Storage Method, Device, Storage Medium and Electronic Device for Sandbox Report

By hashing the row data reported by sandbox, generating hash values and replacing redundant data, the problem of low storage capacity of sandbox reports is solved and more efficient server storage is achieved.

CN115576951BActive Publication Date: 2025-07-18BEIJING HILLSTONE NETWORKS INFORMATION TECHCO
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211362738.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-02
Publication Date
2025-07-18
Estimated Expiration
2042-11-02

AI Technical Summary

Technical Problem

In the prior art, sandbox reports have low storage capacity, resulting in excessive pressure on server data storage.

Method used

By hashing the row data reported by the sandbox, a hash value is generated, and redundant data is replaced in the preset hash table, a second detection report with less memory is generated and stored to the server.

Benefits of technology

Improves the storage capacity of sandbox reports and reduces the pressure on server data storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115576951B_ABST
    Figure CN115576951B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, device, storage medium and electronic device for storing sandbox reports. The method includes: obtaining a first detection report, where the first detection report is a report generated after a sandbox detects a target file; performing a hash calculation on the row data included in the first detection report to obtain a hash value corresponding to the row data, where the row data is each row of data in the first detection report; when it is detected that there is a hash value in a preset hash table, updating the row data corresponding to the hash value in the first detection report to the hash value to obtain a second detection report, where the preset hash table is used to store redundant data in the first detection report and the hash values corresponding to the redundant data; and storing the second detection report in a server. The present invention solves the technical problem of low storage capacity of sandbox reports in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technologies, and in particular, to a method, device, storage medium, and electronic device for storing sandbox reports. Background Art

[0002] A Sandbox (also known as a sandbox or sand table) is a virtual system program that allows browsers or other programs to run in a sandbox environment, so that the changes generated during the operation can be deleted subsequently. It creates an independent operating environment similar to a sandbox, and the programs running inside it cannot have a permanent impact on the hard disk. In network security, a sandbox refers to a tool used to test the behaviors of untrusted files or application programs in an isolated environment.

[0003] In the prior art, a large number of suspicious samples are detected on a cloud sandbox every day, and a behavior detection report of the samples is generated after the detection is completed. Not all of the generated behavior detection reports are valuable, but these low-value reports need to be stored on the cloud server for a long time, and the number of times of export and use is not much, which causes a great data storage pressure on the server. And due to the existence of a large amount of redundant data in the generated behavior detection reports, the storage capacity of the sandbox reports is low.

[0004] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention

[0005] Embodiments of the present invention provide a method, device, storage medium, and electronic device for storing sandbox reports, so as to at least solve the technical problem of low storage capacity of sandbox reports in the prior art.

[0006] According to one aspect of the embodiments of the present invention, a method for storing a sandbox report is provided, including: obtaining a first detection report, where the first detection report is a report generated after a sandbox detects a target file; performing a hash calculation on the row data included in the first detection report to obtain a hash value corresponding to the row data, where the row data is each row of data in the first detection report; when it is detected that the hash value exists in a preset hash table, updating the row data corresponding to the hash value in the first detection report to the hash value to obtain a second detection report, where the preset hash table is used to store the redundant data in the first detection report and the hash value corresponding to the redundant data; and storing the second detection report in a server.

[0007] Further, the method for storing sandbox reports further includes: before obtaining the first detection report, obtaining a plurality of detection reports generated by the sandbox; performing a hash calculation on the row data in the plurality of detection reports to obtain a plurality of candidate hash values; generating the preset hash table based on the plurality of candidate hash values and the row data corresponding to the plurality of candidate hash values.

[0008] Further, the method for storing sandbox reports further includes: counting the number of times the same hash value appears among the plurality of candidate hash values to obtain a target number; determining, from the plurality of candidate hash values, a plurality of target hash values for which the target number is greater than a preset threshold; generating the preset hash table based on the plurality of target hash values and the row data corresponding to the plurality of target hash values.

[0009] Further, the method for storing sandbox reports further includes: after storing the second detection report in the server, in response to a report export instruction, detecting whether there is a hash value in the row data of the second detection report; when there is a hash value in the row data of the second detection report, reading a plurality of hash values in the second detection report; updating the plurality of hash values to the row data corresponding to the hash value to obtain the first detection report, and performing an export operation on the first detection report.

