A cloud host virus detection method, device and system
By receiving and processing the process number and file information of the cloud host, combined with the matching of the virus database, the cloud host's virus detection efficiency and high payload risk are solved, and efficient and visual virus detection is achieved, improving the user experience.
Patent Information
- Application Number
- CN202210360973.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-07
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2042-04-07
AI Technical Summary
In the prior art, cloud host virus detection efficiency is low, payload risk is high, applicable scenarios are narrow, and user experience is poor, especially when a large number of cloud hosts are detected simultaneously in a cloud platform.
By receiving the process number collected by the cloud host, we can determine whether the process file information is the first detection. If so, generate the process file information collection task and match it with the virus database. If so, use the last detection result to achieve visual display.
It improves the virus detection efficiency of cloud hosts, reduces the load risk of cloud hosts, ensures the operation of cloud host services, expands applicable scenarios for virus detection, and improves user experience.
Smart Images

Figure CN114912111B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technologies, and in particular, to a method, apparatus, and system for detecting viruses in cloud hosts. Background Art
[0002] A cloud host is an electronic computing device used for high-speed computing, which can perform numerical calculations, logical calculations, and also has a storage and memory function. There are a large number of cloud hosts managed on the cloud platform, and there are various types of potential virus files in the cloud hosts. To prevent cloud hosts from being invaded and damaged by viruses, it is necessary to scan the cloud hosts for viruses, kill the processes that have been determined to be viruses or delete the virus files, and perform associated deletion on the started virus processes.
[0003] There are at least the following problems in the prior art:
[0004] When the existing methods face the detection of viruses in cloud hosts, especially when detecting viruses in a large number of cloud hosts on the cloud platform simultaneously, the virus detection efficiency is low, which increases the load risk of the cloud hosts, affects the operation of the cloud hosts' own services, and the display of virus detection results is slow, the applicable scenarios are narrow, and the user experience is poor. Summary of the Invention
[0005] In view of this, embodiments of the present invention provide a method, apparatus, and system for detecting viruses in cloud hosts, which can detect viruses in a large number of cloud hosts simultaneously, improve the virus detection efficiency of cloud hosts, reduce the load risk of cloud hosts, effectively ensure the operation of the cloud hosts' own services, and at the same time, can also visually display the virus detection results, expand the applicable scenarios of the virus detection method, and improve the user experience.
[0006] To achieve the above object, according to one aspect of the embodiments of the present invention, a method for detecting viruses in cloud hosts is provided, which is applied to the cloud and includes:
[0007] Receiving cloud host process numbers collected and sent by one or more cloud hosts; wherein, the cloud host process numbers are collected by the cloud host according to the cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on the cloud host virus detection request;
[0008] Sequentially determining whether the process file information corresponding to the cloud host process number is detected for the first time;
[0009] If so, determine the cloud host number corresponding to the cloud host process number, generate and send a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extract the process file features of the process file information, match the process file features with the virus features in the virus database, and determine the cloud host virus detection result according to the matching result; if not, use the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result.
[0010] Further, the step of receiving the cloud host process numbers collected and sent by one or more cloud hosts includes:
[0011] Receive the cloud host process numbers collected by one or more cloud hosts according to the cloud host process number collection task and sent via the storage system.
[0012] Further, determining the cloud host virus detection result according to the matching result includes:
[0013] Compare the matching degrees of the process file features in the matching result with multiple virus features in the virus database respectively with the matching degree threshold;
[0014] If there is a matching degree exceeding the matching degree threshold, determine the corresponding process file as a virus file.
[0015] Further, it further includes:
[0016] Determine the virus file type, the target cloud host process number corresponding to the virus file type, and the target cloud host including the target cloud host process number;
[0017] Perform visual display according to the target cloud host, the target cloud host process number, and the virus file type.
[0018] Further, the cloud host process number collection task also indicates a collection period; the step of receiving the cloud host process numbers collected and sent by one or more cloud hosts includes:
[0019] Receive the cloud host process numbers collected and sent by one or more cloud hosts at regular intervals according to the collection period.
