Process chain analysis method and device

By analyzing the kill log uploaded by the antivirus software client in the cloud server, generating and counting feature value pairs, the problem of missing process chain information is solved, and the accurate completion of process chain and the improvement of malicious program detection is achieved.

CN112084495BActive Publication Date: 2025-05-16BEIJING QIHOOD TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201910516910.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-06-14
Publication Date
2025-05-16
Estimated Expiration
2039-06-14

AI Technical Summary

Technical Problem

In the prior art, the process chain information obtained by the antivirus software client is often missing and incomplete, resulting in the inability to accurately complete the process chain.

Method used

By receiving the kill logs uploaded by multiple clients, obtaining process feature values ​​at two adjacent moments, generating pairs of same-order eigenvalues ​​and predecessor eigenvalues, and counting the number of occurrences of each eigenvalue pair to determine the predecessor, same-order and post-order eigenvalues ​​of the target eigenvalues.

Benefits of technology

It can accurately determine the strongly associated processes of each process, thereby completing the process chain and improving the accuracy of malicious program detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112084495B_ABST
    Figure CN112084495B_ABST
Patent Text Reader

Abstract

The present invention discloses a process chain analysis method and device, which relates to the field of network security technology, and aims to determine the strongly associated process of each process. The method of the present invention comprises: receiving a killing log uploaded by a client; obtaining a plurality of first characteristic values ​​corresponding to the first moment and a plurality of second characteristic values ​​corresponding to the second moment in the killing log; generating a plurality of same-order characteristic value pairs and a plurality of preceding characteristic value pairs according to the plurality of first characteristic values ​​and the plurality of second characteristic values; determining the preceding characteristic value, the same-order characteristic value and the following characteristic value corresponding to the target characteristic value according to the same-order characteristic value pairs and the preceding characteristic value pairs containing the target characteristic value, and counting the number of occurrences of each preceding characteristic value, each same-order characteristic value and each following characteristic value; determining the target preceding characteristic value, the target same-order characteristic value and the target following characteristic value according to the number of occurrences of each preceding characteristic value, each same-order characteristic value and each following characteristic value. The present invention is applicable to the process of completing the process chain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a process chain analysis method and device. Background Art

[0002] With the increasing development of Internet technology, network security prevention issues are becoming more and more prominent. In order to ensure the network security of terminal devices, users generally use antivirus software clients to detect whether there are malicious programs in the terminal devices. However, in order to avoid detection by antivirus software clients, malicious programs usually use multiple sub-processes to jointly complete malicious behaviors. Therefore, the process chain corresponding to the application can more accurately detect whether the application is a malicious program. Among them, when detecting whether the application is a malicious program based on the process chain corresponding to the application, it is necessary to ensure the integrity of the process chain corresponding to the application. However, the process chain information obtained by the antivirus software client is often missing and incomplete. Therefore, how to accurately complete the process chain is crucial.

[0003] Currently, when the antivirus software client detects malicious programs on the terminal device, it will generate a detection log that records the characteristic value (MD5 value) corresponding to each process running in the terminal device and the running time of each process. Therefore, the staff usually completes the process chain based on the detection log.

[0004] In the process of implementing the present invention, the inventors found that the following technical problems exist in the prior art: the killing log usually records the characteristic values ​​corresponding to each process running successively in seconds. However, seconds are too long for a process, that is, a terminal device can run multiple processes successively within 1 second. Therefore, there will be a situation where the characteristic values ​​of multiple processes correspond to the same running time; for the staff, they cannot accurately distinguish the running order of multiple processes with the same running time, and thus cannot accurately determine the parent process and child process of each process, which leads to the inability to accurately complete the process chain based on the killing log. Summary of the invention

[0005] In view of this, the present invention provides a process chain analysis method and device, the main purpose of which is to determine the strongly associated processes of each process, so as to provide data support for staff to complete the process chain.

[0006] In order to solve the above problems, the present invention mainly provides the following technical solutions:

[0007] In a first aspect, the present invention provides a process chain analysis method, the method comprising:

[0008] Receiving killing logs uploaded by multiple clients, wherein the killing logs contain characteristic values ​​corresponding to multiple processes;

[0009] Acquire a plurality of first characteristic values ​​corresponding to a first moment and a plurality of second characteristic values ​​corresponding to a second moment in the killing log, wherein the second moment is a moment before the first moment;

[0010] Generate a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues;

[0011] According to multiple same-order feature value pairs and multiple preceding-order feature value pairs including a target feature value, multiple preceding-order feature values, multiple same-order feature values, and multiple following-order feature values ​​corresponding to the target feature value are determined, and the number of occurrences corresponding to each of the preceding-order feature values, the number of occurrences corresponding to each of the same-order feature values, and the number of occurrences corresponding to each of the following-order feature values ​​are counted;

[0012] According to the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the in-sequence feature values, and the number of occurrences corresponding to each of the succeeding feature values, a target preceding feature value, a target in-sequence feature value, and a target succeeding feature value corresponding to the target feature value are determined.

[0013] Optionally, obtaining a plurality of first characteristic values ​​corresponding to a first moment and a plurality of second characteristic values ​​corresponding to a second moment in the killing log includes:

[0014] Sorting the multiple characteristic values ​​contained in the killing log in chronological order to generate a characteristic value sequence corresponding to the killing log;

[0015] A plurality of first eigenvalues ​​and a plurality of second eigenvalues ​​are obtained in the eigenvalue sequence based on a preset sliding time window.

[0016] Optionally, generating a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues ​​includes:

[0017] Performing permutation and combination processing on the plurality of the first eigenvalues ​​to generate a plurality of the eigenvalue pairs of the same order;

[0018] The plurality of the first eigenvalues ​​and the plurality of the second eigenvalues ​​are processed by permutation and combination to generate a plurality of the preceding eigenvalue pairs.

[0019] Optionally, determining a target preceding-order feature value, a target in-order feature value, and a target subsequent-order feature value corresponding to the target feature value according to the number of occurrences corresponding to each of the preceding-order feature values, the number of occurrences corresponding to each of the in-order feature values, and the number of occurrences corresponding to each of the subsequent-order feature values ​​includes:

[0020] According to the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values, and the number of occurrences corresponding to each of the succeeding feature values, the plurality of preceding feature values, the plurality of same-sequence feature values, and the plurality of succeeding feature values ​​are sorted respectively;

[0021] The first X pre-order feature values ​​after sorting are determined as the target pre-order feature values, the first Y in-order feature values ​​after sorting are determined as the target in-order feature values, and the first Z post-order feature values ​​after sorting are determined as the target post-order feature values.

[0022] Optionally, determining a target preceding-order feature value, a target in-order feature value, and a target subsequent-order feature value corresponding to the target feature value according to the number of occurrences corresponding to each of the preceding-order feature values, the number of occurrences corresponding to each of the in-order feature values, and the number of occurrences corresponding to each of the subsequent-order feature values ​​includes:

[0023] Determine a preceding feature value among the plurality of preceding feature values, the preceding feature value having a number of occurrences greater than a first preset threshold, as the target preceding feature value;

[0024] Determine the same sequence feature value whose occurrence number is greater than a second preset threshold among the plurality of same sequence feature values ​​as the target same sequence feature value;

[0025] A post-order feature value whose occurrence number is greater than a third preset threshold among the plurality of post-order feature values ​​is determined as the target post-order feature value.

[0026] Optionally, after determining the target preceding-order feature value, the target in-order feature value, and the target subsequent-order feature value corresponding to the target feature value according to the number of occurrences corresponding to each of the preceding-order feature values, the number of occurrences corresponding to each of the in-order feature values, and the number of occurrences corresponding to each of the subsequent-order feature values, the method further includes:

[0027] The target feature value, the target preceding feature value, the target same-order feature value and the target subsequent feature value are output and displayed.