[0010] Further, the method for storing sandbox reports further includes: querying, from the preset hash table, the row data corresponding to the plurality of hash values based on the plurality of hash values to obtain target row data; updating the hash values in the second detection report to the target row data to obtain the first detection report.

[0011] Further, the method for storing sandbox reports further includes: after performing an export operation on the first detection report, sending the first detection report to a client, where the client is used to display the conclusion in the first detection report.

[0012] According to another aspect of the embodiments of the present invention, there is also provided a storage device for sandbox reports, including: a sandbox report acquisition module, configured to acquire a first detection report, where the first detection report is a report generated by a sandbox after detecting a target file; a hash calculation module, configured to perform a hash calculation on the row data included in the first detection report to obtain the hash value corresponding to the row data, where the row data is each row of data in the first detection report; a sandbox report update module, configured to, when detecting that the hash value exists in a preset hash table, update the row data corresponding to the hash value in the first detection report to the hash value to obtain a second detection report, where the preset hash table is used to store redundant data in the first detection report and the hash values corresponding to the redundant data; a sandbox report storage module, configured to store the second detection report in a server.

[0013] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the above-mentioned storage method of the sandbox report when running.

[0014] According to another aspect of the embodiments of the present invention, there is also provided an electronic device including one or more processors; a memory for storing one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement running the program, wherein the program is configured to execute the above-mentioned storage method of the sandbox report when running.

[0015] According to another aspect of the embodiments of the present invention, there is also provided a computer program product including a computer program / instructions, and when the computer program / instructions are executed by a processor, the above-mentioned storage method of the sandbox report is implemented.

[0016] In the embodiments of the present invention, by calculating the hash value of the row data in the first detection report and updating the row data in the first detection report with the hash value, first obtain the first detection report, where the first detection report is a report generated after the sandbox detects the target file; calculate the hash value of the row data included in the first detection report to obtain the hash value corresponding to the row data, where the row data is each row of data in the first detection report; when it is detected that the hash value exists in the preset hash table, update the row data corresponding to the hash value in the first detection report with the hash value to obtain a second detection report, where the preset hash table is used to store the redundant data in the first detection report and the hash value corresponding to the redundant data; store the second detection report in the server.

[0017] In the above process, when it is detected that the hash value exists in the preset hash table, the redundant data corresponding to the hash value in the first detection report is updated with the hash value, and the number of bytes corresponding to the hash value is usually much smaller than the number of bytes of the redundant data in the detection report, so that the system memory occupied by the generated second detection report is smaller than the system memory occupied by the first detection report. Therefore, storing the second detection report in the server can improve the storage capacity of the sandbox report and solve the technical problem of low storage capacity of the sandbox report in the prior art. In addition, storing the second detection report in the server can also reduce the data storage pressure on the server.

[0018] Thus, through the technical solution of the present invention, the purpose of storing the sandbox report is achieved, thereby realizing the technical effect of improving the storage capacity of the server for storing the sandbox report, and further solving the technical problem of low storage capacity of the sandbox report in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The drawings described herein are provided to further understand the present invention and form a part of this application. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:

[0020] Figure 1 is a flowchart of a method for storing a sandbox report according to an embodiment of the present invention;

[0021] Figure 2 is a flowchart of an alternative method for storing a sandbox report according to an embodiment of the present invention;

[0022] Figure 3 is a flowchart of an alternative method for generating a preset hash table according to an embodiment of the present invention;

[0023] Figure 4 is a schematic flowchart of an alternative report export operation according to an embodiment of the present invention;

[0024] Figure 5 is a schematic diagram of an alternative storage device for a sandbox report according to an embodiment of the present invention;

[0025] Figure 6 is a schematic diagram of an alternative server according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0028] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in the present invention are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set up between the present system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned users or institutions through the interface, and after receiving the consent information feedback from the aforementioned users or institutions, the relevant information is obtained.

[0029] Embodiment 1

[0030] According to an embodiment of the present invention, a method embodiment of a method for storing a sandbox report is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.