[0020] According to another aspect of the embodiments of the present invention, there is provided a cloud host virus detection device, which is set in the cloud and includes:
[0021] A process number receiving module, configured to receive the cloud host process numbers collected and sent by one or more cloud hosts; wherein, the cloud host process numbers are collected by the cloud host according to the cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on the cloud host virus detection request;
[0022] A judgment module, configured to sequentially judge whether the process file information corresponding to the cloud host process number is detected for the first time;
[0023] A detection module, if the process file information corresponding to the cloud host process number is detected for the first time, is configured to determine the cloud host number corresponding to the cloud host process number, generate and send a process file information collection task to the cloud host corresponding to the cloud host number, so as to receive the process file information returned by the cloud host, extract the process file features of the process file information, match the process file features with the virus features in the virus database, and determine the cloud host virus detection result according to the matching result; if the process file information corresponding to the cloud host process number is not detected for the first time, is configured to use the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result.
[0024] Further, the detection module is further configured to:
[0025] Compare the matching degrees between the process file features in the matching result and multiple virus features in the virus database with the matching degree threshold respectively;
[0026] If there is a matching degree exceeding the matching degree threshold, determine the corresponding process file as a virus file.
[0027] According to another aspect of the embodiments of the present invention, there is provided a cloud host virus detection system, including a cloud, a user side, and one or more cloud hosts, wherein,
[0028] The user side is configured to generate a cloud host process number collection task based on a cloud host virus detection request, and distribute the cloud host process number collection task to the cloud hosts;
[0029] The cloud host is configured to receive the cloud host process number collection task, collect the cloud host process number according to the cloud host process number collection task, and send the cloud host process number to the cloud;
[0030] The cloud is configured to receive the cloud host process number; sequentially judge whether the process file information corresponding to the cloud host process number is detected for the first time; if so, determine the cloud host number corresponding to the cloud host process number, generate and send a process file information collection task to the cloud host corresponding to the cloud host number, so as to receive the process file information returned by the cloud host, extract the process file features of the process file information, match the process file features with the virus features in the virus database, and determine the cloud host virus detection result according to the matching result; if not, use the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result.
[0031] According to still another aspect of the embodiments of the present invention, there is provided an electronic device for cloud host virus detection, including:
[0032] One or more processors;
[0033] A storage device for storing one or more programs,
[0034] When the one or more programs are executed by one or more processors, the one or more processors implement any of the cloud host virus detection methods as described above.
[0035] According to another aspect of the embodiments of the present invention, there is provided a computer-readable medium having a computer program stored thereon, and when the program is executed by a processor, it implements any of the cloud host virus detection methods as described above.
[0036] One embodiment of the above invention has the following advantages or beneficial effects: By adopting the method of receiving the cloud host process numbers collected and sent by one or more cloud hosts; wherein, the cloud host process numbers are collected by the cloud host according to the cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on the cloud host virus detection request; sequentially determining whether the process file information corresponding to the cloud host process number is detected for the first time; if so, determining the cloud host number corresponding to the cloud host process number, generating and sending a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extracting the process file characteristics of the process file information, matching the process file characteristics with the virus characteristics in the virus database, and determining the cloud host virus detection result according to the matching result; if not, using the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result, the technical problems of the existing methods in the face of cloud host virus detection, especially when detecting viruses for a large number of cloud hosts in a cloud platform at the same time, such as low virus detection efficiency, high cloud host load risk, narrow applicable scenarios, and poor user experience, are overcome. Furthermore, the technical effect of being able to detect viruses for a large number of cloud hosts at the same time, improving the cloud host virus detection efficiency, reducing the load risk of the cloud host, effectively ensuring the operation of the cloud host's own business, and at the same time, being able to visually display the virus detection results, expanding the applicable scenarios of the virus detection method, and improving the user experience is achieved.
[0037] The further effects of the above non-conventional optional methods will be described in conjunction with the specific embodiments below. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The drawings are used to better understand the present invention and do not constitute an improper limitation to the present invention. Among them:
[0039] Figure 1 is a schematic diagram of the main process of the cloud host virus detection method provided by an embodiment of the present invention;
[0040] Figure 2It is a schematic diagram of the main process of the cloud host virus detection method provided according to another embodiment of the present invention;
[0041] Figure 3 It is a schematic diagram of the main modules of the cloud host virus detection device provided according to an embodiment of the present invention;
[0042] Figure 4 It is a schematic diagram of the main modules of the cloud host virus detection system provided according to an embodiment of the present invention;
[0043] Figure 5 It is an exemplary system architecture diagram to which the embodiments of the present invention can be applied;
[0044] Figure 6 It is a schematic structural diagram of a computer system of a terminal device or a server suitable for implementing the embodiments of the present invention. Detailed implementation manners
[0045] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0046] Figure 1 It is a schematic diagram of the main process of the cloud host virus detection method provided according to an embodiment of the present invention; as Figure 1 shown, the cloud host virus detection method provided by the embodiments of the present invention is applied to the cloud and mainly includes:
[0047] Step S101, receiving one or more cloud host process numbers collected and sent by a cloud host; wherein, the cloud host process number is collected by the cloud host according to a cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on a cloud host virus detection request.
