A method, device, equipment and storage medium for processing false alarm files

By receiving and analyzing the detection logs uploaded by the terminal, and generating and automatically issuing false positive black and white files, the problem of low processing efficiency of false positive files is solved, and rapid closed-loop processing and user experience improvement is achieved.

CN115017114BActive Publication Date: 2025-06-20SANGFOR TECH INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210617254.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-01
Publication Date
2025-06-20
Estimated Expiration
2042-06-01

AI Technical Summary

Technical Problem

In the prior art, the processing efficiency of false alarm files is low, and manual intervention is required for multiple links, resulting in a long and untimely processing time.

Method used

By receiving the detection log uploaded by the terminal, false alarm information is analyzed and generated, false alarm information is used to generate false alarm black and white files, and automatically sent to each terminal for them to delete cached data.

Benefits of technology

It realizes the automated processing of false positive files, improves processing efficiency, reduces manual intervention, ensures rapid closed-loop processing of false positives, and improves user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115017114B_ABST
    Figure CN115017114B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, apparatus, device and storage medium for processing false alarm files; in this solution, after the terminal detects a false alarm file, it will automatically report the detection log. After automatically analyzing the detection log to generate false alarm information, false alarm black and white lists can be generated according to the generated false alarm information and automatically sent to each terminal, so that each terminal can automatically delete the corresponding cached files according to the false alarm black and white lists. In this way, automatic processing of false alarm files can be realized, and the processing efficiency can be improved; moreover, in this solution, by deleting cached data, false alarms caused by the cached data can be avoided, and a closed-loop processing of false alarms can be realized, improving the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technologies, and more particularly, to a method, apparatus, device, and storage medium for processing false positive files. Background Art

[0002] Currently, when false positives occur during the scanning of security software in a product line, the following methods are mainly used for processing: First, after a false positive is generated by the security software, it is manually reported to the cloud. After backscanning by the cloud and manual screening, the updated black and white lists are manually entered into the reputation database and manually updated to users. It can be seen that the current method for processing false positives has low efficiency, and multiple intermediate links require manual intervention, making it difficult to process false positive files in a timely and rapid manner. Summary of the Invention

[0003] The purpose of the present invention is to provide a method, apparatus, device, and storage medium for processing false positive files, so as to improve the processing efficiency of false positive files.

[0004] To achieve the above purpose, a method for processing false positive files provided by the present invention includes:

[0005] Receiving detection logs uploaded by a terminal; the detection logs are automatically uploaded by the terminal when a false positive file is detected;

[0006] Analyzing the detection logs to generate false positive information;

[0007] Generating false positive black and white files using the false positive information;

[0008] Automatically sending the false positive black and white files to each terminal, so that each terminal deletes corresponding cached data according to the false positive black and white files.

[0009] Among them, when receiving the detection logs uploaded by the terminal, it further includes:

[0010] Receiving the false positive file uploaded by the terminal;

[0011] Correspondingly, analyzing the detection logs to generate false positive information includes: analyzing the detection logs and the false positive file to generate false positive information.

[0012] Among them, after analyzing the detection logs to generate false positive information, it further includes:

[0013] Storing the false positive information in a database.

[0014] Among them, generating false positive black and white files using the false positive information includes:

[0015] Using the update time of each false positive information to search for unprocessed false positive information in the database;

[0016] Generate a false alarm black and white file based on the unprocessed false alarm information.

[0017] After searching for unprocessed false alarm information in the database, it further includes:

[0018] Update the reputation library file using the unprocessed false alarm information.

[0019] After updating the reputation library file using the unprocessed false alarm information, it further includes:

[0020] Automatically distribute the updated reputation library file to each terminal so that each terminal can perform black and white file detection based on the updated reputation library file.

[0021] Before automatically distributing the updated reputation library file to each terminal, it further includes:

[0022] Test the updated reputation library file;

[0023] If the test passes, continue to execute the step of automatically distributing the updated reputation library file to each terminal.