[0028] In a second aspect, the present invention further provides a process chain analysis device, the device comprising:

[0029] A receiving unit, configured to receive a plurality of killing logs uploaded by a plurality of clients, wherein the killing logs contain characteristic values ​​corresponding to a plurality of processes;

[0030] an acquisition unit, configured to acquire a plurality of first characteristic values ​​corresponding to a first moment and a plurality of second characteristic values ​​corresponding to a second moment in the killing log, wherein the second moment is a moment before the first moment;

[0031] a generating unit, configured to generate a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues;

[0032] A first determining unit is used to determine a plurality of preceding eigenvalues, a plurality of same-order eigenvalues, and a plurality of subsequent-order eigenvalues ​​corresponding to the target eigenvalue according to a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs including the target eigenvalue;

[0033] A statistical unit, used to count the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values, and the number of occurrences corresponding to each of the succeeding feature values;

[0034] The second determining unit is used to determine the target preceding feature value, the target same-sequence feature value and the target subsequent feature value corresponding to the target feature value according to the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values ​​and the number of occurrences corresponding to each of the subsequent feature values.

[0035] Optionally, the acquiring unit includes:

[0036] A first sorting module, used to sort the multiple characteristic values ​​contained in the killing log in chronological order to generate a characteristic value sequence corresponding to the killing log;

[0037] An acquisition module is used to acquire a plurality of first eigenvalues ​​and a plurality of second eigenvalues ​​in the eigenvalue sequence based on a preset sliding time window.

[0038] Optionally, the generating unit includes:

[0039] A first generating module, used for performing permutation and combination processing on the plurality of the first eigenvalues ​​to generate a plurality of the eigenvalue pairs of the same sequence;

[0040] The second generating module is used to perform permutation and combination processing on a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues ​​to generate a plurality of the preceding eigenvalue pairs.

[0041] Optionally, the second determining unit includes:

[0042] A second sorting module is used to sort the plurality of preceding feature values, the plurality of same-sequence feature values, and the plurality of subsequent feature values ​​according to the number of occurrences corresponding to each preceding feature value, the number of occurrences corresponding to each same-sequence feature value, and the number of occurrences corresponding to each subsequent feature value;

[0043] The first determination module is used to determine the first X pre-order feature values ​​after sorting as the target pre-order feature values, determine the first Y in-order feature values ​​after sorting as the target in-order feature values, and determine the first Z post-order feature values ​​after sorting as the target post-order feature values.

[0044] Optionally, the second determining unit further includes:

[0045] A second determination module is used to determine a preceding feature value whose occurrence number among the plurality of preceding feature values ​​is greater than a first preset threshold as the target preceding feature value;

[0046] A third determination module, configured to determine, among the plurality of the same-sequence feature values, a same-sequence feature value whose number of occurrences is greater than a second preset threshold, as the target same-sequence feature value;

[0047] The fourth determination module is used to determine the post-order feature value whose occurrence number is greater than the third preset threshold among the multiple post-order feature values ​​as the target post-order feature value.

[0048] Optionally, the device further comprises:

[0049] An output unit is used to output and display the target characteristic value, the target preceding characteristic value, the target identical-sequence characteristic value and the target subsequent characteristic value after the second determining unit determines the target preceding characteristic value, the target identical-sequence characteristic value and the target subsequent characteristic value corresponding to the target characteristic value according to the number of occurrences corresponding to each of the preceding characteristic values, the number of occurrences corresponding to each of the identical-sequence characteristic values ​​and the number of occurrences corresponding to each of the subsequent characteristic values.

[0050] In a third aspect, the present invention provides a storage medium storing a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the process chain analysis method as described in the first aspect.

[0051] In a fourth aspect, the present invention provides an electronic device, the electronic device comprising a storage medium and a processor;

[0052] The processor is adapted to implement each instruction;

[0053] The storage medium is suitable for storing a plurality of instructions;

[0054] The instructions are suitable for being loaded by the processor and executing the process chain analysis method as described in the first aspect.

[0055] By means of the above technical solution, the technical solution provided by the present invention has at least the following advantages:

[0056] The present invention provides a process chain analysis method and device. Compared with the prior art in which a worker directly completes a process chain based on a kill log, the present invention enables a cloud server to obtain a plurality of first feature values ​​and a plurality of second feature values ​​with running times of two adjacent moments in the kill log after receiving the kill logs uploaded by a plurality of antivirus software clients, and after generating a plurality of same-order feature value pairs and a plurality of preceding feature value pairs according to the plurality of first feature values ​​and the plurality of second feature values, search for all the same-order feature value pairs and all the preceding feature value pairs containing a target feature value, determine the preceding feature value, the same-order feature value and the following feature value corresponding to the target feature value according to all the same-order feature value pairs and all the preceding feature value pairs containing the target feature value, and count the number of occurrences of each preceding feature value, the number of occurrences of each same-order feature value and the number of occurrences of the following feature value corresponding to the target feature value, and finally determine the target preceding feature value, the target same-order feature value and the target following feature value corresponding to the target feature value according to the number of occurrences of each preceding feature value, the number of occurrences of each same-order feature value and the number of occurrences of each following feature value. Since the determined target preceding characteristic value, target in-sequence characteristic value and target subsequent characteristic value are the characteristic values ​​that appear most frequently at the same time as the target characteristic value (that is, the characteristic values ​​that are strongly correlated with the target characteristic value), the staff can accurately determine the parent process and child process of the target process (the process corresponding to the target characteristic value) based on the target preceding characteristic value, target in-sequence characteristic value and target subsequent characteristic value corresponding to the target characteristic value, thereby accurately completing the process chain.

[0057] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented according to the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0059] Figure 1 A flow chart of a process chain analysis method provided by an embodiment of the present invention is shown;

[0060] Figure 2 A flowchart of another process chain analysis method provided by an embodiment of the present invention is shown;

[0061] Figure 3A block diagram showing a composition of a process chain analysis device provided by an embodiment of the present invention;

[0062] Figure 4 A block diagram showing the composition of another process chain analysis device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0063] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0064] The embodiment of the present invention provides a process chain analysis method, such as Figure 1 As shown, the method includes:

[0065] 101. Receive the virus detection logs uploaded by multiple clients.

[0066] In an embodiment of the present invention, when the antivirus software client uses the local detection mode or the cloud detection mode to detect malicious programs on the terminal device, it will generate a detection log that records the characteristic value (MD5 value) corresponding to each process running successively in the terminal device and the running time corresponding to each process, and upload the generated detection log to the cloud server. Therefore, the cloud server can receive a large number of detection logs uploaded by the antivirus software client.

[0067] 102. Obtain multiple first characteristic values ​​corresponding to a first moment and multiple second characteristic values ​​corresponding to a second moment in the killing log.

