Detection Method, Device, Electronic Device and Storage Medium for In-Network Latent Virus
By deploying detection nodes in the intranet environment, receiving and simulating the access traffic of the response terminal devices, and matching virus characteristics, the problem of latent virus detection in the intranet is solved, early detection and isolation of latent viruses is achieved, and the security of the intranet environment is ensured.
Patent Information
- Application Number
- CN202211209707.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-30
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-09-30
AI Technical Summary
The prior art is difficult to detect latent viruses in intranet environments, resulting in large-scale infection of terminal devices and facing the risk of data leakage.
Deploy detection nodes in an intranet environment, and perform simulated responses by receiving access traffic from terminal devices to receive the first data packet of suspicious terminal devices, and match them with the preset virus characteristics to detect latent virus infection.
It can detect terminal device infection before the latent virus is triggered, avoid data loss and data confidentiality issues, and protect the security of the intranet environment.
Smart Images

Figure CN115580467B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present specification relate to the field of network security technology, and more particularly to a method, device, electronic device and storage medium for detecting latent viruses in an intranet. Background Art
[0002] With the widespread use of computer technology in various fields of social life, viruses have also come one after another as its accessories. Due to the infectiousness, replication and destructiveness of these viruses, they have become a major problem threatening computer security.
[0003] At present, in the intranet (i.e. LAN) environment, there may be a large number of latent viruses that are temporarily dormant because they cannot communicate with the attacker's server (i.e. hacker) through the Internet. When the latent virus is not activated, it does not have any adverse behavior on the computer, so it is difficult for the relevant virus detection mechanism to detect whether the computer is infected with the latent virus.
[0004] However, if the latent virus roams and spreads between terminal devices in the intranet environment, it will cause a large-scale virus infection of terminal devices, and the internal core data and confidential data of the infected terminal devices will face the risk of being stolen and leaked. Once the latent virus is activated, it will cause significant losses. Summary of the invention
[0005] In order to detect whether a terminal device in an intranet environment is infected with a latent virus before the latent virus is activated, the embodiments of this specification provide a method, device, electronic device and storage medium for detecting a latent virus in an intranet.
[0006] In a first aspect, an embodiment of the present specification provides a method for detecting a latent virus in an intranet, which is applied to a detection node, wherein the detection node is deployed in an intranet environment, and the method includes:
[0007] In response to a terminal device in the intranet environment sending access traffic to an external network, receiving the access traffic; wherein the access traffic is pulled to the detection node by an external router;
[0008] In response to establishing a communication connection between the terminal device and the detection node, a simulated response is performed on the access traffic to receive a first data packet sent by a suspicious terminal device; wherein the suspicious terminal device is a terminal device suspected of being infected with a latent virus;
[0009] The first data packet is matched with a preset virus feature to detect whether the suspicious terminal device is infected with a latent virus.
[0010] In a possible design, the access traffic is specifically pulled in the following manner:
[0011] If the access traffic is IP access traffic, the router modifies the IP address carried in the access traffic to the IP address of the detection node, so that the router can divert the access traffic to the detection node;
[0012] If the access traffic is domain name access traffic, the router resolves the domain name carried in the access traffic to the IP address of the detection node, so that the router can divert the access traffic to the detection node; wherein, the router is configured with a DNS service.
[0013] In a possible design, an activation feature set for activating latent viruses is stored in the detection node, and the activation feature set is extracted from the first data packet sample when the latent virus sample in the intranet environment communicates with the attacker server over the Internet;
[0014] The receiving of the first data packet sent by the suspicious terminal device includes:
[0015] Sending the activation feature set to the terminal device;
[0016] Receiving the first data packet sent by the suspicious terminal device in response to the activation feature set.
[0017] In a possible design, a plurality of interaction feature sets are further stored in the detection node, and each interaction feature set is extracted from non-first data packet samples when the latent virus sample in the intranet environment communicates with the attacker server over the Internet;
[0018] After detecting that the suspicious terminal device is infected with a latent virus, it further includes:
[0019] Sending a plurality of the interaction feature sets to the target terminal device; wherein, the target terminal device is the terminal device determined to be infected with a latent virus;
[0020] Receiving interaction data sent by the target terminal device in response to the interaction feature sets;
[0021] Based on the interaction data, determining the virus behavior type of the latent virus infected by the target terminal device.
