the detection thread performs file detection on the sub-file node, and the hash value of the sub-file node actually detected is taken as the second hash value.

[0142] In step 3043B, when the second hash value of the sub-file node is different from the first hash value, it is determined that the detection result of the sub-file node is that there is data change.

[0143] Here, the first hash value is the original hash value of the sub-file node stored in the multi-ary tree structure.​

[0144] In an example, the original hash value of the sub-file node stored in the multi-way tree structure is taken as the first hash value. A detection thread is obtained from the thread pool, and the detection thread is called to perform file detection on the sub-file node. The second hash value of the sub-file node is detected. When the second hash value is different from the first hash value, it is determined that the sub-file node has data change.

[0145] In the embodiments of the present application, the nodes in the to-be-detected state are added to the tail of the detection queue, and the detection threads are called to detect each node in the to-be-detected state in turn according to the detection order in the detection queue, so that the detection resources are reasonably allocated, and the detection efficiency of the file is improved.

[0146] With reference to Figure 3A In step 305, in the case where the detection result is data change, the multi-way tree structure is updated based on the detection result.

[0147] In an example, the detection result of each node in the to-be-detected state is determined, and when the detection result is that the node data has changed, the corresponding node data in the multi-way tree structure is updated.

[0148] In some embodiments, in the case where the detection result is data change, and the node in the to-be-detected state corresponding to the detection result is a sub-file node, the hash value of the sub-file node in the multi-way tree structure is replaced with the detected second hash value, and the node state of the sub-file node is marked as the detection completion state.

[0149] In an example, when the detection result of the sub-file node has data change, the original hash value of the sub-file node stored in the multi-way tree structure is replaced with the detected second hash value, the data of the sub-file node in the multi-way tree structure is updated, and the detection state of the sub-file node in the multi-way tree structure is marked as the detection completion state.

[0150] In some embodiments, in the case where the detection result is data change, and the node in the to-be-detected state corresponding to the detection result is a directory node, the data of the directory node in the multi-way tree structure is updated according to the lower-level nodes of the detected directory node, and the node state of the directory node is marked as the detection completion state.

[0151] Here, the types of the lower-level nodes of the directory node include sub-directory nodes and sub-file nodes.

[0152] For example, when the detection result of the directory node exists data change, the original data of the directory node stored in the multi-way tree structure is replaced by the actual data of the detected directory node, that is, the next level node data of the directory node is added or deleted, the data of the next level node of the directory node in the multi-way tree structure is updated, and the detection state of the directory node is marked as a detection completion state. The original subdirectory node and the subfile node under the directory node are added to the detection queue, and the next level directory and file are recursively detected.

[0153] For example, continuing to refer to Figure 6 In state 603, the file or directory is set to a detection completion state, and the detection of the file or directory ends. If the file or directory needs to be re-detected, the detection process is restarted, and the detection state of the file or directory is set again.

[0154] For example, the file or directory has a separate detection state, and each file fragment also has a separate detection state to mark the current detection state. In a file, one file fragment completes detection, and another file fragment does not complete detection, and the file is marked as an incomplete detection state. When all file fragments of a file complete detection, the file is marked as a detection completion state.

[0155] In the embodiment of the application, based on the directory file structure and configuration information of the vehicle-mounted system, a multi-way tree structure for storing vehicle-mounted file data is generated, and the detection requirement of each node in the multi-way tree structure is configured, so as to facilitate management and detection of vehicle-mounted file data; the file data of the vehicle-mounted system is stored through the nodes on the multi-way tree structure, and the detection state of the nodes in the file data is set, and only the nodes in a to-be-detected state are detected, thereby solving the problem of repeated detection of files and saving computing resources; the nodes in the to-be-detected state are added to the tail of the detection queue, the detection threads are called according to the detection order in the detection queue to detect each node in the to-be-detected state in turn, thereby realizing reasonable allocation of detection resources and improving the detection efficiency of files; through the multi-way tree structure for storing vehicle-mounted file data, a real-time detection processing queue and a timing detection processing queue are established, a real-time detection and timing detection combined mode is adopted, and complete integrity detection of file data nodes is realized; the multi-way tree structure is updated according to the detection result, the file or subdirectory under the directory can be updated and modified in time, and the reliability of file integrity detection is improved.

[0156] Next, an example application of the file detection method provided by the embodiment of the application in an actual vehicle-mounted file integrity detection application scenario will be described.

[0157] With the development of intelligence and networking, the vehicle-mounted system may be attacked at any time, such as uploading a Trojan horse, deleting important files, modifying important configuration files, and the like. How to comprehensively detect the integrity of files becomes a necessary condition.

[0158] In the related art, the file integrity detection method is based on the real-time file detection scheme of the Linux inotify command line framework of the Linux operating system and the Linux auditd audit component of the Linux operating system. The file operation monitor is used to monitor files and directories in real time, to determine the modified files in real time, and to achieve the purpose of real-time detection of file integrity. Alternatively, the file is divided into multiple segments, and each segment file is read in parallel to calculate the cyclic redundancy check code of the read segment file. According to the cyclic redundancy check code of each segment file calculated, it is checked whether the file is complete. Since the vehicle-mounted system has limited resources, when checking multiple segments of a large file in parallel, most of the detection resources will be occupied, and other file integrity cannot be detected in time. Moreover, the detection time of a large file is too long, which will cause some file modification messages to be ignored, and in the face of massive file change attack behavior, the change message of the modified key file cannot be found in time.