[0068] In an embodiment of the present invention, after receiving the killing logs uploaded by multiple antivirus software clients, the cloud server can obtain multiple first feature values ​​corresponding to the first moment and multiple second feature values ​​corresponding to the second moment in any one of the killing logs, wherein the first moment and the second moment are any two adjacent moments, and the second moment is the moment before the first moment. For example, the killing log A records the feature values ​​of multiple processes with a running time of 00:00:00 to 01:00:00 on April 24, 2019. The multiple first feature values ​​and multiple second feature values ​​obtained by the cloud server in the killing log A can specifically be: feature values ​​corresponding to multiple processes with a running time of 00:00:05 on April 24, 2019 and feature values ​​of multiple processes with a running time of 00:00:04 on April 24, 2019, or feature values ​​corresponding to multiple processes with a running time of 00:07:15 on April 24, 2019 and feature values ​​of multiple processes with a running time of 00:07:14 on April 24, 2019. Value; the killing log B records the characteristic values ​​of multiple processes whose running time is from 02:00:00 to 04:00:00 on April 24, 2019. The multiple first characteristic values ​​and multiple second characteristic values ​​obtained by the cloud server in the killing log B can specifically be: the characteristic values ​​corresponding to the multiple processes whose running time is 02:36:28 on April 24, 2019 and the characteristic values ​​of the multiple processes whose running time is 02:36:27 on April 24, 2019, or can also be: the characteristic values ​​corresponding to the multiple processes whose running time is 03:26:57 on April 24, 2019 and the characteristic values ​​of the multiple processes whose running time is 03:26:56 on April 24, 2019.

[0069] 103. Generate a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to the plurality of first eigenvalues ​​and the plurality of second eigenvalues.

[0070] In an embodiment of the present invention, after the cloud server obtains multiple first feature values ​​corresponding to the first moment and multiple second feature values ​​corresponding to the second moment in the detection log, it can generate multiple preceding feature value pairs according to the multiple first feature values ​​and multiple second feature values ​​at two adjacent running moments (that is, any first feature value and any second feature value are combined to generate multiple preceding feature value pairs), and generate multiple same-order feature value pairs according to the multiple first feature values ​​at the same running moment (that is, any two first feature values ​​are combined to generate multiple same-order feature value pairs).

[0071] 104. Determine multiple preceding feature values, multiple same-order feature values, and multiple following feature values ​​corresponding to the target feature value based on multiple same-order feature value pairs and multiple preceding feature value pairs including the target feature value, and count the number of occurrences corresponding to each preceding feature value, the number of occurrences corresponding to each same-order feature value, and the number of occurrences corresponding to each following feature value.

[0072] In an embodiment of the present invention, after the cloud server has gone through the above steps 102 and 103, it obtains multiple first feature values ​​and multiple second feature values ​​with running times of two adjacent moments in all the received killing logs, and generates multiple same-order feature value pairs and multiple preceding feature value pairs according to the multiple first feature values ​​and multiple second feature values ​​obtained in each killing log. Then, the cloud server can determine the strongly associated feature value of any feature value (that is, the strongly associated process of any process can be determined) according to the generated multiple same-order feature value pairs and multiple preceding feature value pairs, that is, first arbitrarily select a feature value or receive the feature value (target feature value) input by the staff; then search for all same-order feature value pairs and all preceding feature value pairs containing the target feature value, and determine the preceding feature value, same-order feature value and post-order feature value corresponding to the target feature value according to all same-order feature value pairs and all preceding feature value pairs containing the target feature value, wherein The other eigenvalue in the same-order eigenvalue pair containing the target eigenvalue is the same-order eigenvalue corresponding to the target eigenvalue, and the other eigenvalue in the pre-order eigenvalue pair containing the target eigenvalue is the pre-order eigenvalue or the post-order eigenvalue corresponding to the target eigenvalue: the other eigenvalue in the pre-order eigenvalue pair generated when the target eigenvalue is used as the first eigenvalue is the pre-order eigenvalue of the target eigenvalue, and the other eigenvalue in the pre-order eigenvalue pair generated when the target eigenvalue is used as the second eigenvalue is the post-order eigenvalue of the target eigenvalue; finally, the number of occurrences of each pre-order eigenvalue corresponding to the target eigenvalue, the number of occurrences of each same-order eigenvalue, and the number of occurrences corresponding to the post-order eigenvalue are counted, so as to subsequently determine the target pre-order eigenvalue, the target same-order eigenvalue, and the target post-order eigenvalue (i.e., the eigenvalue strongly associated with the target eigenvalue) corresponding to the target eigenvalue according to the number of occurrences of each pre-order eigenvalue, the number of occurrences of each same-order eigenvalue, and the number of occurrences corresponding to each post-order eigenvalue.

[0073] 105. Determine a target preceding-order feature value, a target in-order feature value, and a target subsequent-order feature value corresponding to the target feature value according to the number of occurrences corresponding to each preceding-order feature value, the number of occurrences corresponding to each in-order feature value, and the number of occurrences corresponding to each subsequent-order feature value.

[0074] In an embodiment of the present invention, after the cloud server has counted the number of occurrences of each preceding feature value, the number of occurrences of each same-sequence feature value, and the number of occurrences of each post-sequence feature value corresponding to the target feature value, it can determine the target preceding feature value, target same-sequence feature value, and target post-sequence feature value corresponding to the target feature value according to the number of occurrences corresponding to each preceding feature value, the number of occurrences corresponding to each same-sequence feature value, and the number of occurrences corresponding to each post-sequence feature value, that is, determine the preceding feature value, the same-sequence feature value, and the post-sequence feature value with a larger number of occurrences as the target preceding feature value, target same-sequence feature value, and target post-sequence feature value corresponding to the target feature value, or rank the preceding feature value with a higher number of occurrences. The preceding characteristic value, the same-order characteristic value and the following characteristic value are determined as the target preceding characteristic value, the same-order characteristic value and the following characteristic value corresponding to the target characteristic value, so that the determined target preceding characteristic value, the same-order characteristic value and the following characteristic value are the characteristic values ​​that appear most frequently with the target characteristic value, that is, the characteristic values ​​that are strongly associated with the target characteristic value, and thus can provide data support for the staff to complete the process chain: the staff can accurately determine the parent process and the child process of the target process (the process corresponding to the target characteristic value) according to the target preceding characteristic value, the same-order characteristic value and the following characteristic value corresponding to the target characteristic value, thereby accurately completing the process chain.

[0075] A process chain analysis method provided by an embodiment of the present invention is compared with the prior art in which a staff member directly completes a process chain based on a kill log. In the embodiment of the present invention, after a cloud server receives kill logs uploaded by multiple antivirus software clients, the cloud server can obtain multiple first feature values ​​and multiple second feature values ​​with running times of two adjacent moments in the kill log, and after generating multiple same-order feature value pairs and multiple preceding feature value pairs according to the multiple first feature values ​​and the multiple second feature values, search for all the same-order feature value pairs and all the preceding feature value pairs containing a target feature value, determine the preceding feature value, the same-order feature value and the following feature value corresponding to the target feature value according to all the same-order feature value pairs and all the preceding feature value pairs containing the target feature value, and count the number of occurrences of each preceding feature value, the number of occurrences of each same-order feature value and the number of occurrences of the following feature value corresponding to the target feature value, and finally determine the target preceding feature value, the target same-order feature value and the target following feature value corresponding to the target feature value according to the number of occurrences of each preceding feature value, the number of occurrences of each same-order feature value and the number of occurrences of each following feature value. Since the determined target preceding characteristic value, target in-sequence characteristic value and target subsequent characteristic value are the characteristic values ​​that appear most frequently at the same time as the target characteristic value (that is, the characteristic values ​​that are strongly correlated with the target characteristic value), the staff can accurately determine the parent process and child process of the target process (the process corresponding to the target characteristic value) based on the target preceding characteristic value, target in-sequence characteristic value and target subsequent characteristic value corresponding to the target characteristic value, thereby accurately completing the process chain.

[0076] Further, based on Figure 1 The method shown in the embodiment of the present invention provides another process chain analysis method, specifically as follows Figure 2 As shown, the method includes:

[0077] 201. Receive the virus detection logs uploaded by multiple clients.