[0048] Specifically, according to the embodiments of the present invention, the cloud host process encoding can be the process name running on the cloud host, the process MD5 value (MD5 Message-Digest Algorithm, a widely used cryptographic hash function that can generate a 128-bit (16-byte) hash value to ensure the integrity and consistency of information transmission), etc., which are used to represent the unique identifier of the process running on the cloud host. Since the cloud host process encodings of the same process are the same, subsequently, it can be determined whether the process file information corresponding to the cloud host process number is detected for the first time. For the process file information corresponding to the same cloud host process encoding, it is only collected once and only detected once, significantly improving the efficiency of virus detection for a large number of cloud hosts.
[0049] Further, according to the embodiments of the present invention, the step of receiving the cloud host process numbers collected and sent by one or more cloud hosts includes:
[0050] Receiving the cloud host process numbers collected by one or more cloud hosts according to the cloud host process number collection task and sent via the storage system.
[0051] In an actual scenario, a large number of processes are running simultaneously in the cloud host, so the order of magnitude of the corresponding process encodings is large. By storing the process encodings collected by the cloud host in the storage system, especially a distributed storage system, and then having the distributed storage system send the corresponding collected cloud host process encodings to the cloud, the efficiency of cloud host virus detection can be further improved.
[0052] According to a preferred embodiment of the embodiments of the present invention, kafka (a distributed, partitioned, multi-replica, multi-subscriber distributed logging system based on zookeeper coordination) can be used to store the cloud host process encodings collected by one or more cloud hosts according to the cloud host process encoding collection task, and upload the corresponding cloud host process encodings to the cloud.
[0053] Preferably, according to the embodiments of the present invention, the cloud host process number collection task also indicates a collection period; the step of receiving the cloud host process numbers collected and sent by one or more cloud hosts includes:
[0054] Receiving the cloud host process numbers collected and sent by one or more cloud hosts at regular intervals according to the collection period.
[0055] Exemplarily, the collection period can be specified in the cloud host process number collection task generated by the user side. For example, the process encodings corresponding to the currently running processes on the cloud host are collected every five minutes.
[0056] Step S102, sequentially determining whether the process file information corresponding to the cloud host process number is detected for the first time.
[0057] Since the cloud host process codes of the same process are the same, by determining whether the process file information corresponding to the cloud host process number is detected for the first time, the process file information corresponding to the same cloud host process code is collected only once and only one detection is required, avoiding the situation that the same process file is collected and detected multiple times because it runs on multiple cloud hosts. This improves the efficiency of virus detection for a large number of cloud hosts. At the same time, it also reduces the load risk of the cloud hosts and effectively guarantees the operation of the cloud hosts' own services.
[0058] Step S103: If so, determine the cloud host number corresponding to the cloud host process number, generate and send a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extract the process file characteristics of the process file information, match the process file characteristics with the virus characteristics in the virus database, and determine the cloud host virus detection result according to the matching result; if not, use the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result.
[0059] Specifically, according to the embodiments of the present invention, determining the cloud host virus detection result according to the matching result includes:
[0060] Compare the matching degrees between the process file characteristics in the matching result and multiple virus characteristics in the virus database with the matching degree threshold respectively;
[0061] If there is a matching degree exceeding the matching degree threshold, determine the corresponding process file as a virus file.
[0062] The virus library is a collection of all known virus characteristics. After extracting the characteristics of the process file information that has not been detected, by sequentially matching the process file characteristics with all the virus characteristics in the virus characteristic set, it can be quickly determined whether the process file is a virus file.
[0063] Further, according to the embodiments of the present invention, the above method further includes:
[0064] Determine the virus file type, the target cloud host process number corresponding to the virus file type, and the target cloud host including the target cloud host process number;
[0065] Perform visual display according to the target cloud host, the target cloud host process number, and the virus file type.
[0066] According to the embodiments of the present invention, the risk level of the virus file can also be determined and displayed in the visual result.
