A file management and storage system

By introducing a file management and preservation system in the internal data protection management of enterprises, using the data encryption module and detection module to identify and store sample virus files into the encrypted storage space, the security detection problems caused by sample virus files are solved, and intercepted information and alarm information are reduced, and the security of storage space is improved.

CN115758360BActive Publication Date: 2025-07-25BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211493732.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-25
Publication Date
2025-07-25
Estimated Expiration
2042-11-25

AI Technical Summary

Technical Problem

In the internal data protection management of enterprises, the existence of sample virus files leads to repeated generation of unnecessary interception information and alarm information during security detection.

Method used

A file management and storage system is adopted, including a data encryption module, a detection module and a backend server. The detection module identifies sample virus files and stores them in an encrypted storage space. The data encryption module is used to establish an encrypted storage space and configures corresponding detection strategies to reduce the number of sample virus files in the regular storage space.

Benefits of technology

It effectively reduces the number of sample virus files in the conventional storage space, avoids repeated security detection, reduces unnecessary interception information and alarm information, and improves the security of storage space.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115758360B_ABST
    Figure CN115758360B_ABST
Patent Text Reader

Abstract

The present invention discloses a file management and storage system, which includes a data encryption module, a detection module and a configuration background server. The data encryption module, the detection module and the configuration background server are communicatively connected to each other pairwise. When the detection module performs file detection on files in the conventional storage space of an electronic device, if a sample virus file is detected, it determines whether there is a target encrypted storage space in the electronic device. If not, according to the initial space configuration information, a space establishment instruction is generated and sent to the data encryption module. The data encryption module establishes an encrypted storage space according to the obtained space establishment instruction. The detection module stores the sample virus file in the encrypted storage space. The present invention can timely remove the sample virus file from the conventional storage space, so that the same sample virus file will not be repeatedly subjected to security detection, thereby reducing the problem of repeatedly generating unnecessary interception information and warning information for the same sample virus file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of secure file storage, and particularly to a file management and storage system. Background Art

[0002] In the internal data protection management of an enterprise, due to the different positions of each employee, there are some differences in the files and programs they need to use. For example, in some operation and maintenance or security research and development positions, some sample virus files are stored in the operating environment to verify the virus detection and protection capabilities of new protection programs. The sample virus files can be aggressive programs or variant documents. Since these sample virus files are necessary files that must be used by R & D personnel during the R & D process, in order to facilitate use, R & D personnel usually directly place such files in the local folder.

[0003] At the same time, in order to ensure the network security of the system, security detections of the above-mentioned operation and maintenance or security research and development positions are often carried out on the operating environment. Thus, whenever a security detection is performed, unnecessary interception information and alarm information are repeatedly generated for these sample virus files. Summary of the Invention

[0004] In view of this, the present invention provides a file management and storage system, which at least partially solves the problem in the prior art that unnecessary interception information and alarm information are repeatedly generated for sample virus files whenever a security detection is performed.

[0005] According to the first aspect of the present application, a file management and storage system is provided. The system includes a data encryption module, a detection module, and a configuration background server. The data encryption module and the detection module are within the same electronic device, and the data encryption module, the detection module, and the configuration background server are communicatively connected to each other pairwise.

[0006] The detection module is used to perform the following steps:

[0007] When the detection module performs file detection on the files in the conventional storage space of the electronic device according to the detection policy, if a sample virus file is detected, it determines whether there is a target encrypted storage space in the electronic device.

[0008] If not, it obtains the initial space configuration information from the configuration background server.

[0009] According to the initial space configuration information, a space creation instruction is generated and sent to the data encryption module.

[0010] The data encryption module creates an encrypted storage space according to the obtained space creation instruction.

[0011] The detection module stores the sample virus file into the encrypted storage space.

[0012] The present invention has at least the following beneficial effects:

[0013] When detecting a sample virus file during file detection of files in the conventional storage space of an electronic device in the present invention, the sample virus file in the conventional storage space will be stored in the corresponding encrypted storage space. Thus, the sample virus file can be removed from the conventional storage space in a timely manner, so that the same sample virus file will not be repeatedly subjected to security detection, thereby reducing the problem of repeatedly generating unnecessary interception information and warning information for the same sample virus file. In addition, by this method, the number of sample virus files existing in the conventional storage space can also be reduced to improve the security of the conventional storage space. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for description in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings according to these drawings without creative efforts.