[0031] Hash is an encryption algorithm, also known as a hash function or a hashing function. A hash function is a public function that can map a message M of any length into a value H(M) with a shorter and fixed length. H(M) is called a hash value, a hash value (Hash Value), a hashing value, or a message digest. It is a one-way cryptographic system, that is, an irreversible mapping from plaintext to ciphertext, with only an encryption process and no decryption process.

[0032] Easy compressibility is a common characteristic of hash algorithms. A hash algorithm can compress a piece of data of any length into a hash value of a fixed length. Using different hash algorithms, the lengths of the obtained hash values will be different. For example, using the MD5 algorithm, the length of the obtained hash value is 128 bits, 16 bytes. Using the SHA256 algorithm, the length of the obtained hash value is 256 bits, 32 bytes. Applying this characteristic to the data storage direction can reduce the data storage pressure on the server and improve the data storage capacity of the server.

[0033] Figure 1 is a flowchart of an optional method for storing a sandbox report according to an embodiment of the present invention, as Figure 1 shown, the method includes the following steps:

[0034] Step S102, obtain a first detection report, where the first detection report is a report generated after the sandbox detects a target file.

[0035] In step S102, the first detection report is a behavior detection report generated after the sandbox detects a suspicious file. In this embodiment, as Figure 2As shown, a first detection report can be obtained based on the system.

[0036] Step S104: Perform a hash calculation on the row data included in the first detection report to obtain the hash value corresponding to the row data, where the row data is each row of data in the first detection report.

[0037] In step S104, as Figure 2 shown in the flowchart of the storage method of the sandbox report, by traversing the first detection report line by line, perform a hash calculation on the row data in the first detection report to obtain the hash value corresponding to the row data. For example, there are sandbox reports A and B, and both reports have row data a. The total length of the row data is 109 bytes, and then perform a hash calculation on the row data a to obtain a hash value with a total length of 32 bytes.

[0038] It should be noted that the sampling method for performing the hash calculation on the row data a includes but is not limited to MD5.

[0039] Step S106: When it is detected that the hash value exists in the preset hash table, update the row data in the first detection report corresponding to the hash value to the hash value to obtain a second detection report, where the preset hash table is used to store the redundant data in the first detection report and the hash values corresponding to the redundant data.

[0040] Step S108: Store the second detection report in the server.

[0041] In steps S106 - S108, as Figure 2 shown in the flowchart of the storage method of the sandbox report, detect whether the hash value exists in the preset hash table. When the hash value does not exist in the preset hash table, determine whether to end the traversal. If the traversal is not ended, repeat the hash calculation until the traversal ends; when the hash value exists in the preset hash table, update the row data in the first detection report corresponding to the hash value to the hash value to obtain a second detection report. For example, based on the above-obtained hash value with a total length of 32 bytes, replace the row data a in sandbox reports A and B with the hash value with a total length of 32 bytes to obtain sandbox reports A1 and B1. Then store the second detection report in the server.

[0042] It should be noted that since the number of bytes corresponding to the hash value is usually much smaller than the number of bytes of the row data in the detection report, the system memory occupied by the generated second detection report is smaller than the system memory occupied by the first detection report. Therefore, by updating the row data in the first detection report corresponding to the hash value to the hash value, the storage capacity of the sandbox report can be improved, the memory capacity of the server occupied by the detection report is reduced, and thus the data storage pressure on the server is alleviated.

[0043] Based on the solution defined in the above steps S102 to S108, it can be known that in the embodiment of the present invention, by calculating the hash value of the row data in the first detection report and updating the row data in the first detection report with the hash value, the first detection report is first obtained, where the first detection report is the report generated after the sandbox detects the target file; calculating the hash value of the row data included in the first detection report to obtain the hash value corresponding to the row data, where the row data is each row of data in the first detection report; when it is detected that the hash value exists in the preset hash table, updating the row data corresponding to the hash value in the first detection report with the hash value to obtain a second detection report, where the preset hash table is used to store the redundant data in the first detection report and the hash value corresponding to the redundant data; storing the second detection report in the server.

[0044] It should be noted that in the above process, when it is detected that the hash value exists in the preset hash table, the redundant data corresponding to the hash value in the first detection report is updated with the hash value, and the number of bytes corresponding to the hash value is usually much smaller than the number of bytes of the redundant data in the detection report, so that the system memory occupied by the generated second detection report is smaller than the system memory occupied by the first detection report. Therefore, storing the second detection report in the server can improve the storage capacity of the sandbox report and solve the technical problem of the low storage capacity of the sandbox report in the prior art. In addition, storing the second detection report in the server can also reduce the data storage pressure on the server.