[0022] In a possible design, each interaction feature set corresponds to an interaction behavior type;
[0023] The determining the virus behavior type of the latent virus infected by the target terminal device based on the interaction data includes:
[0024] Judging whether the interaction data contains fields identical to the interaction feature set;
[0025] If so, determine the interaction behavior type of the interaction feature set corresponding to the interaction data as the virus behavior type of the latent virus infected by the target terminal device.
[0026] In a possible design, after detecting that the suspicious terminal device is infected with a latent virus, it further includes:
[0027] Send an alarm prompt to the terminal device infected with the latent virus to isolate the terminal device infected with the latent virus from other terminal devices not infected with the latent virus for network security.
[0028] In a possible design, after detecting that the suspicious terminal device is infected with a latent virus, it further includes:
[0029] Obtain the creation time of the latent virus in the terminal device;
[0030] For terminal devices infected with latent viruses of the same family, based on the creation time of the latent virus in the terminal device, conduct a traceability analysis of the latent virus.
[0031] In a second aspect, an embodiment of this specification further provides a detection device for latent viruses in an intranet, which is applied to a detection node deployed in an intranet environment. The device includes:
[0032] A receiving module, configured to receive the access traffic in response to the terminal device in the intranet environment sending access traffic to the external network, where the access traffic is pulled by an external router to the detection node;
[0033] A response module, configured to simulate a response to the access traffic in response to establishing a communication connection between the terminal device and the detection node, so as to receive the first data packet sent by the suspicious terminal device, where the suspicious terminal device is a terminal device suspected of being infected with a latent virus;
[0034] A matching module, configured to match the first data packet with a preset virus feature to detect whether the suspicious terminal device is infected with a latent virus.
[0035] In a third aspect, an embodiment of this specification further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the method described in any embodiment of this specification is implemented.
[0036] In a fourth aspect, an embodiment of this specification further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method described in any embodiment of this specification.
[0037] The embodiments of this specification provide a method, device, electronic device, and storage medium for detecting latent viruses in an intranet. By deploying detection nodes in the intranet environment, first, the detection nodes are used to receive the access traffic sent by terminal devices in the intranet environment to the external network. Then, the detection nodes are used to simulate responses to the received access traffic to receive the first data packet sent by a suspicious terminal device. Finally, the detection nodes are used to match the first data packet with preset virus characteristics, so that it is possible to detect that the terminal devices in the intranet environment are infected with latent viruses before the latent viruses are activated. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0039] Figure 1 is a flowchart of a method for detecting latent viruses in an intranet provided by an embodiment of this specification;
[0040] Figure 2 is a hardware architecture diagram of an electronic device provided by an embodiment of this specification;
[0041] Figure 3 is a structural diagram of a device for detecting latent viruses in an intranet provided by an embodiment of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] To make the objectives, technical solutions, and advantages of the embodiments of this specification clearer, the following will clearly and completely describe the technical solutions in the embodiments of this specification with reference to the drawings in the embodiments of this specification. Obviously, the described embodiments are some, but not all, of the embodiments of this specification. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this specification.
[0043] Please refer to Figure 1 , an embodiment of this specification provides a method for detecting latent viruses in an intranet, which is applied to detection nodes deployed in the intranet environment. The method includes:
[0044] Step 100: In response to a terminal device in the intranet environment sending access traffic to the external network, receive the access traffic; where the access traffic is pulled by an external router to the detection node;
[0045] Step 102: In response to establishing a communication connection between the terminal device and the detection node, perform a simulated response to the access traffic to receive the first data packet sent by the suspicious terminal device; wherein, the suspicious terminal device is a terminal device suspected of being infected with a latent virus.
[0046] Step 104: Match the first data packet with the preset virus signature to detect whether the suspicious terminal device is infected with a latent virus.
[0047] In the embodiments of this specification, by deploying a detection node in the intranet environment, first use this detection node to receive the access traffic sent by the terminal devices in the intranet environment to the external network, then use this detection node to perform a simulated response to the received access traffic to receive the first data packet sent by the suspicious terminal device, and finally use this detection node to match the first data packet with the preset virus signature, so as to be able to detect that the terminal devices in the intranet environment are infected with latent viruses before the latent viruses are activated.