[0015] Figure 1 It is a schematic connection structure diagram of a file management and storage system provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0017] According to one aspect of the present application, as Figure 1 shown, a file management and storage system is provided. The system includes a data encryption module 2, a detection module 3, and a configuration background server 1. The data encryption module 2 and the detection module 3 are in the same electronic device, and the data encryption module 2, the detection module 3, and the configuration background server 1 are communicatively connected to each other in pairs.

[0018] Generally, there are multiple different electronic devices in the system, and a data encryption module 2 and a detection module 3 are installed in each electronic device. The configuration background server 1 is used to manage and modify the information corresponding to each electronic device, such as various configuration information. The electronic device can be a PC (Personal Computer), a removable medium, a smart terminal, or a cloud storage space.

[0019] The detection module 3 is used to perform the following steps:

[0020] When the detection module 3 performs file detection on the files in the regular storage space of the electronic device according to the detection strategy, if a sample virus file is detected, it determines whether there is a target encrypted storage space in the electronic device.

[0021] The detection module 3 can determine whether there is a target encrypted storage space in the electronic device according to the pre-configured rules. For example, a storage path corresponding to a certain type of sample virus file can be pre-configured. If the corresponding storage path already exists in the electronic device, it is determined that there is a target encrypted storage space in the electronic device. Otherwise, it is determined that there is no target encrypted storage space in the electronic device.

[0022] The detection module 3 can simply select an existing detection software with the ability to detect sample viruses, such as the Zhijia detection system. This detection module 3 can scan and detect information such as files and links in the specified path and identify virus sample files. Since, in the actual use process, the commonly used virus sample files are different for different positions, so, a detection module 3 with the ability to detect targeted virus sample files can be installed and used on the PCs of different positions.

[0023] At the same time, it is also possible to construct a virus recognition sample based on the characteristic information of all virus sample files, and then input this virus recognition sample into an existing self-learning model to train the model to obtain a virus recognition model. The virus recognition model can identify virus files with a certain type of fixed characteristics.

[0024] If not, obtain the initial space configuration information from the configuration background server 1.

[0025] The initial space configuration information can be information input by the user according to the usage needs into the configuration background server 1.

[0026] Generate a space creation instruction according to the initial space configuration information and send it to the data encryption module 2.

[0027] The data encryption module 2 creates an encrypted storage space according to the obtained space creation instruction. The space creation instruction can be manually input or pre-configured by the configuration background server 1. If the space creation instruction is configured by the configuration background server 1, a json structure can be used to implement the space creation instruction, and the corresponding configuration instruction can be set specifically by configuring the values of the corresponding fields in the json structure. The encrypted storage space can be a file volume, a physical volume or cloud storage.

[0028] The detection module 3 stores the sample virus file in the encrypted storage space. Thus, after detecting the sample virus file, an encrypted storage space can be established according to the obtained initial space configuration information, and the sample virus file can be stored therein. Thus, the sample virus file can be stored in the corresponding encrypted storage space in a timely manner, effectively avoiding the spread of virus files.

[0029] The sample virus file can be a virus file required by security engineers, a virus file required by security operation and maintenance personnel, and a sample required for AI training for virus file recognition. At the same time, important data of users can also be stored in the encrypted storage space.

[0030] In this embodiment, when detecting files in the normal storage space of the electronic device, when a sample virus file is detected, the sample virus file in the normal storage space will be stored in the corresponding encrypted storage space. Thus, the sample virus file can be removed from the normal storage space in a timely manner, so that the same sample virus file will not be repeatedly subjected to security detection, reducing the problem of repeatedly generating unnecessary interception information and alarm information for the same sample virus file. In addition, by this method, the number of sample virus files existing in the normal storage space can also be reduced to improve the security of the normal storage space.

[0031] As a possible implementation manner of the present application, the data encryption module 2 is further configured to perform the following steps:

[0032] After each new encrypted storage space is established, send the new configuration information corresponding to the new encrypted storage space to the configuration background server 1. The data encryption module 2 can use existing programs with the ability to establish encrypted storage spaces, such as a data safe.