[0159] Currently, in the process of detecting the file integrity of the vehicle-mounted system, the following problems exist:

[0160] The existing file integrity detection system only considers using technical means to collect file change messages in real time, but does not consider that in the case of a massive attack, the file integrity system is not sufficient to process all real-time detection file modification messages, and finally some file change messages are ignored, resulting in that some file modifications are not detected.

[0161] Embodiments of the present application propose a file detection method to solve the problems existing in the prior art, which includes the following improvements compared with the prior art:

[0162] (1) By scheduling the execution of the active timing monitoring task and the real-time monitoring task through the scheduling management structure, the combination of active timing monitoring and real-time monitoring is realized, which can solve the problem of detecting all modified files in the case of massive file changes.

[0163] (2) The file nodes in the multi-ary tree structure are managed, and a multi-priority file detection queue is established based on the multi-ary tree structure. The file nodes in the multi-ary tree structure can be added to the detection queues of different priorities according to the priority rules, to ensure high-priority file detection and improve the reliability of the overall file detection.

[0164] Reference Figure 4 , Figure 4 is a schematic diagram of the vehicle-mounted file integrity detection architecture provided by the embodiments of the present application. In the following, the server 200 in Figure 1 is taken as the execution subject, and the file detection method provided by the embodiments of the present application is explained in combination with the steps of Figure 4 .

[0165] Figure 4 The file integrity detection architecture shown in the figure comprises a real-time monitoring module 401, a detection data management structure module 402, a real-time integrity detection module 403, a thread pool module 404, a scheduling controller module 405, and a detection scheduling management structure module 406.

[0166] The real-time monitoring module 401 is configured to listen to and report change information of files, and can use existing technologies such as a Linux operating system command line framework Linux inotify or a Linux operating system audit component Linux auditd.

[0167] The detection data management structure module 402 is configured to generate a detection data tree management structure (file data stored in a multi-way tree structure in the foregoing) according to a directory file structure and a configuration file of the system. The directory file structure itself is a multi-way tree structure.

[0168] For example, the detection data tree management structure comprises files or directories that need to be detected in whole, files or directories that need to be detected in part, and files or directories that do not need to be detected. Whether each file or directory needs to be detected is determined by a configuration file. The files and directories related to system integrity detection are managed in the form of a multi-way tree structure. When a directory is scanned and verified, whether the file or the directory is added or deleted is verified.

[0169] For example, refer to Figure 5 , Figure 5 FIG. 1 is a schematic diagram of a detection data tree management structure provided by an embodiment of the present application. In the detection data tree management structure, a circular node represents a directory, and a square node represents a file.

[0170] The types of nodes comprise nodes that need to be detected in whole, nodes that need to be detected in part, and nodes that do not need to be detected. The nodes that need to be detected in whole indicate that all files and directories under the node need to be detected. The nodes that need to be detected in part indicate that only the nodes existing in the tree management structure need to be detected, and the next level of files and directories do not need to be detected. The nodes that do not need to be detected indicate files or directories that do not need to be detected.

[0171] For example, the node 501 is a root directory node. The root directory is located at the top of the Linux file system and contains all other directories and files.

[0172] For example, the node 502 is a configuration directory etc node, the configuration directory is an important directory in Linux system, generally used to store the configuration files required by the entire file system of the program. The node 503 is a temporary directory tmp node, the temporary directory is used to store temporary files. The node 504 is a user directory usr node, the user directory contains user-installed application programs and files. The configuration directory node 502, the temporary directory node 503 and the user directory node 504 are located at the next level of the root directory node 501.

[0173] For example, the node 505 is a system directory systemd node, the node 506 is a text editing vim directory node, and the node 507 is a shell text file node. The shell text is a file recording the shell version supported by the Linux system, and the shell script is a text file used by a computer program, which consists of a series of shell commands. The system directory node 505, the text editing directory node 505 and the shell text file node 507 are located at the next level of the configuration directory node 502.

[0174] For example, the node 508 is a system file directory system node, and the node 509 is a system configuration file system.conf node. The system file directory node 508 and the system configuration file node 509 are located at the next level of the system directory node 505.

[0175] For example, the node 510 is a system log service syslog.service file node, the system log service file is a configuration file corresponding to the system log or system record service. The node 511 is an open shell text sshd.service file node, and the node 512 is a display service display.service file node. The system log service file node 510, the open shell text file node 511 and the display service file node 512 are located at the next level of the system file directory node 508.

[0176] For example, the node 513 is a text editing configuration vimrc file node, and the text editing configuration file is a file used to configure the vim editor. The text editing configuration file node 513 is located at the next level of the text editing directory node 506.

[0177] For example, the node 514 is a binary bin directory node, the binary directory is a directory containing executable binary files, and the binary directory node 514 is located at the next level of the user directory node 504.