[0078] Regarding step 201, receiving the killing logs uploaded by multiple clients, please refer to Figure 1 The description of the corresponding parts of the embodiments of the present invention will not be repeated here.

[0079] 202. Obtain multiple first characteristic values ​​corresponding to a first moment and multiple second characteristic values ​​corresponding to a second moment in the killing log.

[0080] In an embodiment of the present invention, after receiving the killing logs uploaded by multiple antivirus software clients, the cloud server can obtain multiple first feature values ​​corresponding to the first moment and multiple second feature values ​​corresponding to the second moment in any one of the killing logs, wherein the first moment and the second moment are any two adjacent moments, and the second moment is the moment before the first moment. The following will describe in detail how the cloud server obtains multiple first feature values ​​corresponding to the first moment and multiple second feature values ​​corresponding to the second moment in the killing log.

[0081] (1) Sort multiple feature values ​​contained in the antivirus log in chronological order to generate a feature value sequence corresponding to the antivirus log.

[0082] In an embodiment of the present invention, since the detection and killing log generated by the antivirus software client records the characteristic value (MD5 value) corresponding to each process running successively in the terminal device and the running time corresponding to each process, after receiving the detection and killing log uploaded by the antivirus software client, the cloud server can sort the running time corresponding to each characteristic value recorded in the detection and killing log in chronological order, that is, sort the each characteristic value recorded in the detection and killing log in chronological order, thereby generating a characteristic value sequence corresponding to the detection and killing log.

[0083] (2) Obtaining a plurality of first eigenvalues ​​and a plurality of second eigenvalues ​​in the eigenvalue sequence based on a preset sliding time window.

[0084] In an embodiment of the present invention, after generating a feature value sequence corresponding to the detection and killing log, the cloud server can obtain multiple first feature values ​​and multiple second feature values ​​in the feature value sequence based on a preset sliding time window, that is, use the preset sliding time window to slide in parallel on the feature value sequence, wherein the preset sliding time window moves forward one moment each time in parallel, and when the preset sliding time window stops sliding for the Nth time, the multiple second feature values ​​corresponding to the second moment fall within the preset sliding time window. At this time, the cloud server can obtain the multiple second feature values, and when the preset sliding time window stops sliding for the N+1th time, the multiple first feature values ​​corresponding to the first moment fall within the preset sliding time window. At this time, the cloud server can obtain the multiple first feature values, wherein N is a positive integer.

[0085] 203. Generate a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to the plurality of first eigenvalues ​​and the plurality of second eigenvalues.

[0086] In an embodiment of the present invention, after the cloud server obtains multiple first feature values ​​corresponding to the first moment and multiple second feature values ​​corresponding to the second moment in the killing log, it can generate multiple same-order feature value pairs and multiple preceding feature value pairs according to the multiple first feature values ​​and multiple second feature values ​​at two adjacent moments in the running time. The following will describe in detail how the cloud server generates multiple same-order feature value pairs and multiple preceding feature value pairs according to the multiple first feature values ​​and multiple second feature values.

[0087] (1) Performing permutation and combination processing on a plurality of first eigenvalues ​​to generate a plurality of eigenvalue pairs of the same order.

[0088] In the embodiment of the present invention, the cloud server combines any two first feature values ​​to generate multiple pairs of feature values ​​in the same order, that is, the multiple first feature values ​​are processed by permutation and combination, so as to generate multiple pairs of feature values ​​in the same order. For example, the cloud server obtains multiple first feature values ​​in the killing log A: N1, N2, N3...N n After that, for multiple first eigenvalues: N1, N2, N3…N n Perform permutation and combination processing to generate multiple pairs of eigenvalues ​​in the same order: (N1, N2), (N1, N3)…(N1, N n ), (N2, N3), (N2, N4)…(N2, N n )…(N n-2 , N n-1 )、(N n-2 , N n )、(N n-1 , N n ).

[0089] (2) Performing permutation and combination processing on the plurality of first eigenvalues ​​and the plurality of second eigenvalues ​​to generate a plurality of preceding eigenvalue pairs.

[0090] In an embodiment of the present invention, the cloud server combines any first eigenvalue and any second eigenvalue to generate multiple pre-order eigenvalue pairs, that is, the multiple first eigenvalues ​​and the multiple second eigenvalues ​​are arranged and combined to generate multiple pre-order eigenvalue pairs. For example, the cloud server obtains multiple first eigenvalues ​​in the killing log A: N1, N2, N3...N n and multiple second eigenvalues: M1, M2, M3…M m After that, for multiple first eigenvalues: N1, N2, N3…N n and multiple second eigenvalues: M1, M2, M3…M m Perform permutation and combination processing to generate multiple pre-order eigenvalue pairs: (N1, M1), (N1, M2)…(N1, M m), (N2, M1), (N2, M2)…(N2, M m )…(N n ,M1)、(N n ,M2)…(N n , M m ).

[0091] 204. Determine multiple preceding feature values, multiple same-order feature values, and multiple following feature values ​​corresponding to the target feature value based on multiple same-order feature value pairs and multiple preceding feature value pairs including the target feature value, and count the number of occurrences corresponding to each preceding feature value, the number of occurrences corresponding to each same-order feature value, and the number of occurrences corresponding to each following feature value.

[0092] Among them, regarding step 204, according to the multiple same-order feature value pairs and the multiple previous-order feature value pairs containing the target feature value, determining the multiple previous-order feature values, the multiple same-order feature values, and the multiple subsequent-order feature values ​​corresponding to the target feature value, and counting the number of occurrences corresponding to each previous-order feature value, the number of occurrences corresponding to each same-order feature value, and the number of occurrences corresponding to each subsequent-order feature value, reference can be made to Figure 1 The description of the corresponding parts of the embodiments of the present invention will not be repeated here.

[0093] 205. Determine a target preceding-order feature value, a target in-order feature value, and a target subsequent-order feature value corresponding to the target feature value according to the number of occurrences corresponding to each preceding-order feature value, the number of occurrences corresponding to each in-order feature value, and the number of occurrences corresponding to each subsequent-order feature value.

[0094] In an embodiment of the present invention, after the cloud server has counted the number of occurrences of each preceding feature value, the number of occurrences of each same-sequence feature value, and the number of occurrences of each subsequent feature value corresponding to the target feature value, it can determine the target preceding feature value, the target same-sequence feature value, and the target subsequent feature value corresponding to the target feature value based on the number of occurrences of each preceding feature value, the number of occurrences of each same-sequence feature value, and the number of occurrences of each subsequent feature value.

[0095] Specifically, the cloud server can determine the target preceding-order feature value, the target same-order feature value, and the target following-order feature value corresponding to the target feature value according to the number of occurrences of each preceding-order feature value, the number of occurrences of each same-order feature value, and the number of occurrences of each following-order feature value corresponding to the target feature value in the following two ways:

[0096] 1. After the cloud server has counted the number of occurrences of each preceding feature value, the number of occurrences of each same-sequence feature value, and the number of occurrences of each subsequent feature value corresponding to the target feature value, it can first sort the multiple preceding feature values, the multiple same-sequence feature values, and the multiple subsequent feature values ​​according to the number of occurrences corresponding to each preceding feature value, the number of occurrences corresponding to each same-sequence feature value, and the number of occurrences corresponding to each subsequent feature value; then, the preceding feature value, the same-sequence feature value, and the subsequent feature value with the highest number of occurrences are determined as the target preceding feature value, the target same-sequence feature value, and the target subsequent feature value corresponding to the target feature value. The post-order feature value is to determine the first X pre-order feature values ​​after sorting as the target pre-order feature values ​​corresponding to the target feature value, determine the first Y same-order feature values ​​after sorting as the target same-order feature values ​​corresponding to the target feature value, and determine the first Z post-order feature values ​​after sorting as the target post-order feature values ​​corresponding to the target feature value, wherein X can be but not limited to: 5, 10, 15, etc., Y can be but not limited to: 5, 10, 15, etc., Z can be but not limited to: 5, 10, 15, etc., and X, Y, and Z can have the same value or different values, which is not specifically limited in the embodiment of the present invention.