[0048] In the related art, intranet environments are set up in military and scientific research units and other institutions. Inevitably, there are some vulnerabilities in rich application scenarios. If these vulnerabilities are exploited by lawbreakers, there will be great information security problems. In the technical solution provided in the embodiments of this specification, since the detection node is deployed in the intranet environment, this solution does not require the terminal devices in the intranet environment to be connected to the Internet, that is, the detection of the terminal devices infected with latent viruses can be completed in the intranet environment, thus avoiding possible data loss and data confidentiality problems.
[0049] The following describes Figure 1 The execution methods of the steps shown.
[0050] Regarding step 100:
[0051] Since a detection node is deployed in the intranet environment, the access traffic sent by the terminal devices in the intranet environment to the external network can be diverted through an external router (wherein, the router is used to establish a communication connection between the terminal device and the detection node). In this way, the detection node can be used to perform a targeted simulated response to this access traffic later, so that the detection node can be disguised or simulated as a malicious program control end (i.e., the attacker server) in the external network environment.
[0052] In an embodiment of this specification, the access traffic is diverted in the following specific way:
[0053] If the access traffic is IP access traffic, the router modifies the IP address carried by the access traffic to the IP address of the detection node to divert the access traffic to the detection node;
[0054] If the access traffic is domain name access traffic, the router resolves the domain name carried by the access traffic into the IP address of the detection node, so that the router can divert the access traffic to the detection node; wherein, the router is configured with a DNS service.
[0055] In this embodiment, since the external communication of the latent virus includes two forms: IP address and domain name, it is necessary to configure the router with a DNS service, so that the router can perform DNS resolution on the domain name carried by the access traffic, and complete the diversion of the access traffic based on the IP address obtained by DNS resolution (i.e., the IP address of the detection node).
[0056] For example, when a terminal device in the intranet environment sends access traffic to the extranet (for example, accessing the malicious IP address 117.215.129.210 on the extranet), if the access traffic is IP access traffic and the carried IP address is 117.215.129.210, then this IP address is modified to the IP address of the detection node (for example, the IP address of the detection node is 192.168.100.20), so that the router can divert the access traffic to the detection node; if the access traffic is domain name access traffic (for example, accessing the malicious domain name deftsecurity.com on the extranet), then this domain name is resolved through the DNS service configured on the router to obtain the IP address of the detection node (i.e., 192.168.100.20), so that the router can divert the access traffic to the detection node.
[0057] Regarding step 102:
[0058] After the detection node receives the access traffic, the detection node will establish a communication connection (such as TCP three-way handshake) with all terminal devices that send access traffic to the extranet. After the detection node and the terminal device establish a communication connection, the detection node needs to perform a simulated response to the access traffic (for example, the detection node attempts to connect to www.baidu.com to perform a simulated response based on the TCP / IP protocol), so as to prepare for discovering the terminal devices infected with latent viruses in the intranet environment.
[0059] It should be noted that there are two situations for the suspicious terminal device to send the first data packet: one is after the detection node completes the simulated response to the access traffic (which also means that the terminal device receives this simulated response), at this time the suspicious terminal device will directly send the first data packet to the detection node; the other is after the detection node completes the simulated response to the access traffic, the detection node needs to continue to send the activation feature set for activating the latent virus to the suspicious terminal device.
[0060] The following introduces the second situation where the suspicious terminal device sends the first data packet.
[0061] In one embodiment of this specification, an activation feature set for activating latent viruses is stored in a detection node. The activation feature set is extracted from the first packet samples of latent virus samples in the intranet environment when communicating with an attacker's server over the Internet;
[0062] The step of "receiving the first packet sent by a suspicious terminal device" may specifically include:
[0063] Sending the activation feature set to the terminal device;
[0064] Receiving the first packet sent by the suspicious terminal device in response to the activation feature set.
[0065] In this embodiment, after the detection node sends the activation feature set to the target terminal device, the activation feature set can activate the latent virus of the terminal device, so that the terminal device suspected of being infected with the latent virus (i.e., the suspicious terminal device) mistakenly believes that the detection node is a malicious program control end in the external network environment. Therefore, the suspicious terminal device sends the first packet in response to the activation feature set to the detection node, which is conducive to subsequent detection of whether the suspicious terminal device is infected with the latent virus.