[0178] For example, the node 515 is a search system command which file node, the node 516 is a display directory file ls file node, and the node 517 is a text editing vim file node. The search system command file node 515, the display directory file file node 516, and the text editing file node 517 are located at the next level of the binary directory node 514.

[0179] With reference to the foregoing Figure 4 , the real-time integrity detection module 403 is configured to process the file change information reported from the real-time monitoring module 401, and the processing process is described below.

[0180] For example, according to the detection data tree management structure, it is determined whether the reported file change information needs to be processed. The case in which the file change information does not need to be processed includes the following:

[0181] Case 1, non-detection file or directory. For example, the file or directory corresponding to the file change information is not stored in the configuration file, and the file change information does not need to be processed.

[0182] Case 2, the file or directory has been marked as a to-be-detected state. For example, the file or directory corresponding to the file change information is stored in the configuration file, and the detection state of the file or directory has been marked as a to-be-detected state, and the file change information does not need to be processed.

[0183] For the file change information that needs to be processed, a detection task queue is formed according to the configuration file in which the changed file and directory are stored. If the to-be-detected file and directory are already in the detection task queue, they do not need to be repeatedly added.

[0184] For example, if the file change information needs to be processed, the file or directory corresponding to the file change information is set to a to-be-detected state. In order to facilitate understanding of different states of a node (file or directory), the following is described in conjunction with the accompanying drawings. Referring to Figure 6 , Figure 6 is a detection task state machine migration schematic diagram provided by an embodiment of the present application.

[0185] In state 601, the file or directory is set to a to-be-detected state, and detection of the file or directory is started.

[0186] For example, according to the priority detection task queue rule, the file or directory is added to the tail of the corresponding priority detection task queue linked list, and is queued for detection.

[0187] In state 602, the file or directory is set to a detection-in-progress state, and detection of the file or directory is performed.

[0188] For example, the file or directory has a separate detection state, and each piece of the file has a separate detection state, which is used to mark the current detection state. In a file, one piece of the file has completed detection, and another piece of the file has not completed detection. The file is marked as a state of not completing detection. When all pieces of the file have completed detection, the file has completed detection.

[0189] In the state 603, the file or directory is set to a detection completion state, and the detection of the file or directory is ended.

[0190] For example, if the file or directory needs to be re-detected, the detection is restarted, and the detection state of the file or directory is set again.

[0191] With reference to Figure 4 , the thread pool module 404 is used to manage the pre-allocated detection thread resources.

[0192] For example, when the detection scheduling task is executed, the detection thread resources are obtained from the thread pool, and the corresponding thread resources are called based on the file or directory to be detected to perform detection. The allocated detection thread resources can be added or deleted by using a conventional dynamic adjustment method, or can be simplified to use a fixed allocation detection thread resource method.

[0193] With reference to Figure 4 , the scheduling controller module 405 is used to schedule and allocate the detection tasks in the detection scheduling management structure module 406. The function of the scheduling controller module 405 is explained in detail below.

[0194] For example, the scheduling controller module 405 obtains the timing detection task that reaches the preset execution task time from the detection scheduling management structure module 406. The timing detection task is added to the detection task queue, and when the corresponding timing detection task is executed in the detection task queue, the timing detection task is triggered.

[0195] For example, the scheduling controller module 405 obtains the timing detection task from the detection scheduling management structure module 406, and assigns the file detection 407 and the directory scanning detection 408 in the timing detection task to the thread pool module 404 to call the idle detection thread resources to detect the file or directory.

[0196] For example, the file detection 407 includes: detecting whether the file content is modified by calculating the MD5 hash value of the file content, and comparing the calculated MD5 hash value with the MD5 hash value of the original file. If the hash values are inconsistent, it is determined that the file content is modified.

[0197] For example, the directory scanning detection 408 includes detecting whether there is addition or deletion of files and subdirectories under the directory. If it is detected that there is addition or deletion, the directory change content is synchronized to the detection data tree management structure, and the original files and subdirectories under the directory are added to the detection scheduling management structure module 406 to recursively detect the next level of files and subdirectories.

[0198] For example, the scheduling controller module 405 is configured to limit the execution rate of the detection task, and when the execution rate of the detection task exceeds a preset threshold, the detection task is suspended to release the server resources.

[0199] With reference to the foregoing Figure 4 , the detection scheduling management structure module 406 is configured to manage the detection task scheduling list through a multi-priority detection task bidirectional linked list.

[0200] For example, with reference to the foregoing Figure 7 , Figure 7 is a detection scheduling management structure diagram provided by the embodiment of the present application. The detection scheduling management structure includes a detection task queue 701, a detection task queue 702, a detection task queue 703, a timing detection task queue 704, and a plurality of detection task queues.

[0201] For example, according to the detection scheduling priority rule, the plurality of detection task queues are sequentially called to detect the files or directories. The detection scheduling priority rule includes:

[0202] Rule 1: According to the priority of the detection task queue in the detection scheduling management structure, the detection tasks in the detection task queue are executed in sequence.

