A method and device for virus infection processing based on LuaJIT

Through the luajit-based virus infection treatment method and virus scanning and processing combined with virus identification, the problem of difficulty in maintaining virus detection and killing services in the existing technology is solved, and simplified maintenance of virus detection and killing services is achieved.

CN115062305BActive Publication Date: 2025-06-17ZHUHAI BAOQU TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210743444.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-28
Publication Date
2025-06-17
Estimated Expiration
2042-06-28

AI Technical Summary

Technical Problem

The existing virus detection and killing services are difficult to maintain when facing a huge virus system and rapidly updated viruses, and it is difficult to effectively simplify the maintenance of virus detection and killing services.

Method used

The virus infection treatment method based on luajit is used to compare the file feature information of the target file with the virus feature information in the preset virus processing library to determine whether the target file is a virus-associated file, and the virus identifier is used to obtain the repair script bytecode from the preset virus processing library for processing.

Benefits of technology

By combining virus scanning with virus processing, the flexibility of luajit language and the systematicity of virus identification is effectively simplified in the maintenance of virus detection and killing services, avoiding the chaos and tediousness between virus scanning and processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115062305B_ABST
    Figure CN115062305B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention discloses a method and device for virus infection processing based on LuaJIT, which relates to the field of computer technology and can effectively simplify the maintenance of virus detection and killing services. The method includes: determining whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in a preset virus processing library, where the virus-related file includes a virus file and / or a file infected by a virus, and the preset virus processing library is established based on the LuaJIT language; in response to the target file being the virus-related file, obtaining the virus identifier corresponding to the virus-related file from the preset virus processing library; detecting whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library according to the virus identifier; and processing the target file according to the detection result. The present invention can be used in virus detection and killing services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technologies, and in particular, to a method and device for processing virus infection based on LuaJIT. Background Art

[0002] With the development of science and technology and network technologies, the types of computer viruses are increasing and constantly evolving, illegally intercepting military and commercial secrets, personal privacy, etc. In order to maintain network security, virus detection and killing services have emerged. However, in the face of a huge virus system and a rapid update speed, it is becoming increasingly difficult to maintain virus detection and killing processing services. Summary of the Invention

[0003] In view of this, embodiments of the present invention provide a method, device, electronic device, and storage medium for processing virus infection based on LuaJIT, which can effectively simplify the maintenance of virus detection and killing services.

[0004] In a first aspect, an embodiment of the present invention provides a method for processing virus infection based on LuaJIT, including: determining whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in a preset virus processing library, where the virus-related file includes a virus file and / or a file infected by a virus, and the preset virus processing library is established based on the LuaJIT language; in response to the target file being the virus-related file, obtaining a virus identifier corresponding to the virus-related file from the preset virus processing library; detecting whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library according to the virus identifier; and processing the target file according to the detection result.

[0005] In an implementation manner, the virus identifier includes a sub-library identifier bit and an in-library index bit, and the sub-library identifier bit includes a flag bit, a timestamp bit, and a process identifier bit.

[0006] In an implementation manner, the detecting whether there is a corresponding repair script bytecode in the preset virus processing library according to the virus identifier includes: detecting whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library according to the flag bit in the virus identifier.

[0007] In an implementation manner, the determining whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library includes: comparing the file feature information of the target file with each virus feature information in the scanning sub-library of the preset virus processing library; and in the case where the similarity between the file feature information and any one of the virus feature information is greater than a preset threshold, determining the any one of the virus feature information as a target virus and determining the target file as a virus-related file.

[0008] In one embodiment, the processing of the target file according to the detection result includes: when the detection result indicates that there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library, searching for the repair script bytecode corresponding to the virus identifier in the repair sub-library of the preset virus processing library according to the virus identifier; using the repair script bytecode to repair the target file; or, when the detection result indicates that there is no repair script bytecode corresponding to the virus identifier in the preset virus processing library, deleting the target file.

[0009] In one embodiment, before determining whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library, the method further includes: constructing the preset virus processing library based on the LuaJIT language, where the preset virus processing library includes a scanning sub-library and a repair sub-library. Among them, the scanning sub-library is provided with detection script bytecodes for detecting whether the target file is the virus-related file, and the repair sub-library is provided with repair script bytecodes for repairing the virus-related file; the detection script bytecodes and the repair script bytecodes used to kill the same virus correspond to the same virus identifier.

[0010] In one embodiment, constructing the repair sub-library includes: respectively obtaining the repair scripts corresponding to each virus; respectively converting each of the repair scripts from plaintext to bytecode to obtain the corresponding repair script bytecodes; encapsulating each of the repair script bytecodes according to the first encapsulation rule to obtain the repair sub-library, where the repair sub-library includes a header, a code area, and a code index table. Among them, the header is used to describe the attribute information of the repair sub-library, the code area is used to carry each of the repair script bytecodes, and the code index table is used to indicate the offset address of each of the repair script bytecodes in the repair sub-library.

[0011] In one embodiment, the header includes the version information of the repair sub-library, the identification information of the repair sub-library, the check information of the repair sub-library, and the offset address of the code index table in the repair sub-library.

[0012] In one embodiment, processing the target file according to the detection result includes: when the detection result indicates that there is repair script bytecode corresponding to the virus identifier in the preset virus processing library, searching for the offset address of the code index table in the repair sub-library at the head of the repair sub-library; positioning the code index table according to the offset address of the code index table in the repair sub-library; querying the offset address of the repair script bytecode corresponding to the virus identifier in the code index table according to the virus identifier; obtaining the repair script bytecode from the code area of the repair sub-library according to the offset address of the repair script bytecode in the repair sub-library; and repairing the target file by using the repair script bytecode.

[0013] In one embodiment, the code index table is located at the last position of the repair sub-library; the method further includes: receiving a code adjustment instruction for instructing to delete the first repair script bytecode in the code area; and invalidating the index corresponding to the first repair script bytecode in the code index table according to the code adjustment instruction.