[0033] The configuration background server 1 is configured to perform the following steps:

[0034] Configure a detection policy for each received configuration information according to the detection policy configuration rules. The detection policies corresponding to the encrypted storage space and the normal storage space are different. Preferably, the detection intensity of the detection policy corresponding to the encrypted storage space is less than that of the detection policy corresponding to the normal storage space. For example, the detection policy corresponding to the normal storage space is usually a more detailed scanning policy to ensure that no virus files appear in the normal storage space, thereby ensuring the security of the normal storage space. Usually, the encrypted storage space is dedicated to storing sample virus files or some confidential files, so the corresponding detection policy should detect the encrypted storage space as little as possible, such as a quick detection, to avoid the problem of repeatedly generating unnecessary interception information and alarm information.

[0035] More preferably, the detection policy corresponding to the encrypted storage space includes not performing file detection on the files in the encrypted storage space.

[0036] Obtain the initial space configuration information of multiple electronic devices. The initial space configuration information is the information used to create a target encrypted storage space when it is determined that there is no target encrypted storage space in the electronic device.

[0037] Send the detection policy and the initial space configuration information to the detection module 3.

[0038] In this embodiment, after each creation of an encrypted storage space by the data encryption safe, the corresponding new configuration information is sent to the configuration background server 1. Then, the configuration background server 1 timely generates the detection policy corresponding to the new configuration information and timely issues the new detection policy to the detection module 3. At the same time, the configuration background server 1 is also used to obtain the initial space configuration information and timely issue it to the detection module 3. Thus, through the linkage among the data encryption module 2, the detection module 3, and the configuration background server 1 in this embodiment, after each modification of the corresponding information in the system, the corresponding update information can be timely sent to other relevant modules in the system to ensure the accuracy of the information in the system.

[0039] In this embodiment, the detection module 3 can timely update the detection policies corresponding to the encrypted storage space and the regular storage space in each electronic device, so that the detection module 3 can scan and detect the files in the electronic device according to the latest detection policy. Thus, it can be prevented that the detection module 3 scans the newly created encrypted storage space as a regular storage space, and further reduce the problem of repeatedly generating unnecessary interception information and alarm information for the same sample virus file.

[0040] As a possible implementation manner of this application, the space creation instruction includes a space account, a space password, encryption strength information, and a creation path. The above information can all be configured by the user according to the actual usage scenario.

[0041] The data encryption module 2 is further configured to perform the following steps:

[0042] Create an encrypted storage space under the creation path according to the space account and the space password. The space creation instruction may further include a new space name. Thus, the preliminary creation of the encrypted storage space can be completed through these basic information. At the same time, other relevant information such as the usage permission of the encrypted storage space can also be configured.

[0043] Encrypt the encrypted storage space according to the encryption strength information to generate a space opening file corresponding to the encrypted storage space. The space opening file is used to start the corresponding encrypted storage space. The space opening file can be a shortcut corresponding to the encrypted storage space. After clicking the shortcut, the data encryption module 2 performs the corresponding decryption operation according to the encryption strength information. The corresponding relationship between the encryption process and the decryption process can be stored in advance in the data encryption module 2. When the decryption operation is completed, the corresponding encrypted storage space is opened. At this time, corresponding operations of adding, deleting, querying, and modifying files in the encrypted storage space can be performed. To ensure the security of the encrypted storage space, the executable files in the encrypted storage space need to be set to not allow running.

[0044] During the creation of the encrypted storage space, the user can set the encryption and decryption algorithm strength according to the encryption strength information. The specific encryption strengths are as follows:

[0045] The general strength corresponds to the first-level encryption process: suitable for protecting ordinary files, such as office spreadsheets, documents, etc.

[0046] The intermediate strength corresponds to the second-level encryption process: suitable for storing ordinary files and important materials, such as personal account information, etc., provides an anti-delete backup function, and can perform regular backups, read-write backups, time-based backups, data recovery, etc.

[0047] The high strength corresponds to the third-level encryption process: suitable for storing general files, important materials, sample virus management, etc. In addition to providing the functions of the intermediate strength, it also provides active defenses such as anti-ransomware, anti-worm, and anti-variant documents, as well as the function of erasing files and disk partitions.

[0048] Generate a user token for the encrypted storage space according to the device identifier, space account, and space password corresponding to the creation path.