[0203] For example, it is assumed that there are a detection task queue 1, a detection task queue 2 and a detection task queue 3 in the detection scheduling management structure, the detection task queue 1 is set as the highest priority detection queue, the priority of the detection task queue 2 is the second, and the detection task queue 3 is the lowest priority detection queue. The tasks in the detection task queue 1 are all scheduled and executed, and then the tasks in the detection task queue 2 are executed. The tasks in the detection task queue 2 are all executed, and then the tasks in the detection task queue 3 are executed. For example, after all the detection tasks in the detection task queue 701 are executed, the detection tasks in the detection task queue 702 are executed. After all the detection tasks in the detection task queue 702 are executed, the detection tasks in the detection task queue 703 are executed.

[0204] Rule 2: In the detection task queue at the same level, the detection task is executed from the head of the queue.

[0205] Rule 3, arrange the detection tasks in the timing queue according to the preset detection time in the order of detection tasks. The timing queue is triggered periodically, and the preset detection time of each detection task in the timing queue can be the same or different. For example, the timing queue 704 includes a configuration directory detection task, a text editing detection task, a system directory detection task, and a binary detection task, and each detection task is queued and detected in the order of preset detection time.

[0206] Rule 4, when scanning the directory node in the detection data tree management structure, if there is a newly added subdirectory node under the directory node, the newly added subdirectory node is added to the detection data tree management structure, and the original subdirectory node and the newly added subdirectory node under the directory node are added to the tail of the highest priority detection task queue for queuing and detection.

[0207] For example, continuing to refer to Figure 5 , the next level of the configuration directory node 502 in the detection data tree management structure is the text editing directory node 506 and the shell text file node 507. When scanning the configuration directory node 502, in response to the existence of the newly added system directory node 505, the system directory node 505 is added to the detection data tree management structure, and the configuration directory node 502, the text editing directory node 506, and the shell text file node 507 are added to the tail of the highest priority detection task queue in the detection scheduling management structure for detection.

[0208] For example, the detection data tree management structure is a multi-ary tree, and multiple multi-ary trees can be created according to actual detection needs, and the number of multi-ary trees is not limited. The detection scheduling management structure is initialized to generate a multi-priority detection task queue, which includes the head of n-level queue and the head of timing queue, n is a positive integer, and files or directories are added to the detection task queue according to the priority rule, and the files or directories that have been detected are deleted from the queue.

[0209] For example, the priority of the files or directories in the queue can be determined according to the user's usage frequency, usage time, etc., or the detection priority can be determined according to the importance and type of system files, such as: the startup file of the system has the highest priority, the execution file is very important and cannot be easily rewritten or replaced by the virus; the system configuration file cannot be rewritten, otherwise it may cause the system service to be abnormal, the priority is second; the priority of the log file and the text file is the lowest.

[0210] In the embodiments of the present application, the timing queue is only connected to the root node of the multi-ary tree as an example, and in specific implementation, the timing queue can be connected to other nodes according to the application scenario.

[0211] For example, the scheduled queue can recursively scan all directory nodes below the root node of a multitree, or it can be adjusted to start from any directory node. If a directory node has a high detection priority, the files or subdirectories under that directory node are added to the high-priority detection queue. Starting detection from the root node means that all files or directories will be checked. It can also be used to schedule detection of important files such as system executable files and configuration files.

[0212] Example, reference Figure 8 , Figure 8 It is a schematic diagram of the overall structure provided in the embodiment of this application. Figure 8 Included Figure 5 The tree management structure of detection data and Figure 7 The multi-priority detection task queue integrates the detection data tree management structure 520 and the multiple detection queues 720. Each node in the detection data tree management structure carries a doubly linked list pointer. The double-headed arrow in the figure represents a doubly linked list structure, where elements can find their predecessor and successor nodes. By dynamically adjusting the node's linked list pointer, files or directories can be added to detection task queues of different priorities or scheduled detection task queues.

[0213] For example, the detection data tree management structure can store the key-value pair data of the node. When detecting a directory node, all subdirectories and files under the directory node will be detected to ensure that file additions and deletions can be detected.

[0214] For example, the above describes the file integrity detection architecture and the functions of each module provided by the embodiment of the present application. The following is a detailed description of the detailed process of file detection processing in real-time monitoring mode. Figure 9 , Figure 9 This is a schematic diagram of the file detection processing flow in the real-time monitoring mode provided by an embodiment of the present application.

[0215] In step 901, the real-time monitoring module 401 is started to start monitoring file change messages.

[0216] In step 902 , the real-time monitoring module 401 receives a file change message.

[0217] In step 903, the real-time integrity detection module 403 is started to determine whether the file needs to be detected.

[0218] When it is confirmed that the file does not need to be detected, the process proceeds to step 904 to end the file detection; when it is confirmed that the file needs to be detected, the process proceeds to step 905 to start the detection data management structure module 402, update the detection data management structure, and set the file node status to be detected.

[0219] In step 906, the real-time integrity detection module 403 adds the node to the detection scheduling management structure module 406.

[0220] In step 907, the scheduling controller module 405 is started to read the next scheduling task.

[0221] The scheduling controller module 405 reads the file or directory message in the detection task queue from the detection scheduling management structure module 406.

[0222] In step 908, the scheduling controller module 405 acquires the thread resource from the thread pool module 404.

[0223] The detection thread resource corresponding to the file or directory to be detected is acquired from the thread pool module 404.