[0014] In one embodiment, the method further includes: obtaining the most recent detection time of each virus according to the timestamp bits in each virus identifier in the preset virus processing library; loading at least a part of the repair script bytecodes corresponding to the virus identifiers in the repair sub-library into the cache according to the most recent detection time; and dynamically updating the cache according to the change of the most recent detection time of each virus.

[0015] In one embodiment, constructing the scanning sub-library includes: respectively obtaining the detection scripts corresponding to each virus; respectively converting each of the detection scripts from plaintext into bytecode to obtain corresponding detection script bytecodes; and encapsulating each of the detection script bytecodes according to a second encapsulation rule to obtain the scanning sub-library, where the scanning sub-library includes a head, a code area, and a code index table, and the head is used to describe the attribute information of the scanning sub-library, the code area is used to carry each of the detection script bytecodes, and the code index table is used to indicate the offset address of each detection script bytecode in the scanning sub-library.

[0016] Second aspect, an embodiment of the present invention further provides a virus infection processing device based on LuaJIT, including: a determination unit, configured to determine whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in a preset virus processing library, where the virus-related file includes a virus file and / or a file infected by a virus, and the preset virus processing library is established based on the LuaJIT language; a first acquisition unit, configured to, in response to the target file being the virus-related file, acquire a virus identifier corresponding to the virus-related file from the preset virus processing library; a detection unit, configured to detect whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library according to the virus identifier; and a processing unit, configured to process the target file according to the detection result.

[0017] In an implementation manner, the virus identifier includes a sub-library identifier bit and an in-library index bit, and the sub-library identifier bit includes a flag bit, a timestamp bit, and a process identifier bit.

[0018] In an implementation manner, the detection unit is specifically configured to detect whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library according to the flag bit in the virus identifier.

[0019] In an implementation manner, the determination unit includes: a comparison module, configured to compare the file feature information of the target file with each virus feature information in a scanning sub-library of the preset virus processing library; and a determination module, configured to, when the similarity between the file feature information and any one of the virus feature information is greater than a preset threshold, determine the any one of the virus feature information as a target virus and determine the target file as a virus-related file.

[0020] In an implementation manner, the processing unit is specifically configured to: when the detection result is that there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library, search for the repair script bytecode corresponding to the virus identifier in a repair sub-library of the preset virus processing library according to the virus identifier; and use the repair script bytecode to repair the target file; or, when the detection result is that there is no repair script bytecode corresponding to the virus identifier in the preset virus processing library, delete the target file.

[0021] In one implementation, the device further includes a construction unit configured to construct the preset virus processing library based on the LuaJIT language before determining whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library. The preset virus processing library includes a scanning sub-library and a repair sub-library. Among them, the scanning sub-library is provided with detection script bytecodes for detecting whether the target file is the virus-related file, and the repair sub-library is provided with repair script bytecodes for repairing the virus-related file. The detection script bytecodes and the repair script bytecodes used to kill the same virus correspond to the same virus identifier.

[0022] In one implementation, the construction unit includes: a first acquisition module configured to respectively acquire the repair scripts corresponding to each virus; a first conversion module configured to respectively convert each of the repair scripts from plain text to bytecodes to obtain corresponding repair script bytecodes; a first encapsulation module configured to encapsulate each of the repair script bytecodes according to a first encapsulation rule to obtain the repair sub-library. The repair sub-library includes a header, a code area, and a code index table. Among them, the header is used to describe the attribute information of the repair sub-library, the code area is used to carry each of the repair script bytecodes, and the code index table is used to indicate the offset address of each of the repair script bytecodes in the repair sub-library.

[0023] In one implementation, the header includes the version information of the repair sub-library, the identification information of the repair sub-library, the verification information of the repair sub-library, and the offset address of the code index table in the repair sub-library.

[0024] In one implementation, the processing unit includes: a search module configured to search, in the header of the repair sub-library, for the offset address of the code index table in the repair sub-library when the detection result is that there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library; a positioning module configured to position the code index table according to the offset address of the code index table in the repair sub-library; a query module configured to query, according to the virus identifier, the offset address of the repair script bytecode corresponding to the virus identifier in the code index table in the repair sub-library; a second acquisition module configured to acquire the repair script bytecode from the code area of the repair sub-library according to the offset address of the repair script bytecode in the repair sub-library; a repair module configured to repair the target file by using the repair script bytecode.

[0025] In one embodiment, the code index table is located at the last position of the repair sub-library; the device further includes: a receiving unit, configured to receive a code adjustment instruction for instructing to delete the first repair script bytecode in the code area; an indicating unit, configured to, according to the code adjustment instruction, invalidate the index corresponding to the first repair script bytecode in the code index table.

[0026] In one embodiment, the device further includes: a second obtaining unit, configured to obtain the most recent detection time of each virus according to the timestamp bits in each virus identifier in the preset virus processing library; a loading unit, configured to load, according to the most recent detection time, at least a part of the repair script bytecodes corresponding to the virus identifiers in the repair sub-library into a cache; a cache updating unit, configured to dynamically update the cache according to the change in the most recent detection time corresponding to each virus.

[0027] In one embodiment, the building unit includes: a third obtaining module, configured to obtain the detection scripts corresponding to each virus respectively; a second conversion module, configured to convert each of the detection scripts from plaintext into bytecodes to obtain corresponding detection script bytecodes; a second encapsulation module, configured to encapsulate each of the detection script bytecodes according to a second encapsulation rule to obtain the scanning sub-library, where the scanning sub-library includes a header, a code area, and a code index table, and wherein the header is used to describe the attribute information of the scanning sub-library, the code area is used to carry each of the detection script bytecodes, and the code index table is used to indicate the offset address of each detection script bytecode in the scanning sub-library.

[0028] In a third aspect, an embodiment of the present invention further provides an electronic device, where the electronic device includes: a housing, a processor, a memory, a circuit board, and a power supply circuit, where the circuit board is disposed inside the space surrounded by the housing, and the processor and the memory are disposed on the circuit board; the power supply circuit is configured to supply power to each circuit or device of the above-mentioned electronic device; the memory is used to store executable program codes; the processor runs a program corresponding to the executable program codes by reading the executable program codes stored in the memory, and is used to execute any one of the luajit-based virus infection processing methods provided by the embodiments of the present invention.