[0024] To achieve the above object, the present invention further provides a false alarm file processing device, including:

[0025] A receiving module for receiving the detection log uploaded by the terminal; the detection log is automatically uploaded when the terminal detects a false alarm file;

[0026] An analysis module for analyzing the detection log to generate false alarm information;

[0027] A file generation module for generating a false alarm black and white file using the false alarm information;

[0028] A file distribution module for automatically distributing the false alarm black and white file to each terminal so that each terminal can delete the corresponding cached data according to the false alarm black and white file.

[0029] To achieve the above object, the present invention further provides an electronic device, including:

[0030] A memory for storing a computer program;

[0031] A processor for implementing the steps of the above false alarm file processing method when executing the computer program.

[0032] To achieve the above object, the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above false alarm file processing method are implemented.

[0033] As can be seen from the above solution, an error report file processing method, device, equipment and storage medium provided by an embodiment of the present invention; in this solution, first, it is necessary to receive the detection log uploaded by the terminal; the detection log is automatically uploaded when the terminal detects an error report file; analyze the detection log to generate error report information; use the error report information to generate an error report black and white file, and automatically send the error report black and white file to each terminal, so that each terminal can delete the corresponding cached data according to the error report black and white file.

[0034] It can be seen that in this solution, after the terminal detects an error report file, it will automatically report the detection log. After automatically analyzing the detection log to generate error report information, an error report black and white list can be generated according to the generated error report information and automatically sent to each terminal, so that each terminal can automatically delete the corresponding cached file according to the error report black and white list. Through this method, automatic processing of error report files can be realized, and the processing efficiency can be improved; moreover, in this solution, by deleting the cached data, it is possible to avoid the generation of error reports by the cached data again, realize closed-loop processing of error reports, and improve the user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0036] Figure 1 It is a schematic structural diagram of an error report file processing system disclosed in an embodiment of the present invention;

[0037] Figure 2 It is a schematic flow chart of an error report file processing method disclosed in an embodiment of the present invention;

[0038] Figure 3 It is a schematic flow chart of another error report file processing method disclosed in an embodiment of the present invention;

[0039] Figure 4 It is a schematic flow chart of another error report file processing method disclosed in an embodiment of the present invention;

[0040] Figure 5 It is an overall flow chart of an error report file processing method disclosed in an embodiment of the present invention;

[0041] Figure 6 It is a schematic structural diagram of an error report file processing device disclosed in an embodiment of the present invention;

[0042] Figure 7Schematic structural diagram of an electronic device disclosed in an embodiment of the present invention. Detailed implementation manners

[0043] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0044] For the convenience of understanding, the system architecture applicable to the technical solution of the present application will be introduced below. Refer to Figure 1 , which is a schematic structural diagram of a system for processing misreported files disclosed in an embodiment of the present invention. Refer to Figure 1 , the system includes a terminal 11, a cloud analysis platform 12, and a local terminal operation platform 13.

[0045] In this embodiment, the terminal 11 is each terminal in the product line, and the number of the terminals is not limited. Figure 1 Only one terminal is taken as an example for illustration. A security software is installed in the terminal 11. When the security software performs a security scan on the terminal 11, misreported files will be generated. The misreported files include misreports of black files and misreports of white files. A misreport of a black file means that a normal file is identified as a malicious file, and a misreport of a white file means that a malicious file is identified as a normal file.

[0046] In this embodiment, after the terminal 11 detects a misreported file, it is necessary to analyze the detection log of the misreported file in order to generate automatically updated misreported black and white files to each terminal 11. It should be noted that for the two processes of analyzing the detection log and generating automatically updated misreported black and white files to each terminal 11 in this solution, both can be implemented by the cloud analysis platform 12 or both can be implemented by the local terminal operation platform 13. However, in this solution, in order to make full use of the powerful computing power of the cloud analysis platform 12 and avoid occupying too much cloud processing resources, the process of analyzing the detection log can be implemented by the cloud analysis platform 12, and accurate analysis results can be obtained through the processing resources of the cloud analysis platform 12; for the process of generating misreported black and white files and automatically updating them to each terminal 11, it does not require too many resources and can be implemented by the local terminal operation platform 13. That is: in this solution, after the cloud analysis platform 12 receives the detection log uploaded by the terminal 11, it uses the processing resources of the cloud 11 to analyze the detection log to generate misreport information; after the local terminal operation platform 13 uses the misreport information to generate misreported black and white files, it automatically distributes the misreported black and white files to each terminal 11 so that each terminal 11 can delete the corresponding cached data according to the misreported black and white files.