[0224] In step 909, the scheduling controller module 405 determines whether the scheduling task is a directory detection.

[0225] When the scheduling task is not a directory detection, go to step 910 to re-add the node to the detection scheduling management structure module 406 (the node has excess shards), or go to step 911 to confirm that the scheduling task is a file detection; when the scheduling task is a directory detection, go to step 912 to perform directory scanning detection, and go to step 920 to add the next level file or directory of the directory to the detection scheduling management structure module 406.

[0226] In step 913, the scheduling controller module 405 determines whether the file is to be detected.

[0227] When the file is to be detected, go to step 914 to add the file to be detected to the detection scheduling management structure module 406, and the detection data management structure module 402 updates the file detection state to detection in progress; when the file is not to be detected, go to step 919 to end the file detection.

[0228] In step 915, the scheduling controller module 405 determines whether the file MD5 is consistent.

[0229] The hash value of the content of the file to be detected is compared with the hash value of the original file content.

[0230] When the file MD5 is consistent, go to step 919 to end the file detection. Or go to step 916 to remove the node from the detection scheduling management structure module 406, and go to step 917 to update the file state to detection complete by the detection data management structure module 402; when the file MD5 is inconsistent, go to step 918 to detect that the file detection is inconsistent, and go to step 919 to end the file detection.

[0231] In step 921, the scheduling controller module 405 judges whether the nodes under the directory are consistent with the detection data management structure.

[0232] When the comparison result is consistent, go to step 919, and end the file detection; when the comparison result is inconsistent, go to step 922, the detection data management structure module 402 adds or deletes the nodes under the directory, and go to step 923, the scheduling controller module 405 detects that the directory detection is inconsistent, and go to step 919, and end the file detection.

[0233] For example, the detailed flow of the active timing monitoring is specifically described below. Referring to Figure 10 , Figure 10 FIG. 1 is a schematic diagram of a file detection processing flow in a timing monitoring mode provided by an embodiment of the present application.

[0234] In step 1001, the scheduling controller module 405 is started, and the scheduling task is started.

[0235] In step 1002, the scheduling controller module 405 detects that the Timer timing task is expired.

[0236] The nodes in the timing detection task queue that reach the preset detection time are polled.

[0237] In step 1003, the detection data management structure module 402 is started, the detection data management structure is updated, and the node state is set to be detected.

[0238] In step 1004, the scheduling controller module 405 adds the node into the detection scheduling management structure module 406.

[0239] The node in the detection state is added into the detection scheduling management structure, and the timing detection is triggered.

[0240] In step 1005, the scheduling controller module 405 reads the next scheduling task.

[0241] The detection message of the file or the directory in the timing detection task queue is read from the detection scheduling management structure module 406.

[0242] In step 1006, the scheduling controller module 405 re-adds the node into the Timer timing queue.

[0243] The file or the directory in the timing detection task queue that is detected is re-added into the timing queue, and the timing detection task is reset.

[0244] In step 1007, the scheduling controller module 405 acquires the thread resource.

[0245] The detection thread resource is obtained from the thread pool module 404, and the corresponding thread resource is called to detect the file or directory in the queue.

[0246] In step 1008, the scheduling controller module 405 determines whether the scheduling task is a directory detection.

[0247] When the scheduling task is not a directory detection, go to step 1009 to re-add the node to the detection scheduling management structure module 406 (the node has excess fragments), or go to step 1010 to confirm that the scheduling task is a file detection; when the scheduling task is a directory detection, go to step 1011 to perform a directory scanning detection, and go to step 1019 to add the next level file or directory of the directory to the detection scheduling management structure module 406.

[0248] In step 1012, the scheduling controller module 405 determines whether the file is to be detected.

[0249] When the file is to be detected, go to step 1013 to add the to-be-detected file to the detection scheduling management structure module 406, and the detection data management structure module 402 updates the file detection state to be in detection; when the file is not to be detected, go to step 1018 to end the file detection.

[0250] In step 1014, the scheduling controller module 405 determines whether the file fragment MD5 is consistent.

[0251] The hash values of the contents of each file fragment of the to-be-detected file and the hash value of the original file content are compared.

[0252] When the file fragment MD5 is consistent, go to step 1018 to end the file detection. Or go to step 1015 to remove the node from the detection scheduling management structure module 406, and go to step 1016 to update the file state to detection complete by the detection data management structure module 402; when the file fragment MD5 is inconsistent, go to step 1017 to detect that the file detection is inconsistent, and go to step 1018 to end the file detection.

[0253] In step 1020, the scheduling controller module 405 determines whether the nodes under the directory and the detection data management structure are consistent.

[0254] When the comparison result is consistent, go to step 1018 to end the file detection; when the comparison result is inconsistent, go to step 1021 to add or delete the nodes under the directory by the detection data management structure module 402, go to step 1022 to detect that the directory detection is inconsistent by the scheduling controller module 405, and go to step 1018 to end the file detection.