[0066] It can be understood that the activation feature set can be obtained by manual analysis or sandbox analysis of the first packet samples of a large number of latent virus samples when communicating with an attacker's server over the Internet; the step of sending the activation feature set to the terminal device can be specifically implemented by constructing an activation packet to carry the data in the activation feature set and sending the activation packet to the suspicious terminal device.
[0067] For example, the activation feature set can be: tcp.payload~"info(|U|.*)+Comet 0.1.2.0", and the first packet in response to the activation feature set can be:
[0068] tcp.payload~"info|U|Hacked_F837BEDA|U|WIN-1K3SF5T4RUQ / AT-WW|U|People's Republic of China|U|Win 7 SP1 x86|U|Not Found|U|-|U|1.99 GB|U|Intel(R)Core(TM)i5-6200U CPU@2.30GHz|U|0.1.2.0|U|2020-07-02|U|VMware,Inc.|U|192.168.92.144Comet 0.1.2.0".
[0069] Regarding step 104:
[0070] Continuing with the example in step 102, assume that the preset virus signature includes "Hacked". From this, it can be known that the suspicious terminal device that sent the first data packet of the above response activation signature set is infected with a latent virus. Here, the embodiments of this specification do not enumerate and elaborate on the preset virus signatures. It can be understood that these virus signatures are also obtained through manual analysis or sandbox analysis of latent virus samples in the intranet environment.
[0071] In one embodiment of this specification, the detection node also stores multiple interaction signature sets, and each interaction signature set is extracted from non-first data packet samples when latent virus samples in the intranet environment communicate with the attacker's server over the Internet;
[0072] After detecting that a suspicious terminal device is infected with a latent virus, the above method further includes:
[0073] Sending multiple interaction signature sets to the target terminal device; where the target terminal device is the terminal device determined to be infected with the latent virus;
[0074] Receiving the interaction data in response to the interaction signature set sent by the target terminal device;
[0075] Based on the interaction data, determining the virus behavior type of the latent virus infected by the target terminal device.
[0076] In this embodiment, on the basis of sending the activation signature set to the target terminal device, further sending multiple interaction signature sets to the target terminal device. In this way, not only can the terminal device infected with the latent virus be detected, but also the virus behavior type of the latent virus infected by the target terminal device can be determined, which is beneficial for in-depth analysis of the latent virus. Among them, the step of sending multiple interaction signature sets to the target terminal device can be specifically implemented by constructing an interaction data packet to carry the data in the interaction signature set and sending the interaction data packet to the target terminal device.
[0077] For example, the interaction signature set can be: tcp.payload~"download(|U|.*)+Comet0.1.2.0", and the interaction data in response to the interaction signature set can be:
[0078] tcp.payload~"ProcessSplitcsrss|380|-|2134016|-ProcessSplitservices|556|-|5820416|-ProcessSplittaskhost|1656|C:\Windows\system32\taskhost.exe|3022848|2020 / 5 / 28:17:22ProcessSplitsvchost|992|-|21696512|-ProcessSplitsvchost|900|-|21188608|-ProcessSplitsmss|276|-|372736|-ProcessSplitwpsoffice|1300|C:\ProgramFiles(x86)\Kingsoft\WPSOffice\11.8.6.8697\office6\wpsoffice.exe|19611648|2020 / 6 / 89:58:23ProcessSplitSystem|4|-|163840|-ProcessSplitsvchost|804|-|5009408|-ProcessSplittaskmgr|3796|C:\Windows\system32\taskmgr.exe|3092480|2020 / 7 / 610:54:02ProcessSplitIdle|0|-|0|-ProcessSplit|U|serverComet 0.1.2.0".
[0079] In one embodiment of the present specification, each interaction feature set corresponds to an interaction behavior type;
[0080] The step of "determining the virus behavior type of the latent virus infected by the target terminal device based on the interaction data" may specifically include:
[0081] Determine whether the interaction data contains fields identical to the interaction feature set;
[0082] If so, determine the interaction behavior type of the interaction feature set corresponding to the interaction data as the virus behavior type of the latent virus infected by the target terminal device.
[0083] In this embodiment, by determining whether the interaction data contains fields identical to the interaction feature set, the interaction behavior type of the interaction feature set corresponding to the interaction data is determined as the virus behavior type of the latent virus infected by the target terminal device.