[0097] 2. After the cloud server has counted the number of occurrences of each preceding feature value, the number of occurrences of each same-sequence feature value, and the number of occurrences of each subsequent feature value corresponding to the target feature value, the preceding feature value whose number of occurrences among the multiple preceding feature values ​​is greater than the first preset threshold value may be determined as the target preceding feature value corresponding to the target feature value, the same-sequence feature value whose number of occurrences among the multiple same-sequence feature values ​​is greater than the second preset threshold value may be determined as the target same-sequence feature value corresponding to the target feature value, and the subsequent feature value whose number of occurrences among the multiple subsequent feature values ​​is greater than the third preset threshold value may be determined as the target subsequent feature value corresponding to the target feature value, wherein the first preset threshold value may be but not limited to: 10, 20, 30, etc., the second preset threshold value may be but not limited to: 10, 20, 30, etc., the third preset threshold value may be but not limited to: 10, 20, 30, etc., and the first preset threshold value, the second preset threshold value, and the third preset threshold value may be the same value or different values, which is not specifically limited in the embodiment of the present invention.

[0098] 206. Output and display the target characteristic value, the target preceding characteristic value, the target same-order characteristic value, and the target succeeding characteristic value.

[0099] In an embodiment of the present invention, after determining the target preceding feature value, target in-sequence feature value and target post-sequence feature value corresponding to the target feature value, the cloud server can output and display the target feature value, the target preceding feature value, the target in-sequence feature value and the target post-sequence feature value, so that the staff can determine the parent process and child process of the target process (the process corresponding to the target feature value) according to the target preceding feature value, target in-sequence feature value and target post-sequence feature value (the feature value that appears most frequently with the target feature value) corresponding to the target feature value, thereby accurately completing the process chain.

[0100] Furthermore, as a response to the above Figure 1 and Figure 2 In order to realize the method shown in the figure, another embodiment of the present invention further provides a device for analyzing a process chain. This device embodiment corresponds to the aforementioned method embodiment. For ease of reading, this device embodiment will not repeat the details of the aforementioned method embodiment one by one, but it should be clear that the device in this embodiment can correspond to all the contents of the aforementioned method embodiment. This device is used to determine the strongly associated processes of each process, so as to provide data support for the staff to complete the process chain. Figure 3 As shown, the device comprises:

[0101] The receiving unit 31 is used to receive the killing logs uploaded by multiple clients, wherein the killing logs contain characteristic values ​​corresponding to multiple processes;

[0102] An acquisition unit 32 is used to acquire a plurality of first characteristic values ​​corresponding to a first moment and a plurality of second characteristic values ​​corresponding to a second moment in the killing log, wherein the second moment is a moment before the first moment;

[0103] A generating unit 33, configured to generate a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues;

[0104] A first determining unit 34 is used to determine a plurality of preceding eigenvalues, a plurality of same-order eigenvalues, and a plurality of subsequent eigenvalues ​​corresponding to the target eigenvalue according to a plurality of same-order eigenvalue pairs and a plurality of preceding eigenvalue pairs including the target eigenvalue;

[0105] A counting unit 35, used for counting the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values, and the number of occurrences corresponding to each of the succeeding feature values;

[0106] The second determining unit 36 ​​is used to determine the target preceding feature value, the target in-sequence feature value and the target subsequent feature value corresponding to the target feature value according to the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the in-sequence feature values ​​and the number of occurrences corresponding to each of the subsequent feature values.

[0107] Further, such as Figure 4 As shown, the acquisition unit 32 includes:

[0108] A first sorting module 321 is used to sort the multiple feature values ​​contained in the killing log in chronological order to generate a feature value sequence corresponding to the killing log;

[0109] The acquisition module 322 is used to acquire a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues ​​in the eigenvalue sequence based on a preset sliding time window.

[0110] Further, such as Figure 4 As shown, the generating unit 33 includes:

[0111] A first generating module 331 is used to perform permutation and combination processing on the plurality of the first eigenvalues ​​to generate a plurality of the eigenvalue pairs of the same sequence;

[0112] The second generating module 332 is used to perform permutation and combination processing on the plurality of the first eigenvalues ​​and the plurality of the second eigenvalues ​​to generate a plurality of the preceding eigenvalue pairs.

[0113] Further, such as Figure 4 As shown, the second determining unit 36 ​​includes:

[0114] A second sorting module 361 is used to sort the plurality of preceding feature values, the plurality of same-sequence feature values, and the plurality of subsequent feature values ​​according to the number of occurrences corresponding to each preceding feature value, the number of occurrences corresponding to each same-sequence feature value, and the number of occurrences corresponding to each subsequent feature value;

[0115] The first determination module 362 is used to determine the first X pre-order feature values ​​after sorting as the target pre-order feature values, determine the first Y in-order feature values ​​after sorting as the target in-order feature values, and determine the first Z post-order feature values ​​after sorting as the target post-order feature values.

[0116] Further, such as Figure 4 As shown, the second determining unit 36 ​​also includes:

[0117] A second determining module 363, configured to determine a preceding feature value whose occurrence number among the plurality of preceding feature values ​​is greater than a first preset threshold as the target preceding feature value;

[0118] A third determination module 364 is used to determine the same sequence feature value whose number of occurrences is greater than a second preset threshold among the multiple same sequence feature values ​​as the target same sequence feature value;

[0119] The fourth determining module 365 is used to determine the post-order feature value whose occurrence times among the plurality of post-order feature values ​​is greater than the third preset threshold as the target post-order feature value.

[0120] Further, such as Figure 4 As shown, the device also includes:

[0121] The output unit 37 is used to output and display the target characteristic value, the target preceding characteristic value, the target identical-sequence characteristic value and the target subsequent characteristic value after the second determining unit 36 ​​determines the target preceding characteristic value, the target identical-sequence characteristic value and the target subsequent characteristic value corresponding to the target characteristic value according to the number of occurrences corresponding to each of the preceding characteristic values, the number of occurrences corresponding to each of the identical-sequence characteristic values ​​and the number of occurrences corresponding to each of the subsequent characteristic values.

[0122] An analysis device for a process chain provided by an embodiment of the present invention can, compared with the prior art in which a staff member directly completes a process chain based on a detection and killing log, enable the cloud server to obtain multiple first feature values ​​and multiple second feature values ​​with running times of two adjacent moments in the detection and killing log after receiving the detection and killing log uploaded by multiple antivirus software clients, and after generating multiple same-order feature value pairs and multiple preceding feature value pairs according to the multiple first feature values ​​and the multiple second feature values, search for all the same-order feature value pairs and all the preceding feature value pairs containing a target feature value, determine the preceding feature value, the same-order feature value and the following feature value corresponding to the target feature value according to all the same-order feature value pairs and all the preceding feature value pairs containing the target feature value, and count the number of occurrences of each preceding feature value, the number of occurrences of each same-order feature value and the number of occurrences of the following feature value corresponding to the target feature value, and finally determine the target preceding feature value, the target same-order feature value and the target following feature value corresponding to the target feature value according to the number of occurrences of each preceding feature value, the number of occurrences of each same-order feature value and the number of occurrences of each following feature value. Since the determined target preceding characteristic value, target in-sequence characteristic value and target subsequent characteristic value are the characteristic values ​​that appear most frequently at the same time as the target characteristic value (that is, the characteristic values ​​that are strongly correlated with the target characteristic value), the staff can accurately determine the parent process and child process of the target process (the process corresponding to the target characteristic value) based on the target preceding characteristic value, target in-sequence characteristic value and target subsequent characteristic value corresponding to the target characteristic value, thereby accurately completing the process chain.