[0047] It can be seen that for the entire processing process of false positive files in this solution, from the automatic reporting of false positive files, the automatic analysis of detection logs, to the automatic distribution and update of false positive black and white files, no manual processing is required, which improves the processing efficiency. Moreover, this solution can quickly clear the cached data of false positive files, achieve fast closed-loop processing of false positives, avoid false positives caused by cached data again, and improve the user experience.

[0048] See Figure 2 , which is a schematic flowchart of a method for processing false positive files disclosed in an embodiment of the present invention, including:

[0049] S101. Receive the detection log uploaded by the terminal; the detection log is automatically uploaded when the terminal detects a false positive file;

[0050] In this embodiment, after each terminal detects a false positive file, it will automatically upload the detection log of the false positive file. By this means, manual uploading of false positive files can be avoided, thereby realizing timely processing of false positive files.

[0051] Specifically, the false positive file can be a file of an uncertain black and white type detected by each terminal, and the terminal can detect false positive files through various methods. For example, false positive files can be detected through multiple methods such as an AI (Artificial Intelligence) engine and an antivirus engine, and the false positive file is reported to identify false positive information. In this embodiment, the detection log includes detection information such as the hash value of the false positive file, the detection result of the false positive file, and how the terminal generates the false positive file. The detection result of the false positive file is the preliminary determination by the terminal of the black and white type of the false positive file, which can be a black file or a white file. Among them, a black file refers to a file whose static characteristics or activities pose a threat to the system environment where it is located and damage the system, and vice versa for a white file.

[0052] S102. Analyze the detection log to generate false positive information;

[0053] In this embodiment, when analyzing the detection log to generate false positive information, it can be analyzed through the local terminal operation platform or through the cloud analysis platform. In this embodiment, in order to improve the analysis accuracy and efficiency, the analysis through the cloud analysis platform is taken as an example for illustration. When this embodiment analyzes and processes the detection log, it will scan through the cloud analysis platform and identify false positive information through multiple analysis engines. The information recorded in the false positive information includes: update time, hash value, black / white type, virus name, whether there is a sample in the cloud analysis platform, and other information. Generally, the cloud analysis platform can determine the false positive information by parsing the detection log to analyze the source of the false positive file, etc. In extreme cases, if the cloud analysis platform cannot automatically analyze the false positive information, manual identification can be introduced.

[0054] S103. Generate false positive black / white files using the false positive information;

[0055] In this embodiment, for all false positive information generated by terminals uploading detection logs, corresponding false positive black / white files will be generated and sent to each terminal. The false positive black / white file records: hash value, black / white type, etc. The role of the false positive black / white file is to clear the local cache data of each terminal to prevent false positives from existing for a long time due to the existence of cache data.

[0056] S104. Automatically send the false positive black / white files to each terminal so that each terminal can delete the corresponding cache data according to the false positive black / white files.

[0057] Specifically, in the traditional solution, during the process of each terminal generating a detection log for a false positive file, a copy of the cache data will also be saved locally. The cache data records the detection process data of the false positive file, including the above detection log, false positive file hash value, black / white type, and other information. If the cache data is always stored locally on the terminal, then during each security scan, the terminal will scan out the corresponding cache data and determine again that there is a false positive file on the terminal, making it impossible to achieve a closed-loop processing of the false positive file. Therefore, in this embodiment, it is necessary to generate a false positive black / white file according to the false positive information. After sending the false positive black / white file to each terminal, each terminal uses the hash value recorded in the false positive black / white file to match the hash value of the false positive file in each cache data. If the hash value recorded in the false positive black / white file is the same as the hash value of the false positive file recorded in the cache data, it means that the detection log of the false positive file corresponding to the cache data has been processed by the cloud analysis platform. At this time, the cache data can be deleted to achieve a closed-loop processing of the false positive file.