[0029] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, where the computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement any one of the luajit-based virus infection processing methods provided by the embodiments of the present invention.

[0030] The virus infection processing method, device, electronic device and storage medium provided by the embodiments of the present invention can determine whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library. In response to the target file being the virus-related file, obtain the virus identifier corresponding to the virus-related file from the preset virus processing library, and detect whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library according to the virus identifier, and process the target file according to the detection result. In this way, since the preset virus processing library is established based on the LuaJIT language, it has strong flexibility. Also, since the virus scanning and virus processing are cleverly combined through the virus identifier in the preset virus processing library, it has strong systematicness, can effectively avoid confusion, redundancy or duplication between virus scanning and virus processing, and thus effectively simplifies the maintenance of virus killing services. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings according to these drawings without creative efforts.

[0032] Figure 1 FIG. is a flowchart of a virus infection processing method based on LuaJIT provided by an embodiment of the present invention;

[0033] Figure 2 FIG. is a schematic structural diagram of a virus identifier in an embodiment of the present invention;

[0034] Figure 3 FIG. is a schematic structural diagram of a repair sub-library in an embodiment of the present invention;

[0035] Figure 4 FIG. is a detailed flowchart of a virus infection processing method based on LuaJIT provided by an embodiment of the present invention;

[0036] Figure 5 FIG. is a schematic structural diagram of a virus infection processing device based on LuaJIT provided by an embodiment of the present invention;

[0037] Figure 6 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0038] The following will describe the embodiments of the present invention in detail with reference to the drawings.

[0039] It should be clear that the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0040] In a first aspect, an embodiment of the present invention provides a virus infection processing method based on LuaJIT, which can skillfully combine virus scanning and virus processing through virus identification using the LuaJIT language, effectively simplifying the maintenance of virus killing services.

[0041] As Figure 1 shown, a virus infection processing method based on LuaJIT provided by an embodiment of the present invention may include:

[0042] S11, determine whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library, where the virus-related file includes a virus file and / or a file infected by a virus, and the preset virus processing library is established based on the LuaJIT language;

[0043] The target file may refer to a file that needs to be scanned for viruses. The preset virus processing library may refer to a system that provides virus killing services. The preset virus processing library may pre-store the characteristics corresponding to various viruses, and the characteristics of these viruses may be stored in the form of virus identification - virus characteristics, for example. When scanning for viruses, the file feature information of the target file can be extracted and compared with the various virus feature information in the preset virus processing library one by one to determine whether the target file is a virus-related file. Among them, the virus-related file can refer to either the virus file itself or a file infected by a virus.

[0044] Lua is a scripting language developed to be embedded in other applications, and LuaJIT is a Just-In-Time (runtime compilation) of Lua, which can also be said to be an efficient version of Lua.

[0045] S12, in response to the target file being the virus-related file, obtain the virus identification corresponding to the virus-related file from the preset virus processing library;

[0046] If it is determined through the virus scan of the target file in step S11 that the target file is a virus-related file, then according to the scan result, the virus identification corresponding to the virus-related file can be obtained from the preset virus processing library. Optionally, the virus identification can be composed of one or more combinations of letters, numbers, and symbols. Different viruses correspond to different virus identifications, and the same virus corresponds to the same virus identification.

[0047] S13, detecting whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library according to the virus identifier;

[0048] In one embodiment of the present invention, the virus identifier can not only identify the virus, but also indicate the status of the virus in the preset virus processing library. For example, the virus identifier can indicate whether there is a repair script bytecode in the preset virus processing library that can repair the virus.

[0049] S14: Process the target file according to the detection result.

[0050] Optionally, the detection result in step S13 may be that there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library, or it may be that there is no repair script bytecode corresponding to the virus identifier in the preset virus processing library. Depending on different detection results, the target file can be processed differently.

[0051] The luajit-based virus infection processing method provided by the embodiment of the present invention can determine whether the target file is a virus-associated file based on the file feature information of the target file and the virus feature information in the preset virus processing library. In response to the target file being the virus-associated file, the virus identifier corresponding to the virus-associated file is obtained from the preset virus processing library, and the repair script bytecode corresponding to the virus identifier is detected in the preset virus processing library based on the virus identifier, and the target file is processed according to the detection result. In this way, since the preset virus processing library is established based on the luajit language, it has strong flexibility, and since the virus scanning and virus processing are cleverly combined through the virus identifier in the preset virus processing library, it has strong systematicity, and can effectively avoid the confusion, redundancy or duplication between virus scanning and virus processing, thereby effectively simplifying the maintenance of virus killing services.

[0052] Optionally, in an embodiment of the present invention, the virus processing library may be divided into different sub-libraries according to the specific processing operations performed by the preset virus processing library. For example, in one embodiment of the present invention, the part of the preset virus processing library that performs virus scanning operations may be divided into a scanning sub-library, and the part that performs file repair operations may be divided into a repair sub-library. In order to clearly and conveniently identify each virus in the preset virus processing library, in one embodiment of the present invention, the virus identification may include multiple identification bits, a part of which may be a sub-library identification bit, and another part may be an index bit within the library.

[0053] In order to reflect more information in the virus identifier, in an embodiment of the present invention, the sub-library identifier bits can further include a flag bit, a timestamp bit, a process identifier bit, etc. Among them, the flag bit can be used to indicate whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library. For example, when the flag bit is 0, it means that there is no repair script bytecode corresponding to the virus identifier in the preset virus processing library; when the flag bit is 1, it means that there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library. The timestamp bit can represent the most recent detection time of the virus, and the process identifier bit can represent in which process the virus appears. Optionally, when the preset virus processing library is set in multiple terminal devices, in order to distinguish the preset virus processing libraries in different devices, in an embodiment of the present invention, the sub-library identifier bits can further include a machine identifier bit. Exemplarily, the format of a virus identifier VID can be as Figure 2 shown.