[0084] Continuing with the above example, the field in the interaction data that is the same as the interaction feature set is "tcp.payload". Therefore, this interaction data is targeted, and the interaction behavior type of the interaction feature set corresponding to the interaction data is "download" (i.e., download for stealing secrets). Therefore, it can be determined that the virus behavior type of the latent virus infecting the target terminal device is download for stealing secrets.
[0085] In an embodiment of this specification, after detecting that a suspicious terminal device is infected with a latent virus, the above method further includes:
[0086] Sending an alarm prompt to the terminal device infected with the latent virus to network - securely isolate the terminal device infected with the latent virus from other terminal devices not infected with the latent virus.
[0087] In this embodiment, when the detection node detects that a suspicious terminal device is infected with a latent virus, the detection node can send an alarm prompt to the target terminal device infected with the latent virus to remind the user to network - securely isolate the target terminal device from other terminal devices not infected with the latent virus, thereby protecting the security of other terminal devices not infected with the latent virus.
[0088] Generally speaking, latent viruses exist in the intranet environment in families. Therefore, it is necessary to use the detection node to conduct traceability analysis on latent viruses of the same family.
[0089] In an embodiment of this specification, after detecting that a suspicious terminal device is infected with a latent virus, the above method further includes:
[0090] Obtaining the creation time of the latent virus in the terminal device;
[0091] For terminal devices infected with latent viruses of the same family, based on the creation time of the latent virus in the terminal device, conduct traceability analysis on the latent virus.
[0092] In this embodiment, by obtaining the creation time of the latent virus in the terminal device (for example, it can be obtained by accessing the logs of the terminal device), for terminal devices infected with latent viruses of the same family, traceability analysis can be conducted on the latent virus based on the creation time of the latent virus in the terminal device, and a traceability analysis report can be further output to the user.
[0093] As Figure 2 、 Figure 3 shown, an embodiment of this specification provides a detection device for latent viruses in the intranet. The device embodiment can be implemented by software, or by hardware, or by a combination of software and hardware. At the hardware level, as Figure 2As shown in the figure, it is a hardware architecture diagram of an electronic device where a detection device for intranet latent viruses provided by an embodiment of this specification is located. In addition to Figure 2 the shown processor, memory, network interface, and non-volatile memory, the electronic device where the device in the embodiment is located usually may also include other hardware, such as a forwarding chip responsible for processing packets, etc. Taking software implementation as an example, as Figure 3 shown, as a logically meaningful device, it is formed by the CPU of its corresponding electronic device reading the corresponding computer program in the non-volatile memory into the memory and running it.
[0094] As Figure 3 shown, a detection device for intranet latent viruses provided by this embodiment is applied to a detection node, and the detection node is deployed in an intranet environment. The device includes:
[0095] A receiving module 300, configured to receive the access traffic in response to the terminal device in the intranet environment sending access traffic to the external network, where the access traffic is pulled by an external router to the detection node;
[0096] A response module 302, configured to perform a simulated response to the access traffic in response to establishing a communication connection between the terminal device and the detection node, so as to receive the first data packet sent by a suspicious terminal device, where the suspicious terminal device is a terminal device suspected of being infected with a latent virus;
[0097] A matching module 304, configured to match the first data packet with a preset virus signature to detect whether the suspicious terminal device is infected with a latent virus.
[0098] In an embodiment of this specification, the receiving module 300 may be used to execute step 100 in the above method embodiment, the response module 302 may be used to execute step 102 in the above method embodiment, and the matching module 304 may be used to execute step 104 in the above method embodiment.
[0099] In an embodiment of this specification, the access traffic is specifically pulled in the following manner:
[0100] If the access traffic is IP access traffic, the router modifies the IP address carried in the access traffic to the IP address of the detection node, so that the router pulls the access traffic to the detection node;
[0101] If the access traffic is domain name access traffic, the router resolves the domain name carried in the access traffic to the IP address of the detection node, so that the router pulls the access traffic to the detection node; where the router is configured with a DNS service.
[0102] In one embodiment of this specification, an activation feature set for activating latent viruses is stored in the detection node, and the activation feature set is extracted from the first packet samples of latent virus samples in the intranet environment when communicating with the attacker server over the Internet;
[0103] Receiving the first packet sent by the suspicious terminal device includes:
[0104] Sending the activation feature set to the terminal device;
[0105] Receiving the first packet in response to the activation feature set sent by the suspicious terminal device.