[0045] Thus, through the technical solution of the present invention, the purpose of storing the sandbox report is achieved, thereby achieving the technical effect of improving the storage capacity of the server for storing the sandbox report, and further solving the technical problem of the low storage capacity of the sandbox report in the prior art.

[0046] In an alternative embodiment, before obtaining the first detection report, the system obtains a plurality of detection reports generated by the sandbox; then calculates the hash values of the row data in the plurality of detection reports to obtain a plurality of candidate hash values; and finally generates the preset hash table based on the plurality of candidate hash values and the row data corresponding to the plurality of candidate hash values.

[0047] In this embodiment, as Figure 3Flowchart of the method for generating a preset hash table. Before the system obtains the first detection report, it obtains multiple detection reports generated by the sandbox, traverses the multiple detection reports line by line, then performs hash calculation on the line data in the multiple detection reports to obtain multiple candidate hash values, and generates a preset hash table based on the candidate hash values and the line data corresponding to the candidate hash values. Optionally, the line data corresponding to the candidate hash values is redundant data in the detection report. For example, a preset hash table C with a length of 180 bytes can be generated through the candidate hash values and the line data corresponding to the candidate hash values in the multiple detection reports.

[0048] It should be noted that a preset hash table is generated based on the redundant data in the detection report and the hash values corresponding to the redundant data. By marking the redundant data and the corresponding hash values, it prepares for subsequent report updates.

[0049] Furthermore, the system generates the preset hash table based on the multiple candidate hash values and the line data corresponding to the multiple candidate hash values, including: obtaining a target count by counting the number of times the same hash value appears in the multiple candidate hash values; then determining multiple target hash values from the multiple candidate hash values where the target count is greater than a preset threshold; and finally generating the preset hash table based on the multiple target hash values and the line data corresponding to the multiple target hash values.

[0050] Optionally, as Figure 3 Flowchart of the method for generating a preset hash table. By counting the number of times the same hash value appears in the multiple candidate hash values, a target count is obtained, and it is detected whether the target count is greater than a preset threshold. When the target count is less than the preset threshold, it is determined whether the traversal ends. If the traversal does not end, the detection of the target count is repeated until the traversal ends; when the target count is greater than the preset threshold, the preset hash table is generated based on the multiple target hash values and the line data corresponding to the multiple target hash values.

[0051] Optionally, in this embodiment, the more detection reports with the same line data are used for hash value replacement, the more the storage capacity of the sandbox report can be improved, thereby reducing the storage pressure on the server. For example, based on the above Report A and Report B, and preset hash table C, 180 + 32 * 2 = 244 bytes of data are used to replace the original 109 * 2 = 218 bytes of data in the sandbox. However, when the third report D also has the line data a, 180 + 32 * 3 = 276 bytes of data are used to replace 109 * 3 = 327 bytes of data. And so on, when all four reports have this line data, 308 bytes of data are used to replace 436 bytes of data. In this way, less bytes of data are used to replace the original data.

[0052] Optionally, based on the above, a formula for calculating the data storage efficiency of the sandbox can be obtained:

[0053] (Length of hash table + Length of hash value * N) / (Length of row data * N)

[0054] The row data in the above formula does not specifically refer to the above row data, and N represents the number of reports with row data.

[0055] In addition, M = (180 + 32 * N) / (109 * N). When N > 2, the value of M is less than 1. Among them, M is positively correlated with N, that is, the larger N is, the smaller M is, indicating that the above data storage method is more effective when there are more sandbox reports with the same row data.

[0056] Furthermore, after storing the second detection report in the server, the system responds to the report export instruction, and detects whether there is a hash value in the row data of the second detection report; when there is a hash value in the row data of the second detection report, reads multiple hash values in the second detection report; updates the multiple hash values to the row data corresponding to the hash value, obtains the first detection report, and performs an export operation on the first detection report.