[0054] Specifically, in an embodiment of the present invention, step S11 of determining whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library may include: comparing the file feature information of the target file with each virus feature information in the scanning sub-library of the preset virus processing library; in the case where the similarity between the file feature information and any one of the virus feature information is greater than a preset threshold, determining the any one of the virus feature information as the target virus and determining the target file as a virus-related file. For example, if the similarity between the file feature information of the target file file1 and the virus feature information of the virus identifier VID298 in the preset virus processing library is greater than the preset threshold of 95%, then VID298 is determined as the target virus and the target file file1 is a virus-related file. Based on this, in step S12, in response to the target file being the virus-related file, the virus identifier corresponding to the virus-related file can be obtained from the preset virus processing library. For example, the virus identifier VID298 = 1101010011101111011 is obtained. After obtaining the virus identifier corresponding to the virus-related file, it is possible to detect in step S13 whether there is a corresponding repair script bytecode in the preset virus processing library. In a specific implementation, it is possible to detect whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library according to the flag bit in the virus identifier.

[0055] The detection result of step S13 may be that there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library, or there is no repair script bytecode corresponding to the virus identifier in the preset virus processing library. Based on this, in step S14, different processing can be performed on the target file according to different detection results. Specifically, when the detection result is that there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library, the repair script bytecode corresponding to the virus identifier can be found in the repair sub-library of the preset virus processing library according to the virus identifier; the target file is repaired using the repair script bytecode, so as to obtain a file that is not infected by the virus. Alternatively, when the detection result is that there is no repair script bytecode corresponding to the virus identifier in the preset virus processing library, the target file can be deleted, so as to achieve the purpose of virus removal.

[0056] Further, in order to be able to use the preset virus processing library for virus killing services, in an embodiment of the present invention, before determining whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library in step S11, the virus infection processing method based on luajit provided by the embodiment of the present invention may further include: constructing the preset virus processing library based on the luajit language, the preset virus processing library includes a scanning sub-library and a repair sub-library, wherein, a detection script bytecode for detecting whether the target file is the virus-related file is set in the scanning sub-library, and a repair script bytecode for repairing the virus-related file is set in the repair sub-library; the detection script bytecode and the repair script bytecode for killing the same virus correspond to the same virus identifier. The corresponding scanning script bytecode or repair script bytecode can be found in the scanning sub-library or the repair sub-library according to the virus identifier. Specifically, if the flag bit of the virus identifier is 0, it means that there is no repair script bytecode corresponding to the virus identifier in the repair sub-library. At this time, the library index is only the index in the scanning library. Therefore, the corresponding scanning script bytecode can be obtained in the scanning sub-library according to the library index; if the flag bit of the virus identifier is 1, it means that there is a repair script bytecode corresponding to the virus identifier in the repair sub-library. At this time, the library index is the common index of the scanning sub-library and the repair sub-library. Therefore, according to this library index, the scanning script bytecode can be obtained in the scanning sub-library and the repair script bytecode can be obtained in the repair sub-library respectively.

[0057] In an embodiment of the present invention, the repair sub-library and the scanning sub-library can be constructed separately to build the preset virus processing library.

[0058] Among them, constructing the repair sub-library can specifically include: respectively obtaining the repair scripts corresponding to each virus; respectively converting each of the repair scripts from plaintext to bytecode to obtain the corresponding repair script bytecodes; encapsulating each of the repair script bytecodes according to the first encapsulation rule to obtain the repair sub-library, where the repair sub-library includes a header, a code area, and a code index table. Among them, the header can be used to describe the attribute information of the repair sub-library, the code area can be used to carry each of the repair script bytecodes, and the code index table can be used to indicate the offset address of each of the repair script bytecodes in the repair sub-library. Optionally, in an embodiment of the present invention, the header can specifically include information such as the version information of the repair sub-library, the identification information of the repair sub-library, the verification information of the repair sub-library, and the offset address of the code index table in the repair sub-library. Exemplarily, a data structure of the repair sub-library can be as Figure 3 shown. In Figure 3 the embodiment shown, the header and each piece of code (LP-codeN) in the code area respectively correspond to their own verification information. Among them, the verification information of the header can be used to verify whether the repair sub-library has errors, and the verification information corresponding to each piece of code can be used to verify whether the corresponding code has errors.

[0059] Based on the above data structure of the repair sub-library, in an embodiment of the present invention, processing the target file according to the detection result in step S14 can specifically include: when the detection result is that there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library, in the header of the repair sub-library, find the offset address of the code index table in the repair sub-library; according to the offset address of the code index table in the repair sub-library, locate the code index table; according to the virus identifier, query the offset address of the repair script bytecode corresponding to the virus identifier in the repair sub-library in the code index table. Specifically, the offset address of the corresponding repair script bytecode in the repair sub-library can be queried in the code index table according to the in-library index bit in the virus identifier; according to the offset address of the repair script bytecode in the repair sub-library, obtain the repair script bytecode from the code area of the repair sub-library; use the repair script bytecode to repair the target file. In this way, based on the data structure of the repair sub-library, the repair script code corresponding to the virus can be quickly found to repair the target file.

[0060] Optionally, in an embodiment of the present invention, the head of the repair sub-library may be located at the start position of the repair sub-library, followed by a code area and a code index table. The front and rear positions of the code area and the code index table are not limited. However, in an embodiment of the present invention, in order to minimize the read and write operations of the repair sub-library caused by code modification, the code index table may be located at the last position of the repair sub-library; based on this, the method for handling virus infection based on LuaJIT provided by the embodiment of the present invention may further include: receiving a code adjustment instruction for instructing to delete the first repair script bytecode in the code area; according to the code adjustment instruction, in the code index table, perform an invalidation indication on the index corresponding to the first repair script bytecode. Wherein, the first repair script bytecode may be any repair script bytecode in the code area. In this way, when it is necessary to delete any repair script bytecode in the code area, only the corresponding mark needs to be made in the code index table located at the last position of the repair sub-library, without any read and write operations on the code area in the middle position, and it also avoids further adjustment of the subsequent code after the code in the middle position is deleted. Therefore, the maintenance of virus killing is further simplified.