[0106] In one embodiment of this specification, a plurality of interaction feature sets are further stored in the detection node, and each interaction feature set is extracted from non-first packet samples of latent virus samples in the intranet environment when communicating with the attacker server over the Internet;
[0107] It further includes:
[0108] A determination module for performing the following operations:
[0109] After detecting that the suspicious terminal device is infected with a latent virus, sending a plurality of the interaction feature sets to the target terminal device; wherein, the target terminal device is the terminal device determined to be infected with the latent virus;
[0110] Receiving the interaction data in response to the interaction feature set sent by the target terminal device;
[0111] Based on the interaction data, determining the virus behavior type of the latent virus infected by the target terminal device.
[0112] In one embodiment of this specification, each interaction feature set corresponds to an interaction behavior type;
[0113] When the determination module performs the operation of determining the virus behavior type of the latent virus infected by the target terminal device based on the interaction data, it is used to perform the following operations:
[0114] Judging whether the interaction data contains fields identical to the interaction feature set;
[0115] If so, determining the interaction behavior type of the interaction feature set corresponding to the interaction data as the virus behavior type of the latent virus infected by the target terminal device.
[0116] In one embodiment of this specification, it further includes:
[0117] A sending module, configured to send an alarm prompt to the terminal device infected with the latent virus after detecting that the suspicious terminal device is infected with the latent virus, so as to isolate the terminal device infected with the latent virus from other terminal devices not infected with the latent virus for network security.
[0118] In one embodiment of the present specification, it further includes:
[0119] A tracing module, configured to perform the following operations:
[0120] After detecting that the suspicious terminal device is infected with the latent virus, obtain the creation time of the latent virus in the terminal device;
[0121] For terminal devices infected with latent viruses of the same family, based on the creation time of the latent virus in the terminal device, perform a tracing analysis on the latent virus.
[0122] It can be understood that the structure illustrated in the embodiments of the present specification does not constitute a specific limitation on a detection device for latent viruses in an intranet. In other embodiments of the present specification, a detection device for latent viruses in an intranet may include more or fewer components than those shown in the figure, or combine certain components, or split certain components, or have different component arrangements. The components shown in the figure can be implemented in hardware, software, or a combination of software and hardware.
[0123] Regarding the information interaction, execution process, etc. between the various modules within the above-mentioned device, since it is based on the same concept as the method embodiments of the present specification, the specific content can be referred to the description in the method embodiments of the present specification, and will not be elaborated here.
[0124] The embodiments of the present specification further provide an electronic device, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, it implements a method for detecting latent viruses in an intranet according to any embodiment of the present specification.
[0125] The embodiments of the present specification further provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the processor is enabled to execute a method for detecting latent viruses in an intranet according to any embodiment of the present specification.
[0126] Specifically, a system or device equipped with a storage medium can be provided, on which software program codes for implementing the functions of any one of the above-mentioned embodiments are stored, and the computer (or CPU or MPU) of the system or device is enabled to read and execute the program codes stored in the storage medium.
[0127] In this case, the program code read from the storage medium itself can implement the functions of any of the above-described embodiments. Therefore, the program code and the storage medium storing the program code constitute a part of this specification.
[0128] Examples of the storage medium for providing the program code include a floppy disk, a hard disk, a magneto-optical disk, an optical disk (such as a CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), a magnetic tape, a non-volatile memory card, and a ROM. Alternatively, the program code can be downloaded from a server computer via a communication network.
[0129] In addition, it should be clear that not only can the functions of any of the above-described embodiments be implemented by executing the program code read by a computer, but also by causing an operating system or the like operating on the computer to perform some or all of the actual operations based on the instructions of the program code.
[0130] Furthermore, it can be understood that the program code read from the storage medium is written into the memory provided in an expansion board inserted into the computer or into the memory provided in an expansion module connected to the computer, and then based on the instructions of the program code, a CPU or the like installed on the expansion board or the expansion module is caused to perform some and all of the actual operations, thereby implementing the functions of any of the above-described embodiments.
[0131] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprises", "comprising" or any other variation thereof is intended to cover a non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0132] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including the above method embodiments; and the foregoing storage medium includes various media such as ROM, RAM, magnetic disk, or optical disk that can store program code.