[0123] Furthermore, according to the above method embodiment, another embodiment of the present invention also provides a storage medium, wherein the storage medium stores a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the above process chain analysis method.

[0124] The instructions in the process chain analysis storage medium provided by the embodiment of the present invention can enable the cloud server to obtain multiple first feature values ​​and multiple second feature values ​​with running times of two adjacent moments in the detection and killing log after the cloud server receives the detection and killing logs uploaded by multiple antivirus software clients, and after generating multiple same-order feature value pairs and multiple preceding feature value pairs based on the multiple first feature values ​​and the multiple second feature values, search for all same-order feature value pairs and all preceding feature value pairs containing the target feature value, and determine the preceding feature value, the same-order feature value and the following feature value corresponding to the target feature value based on all the same-order feature value pairs and all preceding feature value pairs containing the target feature value, and count the number of occurrences of each preceding feature value, the number of occurrences of each same-order feature value and the number of occurrences of the following feature value corresponding to the target feature value, and finally determine the target preceding feature value, the target same-order feature value and the target following feature value corresponding to the target feature value based on the number of occurrences of each preceding feature value, the number of occurrences of each same-order feature value and the number of occurrences of each following feature value. Since the determined target preceding characteristic value, target in-sequence characteristic value and target subsequent characteristic value are the characteristic values ​​that appear most frequently at the same time as the target characteristic value (that is, the characteristic values ​​that are strongly correlated with the target characteristic value), the staff can accurately determine the parent process and child process of the target process (the process corresponding to the target characteristic value) based on the target preceding characteristic value, target in-sequence characteristic value and target subsequent characteristic value corresponding to the target characteristic value, thereby accurately completing the process chain.

[0125] Further, according to the above method embodiment, another embodiment of the present invention also provides an electronic device, the electronic device includes a storage medium and a processor;

[0126] The processor is adapted to implement each instruction;

[0127] The storage medium is suitable for storing a plurality of instructions;

[0128] The instructions are suitable for being loaded by the processor and executing the process chain analysis method as described above.

[0129] The process chain analysis electronic device provided by the embodiment of the present invention can, after the cloud server receives the detection and killing logs uploaded by multiple antivirus software clients, enable the cloud server to obtain multiple first feature values ​​and multiple second feature values ​​with running times of two adjacent moments in the detection and killing log, and after generating multiple same-order feature value pairs and multiple preceding feature value pairs based on the multiple first feature values ​​and the multiple second feature values, search for all same-order feature value pairs and all preceding feature value pairs containing the target feature value, and determine the preceding feature value, the same-order feature value and the following feature value corresponding to the target feature value based on all the same-order feature value pairs and all preceding feature value pairs containing the target feature value, and count the number of occurrences of each preceding feature value, the number of occurrences of each same-order feature value and the number of occurrences of the following feature value corresponding to the target feature value, and finally determine the target preceding feature value, the target same-order feature value and the target following feature value corresponding to the target feature value based on the number of occurrences of each preceding feature value, the number of occurrences of each same-order feature value and the number of occurrences of each following feature value. Since the determined target preceding characteristic value, target in-sequence characteristic value and target subsequent characteristic value are the characteristic values ​​that appear most frequently at the same time as the target characteristic value (that is, the characteristic values ​​that are strongly correlated with the target characteristic value), the staff can accurately determine the parent process and child process of the target process (the process corresponding to the target characteristic value) based on the target preceding characteristic value, target in-sequence characteristic value and target subsequent characteristic value corresponding to the target characteristic value, thereby accurately completing the process chain.

[0130] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0131] It is understandable that the related features in the above methods and devices can be referenced to each other. In addition, the "first", "second" and the like in the above embodiments are used to distinguish the embodiments, but do not represent the advantages and disadvantages of the embodiments.

[0132] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0133] The algorithm and display provided herein are not inherently related to any particular computer, virtual system or other device. Various general purpose systems can also be used together with the teachings based on this. According to the above description, it is obvious that the structure required for constructing such systems. In addition, the present invention is not directed to any specific programming language either. It should be understood that various programming languages ​​can be utilized to realize the content of the present invention described herein, and the description of the above specific languages ​​is for disclosing the best mode of the present invention.

[0134] In the description provided herein, a large number of specific details are described. However, it is understood that embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures and techniques are not shown in detail so as not to obscure the understanding of this description.

[0135] Similarly, it should be understood that in order to streamline the present disclosure and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, this disclosed method should not be interpreted as reflecting the following intention: that the claimed invention requires more features than those explicitly recited in each claim. More specifically, as reflected in the claims below, inventive aspects lie in less than all the features of the individual embodiments disclosed above. Therefore, the claims that follow the specific embodiment are hereby expressly incorporated into the specific embodiment, with each claim itself serving as a separate embodiment of the present invention.

[0136] Those skilled in the art will appreciate that the modules in the devices in the embodiments may be adaptively changed and arranged in one or more devices different from the embodiments. The modules or units or components in the embodiments may be combined into one module or unit or component, and in addition they may be divided into a plurality of submodules or subunits or subcomponents. Except that at least some of such features and / or processes or units are mutually exclusive, all features disclosed in this specification (including the accompanying claims, abstracts and drawings) and all processes or units of any method or device disclosed in this manner may be combined in any combination. Unless otherwise expressly stated, each feature disclosed in this specification (including the accompanying claims, abstracts and drawings) may be replaced by an alternative feature providing the same, equivalent or similar purpose.

[0137] In addition, those skilled in the art will appreciate that, although some embodiments described herein include certain features included in other embodiments but not other features, the combination of features of different embodiments is meant to be within the scope of the present invention and form different embodiments. For example, in the following claims, any one of the claimed embodiments can be used in any combination.

[0138] The various component embodiments of the present invention may be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. It should be understood by those skilled in the art that a microprocessor or a digital signal processor (DSP) may be used in practice to implement some or all of the functions of some or all of the components of the proof-of-work method and apparatus according to an embodiment of the present invention. The present invention may also be implemented as a device or apparatus program (e.g., a computer program and a computer program product) for executing part or all of the methods described herein. Such a program implementing the present invention may be stored on a computer-readable medium, or may be in the form of one or more signals. Such a signal may be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0139] It should be noted that the above embodiments illustrate the present invention rather than limit it, and that those skilled in the art may devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference symbol between brackets shall not be construed as a limitation on the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "one" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention may be implemented by means of hardware comprising a number of different elements and by means of a suitably programmed computer. In a unit claim enumerating a number of devices, several of these devices may be embodied by the same hardware item. The use of the words first, second, and third, etc., does not indicate any order. These words may be interpreted as names.