[0255] In the example, Figure 9 the file detection processing flow in the real-time monitoring mode andFigure 10 The scheduling controller module is used in the file detection processing flow in the timing monitoring mode of the application. The flow of reading the file or directory message in the detection task queue, obtaining the detection thread resource from the thread pool module, and detecting the file or directory is consistent. The main difference between real-time monitoring and active timing monitoring of changing files is that the way of adding the detection node to the detection scheduling management structure is different. Active timing monitoring is that when the detection task in the timing queue reaches the preset detection time, the detection task is added to the detection scheduling management structure by the scheduling controller module, thereby triggering a series of recursive detection and adding the detection task to the timing queue. Real-time monitoring is that the file change message is detected by the real-time monitoring module, and finally the detection task is added to the detection scheduling management structure by the real-time integrity detection module, thereby triggering further real-time detection.

[0256] In the application scenario of the vehicle-mounted file integrity detection described above, the unified scheduling of real-time monitoring and active timing monitoring is realized through the detection scheduling management structure. The problem that the file integrity system performance is insufficient to process all real-time detection file modification messages in the case of a massive file attack, and finally some file change messages in real-time monitoring are ignored, resulting in that some file modifications are not detected in real time, is solved. Through the data model of the multi-way tree structure management detection node and the multi-priority queue combination, the problem that the file or subdirectory under a certain directory in the file system is increased or decreased, and cannot be detected when modified, is solved. In the case of responding to the modification and update attack of a large file or a normal small file, the file integrity is protected, and the file that the attacker really wants to modify is found, which has a wide application market prospect.

[0257] The following continues to illustrate an example structure of the file detection device 455 implemented as a software module provided in an embodiment of the application. In some embodiments, as shown in FIG. 4, the software module stored in the file detection device 455 of the memory 450 can include: Figure 2 As shown in FIG. 4, the software module stored in the file detection device 455 of the memory 450 can include: a file acquisition module 4551 configured to acquire file data of a vehicle-mounted system, wherein the file data is stored in a multi-way tree structure, and the multi-way tree structure includes a plurality of nodes, and types of the nodes include directory nodes and sub-file nodes; for each node of the multi-way tree structure, the following processing is performed: in a case where the node in the file data satisfies a to-be-detected condition, marking a node state of the node as a to-be-detected state; a file detection module 4552 configured to add the node in the to-be-detected state to a tail of a detection queue, wherein the detection queue includes a plurality of nodes in the to-be-detected state; according to a detection order in the detection queue, calling a detection thread to sequentially detect each node in the to-be-detected state to obtain a detection result; and a result processing module 4553 configured to, in a case where the detection result is data change, updating the multi-way tree structure based on the detection result.

[0258] In some embodiments, the file obtaining module 4551 is configured to, before obtaining the file data of the vehicle-mounted system, obtain a directory file structure and configuration information of the vehicle-mounted system, wherein the configuration information comprises information of a to-be-detected sub-file and a directory, the type of the directory file structure is a multi-ary tree structure, each node of the multi-ary tree structure stores data of a corresponding sub-file or directory; and each node in the multi-ary tree structure is configured according to the configuration information, to obtain the file data of the vehicle-mounted system.

[0259] In some embodiments, the to-be-detected condition comprises a first condition; and the file obtaining module 4551 is configured to, in a case where a node in the file data satisfies the first condition, obtain the type of the node, wherein the first condition comprises that data of the node in the file data is changed; and in a case where the node is a to-be-detected sub-file node or a to-be-detected directory node, mark a node state of the node as a to-be-detected state.

[0260] In some embodiments, the to-be-detected condition comprises a second condition; and the file obtaining module 4551 is configured to, in a case where a node in the file data satisfies the second condition, mark a node state of the node as a to-be-detected state, wherein the second condition comprises that a current time reaches a periodic detection time corresponding to the node, and the node is a to-be-detected sub-file node or a to-be-detected directory node.

[0261] In some embodiments, the to-be-detected condition comprises a first condition and a second condition, and the detection queue comprises a first detection queue and a second detection queue; and the file detection module 4552 is configured to, in a case where a node satisfies the first condition, add the node in the to-be-detected state to a tail of the first detection queue, wherein the first detection queue comprises a plurality of sub-detection queues, each of the sub-detection queues has a priority order, and nodes in the to-be-detected state in each of the sub-detection queues are detected in turn according to the priority order; and in a case where the node satisfies the second condition, add the node in the to-be-detected state to a tail of the second detection queue, wherein each of the nodes in the to-be-detected state in the second detection queue has a time sequence, each of the nodes in the to-be-detected state in the second detection queue is detected in turn according to the time sequence, and the time sequence is pre-configured for each of the nodes in the to-be-detected state.

[0262] In some embodiments, the file detection module 4552 is configured to, according to a detection order in the detection queue, call the detection thread to sequentially traverse each node of the to-be-detected state in the detection queue; when the traversed node of the to-be-detected state is a directory node, call the detection thread to recursively detect a child directory node associated with the target node and each child file node, where the child directory node is a lower-level node of the directory node; when a second association relationship between the target node and the child directory node is different from a first association relationship, determine that a detection result of the child directory node is that there is data change, where the first association relationship is an association relationship between the target node and the child directory node in the multi-ary tree structure, and the second association relationship is an association relationship between the target node and the child directory node obtained by detection; when a second hash value of the child file node is different from a first hash value, determine that a detection result of the child file node is that there is data change, where the first hash value is an original hash value of the child file node stored in the multi-ary tree structure, and the second hash value is a hash value of the child file node obtained by detection.