[0057] Optionally, after storing the second detection report in the server, the client of the system sends a report export instruction to the server, and the server responds to the report export instruction, and then as Figure 4 shown in the flow schematic diagram of the report export operation, traverses the second detection report line by line, and then detects whether there is a hash value in the second detection report. If there is no hash value in the second detection report, it is confirmed whether the traversal is over; if there is a hash value in the second detection report, reads the hash value in the second detection report, and updates the hash value to the row data corresponding to the hash value, obtains the first detection report, and performs an export operation on the first detection report.

[0058] In another alternative embodiment, the system also queries the row data corresponding to the multiple hash values from the preset hash table based on the multiple hash values, to obtain the target row data; updates the hash values in the second detection report to the target row data, to obtain the first detection report.

[0059] In this embodiment, as Figure 4 shown in the flow schematic diagram of the report export operation, when it is detected that there is a hash value in the second detection report, queries the target row data corresponding to the hash value from the preset hash table based on the hash value, and updates the hash value in the second detection report to the target row data, to obtain the first detection report.

[0060] It should be noted that by updating the hash value to the target row data corresponding to the hash value, a first detection report is obtained, and the report is restored to the original report, improving the accuracy of the detection report.

[0061] Furthermore, after performing an export operation on the first detection report, the system sends the first detection report to the client, where the client is used to display the conclusion in the first detection report.

[0062] Optionally, after performing an export operation on the first detection report, the first detection report can be sent to the client to display the conclusion in the first detection report, and the user can analyze the suspicious file based on the conclusion in the first detection report.

[0063] As can be seen from the above, in this application, a hash table is constructed by calculating the hash value of the row data of the sample behavior report of the cloud sandbox. Then, before storing the sample behavior report of the cloud sandbox, the row data is replaced with the hash value and then saved, reducing the storage space occupied by the report. Finally, before exporting the sample behavior report of the cloud sandbox, the hash value in the report is replaced back with the target data and then exported, thereby improving the storage capacity of the sandbox report and reducing the data storage pressure on the server.

[0064] Embodiment 2

[0065] According to an embodiment of the present invention, an embodiment of a storage device for a sandbox report is further provided, where Figure 5 is a schematic diagram of an optional storage device for a sandbox report according to an embodiment of the present invention, as Figure 5 shown, the device includes: a sandbox report acquisition module 501, a hash calculation module 503, a sandbox report update module 505, and a sandbox report storage module 507.

[0066] Among them, the sandbox report acquisition module 501 is used to acquire a first detection report, where the first detection report is a report generated after the sandbox detects a target file.

[0067] Optionally, the first detection report is a behavior detection report generated after the sandbox detects a suspicious file. In this embodiment, as Figure 2 shown, the first detection report can be acquired based on the system.

[0068] The hash calculation module 503 is used to perform hash calculation on the row data included in the first detection report to obtain the hash value corresponding to the row data, where the row data is each row of data in the first detection report.

[0069] Optionally, as Figure 2Flowchart of the storage method of the sandbox report shown. By traversing the first detection report line by line, hash calculation is performed on the line data in the first detection report to obtain the hash value corresponding to the line data. For example, there are sandbox reports A and B, and both reports have line data a with a total line data length of 109 bytes. Then, hash calculation is performed on line data a to obtain a hash value with a total length of 32 bytes.

[0070] It should be noted that the sampling method for performing the above hash calculation on line data a includes, but is not limited to, MD5.

[0071] The sandbox report update module 505 is used to update the line data corresponding to the hash value in the first detection report to the hash value when it is detected that the hash value exists in the preset hash table, to obtain a second detection report, where the preset hash table is used to store the redundant data in the first detection report and the hash value corresponding to the redundant data.

[0072] The sandbox report storage module 507 is used to store the second detection report in the server.

[0073] Optionally, as Figure 2 Flowchart of the storage method of the sandbox report shown. Detect whether the hash value exists in the preset hash table. When the hash value does not exist in the preset hash table, determine whether to end the traversal. If the traversal does not end, repeat the hash calculation until the traversal ends; when the hash value exists in the preset hash table, update the line data corresponding to the hash value in the first detection report to the hash value to obtain a second detection report. For example, based on the above-obtained hash value with a total length of 32 bytes, replace the line data a in sandbox reports A and B with the hash value with a total length of 32 bytes to obtain sandbox reports A1 and B1. Then store the second detection report in the server.