[0061] In order to improve the virus killing speed of the target file, in an embodiment of the present invention, a part of the content in the preset virus processing library may be loaded into the cache. In order to improve the cache hit rate, the method for handling virus infection based on LuaJIT provided by the embodiment of the present invention may further include: obtaining the most recent detection time of each virus according to the timestamp bit in each virus identifier in the preset virus processing library; according to the most recent detection time, loading at least a part of the repair script bytecodes corresponding to the virus identifiers in the repair sub-library into the cache; dynamically updating the cache according to the change of the most recent detection time of each virus. In this way, the most recently and frequently used repair script bytecodes can be loaded into the cache according to the most recent detection time, thus effectively improving the virus killing efficiency.

[0062] The construction and maintenance of the repair sub-library have been described in detail above. Similar to the construction of the repair sub-library, in an embodiment of the present invention, constructing a scanning sub-library may specifically include: respectively obtaining the detection scripts corresponding to each virus; respectively converting each of the detection scripts from plain text to bytecodes to obtain the corresponding detection script bytecodes; encapsulating each of the detection script bytecodes according to a second encapsulation rule to obtain the scanning sub-library, where the scanning sub-library includes a head, a code area, and a code index table, wherein the head is used to describe the attribute information of the scanning sub-library, the code area is used to carry each of the detection script bytecodes, and the code index table is used to indicate the offset address of each of the detection script bytecodes in the scanning sub-library. The maintenance of the scanning sub-library can be based on a principle similar to that of the maintenance of the repair sub-library, which will not be elaborated here.

[0063] The following provides a detailed description of the virus infection processing method based on LuaJIT provided by the embodiments of the present invention through a specific embodiment.

[0064] As Figure 4 shown, the virus infection processing method based on LuaJIT provided by the embodiments of the present invention may include:

[0065] S201. Build a preset virus processing library based on the LuaJIT language, where the preset virus processing library includes a scanning sub-library and a repair sub-library.

[0066] Among them, a detection script bytecode for detecting whether a target file is a virus-associated file is set in the scanning sub-library, and a repair script bytecode for repairing the virus-associated file is set in the repair sub-library; the detection script bytecode and the repair script bytecode for killing the same virus correspond to the same virus identifier.

[0067] S202. Compare the file feature information of the target file with each virus feature information in the scanning sub-library of the preset virus processing library.

[0068] S203. In the case where the similarity between the file feature information and any one of the virus feature information is greater than a preset threshold, determine the any one of the virus feature information as the target virus and determine the target file as a virus-associated file.

[0069] S204. In response to the target file being a virus-associated file, obtain the virus identifier corresponding to the virus-associated file from the preset virus processing library.

[0070] For example, the virus identifier VID3 = 101000111011111110.

[0071] S205. According to the flag bit in the virus identifier, detect whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library.

[0072] Since the first bit of VID3 is 1, that is, the flag bit is 1, it is determined that there is a repair script bytecode corresponding to the virus identifier VID3 in the preset virus processing library.

[0073] S206. In the case where the detection result is that there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library, find the offset address of the code index table in the repair sub-library at the head of the repair sub-library.

[0074] S207. Locate the code index table according to the offset address of the code index table in the repair sub-library.

[0075] S208. Query the offset address of the repair script bytecode corresponding to the virus identifier in the repair sub-library in the code index table according to the virus identifier.

[0076] S209. Obtain the repair script bytecode from the code area of the repair sub-library according to the offset address of the repair script bytecode in the repair sub-library.

[0077] S210. Repair the target file using the repair script bytecode.

[0078] In a second aspect, an embodiment of the present invention provides a virus infection processing device based on LuaJIT, which can skillfully combine virus scanning and virus processing through a virus identifier using the LuaJIT language, effectively simplifying the maintenance of virus killing services.

[0079] As Figure 5 shown, the virus infection processing device based on LuaJIT provided by the embodiment of the present invention may include:

[0080] A determination unit 31, configured to determine whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library, where the virus-related file includes a virus file and / or a file infected by a virus, and the preset virus processing library is established based on the LuaJIT language;

[0081] A first acquisition unit 32, configured to, in response to the target file being the virus-related file, acquire the virus identifier corresponding to the virus-related file from the preset virus processing library;

[0082] A detection unit 33, configured to detect whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library according to the virus identifier;

[0083] A processing unit 34, configured to process the target file according to the detection result.

[0084] The virus infection processing device based on LuaJIT provided by the embodiments of the present invention can determine whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library. In response to the target file being the virus-related file, it obtains the virus identifier corresponding to the virus-related file from the preset virus processing library, and detects whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library according to the virus identifier, and processes the target file according to the detection result. In this way, since the preset virus processing library is established based on the LuaJIT language, it has strong flexibility. Also, since the virus scanning and virus processing are cleverly combined through the virus identifier in the preset virus processing library, it has strong systematicness, can effectively avoid the confusion, redundancy or repetition between virus scanning and virus processing, and thus effectively simplifies the maintenance of virus killing services.

[0085] In one implementation, the virus identifier may include a sub-library identifier bit and an in-library index bit, and the sub-library identifier bit includes a flag bit, a timestamp bit, and a process identifier bit.

[0086] In one implementation, the detection unit 33 can specifically be used to detect whether there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library according to the flag bit in the virus identifier.

[0087] In one implementation, the determination unit 31 may include:

[0088] A comparison module, configured to compare the file feature information of the target file with each virus feature information in the scanning sub-library of the preset virus processing library;

[0089] A determination module, configured to determine the any virus feature information as the target virus and determine the target file as a virus-related file when the similarity between the file feature information and any virus feature information is greater than a preset threshold.