[0049] Save the user token locally. The user token can be a sha1 user token, which is only saved by the local user. The configuration background server 1 does not save it to prevent token leakage.

[0050] When the encrypted storage space is established in the cloud storage space, other users can be allowed to access the encrypted storage space in the corresponding cloud storage space by sharing the user token. Thus, the convenience of using the encrypted storage space can be improved.

[0051] In this embodiment, various information and permissions of the newly created encrypted storage space can be configured according to the information in the space creation instruction. At the same time, after the encrypted storage space is created, the encrypted storage space will be encrypted with the corresponding strength. Thus, not only can the flexibility of the configuration of the encrypted storage space be improved, but also the encrypted storage space can be encrypted with different strengths, thereby further improving the security of the encrypted storage space.

[0052] As a possible implementation manner of this application, after the data encryption module 2 creates each new encrypted storage space, it sends the configuration information corresponding to the new encrypted storage space to the configuration background server 1, including:

[0053] Use the remaining information in the space creation instruction as the new configuration information of the new encrypted storage space. The remaining information is the information remaining in the space creation instruction after deleting the space password.

[0054] Send the new configuration information to the configuration background server 1.

[0055] Store the space password in the password database of the configuration background server 1.

[0056] Since the configuration background server 1 will configure a detection policy for each new configuration information, that is, the content of the new configuration information will be displayed in the configuration background server 1, and then the user will configure the corresponding detection policy according to the corresponding rules and the specific content displayed in the new configuration information. Therefore, if the new configuration information includes the space password, it will increase the risk of the space password being leaked. The new configuration information in this embodiment does not include the space password of the new encrypted storage space, and the space password is stored in a dedicated password database. Thus, the risk of the space password being leaked can be reduced without affecting the configuration of the detection policy.

[0057] As a possible implementation manner of this application, the encrypted storage space is encrypted according to the encryption strength information to generate a space opening file corresponding to the encrypted storage space, including:

[0058] Perform primary encryption processing or secondary encryption processing or tertiary encryption processing on the encrypted storage space according to the encryption strength information.

[0059] The primary encryption processing is to encrypt the encrypted storage space through the first encryption algorithm to generate a primary space opening file corresponding to the encrypted storage space. The first encryption algorithm can be any one of SM4, AES or ChaCha20.

[0060] The secondary encryption process encrypts the first-level space opening file through a second encryption algorithm to generate a second-level space opening file corresponding to the encrypted storage space. The second encryption algorithm can be any one of SM4, AES, or ChaCha20 that is different from the first encryption algorithm.

[0061] The tertiary encryption process encrypts the second-level space opening file through a third encryption algorithm to generate a third-level space opening file corresponding to the encrypted storage space. The first encryption algorithm, the second encryption algorithm, and the third encryption algorithm are different from each other. The third encryption algorithm can be one of the remaining algorithms among SM4, AES, or ChaCha20 after removing the first encryption algorithm and the second encryption algorithm.

[0062] In this embodiment, the encryption process with low encryption intensity has a faster encryption speed, and the encryption process with high encryption intensity has higher security. Thus, different levels of encryption processing can be set according to the importance level and size of the files placed in the encrypted storage space, and then the encrypted storage space can be encrypted better.

[0063] As a possible implementation manner of the present application, the initial space configuration information includes a preset storage path. The detection policy corresponding to the encrypted storage space includes the encrypted storage path of the encrypted storage space.

[0064] Determining whether there is a target encrypted storage space in the electronic device includes:

[0065] Then, the preset storage path is matched with any existing encrypted storage path of the detection module 3.

[0066] When the matching fails, it is determined that there is no target encrypted storage space in the electronic device.

[0067] When the matching succeeds, it is determined that there is a target encrypted storage space in the electronic device.

[0068] Further, after determining that there is a target encrypted storage space in the electronic device, the detection module 3 is further configured to perform the following method:

[0069] Store the sample virus file in the target encrypted storage space.

[0070] This embodiment can use the storage path as a criterion for determining whether there is a target encrypted storage space in the electronic device, and then the determination can be made more accurately and quickly.

[0071] As a possible implementation manner of the present application, the configured background server 1 is further configured to perform the following steps:

[0072] When receiving new configuration information, configure the corresponding detection policy for the received new configuration information according to the detection policy configuration rules. The new configuration information is new configuration information or new initial space configuration information.