[0263] In some embodiments, the file detection module 4552 is configured to, according to a detection order in the detection queue, call the detection thread to sequentially traverse each node of the to-be-detected state in the detection queue; when the traversed node of the to-be-detected state is a child file node, call the detection thread to detect a second hash value of the child file node, where the second hash value is a hash value of the child file node obtained by detection; when the second hash value of the child file node is different from a first hash value, determine that a detection result of the child file node is that there is data change, where the first hash value is an original hash value of the child file node stored in the multi-ary tree structure.

[0264] In some embodiments, the result processing module 4553 is configured to, in a case where the detection result is data change and the node of the to-be-detected state corresponding to the detection result is a child file node, replace a hash value of the child file node in the multi-ary tree structure with the second hash value obtained by detection, and mark a node state of the child file node as a detection completion state; in a case where the detection result is data change and the node of the to-be-detected state corresponding to the detection result is a directory node, update data of the directory node in the multi-ary tree structure according to a lower-level node of the directory node obtained by detection, and mark a node state of the directory node as a detection completion state, where a type of the lower-level node of the directory node includes a child directory node and a child file node.

[0265] The embodiment of the present application provides a computer program product, which comprises computer executable instructions or computer programs stored in a computer readable storage medium. The processor of an electronic device reads the computer executable instructions or computer programs from the computer readable storage medium, and the processor executes the computer executable instructions or computer programs, so that the electronic device executes the file detection method provided by the embodiment of the present application.

[0266] The embodiment of the present application provides a computer readable storage medium storing computer executable instructions, wherein the computer executable instructions or computer programs are stored, and when the computer executable instructions or computer programs are executed by a processor, the processor executes the file detection method provided by the embodiment of the present application, for example, the file detection method shown in the embodiment of the present application. Figure 3A

[0267] In some embodiments, the computer readable storage medium can be RAM, ROM, flash memory, magnetic surface memory, optical disc, or CD-ROM memory, etc.; and can also be various devices including one or any combination of the above storage.

[0268] In some embodiments, the computer executable instructions can be in the form of programs, software, software modules, scripts or codes, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and can be deployed in any form, including being deployed as independent programs or being deployed as modules, components, subroutines or other units suitable for use in a computing environment.

[0269] As an example, the computer executable instructions can but not necessarily correspond to files in a file system, can be stored in part of a file storing other programs or data, for example, stored in one or more scripts in a Hyper Text Markup Language (HTML) document, stored in a single file dedicated to the program in question, or stored in multiple cooperative files (for example, files storing one or more modules, subroutines or code portions).

[0270] As an example, the computer executable instructions can be deployed to be executed on one electronic device, or executed on multiple electronic devices located in one place, or executed on multiple electronic devices distributed in multiple places and interconnected through a communication network.

[0271] ​In summary, the file data is stored as nodes on a multi-branched tree structure, and the detection state of the nodes is set, thereby solving the problem of repeated detection of large files and saving computing resources; by adding the nodes in the to-be-detected state to the tail of the detection queue, and according to the detection order in the detection queue, the detection thread is called to detect each node in the to-be-detected state in turn, thereby realizing reasonable allocation of detection resources and improving the detection efficiency of the file; and the multi-branched tree structure is updated according to the detection result, so that the files or subdirectories under the directory can be updated and modified in a timely manner, and the reliability of the file integrity detection is improved.

[0272] The above merely describes the embodiments of the present application, and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. within the spirit and scope of the present application shall be included in the protection scope of the present application.

Claims

1. A method of detecting a file, characterized by, The method comprises: acquiring file data of the vehicle-mounted system, wherein the file data is stored in a multi-way tree structure, the multi-way tree structure comprises a plurality of nodes, and types of the nodes comprise directory nodes and sub-file nodes; for each node of the multi-way tree structure, the following processing is performed: in a case where the node in the file data meets a to-be-detected condition, marking a node state of the node as a to-be-detected state; adding the node in the to-be-detected state to a tail of a detection queue, wherein the detection queue comprises a plurality of nodes in the to-be-detected state; according to a detection order in the detection queue, calling a detection thread to sequentially detect each node in the to-be-detected state to obtain a detection result; in a case where the detection result is data change, updating the multi-way tree structure based on the detection result.

2. The method of claim 1, wherein, Before the acquiring the file data of the vehicle-mounted system, the method further comprises: acquiring a directory file structure and configuration information of the vehicle-mounted system, wherein the configuration information comprises information of sub-files and directories to be detected, a type of the directory file structure is a multi-way tree structure, and each node of the multi-way tree structure stores data of a corresponding sub-file or directory; configuring each node of the multi-way tree structure according to the configuration information to obtain the file data of the vehicle-mounted system.

3. The method of claim 1, wherein, The to-be-detected condition comprises a first condition; The marking, in a case where the node in the file data meets a to-be-detected condition, a node state of the node as a to-be-detected state comprises: in a case where the node in the file data meets the first condition, acquiring a type of the node, wherein the first condition comprises that data of the node in the file data is changed; in a case where the node is a sub-file node or a directory node to be detected, marking the node state of the node as the to-be-detected state.