[0058] In this embodiment, S103 and S104 can be directly implemented through the cloud analysis platform or through the local terminal operation platform. Here, only the implementation through the local terminal operation platform is taken as an example for illustration.

[0059] Specifically, when the local terminal operation platform generates false alarm black and white files using false alarm information, the timing for the local terminal operation platform to generate false alarm black and white files can be determined according to the priority of each false alarm information. For example: If the generated false alarm information has a relatively low priority, the local terminal operation platform can be set to actively obtain false alarm information from the cloud analysis platform every other day; if the generated false alarm information has a relatively high priority, the cloud analysis platform can be made to actively send the corresponding false alarm information to the local terminal operation platform, or the local terminal operation platform can be notified to actively obtain false alarm information from the cloud analysis platform. The priority of false alarm information can be determined according to different rules. For example, if the priority is determined according to the impact degree of the false alarm file, the priority of the false alarm information of the black file is greater than that of the false alarm information of the white file; if the priority is determined according to the occurrence times of the false alarm file, the higher the occurrence times of the false alarm file, the higher its priority.

[0060] In summary, it can be seen that this solution can achieve automatic closed-loop processing of false alarms according to the false alarm black and white lists. During the entire processing process of false alarm files, from the unified automatic reporting of false alarm files, the automatic analysis of detection logs, the automatic distribution and update of false alarm black and white files, to the clearing of cache data on the terminal, no manual processing is required, reducing manual input and improving processing efficiency; moreover, this solution can quickly clear the cache data of false alarm files, achieve fast closed-loop processing of false alarms, avoid false alarms caused by cache data again, and improve the user experience.

[0061] See Figure 3 , which is a schematic flow diagram of another method for processing false alarm files disclosed in an embodiment of the present invention, including:

[0062] S201. Receive the detection log and false alarm file uploaded by the terminal; the detection log is automatically uploaded by the terminal when a false alarm file is detected;

[0063] S202. Analyze the detection log and false alarm file to generate false alarm information;

[0064] S203. Store the false alarm information in the database;

[0065] S204. Use the update time of each false alarm information to find the unprocessed false alarm information in the database, and generate false alarm black and white files according to the unprocessed false alarm information;

[0066] S205. Automatically distribute the false alarm black and white files to each terminal so that each terminal can delete the corresponding cache data according to the false alarm black and white files.

[0067] In this embodiment, when the terminal detects a false alarm file, it can upload only the detection log of the false alarm file, or upload the false alarm file and the detection log together. Specifically, how to upload it needs to be determined according to the user's pre-setting. If the user does not want to upload the original false alarm file, only the detection log can be uploaded. If the content uploaded by the terminal includes the detection log and the false alarm file, when the cloud analysis platform analyzes, it can analyze based on both the detection log and the false alarm file to obtain false alarm information. Moreover, for the generated false alarm information, it can be recorded in the Hive database. This Hive is a set of data warehouse analysis systems built based on Hadoop (distributed file system), and it provides rich SQL query methods to analyze the data stored in Hadoop. Since the false alarm information recorded in the database includes the update time, when the local terminal operation platform obtains the false alarm information from the database, it can determine the unprocessed false alarm information by comparing the time of the last acquisition of the false alarm information with the update time of each false alarm information, so as to generate false alarm black and white files according to the unprocessed false alarm information. For example, if the time of the last acquisition of the false alarm information is 9:00 on January 1st, then for the false alarm information with the update time between 9:00 on January 1st and the current time, it is the unprocessed false alarm information. It should be noted that this embodiment is not limited to the above-mentioned determination method. This embodiment can also determine the unprocessed false alarm information through other methods. For example, in the database, record the processing status of each false alarm information. If the false alarm information has not been obtained by the local terminal operation platform, its processing status is unprocessed. If the false alarm information has been obtained by the local terminal operation platform, its processing status is processed.