[0067] According to the technical solution of the embodiment of the present invention, by receiving the cloud host process numbers collected and sent by one or more cloud hosts; wherein, the cloud host process numbers are collected by the cloud host according to the cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on the cloud host virus detection request; then successively determining whether the process file information corresponding to the cloud host process number is detected for the first time; if so, determining the cloud host number corresponding to the cloud host process number, generating and sending a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extracting the process file features of the process file information, matching the process file features with the virus features in the virus database, and determining the cloud host virus detection result according to the matching result; if not, using the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result, the technical problems existing in the existing methods for cloud host virus detection, especially when detecting viruses for a large number of cloud hosts in a cloud platform at the same time, such as low virus detection efficiency, high cloud host load risk, narrow applicable scenarios, and poor user experience, are overcome. Furthermore, the technical effect of being able to detect viruses for a large number of cloud hosts at the same time, improving the cloud host virus detection efficiency, reducing the load risk of the cloud host, effectively ensuring the operation of the cloud host's own business, and at the same time, being able to visually display the virus detection result, expanding the applicable scenarios of the virus detection method, and improving the user experience is achieved.
[0068] Figure 2 It is a schematic diagram of the main process of the cloud host virus detection method provided by another embodiment of the present invention; as Figure 2 shown, the cloud host virus detection method provided by the embodiment of the present invention is applied to a cloud host virus detection system, and mainly includes:
[0069] Step S201, the user side generates a cloud host process number collection task based on the cloud host virus detection request, and distributes the cloud host process number collection task to the cloud host.
[0070] Furthermore, according to the embodiment of the present invention, after the user side generates the cloud host process number collection task, the cloud host process number collection task can be stored first, for example, stored in redis (a key - value storage system), and then the cloud host process number collection task is distributed to multiple cloud hosts through the task scheduling center. Among them, the task scheduling center can be a separate component or a component set in the user side.
[0071] Step S202, the cloud host receives the cloud host process number collection task, collects the cloud host process number according to the cloud host process number collection task, and sends the cloud host process number to the cloud.
[0072] Specifically, according to the embodiments of the present invention, a large number of processes are running simultaneously in the cloud host. Therefore, the order of magnitude of the corresponding process codes is relatively large. By storing the process codes collected by the cloud host in a storage system, especially a distributed storage system, and then having the distributed storage system send the collected cloud host process codes to the cloud, the virus detection efficiency of the cloud host can be further improved.
[0073] According to a preferred embodiment of the embodiments of the present invention, one or more cloud host process codes collected by one or more cloud hosts according to the cloud host process code collection task can be stored through Kafka (a distributed, partitioned, multi-copy, multi-subscriber distributed log system based on ZooKeeper coordination), and the corresponding cloud host process codes can be uploaded to the cloud.
[0074] Step S203: The cloud receives the cloud host process number and determines whether the process file information corresponding to the cloud host process number is detected for the first time. If so, execute step S204; if not, execute step S205.
[0075] Since the cloud host process codes of the same process are the same, by determining whether the process file information corresponding to the cloud host process number is detected for the first time, the process file information corresponding to the same cloud host process code is only collected once and only needs to be detected once, avoiding the situation where the same process file is collected and detected multiple times because it runs on multiple cloud hosts. Furthermore, the virus detection efficiency of a large number of cloud hosts is improved. At the same time, the load risk of the cloud host is reduced, effectively ensuring the operation of the cloud host's own services.
[0076] Step S204: Determine the cloud host number corresponding to the cloud host process number, generate and send a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extract the process file features of the process file information, match the process file features with the virus features in the virus database, and determine the cloud host virus detection result according to the matching result.
[0077] Specifically, according to the embodiments of the present invention, determining the cloud host virus detection result according to the matching result includes:
[0078] Compare the matching degrees between the process file features in the matching result and multiple virus features in the virus database with the matching degree threshold respectively;
[0079] If there is a matching degree exceeding the matching degree threshold, determine the corresponding process file as a virus file.
[0080] The virus database is a collection of all known virus characteristics. After extracting the characteristics of the untested process file information, the characteristics of the process file are sequentially matched with all the virus characteristics in the virus characteristic set, and it can be quickly determined whether the process file is a virus file.
[0081] Step S205: Use the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result.
[0082] Step S206: Determine the virus file type, the target cloud host process number corresponding to the virus file type, and the target cloud host including the target cloud host process number; perform visual display according to the target cloud host, the target cloud host process number, and the virus file type.
[0083] According to the embodiments of the present invention, the risk level of the virus file can also be determined and displayed in the visual result.