[0074] It should be noted that since the number of bytes corresponding to the hash value is usually much smaller than the number of bytes of the line data in the detection report, the system memory occupied by the generated second detection report is smaller than the system memory occupied by the first detection report. Therefore, by updating the line data corresponding to the hash value in the first detection report to the hash value, the storage capacity of the sandbox report can be improved, the memory capacity of the server occupied by the detection report is reduced, and thus the data storage pressure on the server is alleviated.

[0075] In an embodiment of the present invention, a method is adopted in which the row data in the first detection report is hashed, and the row data in the first detection report is updated to the hash value. First, the first detection report is obtained, where the first detection report is a report generated after the sandbox detects the target file; the row data included in the first detection report is hashed to obtain the hash value corresponding to the row data, where the row data is each row of data in the first detection report; when it is detected that the hash value exists in the preset hash table, the row data in the first detection report corresponding to the hash value is updated to the hash value to obtain a second detection report, where the preset hash table is used to store the redundant data in the first detection report and the hash value corresponding to the redundant data; and the second detection report is stored in the server.

[0076] It should be noted that in the above process, when it is detected that the hash value exists in the preset hash table, the redundant data in the first detection report corresponding to the hash value is updated to the hash value, and the number of bytes corresponding to the hash value is usually much smaller than the number of bytes of the redundant data in the detection report. As a result, the system memory occupied by the generated second detection report is smaller than the system memory occupied by the first detection report. Therefore, storing the second detection report in the server can improve the storage capacity of the sandbox report and solve the technical problem of the low storage capacity of the sandbox report in the prior art. In addition, storing the second detection report in the server can also reduce the data storage pressure on the server.

[0077] It can be seen that through the technical solution of the present invention, the purpose of storing the sandbox report is achieved, thereby realizing the technical effect of improving the storage capacity of the server for storing the sandbox report, and further solving the technical problem of the low storage capacity of the sandbox report in the prior art.

[0078] Optionally, the storage device of the sandbox report further includes: a first acquisition module, a calculation module, and a generation module. Among them, the first acquisition module is used to obtain multiple detection reports generated by the sandbox before obtaining the first detection report; the calculation module is used to hash the row data in the multiple detection reports to obtain multiple candidate hash values; the generation module is used to generate the preset hash table based on the multiple candidate hash values and the row data corresponding to the multiple candidate hash values.

[0079] Optionally, in this embodiment, as Figure 3Flowchart of the method for generating a preset hash table. Before obtaining the first detection report, the system obtains multiple detection reports generated by the sandbox, traverses the multiple detection reports line by line, then performs hash calculation on the line data in the multiple detection reports to obtain multiple candidate hash values, and generates a preset hash table based on the candidate hash values and the line data corresponding to the candidate hash values. Optionally, the line data corresponding to the candidate hash values is redundant data in the detection report. For example, a preset hash table C with a length of 180 bytes can be generated through the candidate hash values and the line data corresponding to the candidate hash values in the multiple detection reports.

[0080] It should be noted that a preset hash table is generated based on the redundant data in the detection report and the hash values corresponding to the redundant data. By marking the redundant data and the corresponding hash values, it prepares for subsequent report updates.

[0081] Optionally, the generating module further includes: a statistics unit, a hash calculation unit, and a generating unit. Among them, the statistics unit is used to count the number of times the same hash value appears in the multiple candidate hash values to obtain a target number; the hash calculation unit is used to determine multiple target hash values from the multiple candidate hash values for which the target number is greater than a preset threshold; the generating unit is used to generate the preset hash table based on the multiple target hash values and the line data corresponding to the multiple target hash values.

[0082] Optionally, as Figure 3 Flowchart of the method for generating a preset hash table. By counting the number of times the same hash value appears in the multiple candidate hash values to obtain a target number, detecting whether the target number is greater than a preset threshold, when the target number is less than the preset threshold, determining whether the traversal ends, if the traversal does not end, repeating the detection of the target number until the traversal ends; when the target number is greater than the preset threshold, generating the preset hash table based on the multiple target hash values and the line data corresponding to the multiple target hash values.

