Process black and white list-oriented security detection method, device, equipment and medium

By collecting static attributes of executable files and learning global reputation, a multi-level process knowledge base is constructed. Combined with contextual profiling and real-time risk assessment, this solves the problem of insufficient identification of unknown threats in traditional process security management, and achieves high-precision process security detection and dynamic response.

CN122113120APending Publication Date: 2026-05-29NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NO 15 INST OF CHINA ELECTRONICS TECH GRP
Filing Date
2026-02-26
Publication Date
2026-05-29

Smart Images

  • Figure CN122113120A_ABST
    Figure CN122113120A_ABST
Patent Text Reader

Abstract

The present disclosure provides a process-oriented whitelist / blacklist security detection method, device, equipment and medium, comprising: collecting static attributes of all executable files from a terminal device; performing global reputation learning on the executable files to obtain global reputation features of the executable files; constructing a context portrait of the executable files; generating a multi-level process knowledge base according to the static attributes of the executable files, the global reputation features of the executable files, and the context portrait of the executable files; intercepting a target process when a creation request of the target process is detected, and obtaining process file information corresponding to the target process; creating a process context according to the process file information corresponding to the target process; intelligently matching the process context according to the multi-level process knowledge base to obtain a real-time risk value corresponding to the target process; and determining a security detection result of the target process according to the real-time risk value corresponding to the target process. Thus, the security detection accuracy of the process is effectively improved.
Need to check novelty before this filing date? Find Prior Art