[0073] Send the detection policy corresponding to the new configuration information to detection module 3.

[0074] In this embodiment, whenever the configuration background server 1 receives new configuration information, it will correspondingly synchronize the relevant update information generated according to the new configuration information to detection module 3 in a timely manner. This can ensure that detection module 3 can obtain the latest and most accurate detection policy in a timely manner, and thus can reduce the number of misdetections when detection module 3 performs file detection.

[0075] As a possible implementation manner of this application, detection module 3 is further configured to execute the following method:

[0076] Send heartbeat information to configuration background server 1 at a preset interval to determine whether detection module 3 and configuration background server 1 are in a communication connection state.

[0077] Receive heartbeat response information. The heartbeat response information is generated by configuration background server 1 according to the received heartbeat information.

[0078] Each time detection module 3 receives heartbeat response information, it will reset the timer, and at this time the timer will start accumulating time again. The time recorded by the timer is the time interval between any two adjacent heartbeat response information.

[0079] When the time interval between any two adjacent heartbeat response information is greater than the update duration threshold, obtain the existing detection policy in configuration background server 1. The update duration threshold can be 5 minutes. The update duration threshold is greater than or equal to the preset interval.

[0080] In this embodiment, after detection module 3 establishes a connection with configuration background server 1, it can detect whether the communication line between detection module 3 and configuration background server 1 remains connected in real time by sending heartbeat information. If a heartbeat response information is received immediately after sending the heartbeat information, it indicates that the communication line between detection module 3 and configuration background server 1 remains connected. Otherwise, it indicates that the communication line between detection module 3 and configuration background server 1 has been disconnected. Thus, after the communication line between detection module 3 and configuration background server 1 is disconnected, detection module 3 will actively obtain the existing detection policy in configuration background server 1 to update the detection policy in detection module 3 in a timely manner. This further ensures that detection module 3 can obtain the latest and most accurate detection policy in a timely manner, and thus can reduce the number of misdetections when detection module 3 performs file detection.

[0081] In this application, the configuration background server 1 can be used to flexibly configure the encrypted storage space. After creating the encrypted storage space, it can be displayed and modified on the configuration background server 1, and the control permissions for the files in the encrypted storage space (controlling whether the files in the space are readable and operations such as not being able to be added, deleted, or modified) can be configured. Additionally, it is possible to configure whether the space is automatically locked and the function of changing tokens.

[0082] The permissions for files in the encrypted storage space include the following types:

[0083] Read: Users can view the file content and properties.

[0084] Write: Users can change the file content and properties.

[0085] Script resource access: Users can access the source code of the file, such as the script for script resource access in an Active Server Pages (ASP) application. This option can only be used when the "Read" or "Write" permission is assigned. Users can access the source file. If the "Read" permission is assigned, the source code can be read. If the "Write" permission is assigned, the source code can also be written to.

[0086] Directory browsing: Users can view the file list and collection.

[0087] Record access: Create a log entry for each website access. Recording access to an indexed resource allows the indexing service to index the resource.

[0088] Pure script: Setting the permissions of the application to "pure script" can enable the application mapped to the script engine to run in this directory without having the permissions set for executable files. Setting the permissions to "pure script" is safer than setting them to "script and executable file" because you can limit the applications that can run in this directory.

[0089] Script and executable file: Setting the permissions of the application to "script and executable file" allows the application to run in this script and executable file directory, including applications mapped to the script engine and Windows binary files (.dll and.exe files).

[0090] An embodiment of the present invention also provides a non-transitory computer-readable storage medium. This storage medium can be set in an electronic device to save at least one instruction or at least one program segment related to a method for implementing a method in a method embodiment. The at least one instruction or the at least one program segment is loaded and executed by the processor to implement the method provided in the above embodiment.

[0091] An embodiment of the present invention also provides an electronic device, including a processor and the aforementioned non-transitory computer-readable storage medium.

[0092] An embodiment of the present invention also provides a computer program product, which includes program code. When the program product runs on an electronic device, the program code is used to cause the electronic device to execute the steps in the methods according to various exemplary embodiments of the present invention described above in this specification.

[0093] Although some specific embodiments of the present invention have been described in detail by way of examples, those skilled in the art should understand that the above examples are for illustrative purposes only and not for limiting the scope of the present invention. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the present invention. The scope of the present invention is defined by the appended claims.