[0083] Optionally, in this embodiment, the more detection reports with the same line data are used for hash value replacement, the more the storage capacity of the sandbox report can be improved, thereby reducing the storage pressure on the server. For example, based on the above Report A and Report B, and preset hash table C, 180 + 32 * 2 = 244 bytes of data are used to replace the original 109 * 2 = 218 bytes of data in the sandbox. However, when the third report D also has the line data a, 180 + 32 * 3 = 276 bytes of data are used to replace 109 * 3 = 327 bytes of data. And so on, when all four reports have this line data, 308 bytes of data are used to replace 436 bytes of data. In this way, less bytes of data are used to replace the original data.

[0084] Optionally, based on the above, a formula for calculating the data storage efficiency of the sandbox can be obtained:

[0085] (Length of hash table + Length of hash value * N) / (Length of row data * N)

[0086] The row data in the above formula does not specifically refer to the above row data, and N represents the number of reports with row data.

[0087] In addition, M = (180 + 32 * N) / (109 * N). When N > 2, the value of M is less than 1. Among them, M is positively correlated with N, that is, the larger N is, the smaller M is, indicating that the above data storage method is more effective when there are more sandbox reports with the same row data.

[0088] Optionally, the storage device of the sandbox report further includes: a detection module, a reading module, and an update module. Among them, the detection module is used to detect whether there is a hash value in the row data of the second detection report in response to a report export instruction after storing the second detection report in the server; the reading module is used to read multiple hash values in the second detection report when there is a hash value in the row data of the second detection report; the update module is used to update the multiple hash values to the row data corresponding to the hash values to obtain the first detection report, and perform an export operation on the first detection report.

[0089] Optionally, after storing the second detection report in the server, the client of the system sends a report export instruction to the server, and the server responds to the report export instruction, and then as Figure 4 shown in the schematic flow diagram of the report export operation, traverses the second detection report line by line, and then detects whether there is a hash value in the second detection report. If there is no hash value in the second detection report, it is confirmed whether the traversal is over; if there is a hash value in the second detection report, the hash value in the second detection report is read, and the hash value is updated to the row data corresponding to the hash value to obtain the first detection report, and an export operation is performed on the first detection report.

[0090] Optionally, the update module further includes: a query unit and an update unit. Among them, the query unit is used to query the row data corresponding to the multiple hash values from the preset hash table to obtain the target row data; the update unit is used to update the hash values in the second detection report to the target row data to obtain the first detection report.

[0091] Optionally, in this embodiment, as Figure 4The schematic flowchart of the report export operation is shown. When a hash value is detected in the second detection report, the target row data corresponding to the hash value is queried from a preset hash table, and the hash value in the second detection report is updated with the target row data to obtain the first detection report.

[0092] It should be noted that by updating the hash value with the target row data corresponding to the hash value to obtain the first detection report and restoring the report to the initial report, the accuracy of the detection report is improved.

[0093] Optionally, the storage device of the sandbox report further includes: a sending module, configured to send the first detection report to a client after performing an export operation on the first detection report, where the client is used to display the conclusion in the first detection report.

[0094] Optionally, after performing an export operation on the first detection report, the first detection report can be sent to a client to display the conclusion in the first detection report for the user, and the user can analyze the suspicious file based on the conclusion in the first detection report.

[0095] Embodiment 3

[0096] On the other hand, according to an embodiment of the present invention, there is also provided a computer-readable storage medium storing a computer program, where the computer program is configured to execute the above-mentioned storage method of the sandbox report when running.

[0097] Embodiment 4

[0098] On the other hand, according to an embodiment of the present invention, there is also provided an electronic device, where Figure 6 is a schematic diagram of an optional electronic device according to an embodiment of the present invention, as Figure 6 shown, the electronic device includes one or more processors; a memory for storing one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement a program for running, where the program is configured to execute the above-mentioned storage method of the sandbox report when running.

[0099] Embodiment 5

[0100] On the other hand, according to an embodiment of the present invention, there is also provided a computer program product including a computer program / instructions, and when the computer program / instructions are executed by a processor, the above-mentioned storage method of the sandbox report is implemented.

[0101] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages and disadvantages of the embodiments.

[0102] In the above embodiments of the present invention, the descriptions of the various embodiments each have their own emphasis. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0103] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of units can be a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.

[0104] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0105] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0106] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs and other various media that can store program codes.