[0084] According to the technical solution of the embodiments of the present invention, since it adopts the method of receiving the cloud host process numbers collected and sent by one or more cloud hosts; wherein, the cloud host process number is collected by the cloud host according to the cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on the cloud host virus detection request; sequentially determine whether the process file information corresponding to the cloud host process number is detected for the first time; if so, determine the cloud host number corresponding to the cloud host process number, generate and send a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extract the process file characteristics of the process file information, match the process file characteristics with the virus characteristics in the virus database, and determine the cloud host virus detection result according to the matching result; if not, use the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result, it overcomes the technical problems of the existing methods in the face of cloud host virus detection, especially when virus detection is performed on a large number of cloud hosts in a cloud platform at the same time, such as low virus detection efficiency, high cloud host load risk, narrow applicable scenarios, and poor user experience. Furthermore, it can achieve the technical effect of being able to perform virus detection on a large number of cloud hosts at the same time, improving the cloud host virus detection efficiency, reducing the load risk of the cloud host, effectively ensuring the operation of the cloud host's own business, and at the same time, the virus detection result can be visually displayed, expanding the applicable scenarios of the virus detection method and improving the user experience.
[0085] Figure 3 It is a schematic diagram of the main modules of the cloud host virus detection device provided by the embodiments of the present invention; as Figure 3 shown, the cloud host virus detection device 300 provided by the embodiments of the present invention is applied to the cloud and mainly includes:
[0086] The process ID receiving module 301 is configured to receive one or more cloud host process IDs collected and sent by cloud hosts; wherein, the cloud host process ID is collected by the cloud host according to the cloud host process ID collection task, and the cloud host process ID collection task is generated by the user side based on the cloud host virus detection request.
[0087] Specifically, according to an embodiment of the present invention, the cloud host process code may be a process name running on the cloud host, a process MD5 value, etc., which is used to represent the unique identifier of the process running on the cloud host. Since the cloud host process codes of the same process are the same, subsequently, it can be determined whether the process file information corresponding to the cloud host process ID is detected for the first time, and the process file information corresponding to the same cloud host process code is collected only once and only detected once, significantly improving the efficiency of virus detection for a large number of cloud hosts.
[0088] Further, according to an embodiment of the present invention, the above process ID receiving module 301 is further configured to:
[0089] Receive one or more cloud host process IDs collected by the cloud host according to the cloud host process ID collection task and sent via the storage system.
[0090] In an actual scenario, a large number of processes are running simultaneously in the cloud host, so the order of magnitude of the corresponding process codes is large. By storing the process codes collected by the cloud host in the storage system, especially the distributed storage system, and then the distributed storage system sends the corresponding collected cloud host process codes to the cloud, the efficiency of cloud host virus detection can be further improved.
[0091] According to a preferred embodiment of the present invention, one or more cloud host process IDs collected by the cloud host according to the cloud host process code collection task can be stored through kafka (a distributed, partitioned, multi-copy, multi-subscriber distributed log system based on zookeeper coordination), and the corresponding cloud host process codes are uploaded to the cloud.
[0092] Preferably, according to an embodiment of the present invention, the above cloud host process ID collection task also indicates a collection period; the above process ID receiving module 301 is further configured to:
[0093] Receive one or more cloud host process IDs collected and sent by the cloud host at regular intervals according to the collection period.
[0094] Exemplarily, the collection period can be specified in the cloud host process ID collection task generated by the user side, for example, collect the process codes corresponding to the currently running processes on the cloud host every five minutes.
[0095] The judgment module 302 is configured to sequentially judge whether the process file information corresponding to the cloud host process ID is detected for the first time.
[0096] Since the cloud host process codes of the same process are the same, by determining whether the process file information corresponding to the cloud host process number is detected for the first time, the process file information corresponding to the same cloud host process code is collected only once and only detected once, avoiding the situation where the same process file is collected and detected multiple times because it runs on multiple cloud hosts. This improves the efficiency of virus detection for a large number of cloud hosts. At the same time, it also reduces the load risk of the cloud hosts and effectively guarantees the operation of the cloud hosts' own services.
[0097] The detection module 303, if the process file information corresponding to the cloud host process number is detected for the first time, is used to determine the cloud host number corresponding to the cloud host process number, generate and send a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extract the process file characteristics of the process file information, match the process file characteristics with the virus characteristics in the virus database, and determine the cloud host virus detection result according to the matching result; if the process file information corresponding to the cloud host process number is not detected for the first time, it is used to use the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result.