4. The method of claim 1, wherein, The to-be-detected condition comprises a second condition; The marking, in a case where the node in the file data meets a to-be-detected condition, a node state of the node as a to-be-detected state comprises: in a case where the node in the file data meets the second condition, marking the node state of the node as the to-be-detected state, wherein the second condition comprises that a current time reaches a periodic detection time corresponding to the node, and the node is a sub-file node or a directory node to be detected.

5. The method of claim 1, wherein, The to-be-detected condition comprises a first condition and a second condition, and the detection queue comprises a first detection queue and a second detection queue; and the adding, to a tail of a detection queue, of a node in the to-be-detected state comprises: in a case where the node meets the first condition, adding the node in the to-be-detected state to a tail of the first detection queue, wherein the first detection queue comprises a plurality of sub-detection queues, each sub-detection queue has a priority order, and the node in the to-be-detected state in each sub-detection queue is detected in sequence according to the priority order. add the node in the to-be-detected state to a tail of the second detection queue in a case where the node meets the second condition, wherein each node in the to-be-detected state in the second detection queue has a time sequence, each node in the to-be-detected state in the second detection queue is detected in turn according to the time sequence, and the time sequence is preconfigured for each node in the to-be-detected state.

6. The method of claim 1, wherein, The detection thread is called in turn to detect each node in the to-be-detected state according to a detection sequence in the detection queue, and a detection result is obtained, including: The detection thread is called in turn to traverse each node in the to-be-detected state in the detection queue according to a detection sequence in the detection queue; when the node in the to-be-detected state traversed is the directory node, the detection thread is called to recursively detect a target node associated sub-directory node and each sub-file node, wherein the sub-directory node is a lower node of the directory node; when a second association relationship between the target node and the sub-directory node is different from a first association relationship, it is determined that a detection result of the sub-directory node is that data is changed, wherein the first association relationship is an association relationship between the target node and the sub-directory node in the multi-ary tree structure, and the second association relationship is an association relationship between the target node and the sub-directory node obtained by detection; when a second hash value of the sub-file node is different from a first hash value, it is determined that a detection result of the sub-file node is that data is changed, wherein the first hash value is an original hash value of the sub-file node stored in the multi-ary tree structure, and the second hash value is a hash value of the sub-file node obtained by detection.

7. The method of claim 1, wherein, The detection thread is called in turn to detect each node in the to-be-detected state according to a detection sequence in the detection queue, and a detection result is obtained, including: The detection thread is called in turn to traverse each node in the to-be-detected state in the detection queue according to a detection sequence in the detection queue; when the node in the to-be-detected state traversed is the sub-file node, the detection thread is called to detect a second hash value of the sub-file node, wherein the second hash value is a hash value of the sub-file node obtained by detection; when the second hash value of the sub-file node is different from a first hash value, it is determined that a detection result of the sub-file node is that data is changed, wherein the first hash value is an original hash value of the sub-file node stored in the multi-ary tree structure.

8. The method of claim 1, wherein, In a case where the detection result is data change, the multi-ary tree structure is updated based on the detection result, including: in a case where the detection result is data change and the node in the to-be-detected state corresponding to the detection result is the sub-file node, a hash value of the sub-file node in the multi-ary tree structure is replaced with a second hash value obtained by detection, and a node state of the sub-file node is marked as a detection completion state; In a case where the detection result is data change, and the node of the to-be-detected state corresponding to the detection result is the directory node, data of the directory node in the multi-way tree structure is updated according to the detected lower-level node of the directory node, and the node state of the directory node is marked as a detection completion state, wherein the type of the lower-level node of the directory node includes a subdirectory node and a subfile node.

9. An apparatus for detecting a file, characterized by comprising: The apparatus comprises: a file acquisition module configured to acquire file data of a vehicle-mounted system, wherein the file data is stored in a multi-way tree structure, the multi-way tree structure comprises a plurality of nodes, and the type of the node comprises a directory node and a subfile node; for each node of the multi-way tree structure, the following processing is performed: in a case where the node in the file data satisfies a to-be-detected condition, the node state of the node is marked as a to-be-detected state; a file detection module configured to add the node in the to-be-detected state to the tail of a detection queue, wherein the detection queue comprises a plurality of nodes in the to-be-detected state; according to a detection order in the detection queue, a detection thread is called to detect each node in the to-be-detected state in sequence to obtain a detection result; a result processing module configured to, in a case where the detection result is data change, update the multi-way tree structure based on the detection result.

10. An electronic device, comprising: The electronic device comprises: a memory configured to store computer executable instructions or computer programs; a processor configured to execute the computer executable instructions or computer programs stored in the memory to implement the file detection method in any one of claims 1 to 8.

11. A computer readable storage medium storing computer-executable instructions or a computer program, characterized in that, The computer executable instructions or computer programs are executed by the processor to implement the file detection method in any one of claims 1 to 8.

12. A computer program product comprising computer-executable instructions or a computer program, characterized in that, The computer executable instructions or computer programs are executed by the processor to implement the file detection method in any one of claims 1 to 8. The computer executable instructions or computer programs are executed by the processor to implement the file detection method in any one of claims 1 to 8.