[0068] It can be seen that in this embodiment, when each terminal uploads the detection log, it can report the false alarm file to the cloud analysis platform together, so that the cloud analysis platform can obtain a more accurate analysis result through the analysis of the detection log and the false alarm file. Moreover, after this solution stores the false alarm information in the database, the local terminal operation platform can accurately find the unprocessed false alarm information according to the update time recorded in each false alarm information. In this way, it can be avoided that the false alarm black and white files are repeatedly sent to each terminal, thus avoiding waste of resources.

[0069] See Figure 4 , which is a schematic flowchart of another method for processing false alarm files disclosed in the embodiment of the present invention, including:

[0070] S301. Receive the detection log and the false alarm file uploaded by the terminal; the detection log is automatically uploaded when the terminal detects the false alarm file;

[0071] S302. Analyze the detection log and the false alarm file to generate false alarm information;

[0072] S303. Store the false alarm information in the database;

[0073] S304. Use the update time of each false alarm message to search for unprocessed false alarm messages in the database;

[0074] S305. Generate a false alarm black and white file based on the unprocessed false alarm messages, and update the reputation library file using the unprocessed false alarm messages;

[0075] S306. Automatically distribute the false alarm black and white file to each terminal so that each terminal can delete the corresponding cached data according to the false alarm black and white file; automatically distribute the updated reputation library file to each terminal so that each terminal can perform black and white file detection according to the updated reputation library file.

[0076] In this embodiment, the reputation library records black and white lists. The black list refers to a file list composed of black file hash values, and the white list refers to a file list composed of white file hash values. When each terminal performs file scanning, it will compare and judge the file hash value according to the black and white lists in the reputation library to distinguish the file type. Therefore, in this embodiment, after the cloud analysis platform obtains the false alarm information of the false alarm file, the local terminal operation platform can also update the reputation library file according to the black and white type and file hash in the unprocessed false alarm information. After the updated reputation library file is also distributed to each terminal, each terminal can identify black and white files according to the updated reputation library file to avoid generating false alarms again.

[0077] It should be noted that since the unprocessed false alarm information obtained in this embodiment also needs to update the reputation library file, this embodiment preferentially determines the priority according to the occurrence times of the false alarm file, that is: if the cloud analysis platform finds that there are more than a predetermined number of terminals uploading the detection logs corresponding to the same false alarm file within a short period of time, at this time, in order to avoid more terminals uploading the detection logs corresponding to the false alarm file, the cloud analysis platform can actively distribute the false alarm information corresponding to the false alarm file so that the local terminal operation platform can update the reputation library file according to the false alarm information and distribute it to each terminal to avoid more terminals generating false alarms and achieve a fast closed-loop of false alarms.

[0078] In the traditional solution, different departments need to maintain different black and white lists. For example, the cloud analysis platform needs to maintain a black and white list, and different processing engines of the terminal also need to maintain different black and white lists, and different departments have different disposal standards for the black and white lists, resulting in the non-uniformity of the black and white lists; while in this application, the cloud analysis platform can update the black and white lists recorded in the database by storing the false alarm information in the database, and the local terminal operation platform in this solution also needs to update the reputation library file in the terminal according to the false alarm information of the cloud analysis platform, so as to realize the unified maintenance of the black and white lists of different departments and reduce the operation cost.

[0079] In this embodiment, before automatically distributing the updated reputation library file to each terminal, it is also necessary to test the updated reputation library file; if the test passes, then continue to automatically distribute the updated reputation library file to each terminal. Specifically, this solution can test the updated reputation library file through the local terminal operation platform. The specific test content can be: using the updated reputation library file for file type identification, determining whether there is a false alarm again, determining whether it will affect the previous determination results, etc., which are not specifically limited here. If the test is successful, then update the false alarm black and white files and the updated reputation library file to the terminals of each product line across the network; if the test fails, then there is no need to distribute the false alarm black and white files and the updated reputation library file to the terminals to ensure the accuracy of the reputation library.