[0098] Specifically, according to the embodiment of the present invention, the detection module 303 is further used for:
[0099] Compare the matching degrees between the process file characteristics in the matching result and multiple virus characteristics in the virus database with the matching degree threshold respectively;
[0100] If there is a matching degree exceeding the matching degree threshold, determine the corresponding process file as a virus file.
[0101] The virus library is a collection of all known virus characteristics. After extracting the characteristics of the untested process file information, by sequentially matching the process file characteristics with all the virus characteristics in the virus characteristic set, it can be quickly determined whether the process file is a virus file.
[0102] Further, according to the embodiment of the present invention, the above cloud host virus detection device 300 further includes a visual display module, which is used for:
[0103] Determine the virus file type, the target cloud host process number corresponding to the virus file type, and the target cloud host including the target cloud host process number;
[0104] Perform visual display according to the target cloud host, the target cloud host process number, and the virus file type.
[0105] According to the embodiment of the present invention, the virus file risk level can also be determined and displayed in the visual result.
[0106] According to the technical solution of the embodiment of the present invention, by receiving the cloud host process numbers collected and sent by one or more cloud hosts; wherein, the cloud host process numbers are collected by the cloud host according to the cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on the cloud host virus detection request; successively determining whether the process file information corresponding to the cloud host process number is detected for the first time; if so, determining the cloud host number corresponding to the cloud host process number, generating and sending a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extracting the process file characteristics of the process file information, matching the process file characteristics with the virus characteristics in the virus database, and determining the cloud host virus detection result according to the matching result; if not, using the result corresponding to the previous detection of the cloud host process number as the cloud host virus detection result, the technical problems of low virus detection efficiency, high cloud host load risk, narrow applicable scenarios, and poor user experience existing in the existing methods for cloud host virus detection, especially for virus detection of a large number of cloud hosts in a cloud platform at the same time, are overcome. Furthermore, the technical effect of being able to detect viruses for a large number of cloud hosts at the same time, improving the cloud host virus detection efficiency, reducing the load risk of the cloud host, effectively ensuring the operation of the cloud host's own business, and at the same time, being able to visually display the virus detection result, expanding the applicable scenarios of the virus detection method, and enhancing the user experience is achieved.
[0107] Figure 4 It is a schematic diagram of the main modules of the cloud host virus detection system provided by the embodiment of the present invention; as Figure 4 shown, the cloud host virus detection system 400 provided by the embodiment of the present invention mainly includes a cloud end, a user end, and one or more cloud hosts, wherein,
[0108] The user end 401 is used to generate a cloud host process number collection task based on the cloud host virus detection request and distribute the cloud host process number collection task to the cloud host 402.
[0109] The cloud host 402 is used to receive the cloud host process number collection task, collect the cloud host process number according to the cloud host process number collection task, and send the cloud host process number to the cloud end.
[0110] The cloud 300 (i.e., the cloud host virus detection device in the above text) is used to receive the cloud host process numbers collected by one or more cloud hosts 402 according to the cloud host process numbers; sequentially determine whether the process file information corresponding to the cloud host process number is detected for the first time; if so, determine the cloud host number corresponding to the cloud host process number, generate and send a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extract the process file features of the process file information, match the process file features with the virus features in the virus database, and determine the cloud host virus detection result according to the matching result; if not, use the result corresponding to the previous detection of the cloud host process number as the cloud host virus detection result.
[0111] According to the technical solution of the embodiment of the present invention, by adopting the method of receiving the cloud host process numbers collected and sent by one or more cloud hosts; wherein, the cloud host process numbers are collected by the cloud host according to the cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on the cloud host virus detection request; sequentially determine whether the process file information corresponding to the cloud host process number is detected for the first time; if so, determine the cloud host number corresponding to the cloud host process number, generate and send a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extract the process file features of the process file information, match the process file features with the virus features in the virus database, and determine the cloud host virus detection result according to the matching result; if not, use the result corresponding to the previous detection of the cloud host process number as the cloud host virus detection result, the technical problems existing in the existing methods for cloud host virus detection, especially when detecting viruses for a large number of cloud hosts in a cloud platform at the same time, such as low virus detection efficiency, high cloud host load risk, narrow applicable scenarios, and poor user experience, are overcome. Furthermore, the technical effect of being able to detect viruses for a large number of cloud hosts at the same time, improving the cloud host virus detection efficiency, reducing the load risk of the cloud host, effectively ensuring the operation of the cloud host's own business, and at the same time, being able to visually display the virus detection result, expanding the applicable scenarios of the virus detection method, and enhancing the user experience is achieved.