[0140] The present invention also discloses the following technical solution:

[0141] A1. A process chain analysis method, comprising:

[0142] Receiving killing logs uploaded by multiple clients, wherein the killing logs contain characteristic values ​​corresponding to multiple processes;

[0143] Acquire a plurality of first characteristic values ​​corresponding to a first moment and a plurality of second characteristic values ​​corresponding to a second moment in the killing log, wherein the second moment is a moment before the first moment;

[0144] Generate a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues;

[0145] According to multiple same-order feature value pairs and multiple preceding-order feature value pairs including a target feature value, multiple preceding-order feature values, multiple same-order feature values, and multiple following-order feature values ​​corresponding to the target feature value are determined, and the number of occurrences corresponding to each of the preceding-order feature values, the number of occurrences corresponding to each of the same-order feature values, and the number of occurrences corresponding to each of the following-order feature values ​​are counted;

[0146] According to the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the in-sequence feature values, and the number of occurrences corresponding to each of the succeeding feature values, a target preceding feature value, a target in-sequence feature value, and a target succeeding feature value corresponding to the target feature value are determined.

[0147] A2. According to the method described in A1, obtaining a plurality of first characteristic values ​​corresponding to the first moment and a plurality of second characteristic values ​​corresponding to the second moment in the killing log includes:

[0148] Sorting the multiple characteristic values ​​contained in the killing log in chronological order to generate a characteristic value sequence corresponding to the killing log;

[0149] A plurality of first eigenvalues ​​and a plurality of second eigenvalues ​​are obtained in the eigenvalue sequence based on a preset sliding time window.

[0150] A3. The method according to A1, wherein generating a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues ​​comprises:

[0151] Performing permutation and combination processing on the plurality of the first eigenvalues ​​to generate a plurality of the eigenvalue pairs of the same order;

[0152] The plurality of the first eigenvalues ​​and the plurality of the second eigenvalues ​​are processed by permutation and combination to generate a plurality of the preceding eigenvalue pairs.

[0153] A4. The method according to A1, wherein the target preceding-order feature value, the target in-order feature value, and the target subsequent-order feature value corresponding to the target feature value are determined according to the number of occurrences corresponding to each of the preceding-order feature values, the number of occurrences corresponding to each of the in-order feature values, and the number of occurrences corresponding to each of the subsequent-order feature values, including:

[0154] According to the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values, and the number of occurrences corresponding to each of the succeeding feature values, the plurality of preceding feature values, the plurality of same-sequence feature values, and the plurality of succeeding feature values ​​are sorted respectively;

[0155] The first X pre-order feature values ​​after sorting are determined as the target pre-order feature values, the first Y in-order feature values ​​after sorting are determined as the target in-order feature values, and the first Z post-order feature values ​​after sorting are determined as the target post-order feature values.

[0156] A5. The method according to A1, wherein the target preceding-order feature value, the target in-order feature value, and the target subsequent-order feature value corresponding to the target feature value are determined according to the number of occurrences corresponding to each of the preceding-order feature values, the number of occurrences corresponding to each of the in-order feature values, and the number of occurrences corresponding to each of the subsequent-order feature values, including:

[0157] Determine a preceding feature value among the plurality of preceding feature values, the preceding feature value having a number of occurrences greater than a first preset threshold, as the target preceding feature value;

[0158] Determine the same sequence feature value whose occurrence number is greater than a second preset threshold among the plurality of same sequence feature values ​​as the target same sequence feature value;

[0159] A post-order feature value whose occurrence number is greater than a third preset threshold among the plurality of post-order feature values ​​is determined as the target post-order feature value.

[0160] A6. According to any one of the methods A1-A5, after determining the target preceding-order feature value, the target in-order feature value, and the target subsequent-order feature value corresponding to the target feature value according to the number of occurrences corresponding to each of the preceding-order feature values, the number of occurrences corresponding to each of the in-order feature values, and the number of occurrences corresponding to each of the subsequent-order feature values, the method further comprises:

[0161] The target feature value, the target preceding feature value, the target same-order feature value and the target subsequent feature value are output and displayed.

[0162] B7. A process chain analysis device, comprising:

[0163] A receiving unit, configured to receive a plurality of killing logs uploaded by a plurality of clients, wherein the killing logs contain characteristic values ​​corresponding to a plurality of processes;

[0164] an acquisition unit, configured to acquire a plurality of first characteristic values ​​corresponding to a first moment and a plurality of second characteristic values ​​corresponding to a second moment in the killing log, wherein the second moment is a moment before the first moment;

[0165] a generating unit, configured to generate a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues;

[0166] A first determining unit is used to determine a plurality of preceding eigenvalues, a plurality of same-order eigenvalues, and a plurality of subsequent-order eigenvalues ​​corresponding to the target eigenvalue according to a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs including the target eigenvalue;

[0167] A statistical unit, used to count the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values, and the number of occurrences corresponding to each of the succeeding feature values;

[0168] The second determining unit is used to determine the target preceding feature value, the target same-sequence feature value and the target subsequent feature value corresponding to the target feature value according to the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values ​​and the number of occurrences corresponding to each of the subsequent feature values.

[0169] B8. According to the device described in B7, the acquisition unit includes:

[0170] A first sorting module, used to sort the multiple characteristic values ​​contained in the killing log in chronological order to generate a characteristic value sequence corresponding to the killing log;

[0171] An acquisition module is used to acquire a plurality of first eigenvalues ​​and a plurality of second eigenvalues ​​in the eigenvalue sequence based on a preset sliding time window.

[0172] B9. According to the device described in B7, the generating unit includes:

[0173] A first generating module, used for performing permutation and combination processing on the plurality of the first eigenvalues ​​to generate a plurality of the eigenvalue pairs of the same sequence;

[0174] The second generating module is used to perform permutation and combination processing on a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues ​​to generate a plurality of the preceding eigenvalue pairs.

[0175] B10. According to the apparatus of B7, the second determining unit comprises:

[0176] A second sorting module is used to sort the plurality of preceding feature values, the plurality of same-sequence feature values, and the plurality of subsequent feature values ​​according to the number of occurrences corresponding to each preceding feature value, the number of occurrences corresponding to each same-sequence feature value, and the number of occurrences corresponding to each subsequent feature value;

[0177] The first determination module is used to determine the first X pre-order feature values ​​after sorting as the target pre-order feature values, determine the first Y in-order feature values ​​after sorting as the target in-order feature values, and determine the first Z post-order feature values ​​after sorting as the target post-order feature values.

[0178] B11. According to the apparatus of B7, the second determining unit further comprises:

[0179] A second determining module, configured to determine a preceding feature value whose occurrence number among the plurality of preceding feature values ​​is greater than a first preset threshold as the target preceding feature value;

[0180] A third determination module, configured to determine, among the plurality of the same-sequence feature values, a same-sequence feature value whose number of occurrences is greater than a second preset threshold, as the target same-sequence feature value;

[0181] The fourth determination module is used to determine the post-order feature value whose number of occurrences among the multiple post-order feature values ​​is greater than the third preset threshold as the target post-order feature value.

[0182] B12. The device according to any one of B7 to B11, further comprising:

[0183] An output unit is used to output and display the target characteristic value, the target preceding characteristic value, the target identical-sequence characteristic value and the target subsequent characteristic value after the second determining unit determines the target preceding characteristic value, the target identical-sequence characteristic value and the target subsequent characteristic value corresponding to the target characteristic value according to the number of occurrences corresponding to each of the preceding characteristic values, the number of occurrences corresponding to each of the identical-sequence characteristic values ​​and the number of occurrences corresponding to each of the subsequent characteristic values.

[0184] C13. A storage medium storing a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the process chain analysis method described in any one of A1-A6.

[0185] D14. An electronic device, comprising a storage medium and a processor;

[0186] The processor is adapted to implement each instruction;

[0187] The storage medium is suitable for storing a plurality of instructions;

[0188] The instructions are suitable for being loaded by the processor and executing the process chain analysis method as described in any one of A1-A6.