[0090] In one implementation, the processing unit 34 can specifically be used for:

[0091] When the detection result is that there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library, according to the virus identifier, search for the repair script bytecode corresponding to the virus identifier in the repair sub-library of the preset virus processing library; use the repair script bytecode to repair the target file;

[0092] Or

[0093] In the case that the detection result indicates that there is no repair script bytecode corresponding to the virus identifier in the preset virus processing library, delete the target file.

[0094] In one embodiment, the device may further include a construction unit, configured to construct the preset virus processing library based on the LuaJIT language before determining whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library. The preset virus processing library includes a scanning sub-library and a repair sub-library. Among them, the scanning sub-library is provided with detection script bytecodes for detecting whether the target file is the virus-related file, and the repair sub-library is provided with repair script bytecodes for repairing the virus-related file; the detection script bytecodes and the repair script bytecodes used to kill the same virus correspond to the same virus identifier.

[0095] In one embodiment, the construction unit includes:

[0096] A first acquisition module, configured to respectively acquire the repair scripts corresponding to each virus;

[0097] A first conversion module, configured to respectively convert each of the repair scripts from plain text to bytecodes to obtain corresponding repair script bytecodes;

[0098] A first encapsulation module, configured to encapsulate each of the repair script bytecodes according to a first encapsulation rule to obtain the repair sub-library. The repair sub-library includes a header, a code area, and a code index table. Among them, the header is used to describe the attribute information of the repair sub-library, the code area is used to carry each of the repair script bytecodes, and the code index table is used to indicate the offset address of each repair script bytecode in the repair sub-library.

[0099] In one embodiment, the header includes the version information of the repair sub-library, the identification information of the repair sub-library, the verification information of the repair sub-library, and the offset address of the code index table in the repair sub-library.

[0100] In one embodiment, the processing unit 34 may include:

[0101] A search module, configured to search for the offset address of the code index table in the header of the repair sub-library in the case that the detection result indicates that there is a repair script bytecode corresponding to the virus identifier in the preset virus processing library;

[0102] A positioning module, configured to position the code index table according to the offset address of the code index table in the repair sub-library;

[0103] A query module, configured to query, according to the virus identifier, an offset address of the repair script bytecode corresponding to the virus identifier in the repair sub-library in the code index table;

[0104] A second acquisition module, configured to acquire the repair script bytecode from the code area of the repair sub-library according to the offset address of the repair script bytecode in the repair sub-library;

[0105] A repair module, configured to repair the target file by using the repair script bytecode.

[0106] In an implementation, the code index table is located at the last position of the repair sub-library; the apparatus further includes:

[0107] A receiving unit, configured to receive a code adjustment instruction for instructing to delete a first repair script bytecode in the code area;

[0108] An indicating unit, configured to perform an invalidation indication on an index corresponding to the first repair script bytecode in the code index table according to the code adjustment instruction.

[0109] In an implementation, the apparatus may further include:

[0110] A second acquisition unit, configured to obtain the most recent detection time of each virus according to a timestamp bit in each virus identifier in the preset virus processing library;

[0111] A loading unit, configured to load, according to the most recent detection time, repair script bytecodes corresponding to at least a part of virus identifiers in the repair sub-library into a cache;

[0112] A cache update unit, configured to dynamically update the cache according to a change in the most recent detection time corresponding to each virus.

[0113] In an implementation, the construction unit may specifically include:

[0114] A third acquisition module, configured to respectively acquire detection scripts corresponding to each virus;

[0115] A second conversion module, configured to respectively convert each of the detection scripts from plaintext into bytecodes to obtain corresponding detection script bytecodes;

[0116] A second encapsulation module, configured to encapsulate each of the detected script bytecodes according to a second encapsulation rule to obtain the scanning sub-library, where the scanning sub-library includes a header, a code area, and a code index table. The header is used to describe the attribute information of the scanning sub-library, the code area is used to carry each of the detected script bytecodes, and the code index table is used to indicate the offset address of each of the detected script bytecodes in the scanning sub-library.

[0117] In a third aspect, an embodiment of the present invention provides an electronic device, which can effectively simplify the maintenance of virus detection services.

[0118] As Figure 6 shown, the electronic device provided by the embodiment of the present invention may include: a housing 51, a processor 52, a memory 53, a circuit board 54, and a power supply circuit 55. The circuit board 54 is disposed inside the space surrounded by the housing 51, and the processor 52 and the memory 53 are disposed on the circuit board 54. The power supply circuit 55 is configured to supply power to each circuit or device of the above-mentioned electronic device. The memory 53 is used to store executable program codes. The processor 52 runs a program corresponding to the executable program code by reading the executable program codes stored in the memory 53, and is configured to execute the virus infection processing method based on luajit provided in any of the foregoing embodiments.

[0119] For the specific execution process of the above steps by the processor 52 and the further steps executed by the processor 52 by running the executable program code, reference may be made to the description of the foregoing embodiments, which will not be elaborated herein.

[0120] The above-mentioned electronic devices exist in various forms, including but not limited to:

[0121] (1) Mobile communication devices: These devices are characterized by having mobile communication functions and mainly aim to provide voice and data communication. Such terminals include: smart phones (such as iPhone), multimedia phones, functional phones, and low-end phones, etc.

[0122] (2) Ultra-mobile personal computer devices: These devices belong to the category of personal computers, have computing and processing functions, and generally also have the characteristic of mobile Internet access. Such terminals include: PDA, MID, and UMPC devices, etc., such as iPad.

[0123] (3) Portable entertainment devices: These devices can display and play multimedia content. Such devices include: audio and video players (such as iPod), handheld game consoles, e-books, and smart toys and portable vehicle navigation devices.

[0124] (4) Server: A device that provides computing services. The server consists of a processor, hard disk, memory, system bus, etc. The server is similar to a general computer architecture, but due to the need to provide highly reliable services, it has higher requirements in terms of processing power, stability, reliability, security, scalability, manageability, etc.

[0125] (5) Other electronic devices with data interaction functions.