[0112] Figure 5 An exemplary system architecture 500 is shown in which the cloud host virus detection method or the cloud host virus detection device according to the embodiment of the present invention can be applied.
[0113] As Figure 5As shown, the system architecture 500 may include terminal devices 501, 502, 503, a network 504, and a server 505 (this architecture is merely an example, and the components included in the specific architecture can be adjusted according to the specific circumstances of the application). The network 504 is used to provide a medium for communication links between the terminal devices 501, 502, 503 and the server 505. The network 504 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0114] Users can use the terminal devices 501, 502, 503 to interact with the server 505 through the network 504 to receive or send messages, etc. Various communication client applications may be installed on the terminal devices 501, 502, 503, such as cloud host virus detection applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only examples).
[0115] The terminal devices 501, 502, 503 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.
[0116] The server 505 may be a server that provides various services, such as a server for (performing cloud host virus detection / processing data) by users using the terminal devices 501, 502, 503 (only an example). The server may analyze and process data such as the cloud host process number received, and feedback the processing results (such as cloud host virus detection results - only an example) to the terminal devices.
[0117] It should be noted that the cloud host virus detection method provided by the embodiments of the present invention is generally executed by the server 505. Correspondingly, the cloud host virus detection device is generally set in the server 505.
[0118] It should be understood that Figure 5 the numbers of terminal devices, networks, and servers in
[0119] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 6 The following refers to Figure 6 which shows a schematic structural diagram of a computer system 600 of a terminal device or a server suitable for implementing the embodiments of the present invention. Figure 6 The shown terminal device or server is merely an example and should not impose any limitations on the functions and usage scopes of the embodiments of the present invention.
[0120] As Figure 6As shown, computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage section 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the system 600 are also stored. The CPU 601, ROM 602, and RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0121] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed so that a computer program read from it can be installed into the storage section 608 as needed.
[0122] Specifically, according to the embodiments disclosed in the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present invention include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 609, and / or installed from the removable medium 611. When the computer program is executed by the central processing unit (CPU) 601, the above-described functions defined in the system of the present invention are executed.
[0123] It should be noted that the computer-readable medium shown in the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the above two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0124] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0125] The modules involved in the embodiments of the present invention can be implemented in software or in hardware. The described modules can also be provided in a processor. For example, it can be described as: a processor includes a process number receiving module, a judgment module, and a detection module. Among them, the names of these modules do not constitute a limitation to the module itself in some cases. For example, the process number receiving module can also be described as "a module for receiving the cloud host process numbers collected and sent by one or more cloud hosts".
[0126] As another aspect, the present invention also provides a computer-readable medium. The computer-readable medium can be included in the device described in the above embodiments; or it can exist separately without being assembled into the device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the device, the device includes: receiving the cloud host process numbers collected and sent by one or more cloud hosts; wherein, the cloud host process numbers are collected by the cloud host according to the cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on the cloud host virus detection request; sequentially judging whether the process file information corresponding to the cloud host process number is detected for the first time; if so, determining the cloud host number corresponding to the cloud host process number, generating and sending a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extracting the process file features of the process file information, matching the process file features with the virus features in the virus database, and determining the cloud host virus detection result according to the matching result; if not, using the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result.
[0127] According to the technical solution of the embodiment of the present invention, by receiving the cloud host process numbers collected and sent by one or more cloud hosts; wherein, the cloud host process numbers are collected by the cloud host according to the cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on the cloud host virus detection request; successively determining whether the process file information corresponding to the cloud host process number is detected for the first time; if so, determining the cloud host number corresponding to the cloud host process number, generating and sending a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extracting the process file features of the process file information, matching the process file features with the virus features in the virus database, and determining the cloud host virus detection result according to the matching result; if not, using the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result, the technical problems of the existing method in the face of cloud host virus detection, especially when detecting viruses for a large number of cloud hosts in the cloud platform at the same time, such as low virus detection efficiency, high cloud host load risk, narrow applicable scenarios, and poor user experience are overcome. Furthermore, the technical effect of being able to detect viruses for a large number of cloud hosts at the same time, improving the cloud host virus detection efficiency, reducing the load risk of the cloud host, effectively ensuring the operation of the cloud host's own business, and at the same time, being able to visually display the virus detection results, expanding the applicable scenarios of the virus detection method, and enhancing the user experience is achieved.