[0080] As can be seen from the above, this solution generates false alarm information through the cloud analysis platform, and the local terminal operation platform generates false alarm black and white lists and reputation library files according to this false alarm information, and distributes them to each terminal to eliminate false alarms. In this way, the operation cost is reduced, the false alarm handling efficiency is improved, a fast closed-loop for false alarms is achieved, and the user experience is effectively improved.

[0081] See Figure 5 , which is the overall flowchart of a method for processing false alarm files disclosed in an embodiment of the present invention. In this embodiment, when a product line detects a false alarm file during sample scanning, it will report its detection log and sample (false alarm file) to the cloud analysis platform, and use the processing ability of the cloud analysis platform to identify the reported detection log and sample. When the cloud analysis platform parses the corresponding source when parsing the product line detection log and discovers false alarm information, it will enter the false alarm information into the hive database to record in real time the situation of false alarms generated by each engine and component of the operating product line. Further, the local terminal operation platform obtains the false alarm information from the cloud analysis platform, generates false alarm black and white files and a reputation library file according to it, and packages them for testing. After the test is error-free, the whole network can be updated. After the update, the product line will clear the cache according to the false alarm black and white files to prevent false alarms from occurring again. The whole process does not require manual participation under normal circumstances, greatly saving the operation cost, improving the efficiency of false alarm handling, and achieving a fast closed-loop for false alarms.

[0082] It can be seen that compared with the existing method, this solution can realize automatic processing and update of false alarms, clear false alarms in the product line, and achieve a fast closed-loop by uniformly reporting the detection log and false alarm files. Moreover, this solution can unify the reputation library storage standard, and the whole process does not require manual participation under normal circumstances, greatly saving the operation cost, improving the efficiency of false alarm handling, and achieving a fast closed-loop for false alarms.

[0083] The processing device, equipment, and storage medium provided by the embodiments of the present invention will be introduced below. The processing device, equipment, and storage medium described below can be referred to each other with the processing method described above.

[0084] See Figure 6 , a schematic structural diagram of a processing device for false alarm files provided by an embodiment of the present invention, including:

[0085] A receiving module 21, configured to receive the detection log uploaded by the terminal; the detection log is automatically uploaded by the terminal when a false alarm file is detected;

[0086] An analysis module 22, configured to analyze the detection log to generate false alarm information;

[0087] A file generation module 23, configured to generate a false alarm black and white file by using the false alarm information;

[0088] A file distribution module 24, configured to automatically distribute the false alarm black and white file to each terminal, so that each terminal deletes the corresponding cached data according to the false alarm black and white file.

[0089] Among them, the receiving module is further configured to: receive the false alarm file uploaded by the terminal;

[0090] Correspondingly, the analysis module is specifically configured to: analyze the detection log and the false alarm file to generate false alarm information.

[0091] Among them, the processing device further includes:

[0092] A storage module, configured to store the false alarm information in a database.

[0093] Among them, the file generation module includes:

[0094] A search unit, configured to search for unprocessed false alarm information in the database by using the update time of each false alarm information;

[0095] A first generation unit, configured to generate a false alarm black and white file according to the unprocessed false alarm information.

[0096] Among them, the file generation module further includes:

[0097] A second generation unit, configured to update the reputation library file by using the unprocessed false alarm information.

[0098] Among them, the file distribution module is further configured to: automatically distribute the updated reputation library file to each terminal, so that each terminal performs black and white file detection according to the updated reputation library file.

[0099] Among them, the file generation module further includes:

[0100] A test unit for testing the updated credit database file; if the test passes, the file distribution module is triggered.

[0101] See Figure 7 , which is a schematic structural diagram of an electronic device disclosed in an embodiment of the present invention; the device includes:

[0102] A memory 31 for storing a computer program;

[0103] A processor 32 for implementing the steps of the method for processing false alarm files as described in any of the above method embodiments when executing the computer program.

[0104] In this embodiment, the device may be a server of a cloud analysis platform, or a terminal or a server in a local terminal operation platform.

[0105] The device may include a memory 31, a processor 32, and a bus 33.