[0133] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this specification, rather than limiting them; although the above embodiments have been described in detail with reference to this specification, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of this specification.
Claims
1. A detection method for an intranet latent virus, characterized in that, Applied to a detection node, the detection node is deployed in an internal network environment, and the method includes: In response to a terminal device in the internal network environment sending access traffic to the external network, receiving the access traffic; wherein, the access traffic is pulled to the detection node by an external router; In response to establishing a communication connection between the terminal device and the detection node, simulating an answer to the access traffic to receive the first data packet sent by a suspicious terminal device; wherein, the suspicious terminal device is a terminal device suspected of being infected with a latent virus; Matching the first data packet with a preset virus signature to detect whether the suspicious terminal device is infected with a latent virus.
2. The method according to claim 1, wherein The access traffic is specifically pulled in the following manner: If the access traffic is IP access traffic, the router modifies the IP address carried by the access traffic to the IP address of the detection node, so that the router pulls the access traffic to the detection node; If the access traffic is domain name access traffic, the router resolves the domain name carried by the access traffic to the IP address of the detection node, so that the router pulls the access traffic to the detection node; wherein, the router is configured with a DNS service.
3. The method according to claim 1, wherein The detection node stores an activation signature set for activating latent viruses, and the activation signature set is extracted from the first data packet samples of latent virus samples in the internal network environment during Internet communication with an attacker server; Receiving the first data packet sent by a suspicious terminal device includes: Sending the activation signature set to the terminal device; Receiving the first data packet sent by the suspicious terminal device in response to the activation signature set.
4. The method according to claim 3, characterized in that, The detection node also stores multiple interaction signature sets, and each interaction signature set is extracted from non-first data packet samples of latent virus samples in the internal network environment during Internet communication with an attacker server; After detecting that the suspicious terminal device is infected with a latent virus, it further includes: Sending multiple interaction signature sets to a target terminal device; wherein, the target terminal device is a terminal device determined to be infected with a latent virus; Receiving interaction data sent by the target terminal device in response to the interaction signature sets; Based on the interaction data, determining the virus behavior type of the latent virus infected by the target terminal device.
5. The method according to claim 4, characterized in that, Each interaction signature set corresponds to an interaction behavior type; Based on the interaction data, determining the virus behavior type of the latent virus infected by the target terminal device includes: Judging whether the interaction data contains fields identical to the interaction signature set; If so, determining the interaction behavior type of the interaction signature set corresponding to the interaction data as the virus behavior type of the latent virus infected by the target terminal device.
6. The method according to any one of claims 1-5, characterized in that, After detecting that the suspicious terminal device is infected with a latent virus, it further includes: Sending an alarm prompt to the terminal device infected with the latent virus to isolate the terminal device infected with the latent virus from other terminal devices not infected with the latent virus in terms of network security.
7. The method according to any one of claims 1-5, characterized in that, After detecting that the suspicious terminal device is infected with a latent virus, it further includes: Obtain the creation time of the latent virus in the terminal device; For terminal devices infected with latent viruses of the same family, based on the creation time of the latent virus in the terminal device, conduct a traceability analysis of the latent virus.
8. A detection device for an intranet latent virus, characterized in that, Applied to a detection node, the detection node is deployed in an intranet environment, and the device includes: A receiving module, configured to receive the access traffic in response to the terminal device in the intranet environment sending access traffic to the external network; wherein, the access traffic is pulled by an external router to the detection node; A response module, configured to simulate a response to the access traffic in response to establishing a communication connection between the terminal device and the detection node, so as to receive the first data packet sent by the suspicious terminal device; wherein, the suspicious terminal device is a terminal device suspected of being infected with a latent virus; A matching module, configured to match the first data packet with a preset virus signature to detect whether the suspicious terminal device is infected with a latent virus.
9. An electronic device, characterized in that, It includes a memory and a processor. When the processor executes a computer program stored in the memory, the method described in any one of claims 1-7 is implemented.
10. A computer-readable storage medium, characterized in that, A computer program is stored thereon. When the computer program is executed on a computer, the computer is made to execute the method described in any one of claims 1-7.
Citation Information
Patent Citations
Network switching method and system based on multi-access edge computing
CN113891325A
Secure network cache content
US8584234B1