[0128] The above specific embodiments do not constitute a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub - combinations and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A cloud host virus detection method, characterized in that, Applied to the cloud, including: Receiving the cloud host process numbers collected and sent by one or more cloud hosts; wherein, the cloud host process numbers are collected by the cloud host according to the cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on the cloud host virus detection request; Sequentially determining whether the process file information corresponding to the cloud host process number is for the first detection; If so, determining the cloud host number corresponding to the cloud host process number, generating and sending a process file information collection task to the cloud host corresponding to the cloud host number to receive the process file information returned by the cloud host, extracting the process file features of the process file information, matching the process file features with the virus features in the virus database, and determining the cloud host virus detection result according to the matching result; if not, using the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result.
2. The cloud host virus detection method according to claim 1, characterized in that, The step of receiving the cloud host process numbers collected and sent by one or more cloud hosts includes: Receiving the cloud host process numbers collected by one or more cloud hosts according to the cloud host process number collection task and sent via the storage system.
3. The cloud host virus detection method according to claim 1, characterized in that, The determining the cloud host virus detection result according to the matching result includes: Comparing the matching degrees of the process file features in the matching result with multiple virus features in the virus database respectively with the matching degree threshold; If there is a matching degree exceeding the matching degree threshold, determining the corresponding process file as a virus file.
4. The cloud host virus detection method according to claim 3, characterized in that, It also includes: Determining the virus file type, the target cloud host process number where the virus file corresponding to the virus file type is located, and the target cloud host including the target cloud host process number; Performing visual display according to the target cloud host, the target cloud host process number, and the virus file type.
5. The cloud host virus detection method according to claim 1 or 2, characterized in that, The cloud host process number collection task also indicates a collection period; the step of receiving the cloud host process numbers collected and sent by one or more cloud hosts includes: Receiving the cloud host process numbers collected and sent by one or more cloud hosts at regular intervals according to the collection period.
6. A cloud host virus detection device, characterized in that, Set in the cloud, including: A process number receiving module, configured to receive the cloud host process numbers collected and sent by one or more cloud hosts; wherein, the cloud host process numbers are collected by the cloud host according to the cloud host process number collection task, and the cloud host process number collection task is generated by the user side based on the cloud host virus detection request; A judgment module, configured to sequentially determine whether the process file information corresponding to the cloud host process number is for the first detection; A detection module, if the process file information corresponding to the cloud host process number is detected for the first time, is used to determine the cloud host number corresponding to the cloud host process number, generate and send a process file information collection task to the cloud host corresponding to the cloud host number, so as to receive the process file information returned by the cloud host, extract the process file features of the process file information, match the process file features with the virus features in the virus database, and determine the cloud host virus detection result according to the matching result; if the process file information corresponding to the cloud host process number is not detected for the first time, is used to use the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result.
7. The cloud host virus detection device according to claim 6, characterized in that, The detection module is further used for: Comparing the matching degrees between the process file features in the matching result and multiple virus features in the virus database with the matching degree threshold respectively; If there is a matching degree exceeding the matching degree threshold, determining the corresponding process file as a virus file.
8. A cloud host virus detection system, characterized in that, It includes a cloud end, a user end and one or more cloud hosts, wherein, The user end is used to generate a cloud host process number collection task based on a cloud host virus detection request and distribute the cloud host process number collection task to the cloud host; The cloud host is used to receive the cloud host process number collection task, collect the cloud host process number according to the cloud host process number collection task, and send the cloud host process number to the cloud end; The cloud end is used to receive the cloud host process number; successively determine whether the process file information corresponding to the cloud host process number is detected for the first time; if so, determine the cloud host number corresponding to the cloud host process number, generate and send a process file information collection task to the cloud host corresponding to the cloud host number, so as to receive the process file information returned by the cloud host, extract the process file features of the process file information, match the process file features with the virus features in the virus database, and determine the cloud host virus detection result according to the matching result; if not, use the result corresponding to the last detection of the cloud host process number as the cloud host virus detection result.
9. An electronic device for cloud host virus detection, characterized in that, It includes: One or more processors; A storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the method according to any one of claims 1-5.
10. A computer-readable medium having a computer program stored thereon, characterized in that, The program, when executed by the processor, implements the method according to any one of claims 1-5.
Citation Information
Patent Citations
Suspicious process detection method and device
CN106033514A
Cloud host security detection system and method
CN110099044A