[0126] Correspondingly, in a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium. The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement any one of the virus infection processing methods based on LuaJIT provided in the foregoing embodiments. Therefore, corresponding technical effects can also be achieved. Details have been described in detail above and will not be repeated here.

[0127] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

[0128] Each embodiment in this specification is described in a related manner. For the same or similar parts between the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments.

[0129] In particular, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the related parts, reference can be made to the partial description of the method embodiments.

[0130] For the convenience of description, the above device is described by dividing it into various units / modules according to functions. Of course, when implementing the present invention, the functions of each unit / module can be implemented in the same or multiple software and / or hardware.

[0131] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disc, a read-only memory (ROM), or a random access memory (RAM), etc.

[0132] As mentioned above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A method for virus infection processing based on LuaJIT, characterized in that, Including: Determine whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library. The virus-related file includes a virus file and / or an infected file, and the preset virus processing library is established based on the LuaJIT language; In response to the target file being the virus-related file, obtain the virus identifier corresponding to the virus-related file from the preset virus processing library. The virus identifier includes a sub-library identifier bit and an in-library index bit; Detect whether there is bytecode corresponding to the repair script corresponding to the virus identifier in the preset virus processing library according to the virus identifier; Process the target file according to the detection result; Among them, before determining whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library, the method further includes: Construct the preset virus processing library based on the LuaJIT language. The preset virus processing library includes a scanning sub-library and a repair sub-library. Among them, the scanning sub-library is provided with detection script bytecodes for detecting whether the target file is the virus-related file, and the repair sub-library is provided with bytecodes corresponding to the repair scripts for repairing the virus-related file; the detection script bytecodes and the bytecodes corresponding to the repair scripts for killing the same virus correspond to the same virus identifier.

2. The method according to claim 1, characterized in that, The sub-library identifier bit includes a flag bit, a timestamp bit, and a process identifier bit.

3. The method according to claim 2, characterized in that, The detecting whether there is bytecode corresponding to the repair script corresponding to the virus identifier in the preset virus processing library according to the virus identifier includes: Detect whether there is bytecode corresponding to the repair script corresponding to the virus identifier in the preset virus processing library according to the flag bit in the virus identifier.

4. The method according to claim 1, characterized in that, Determining whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library includes: Compare the file feature information of the target file with each virus feature information in the scanning sub-library of the preset virus processing library; In the case where the similarity between the file feature information and any one of the virus feature information is greater than a preset threshold, determine the any one of the virus feature information as the target virus and determine the target file as a virus-related file.

5. The method according to claim 1, characterized in that, Processing the target file according to the detection result includes: In the case where the detection result is that there is bytecode of the repair script corresponding to the virus identifier in the preset virus processing library, according to the virus identifier, find the bytecode of the repair script corresponding to the virus identifier in the repair sub-library of the preset virus processing library; use the bytecode of the repair script to repair the target file; Or In the case where the detection result is that there is no bytecode of the repair script corresponding to the virus identifier in the preset virus processing library, delete the target file.

6. The method according to claim 1, characterized in that, Constructing the repair sub-library includes: Obtain the repair scripts corresponding to each virus respectively; Convert each of the repair scripts from plain text to bytecode to obtain the bytecode corresponding to the corresponding repair script; Encapsulate the bytecodes corresponding to each of the repair scripts according to the first encapsulation rule to obtain the repair sub-library. The repair sub-library includes a header, a code area, and a code index table. Among them, the header is used to describe the attribute information of the repair sub-library, the code area is used to carry the bytecodes corresponding to each of the repair scripts, and the code index table is used to indicate the offset address of the bytecode corresponding to each repair script in the repair sub-library.

7. The method according to claim 6, characterized in that, The header includes the version information of the repair sub-library, the identification information of the repair sub-library, the verification information of the repair sub-library, and the offset address of the code index table in the repair sub-library.

8. The method according to claim 7, characterized in that, The processing of the target file according to the detection result includes: When the detection result is that there is bytecode corresponding to the repair script corresponding to the virus identifier in the preset virus processing library, find the offset address of the code index table in the repair sub-library at the header of the repair sub-library; Locate the code index table according to the offset address of the code index table in the repair sub-library; Query the offset address of the bytecode corresponding to the repair script corresponding to the virus identifier in the code index table according to the virus identifier; Obtain the bytecode corresponding to the repair script from the code area of the repair sub-library according to the offset address of the bytecode corresponding to the repair script in the repair sub-library; Repair the target file using the bytecode corresponding to the repair script.

9. The method according to claim 6, characterized in that, The code index table is located at the last position of the repair sub-library; The method further includes: Receive a code adjustment instruction, which is used to instruct to delete the bytecode corresponding to the first repair script in the code area; According to the code adjustment instruction, in the code index table, indicate the index corresponding to the bytecode corresponding to the first repair script as invalid.

10. The method according to claim 6, wherein, The method further includes: Obtain the most recent detection time of each virus according to the timestamp bit in each virus identifier in the preset virus processing library; According to the most recent detection time, load the bytecodes corresponding to the repair scripts corresponding to at least some of the virus identifiers in the repair sub-library into the cache; Dynamically update the cache according to the change of the most recent detection time corresponding to each virus.

11. The method according to claim 5, wherein, Constructing the scanning sub-library includes: Obtain the detection scripts corresponding to each virus respectively; Convert each of the detection scripts from plaintext to bytecode to obtain the corresponding detection script bytecodes; Encapsulate each of the detection script bytecodes according to the second encapsulation rule to obtain the scanning sub-library. The scanning sub-library includes a header, a code area, and a code index table. Among them, the header is used to describe the attribute information of the scanning sub-library, the code area is used to carry each detection script bytecode, and the code index table is used to indicate the offset address of each detection script bytecode in the scanning sub-library.