[0107] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A storage method for sandbox reports, characterized in that including: obtaining a first detection report, where the first detection report is a report generated after a sandbox detects a target file; performing a hash calculation on the line data included in the first detection report to obtain a hash value corresponding to the line data, where the line data is each line of data in the first detection report; when it is detected that the hash value exists in a preset hash table, updating the line data corresponding to the hash value in the first detection report to the hash value to obtain a second detection report, where the preset hash table is used to store redundant data in the first detection report and hash values corresponding to the redundant data; storing the second detection report in a server; wherein, before obtaining the first detection report, the method further includes: obtaining a plurality of detection reports generated by the sandbox; performing a hash calculation on the line data in the plurality of detection reports to obtain a plurality of candidate hash values; generating the preset hash table based on the plurality of candidate hash values and the line data corresponding to the plurality of candidate hash values; wherein, generating the preset hash table based on the plurality of candidate hash values and the line data corresponding to the plurality of candidate hash values includes: counting the number of times the same hash value appears in the plurality of candidate hash values to obtain a target number; determining a plurality of target hash values in the plurality of candidate hash values where the target number is greater than a preset threshold; generating the preset hash table based on the plurality of target hash values and the line data corresponding to the plurality of target hash values.

2. The method according to claim 1, characterized in that, after storing the second detection report in the server, the method further includes: responding to a report export instruction, and detecting whether there is a hash value in the line data of the second detection report; when there is a hash value in the line data of the second detection report, reading a plurality of hash values in the second detection report; updating the plurality of hash values to the line data corresponding to the hash value to obtain the first detection report, and performing an export operation on the first detection report.

3. The method according to claim 2, wherein updating the plurality of hash values to the line data corresponding to the hash value to obtain the first detection report includes: querying, from the preset hash table, the line data corresponding to the plurality of hash values based on the plurality of hash values to obtain target line data; updating the hash values in the second detection report to the target line data to obtain the first detection report.

4. The method according to claim 3, wherein after performing the export operation on the first detection report, the method further includes: sending the first detection report to a client, where the client is used to display the conclusion in the first detection report.

5. A storage device for sandbox reports, characterized in that, including: a sandbox report acquisition module, configured to obtain a first detection report, where the first detection report is a report generated after a sandbox detects a target file; a hash calculation module, configured to perform a hash calculation on the line data included in the first detection report to obtain a hash value corresponding to the line data, where the line data is each line of data in the first detection report; A sandbox report update module, configured to update the row data corresponding to the hash value in the first detection report to the hash value when it is detected that the hash value exists in the preset hash table, so as to obtain a second detection report, where the preset hash table is used to store the redundant data in the first detection report and the hash value corresponding to the redundant data; A sandbox report storage module, configured to store the second detection report in a server; Wherein, the storage device of the sandbox report further includes: a first acquisition module, configured to acquire a plurality of detection reports generated by the sandbox before acquiring the first detection report; perform hash calculation on the row data in the plurality of detection reports to obtain a plurality of candidate hash values; a generation module, configured to generate the preset hash table based on the plurality of candidate hash values and the row data corresponding to the plurality of candidate hash values; The generation module further includes: a statistics unit, configured to count the number of times the same hash value appears in the plurality of candidate hash values to obtain a target number; a hash calculation unit, configured to determine a plurality of target hash values from the plurality of candidate hash values, where the target number is greater than a preset threshold; a generation unit, configured to generate the preset hash table based on the plurality of target hash values and the row data corresponding to the plurality of target hash values.

6. A computer-readable storage medium, characterized in that, A computer program is stored in a computer-readable storage medium, where the computer program is configured to execute the storage method of the sandbox report described in any one of claims 1 to 4 when running.

7. An electronic device, characterized in that, The electronic device includes one or more processors; A memory, configured to store one or more programs, when the one or more programs are executed by the one or more processors, enabling the one or more processors to implement a program for running, where the program is configured to execute the storage method of the sandbox report described in any one of claims 1 to 4 when running.

8. A computer program product comprising a computer program / instructions, characterized in that, The computer program / instructions, when executed by a processor, implement the storage method of the sandbox report described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Data processing method and device, storage medium and electronic equipment

    CN111090628A

  • Tracking data processing method, device and equipment, and storage medium

    CN112131221A