[0106] Among them, the memory 31 includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program, and the memory provides an environment for the operation of the operating system and computer-readable instructions in the non-volatile storage medium. The processor 32 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips in some embodiments, providing computing and control capabilities for the gateway device, and when executing the computer program stored in the memory 31, it can implement the steps of the execution processing method disclosed in any of the foregoing embodiments.

[0107] The bus 33 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 7 only a thick line is shown in, but it does not mean that there is only one bus or one type of bus.

[0108] Further, the device may further include a network interface 34, and the network interface 34 may optionally include a wired interface and / or a wireless interface (such as a WI-FI interface, a Bluetooth interface, etc.), and is usually used to establish a communication connection between the device and other electronic devices.

[0109] Figure 7 Only the device with components 31-34 is shown, and those skilled in the art can understand that Figure 7The structures shown do not constitute a limitation on the device, which may include fewer or more components than shown, or combine certain components, or have different component arrangements.

[0110] An embodiment of the present invention also discloses a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the method for processing false alarm files described in any of the above method embodiments are implemented.

[0111] Among them, the storage medium may include: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0112] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference may be made to each other.

[0113] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for processing false alarm files, characterized in that, including: Receiving detection logs uploaded by a receiving terminal; the detection logs are automatically uploaded when the terminal detects a false alarm file; Analyzing the detection logs to generate false alarm information; Storing the false alarm information in a database; Generating a false alarm black and white file using the false alarm information; wherein, generating a false alarm black and white file using the false alarm information includes: using the update time of each false alarm information to find unprocessed false alarm information from the database; generating a false alarm black and white file according to the unprocessed false alarm information; the false alarm black and white file is used to clear the local cache data of each terminal; Automatically sending the false alarm black and white file to each terminal so that each terminal deletes the corresponding cache data according to the false alarm black and white file.

2. The processing method according to claim 1, characterized in that, When receiving the detection logs uploaded by the receiving terminal, it further includes: Receiving the false alarm file uploaded by the terminal; Correspondingly, analyzing the detection logs to generate false alarm information includes: analyzing the detection logs and the false alarm file to generate false alarm information.

3. The processing method according to claim 1, characterized in that, After finding unprocessed false alarm information from the database, it further includes: Updating the reputation library file using the unprocessed false alarm information.

4. The processing method according to claim 3, characterized in that, After updating the reputation library file using the unprocessed false alarm information, it further includes: Automatically sending the updated reputation library file to each terminal so that each terminal performs black and white file detection according to the updated reputation library file.

5. The processing method according to claim 4, characterized in that, Before automatically sending the updated reputation library file to each terminal, it further includes: Testing the updated reputation library file; If the test passes, then continue to execute the step of automatically sending the updated reputation library file to each terminal.

6. A device for processing false alarm files, characterized in that, including: A receiving module for receiving detection logs uploaded by a terminal; the detection logs are automatically uploaded when the terminal detects a false alarm file; An analysis module for analyzing the detection logs to generate false alarm information; A storage module for storing the false alarm information in a database; A file generation module for generating a false alarm black and white file using the false alarm information; wherein, the file generation module includes: a search unit for using the update time of each false alarm information to find unprocessed false alarm information from the database; a first generation unit for generating a false alarm black and white file according to the unprocessed false alarm information; the false alarm black and white file is used to clear the local cache data of each terminal; A file sending module for automatically sending the false alarm black and white file to each terminal so that each terminal deletes the corresponding cache data according to the false alarm black and white file.

7. An electronic device, characterized in that, including: A memory for storing a computer program; A processor for implementing the steps of the false alarm file processing method according to any one of claims 1 to 5 when executing the computer program.

8. A computer-readable storage medium, characterized in that, A computer program is stored on a computer-readable storage medium, and when the computer program is executed by a processor, it implements the steps of the false alarm file processing method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Detection and minimization of false positives in anti-malware processing

    CN101901314A

  • Real-time misreport removal method

    CN102737087A

  • A false alarm behavior processing method and device

    CN109815697A