Process black and white list-oriented security detection method, device, equipment and medium
By collecting static attributes of executable files and learning global reputation, a multi-level process knowledge base is constructed. Combined with contextual profiling and real-time risk assessment, this solves the problem of insufficient identification of unknown threats in traditional process security management, and achieves high-precision process security detection and dynamic response.
CN122113120APending Publication Date: 2026-05-29NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 0 Cites 0 Cited by
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NO 15 INST OF CHINA ELECTRONICS TECH GRP
- Filing Date
- 2026-02-26
- Publication Date
- 2026-05-29
Smart Images

Figure CN122113120A_ABST
Abstract
The present disclosure provides a process-oriented whitelist / blacklist security detection method, device, equipment and medium, comprising: collecting static attributes of all executable files from a terminal device; performing global reputation learning on the executable files to obtain global reputation features of the executable files; constructing a context portrait of the executable files; generating a multi-level process knowledge base according to the static attributes of the executable files, the global reputation features of the executable files, and the context portrait of the executable files; intercepting a target process when a creation request of the target process is detected, and obtaining process file information corresponding to the target process; creating a process context according to the process file information corresponding to the target process; intelligently matching the process context according to the multi-level process knowledge base to obtain a real-time risk value corresponding to the target process; and determining a security detection result of the target process according to the real-time risk value corresponding to the target process. Thus, the security detection accuracy of the process is effectively improved.
Need to check novelty before this filing date? Find Prior Art