12. A virus infection processing device based on LuaJIT, wherein, Includes: A determination unit, configured to determine whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in a preset virus processing library, where the virus-related file includes a virus file and / or an infected file, and the preset virus processing library is established based on the LuaJIT language; A first acquisition unit, configured to, in response to the target file being the virus-related file, acquire a virus identifier corresponding to the virus-related file from the preset virus processing library, where the virus identifier includes a sub-library identifier bit and an in-library index bit; A detection unit, configured to detect whether there is bytecode corresponding to a repair script corresponding to the virus identifier in the preset virus processing library according to the virus identifier; A processing unit, configured to process the target file according to the detection result; A construction unit, configured to construct the preset virus processing library based on the LuaJIT language before determining whether the target file is a virus-related file according to the file feature information of the target file and the virus feature information in the preset virus processing library. The preset virus processing library includes a scanning sub-library and a repair sub-library. Among them, detection script bytecodes for detecting whether the target file is the virus-related file are set in the scanning sub-library, and bytecodes corresponding to repair scripts for repairing the virus-related file are set in the repair sub-library; The detection script bytecodes and the bytecodes corresponding to the repair scripts for killing the same virus correspond to the same virus identifier.

13. The device according to claim 12, wherein, The sub-library identifier bit includes a flag bit, a timestamp bit, and a process identifier bit.

14. The device according to claim 13, wherein, The detection unit is specifically configured to detect whether there is bytecode corresponding to a repair script corresponding to the virus identifier in the preset virus processing library according to the flag bit in the virus identifier.

15. The device according to claim 12, wherein, The determination unit includes: A comparison module, configured to compare the file feature information of the target file with each virus feature information in the scanning sub-library of the preset virus processing library; A determination module, configured to, when the similarity between the file feature information and any one of the virus feature information is greater than a preset threshold, determine the any one of the virus feature information as a target virus and determine the target file as a virus-related file.

16. The device according to claim 12, wherein, The processing unit is specifically configured to: When the detection result is that there is bytecode of a repair script corresponding to the virus identifier in the preset virus processing library, search for the bytecode of the repair script corresponding to the virus identifier in the repair sub-library of the preset virus processing library according to the virus identifier; Repair the target file by using the bytecode of the repair script; Or When the detection result is that there is no bytecode of a repair script corresponding to the virus identifier in the preset virus processing library, delete the target file.

17. The device according to claim 12, wherein, The construction unit includes: A first acquisition module, configured to respectively acquire repair scripts corresponding to each virus; A first conversion module, configured to respectively convert each of the repair scripts from plaintext to bytecode to obtain bytecodes corresponding to the corresponding repair scripts; The first encapsulation module is used to encapsulate the bytecodes corresponding to each of the repair scripts according to the first encapsulation rule to obtain the repair sub-library. The repair sub-library includes a header, a code area, and a code index table. Among them, the header is used to describe the attribute information of the repair sub-library, the code area is used to carry the bytecodes corresponding to each of the repair scripts, and the code index table is used to indicate the offset address of the bytecode corresponding to each repair script in the repair sub-library.

18. The device according to claim 17, wherein, The header includes the version information of the repair sub-library, the identification information of the repair sub-library, the verification information of the repair sub-library, and the offset address of the code index table in the repair sub-library.

19. The device according to claim 18, wherein, The processing unit includes: A search module, which is used to search for the offset address of the code index table in the header of the repair sub-library when the detection result is that there is a bytecode corresponding to a repair script corresponding to the virus identifier in the preset virus processing library; A positioning module, which is used to locate the code index table according to the offset address of the code index table in the repair sub-library; A query module, which is used to query the offset address of the bytecode corresponding to the repair script corresponding to the virus identifier in the code index table according to the virus identifier; A second acquisition module, which is used to acquire the bytecode corresponding to the repair script from the code area of the repair sub-library according to the offset address of the bytecode corresponding to the repair script in the repair sub-library; A repair module, which is used to repair the target file by using the bytecode corresponding to the repair script.

20. The device according to claim 17, wherein, The code index table is located at the last position of the repair sub-library; The device further includes: A receiving unit, which is used to receive a code adjustment instruction, and the code adjustment instruction is used to indicate deleting the bytecode corresponding to the first repair script in the code area; An indication unit, which is used to perform an invalidation indication on the index corresponding to the bytecode corresponding to the first repair script in the code index table according to the code adjustment instruction.

21. The device according to claim 17, wherein, It further includes: A second acquisition unit, which is used to obtain the most recent detection time of each virus according to the timestamp bits in each virus identifier in the preset virus processing library; A loading unit, which is used to load the bytecodes corresponding to the repair scripts corresponding to at least some of the virus identifiers in the repair sub-library into the cache according to the most recent detection time; A cache update unit, which is used to dynamically update the cache according to the change of the most recent detection time corresponding to each virus.

22. The device according to claim 16, wherein, The construction unit includes: A third acquisition module, which is used to respectively acquire the detection scripts corresponding to each virus; A second conversion module, which is used to convert each of the detection scripts from plaintext into bytecodes to obtain corresponding detection script bytecodes; A second encapsulation module, which is used to encapsulate each of the detection script bytecodes according to the second encapsulation rule to obtain the scanning sub-library. The scanning sub-library includes a header, a code area, and a code index table. Among them, the header is used to describe the attribute information of the scanning sub-library, the code area is used to carry each detection script bytecode, and the code index table is used to indicate the offset address of each detection script bytecode in the scanning sub-library.

23. An electronic device, wherein, The electronic device includes: a housing, a processor, a memory, a circuit board, and a power supply circuit. Among them, the circuit board is disposed inside the space enclosed by the housing, and the processor and the memory are arranged on the circuit board; the power supply circuit is used to supply power to each circuit or device of the above-mentioned electronic device; the memory is used to store executable program codes; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, and is used to execute the method for processing virus infection based on LuaJIT described in any one of the preceding claims 1 to 11.

24. A computer-readable storage medium, wherein, The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the method for processing virus infection based on LuaJIT described in any one of the preceding claims 1 to 11.

Citation Information

Patent Citations

  • Virus checking and killing method and device

    CN105653953A

  • Virus processing method, device and apparatus

    CN111625841A

  • Method of hindering the propagation of a computer virus

    US20040088564A1