Claims

1. A process chain analysis method, characterized in that: include: Receiving killing logs uploaded by multiple clients, wherein the killing logs contain characteristic values ​​corresponding to multiple processes; Acquire a plurality of first characteristic values ​​corresponding to a first moment and a plurality of second characteristic values ​​corresponding to a second moment in the killing log, wherein the second moment is a moment before the first moment; Generate a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues; According to multiple same-order feature value pairs and multiple preceding-order feature value pairs including a target feature value, multiple preceding-order feature values, multiple same-order feature values, and multiple following-order feature values ​​corresponding to the target feature value are determined, and the number of occurrences corresponding to each of the preceding-order feature values, the number of occurrences corresponding to each of the same-order feature values, and the number of occurrences corresponding to each of the following-order feature values ​​are counted; Determine a target preceding-order feature value, a target in-order feature value, and a target subsequent-order feature value corresponding to the target feature value according to the number of occurrences corresponding to each of the preceding-order feature values, the number of occurrences corresponding to each of the in-order feature values, and the number of occurrences corresponding to each of the subsequent-order feature values; The determining, according to the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values, and the number of occurrences corresponding to each of the following feature values, a target preceding feature value, a target same-sequence feature value, and a target following feature value corresponding to the target feature value comprises: According to the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values, and the number of occurrences corresponding to each of the succeeding feature values, the plurality of preceding feature values, the plurality of same-sequence feature values, and the plurality of succeeding feature values ​​are sorted respectively; The first X pre-order feature values ​​after sorting are determined as the target pre-order feature values, the first Y in-order feature values ​​after sorting are determined as the target in-order feature values, and the first Z post-order feature values ​​after sorting are determined as the target post-order feature values.

2. The method according to claim 1, characterized in that The obtaining of a plurality of first characteristic values ​​corresponding to a first moment and a plurality of second characteristic values ​​corresponding to a second moment in the killing log includes: Sorting the multiple characteristic values ​​contained in the killing log in chronological order to generate a characteristic value sequence corresponding to the killing log; A plurality of first eigenvalues ​​and a plurality of second eigenvalues ​​are obtained in the eigenvalue sequence based on a preset sliding time window.

3. The method according to claim 1, characterized in that The step of generating a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues ​​comprises: Performing permutation and combination processing on the plurality of the first eigenvalues ​​to generate a plurality of the eigenvalue pairs of the same order; The plurality of the first eigenvalues ​​and the plurality of the second eigenvalues ​​are processed by permutation and combination to generate a plurality of the preceding eigenvalue pairs.

4. The method according to claim 1, characterized in that: The determining, according to the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values, and the number of occurrences corresponding to each of the following feature values, a target preceding feature value, a target same-sequence feature value, and a target following feature value corresponding to the target feature value comprises: Determine a preceding feature value among the plurality of preceding feature values, the preceding feature value having a number of occurrences greater than a first preset threshold, as the target preceding feature value; Determine the same sequence feature value whose occurrence number is greater than a second preset threshold among the plurality of same sequence feature values ​​as the target same sequence feature value; A post-order feature value whose occurrence number is greater than a third preset threshold among the plurality of post-order feature values ​​is determined as the target post-order feature value.

5. The method according to any one of claims 1 to 4, characterized in that After determining the target preceding feature value, the target same-sequence feature value, and the target following feature value corresponding to the target feature value according to the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values, and the number of occurrences corresponding to each of the following feature values, the method further includes: The target feature value, the target preceding feature value, the target same-order feature value and the target subsequent feature value are output and displayed.

6. A process chain analysis device, characterized in that: The device comprises: A receiving unit, configured to receive a plurality of killing logs uploaded by a plurality of clients, wherein the killing logs contain characteristic values ​​corresponding to a plurality of processes; an acquisition unit, configured to acquire a plurality of first characteristic values ​​corresponding to a first moment and a plurality of second characteristic values ​​corresponding to a second moment in the killing log, wherein the second moment is a moment before the first moment; a generating unit, configured to generate a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs according to a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues; A first determining unit is used to determine a plurality of preceding eigenvalues, a plurality of same-order eigenvalues, and a plurality of subsequent-order eigenvalues ​​corresponding to the target eigenvalue according to a plurality of same-order eigenvalue pairs and a plurality of preceding-order eigenvalue pairs including the target eigenvalue; A statistical unit, used to count the number of occurrences corresponding to each of the preceding feature values, the number of occurrences corresponding to each of the same-sequence feature values, and the number of occurrences corresponding to each of the succeeding feature values; A second determining unit is used to determine a target preceding-order feature value, a target same-order feature value, and a target subsequent-order feature value corresponding to the target feature value according to the number of occurrences corresponding to each of the preceding-order feature values, the number of occurrences corresponding to each of the same-order feature values, and the number of occurrences corresponding to each of the subsequent-order feature values; The second determining unit includes: A second sorting module is used to sort the plurality of preceding feature values, the plurality of same-sequence feature values, and the plurality of subsequent feature values ​​according to the number of occurrences corresponding to each preceding feature value, the number of occurrences corresponding to each same-sequence feature value, and the number of occurrences corresponding to each subsequent feature value; The first determination module is used to determine the first X pre-order feature values ​​after sorting as the target pre-order feature values, determine the first Y in-order feature values ​​after sorting as the target in-order feature values, and determine the first Z post-order feature values ​​after sorting as the target post-order feature values.

7. The device according to claim 6, characterized in that The acquisition unit comprises: A first sorting module, used to sort the multiple characteristic values ​​contained in the killing log in chronological order to generate a characteristic value sequence corresponding to the killing log; An acquisition module is used to acquire a plurality of first eigenvalues ​​and a plurality of second eigenvalues ​​in the eigenvalue sequence based on a preset sliding time window.

8. The device according to claim 6, characterized in that The generating unit comprises: A first generating module, used for performing permutation and combination processing on the plurality of the first eigenvalues ​​to generate a plurality of the eigenvalue pairs of the same sequence; The second generating module is used to perform permutation and combination processing on a plurality of the first eigenvalues ​​and a plurality of the second eigenvalues ​​to generate a plurality of the preceding eigenvalue pairs.

9. The device according to claim 6, characterized in that The second determining unit further includes: A second determining module, configured to determine a preceding feature value whose occurrence number among the plurality of preceding feature values ​​is greater than a first preset threshold as the target preceding feature value; A third determination module, configured to determine, among the plurality of the same-sequence feature values, a same-sequence feature value whose number of occurrences is greater than a second preset threshold, as the target same-sequence feature value; The fourth determination module is used to determine the post-order feature value whose number of occurrences among the multiple post-order feature values ​​is greater than the third preset threshold as the target post-order feature value.

10. The device according to any one of claims 6 to 9, characterized in that: The device also includes: An output unit is used to output and display the target characteristic value, the target preceding characteristic value, the target identical-sequence characteristic value and the target subsequent characteristic value after the second determining unit determines the target preceding characteristic value, the target identical-sequence characteristic value and the target subsequent characteristic value corresponding to the target characteristic value according to the number of occurrences corresponding to each of the preceding characteristic values, the number of occurrences corresponding to each of the identical-sequence characteristic values ​​and the number of occurrences corresponding to each of the subsequent characteristic values.

11. A storage medium storing a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the process chain analysis method according to any one of claims 1 to 5.

12. An electronic device, comprising a storage medium and a processor; The processor is adapted to implement each instruction; The storage medium is suitable for storing a plurality of instructions; The instructions are suitable for being loaded by the processor and executing the process chain analysis method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Process information acquisition method and device

    CN105608375A

  • Application closing method and device, storage medium and electronic equipment

    CN107734616A