Claims

1. A file management and storage system, characterized in that, The system includes a data encryption module, a detection module, and a configuration background server. The data encryption module and the detection module are within the same electronic device, and the data encryption module, the detection module, and the configuration background server are communicatively connected to each other pairwise; The detection module is used to perform the following steps: When the detection module performs file detection on the files in the regular storage space of the electronic device according to the detection policy, if a sample virus file is detected, it determines whether there is a target encrypted storage space in the electronic device; If not, it obtains the initial space configuration information from the configuration background server; Generates a space creation instruction according to the initial space configuration information and sends it to the data encryption module; The data encryption module creates an encrypted storage space according to the obtained space creation instruction; The detection module stores the sample virus file into the encrypted storage space; The data encryption module is further used to perform the following steps: After each new encrypted storage space is created, it sends the new configuration information corresponding to the new encrypted storage space to the configuration background server; The configuration background server is used to perform the following steps: Configures a detection policy for each received configuration information according to the detection policy configuration rules; the detection policies for the encrypted storage space and the regular storage space are different; Obtains the initial space configuration information of multiple such electronic devices; Sends the detection policy and the initial space configuration information to the detection module; The detection intensity of the detection policy corresponding to the encrypted storage space is less than that of the detection policy corresponding to the regular storage space.

2. The system according to claim 1, wherein The space creation instruction includes a space account, a space password, encryption intensity information, and a creation path; The data encryption module is further used to perform the following steps: Creates an encrypted storage space under the creation path according to the space account and the space password; Performs encryption processing on the encrypted storage space according to the encryption intensity information to generate a space opening file corresponding to the encrypted storage space; The space opening file is used to start the corresponding encrypted storage space; Generates a user token for the encrypted storage space according to the device identifier corresponding to the creation path, the space account, and the space password; Saves the user token locally.

3. The system according to claim 2, wherein After the data encryption module creates each new encrypted storage space, it sends the configuration information corresponding to the new encrypted storage space to the configuration background server, including: Taking the remaining information in the space creation instruction as the new configuration information of the new encrypted storage space; the remaining information is the information remaining in the space creation instruction after deleting the space password; Sends the new configuration information to the configuration background server; Stores the space password into the password database of the configuration background server.

4. The system according to claim 2, wherein Performing encryption processing on the encrypted storage space according to the encryption intensity information to generate a space opening file corresponding to the encrypted storage space, including: Performing primary encryption processing or secondary encryption processing or tertiary encryption processing on the encrypted storage space according to the encryption intensity information; The primary encryption processing is to perform encryption processing on the encrypted storage space through a first encryption algorithm to generate a primary space opening file corresponding to the encrypted storage space; The secondary encryption process is to encrypt the first-level space opening file through a second encryption algorithm to generate a second-level space opening file corresponding to the encrypted storage space; The tertiary encryption process is to encrypt the second-level space opening file through a third encryption algorithm to generate a third-level space opening file corresponding to the encrypted storage space; the first encryption algorithm, the second encryption algorithm, and the third encryption algorithm are different from each other.

5. The system according to claim 1, wherein The initial space configuration information includes a preset storage path; The detection policy corresponding to the encrypted storage space includes the encrypted storage path of the encrypted storage space; Determining whether there is a target encrypted storage space in the electronic device includes: Performing a matching process on the preset storage path and any one of the existing encrypted storage paths of the detection module; When the matching fails, it is determined that there is no target encrypted storage space in the electronic device; When the matching succeeds, it is determined that there is a target encrypted storage space in the electronic device.

6. The system according to claim 1, wherein The configuration background server is further configured to perform the following steps: When receiving new configuration information, configure a corresponding detection policy for the received new configuration information according to the detection policy configuration rule; the new configuration information is new configuration information or new initial space configuration information; Send the detection policy corresponding to the new configuration information to the detection module.

7. The system according to claim 6, wherein The detection module is further configured to perform the following method: Send heartbeat information to the configuration background server at a preset interval; to determine whether the detection module and the configuration background server are in a communication connection state; Receive a heartbeat response message; The heartbeat response message is generated by the configuration background server according to the received heartbeat information; When the time interval between any two adjacent heartbeat response messages is greater than the update duration threshold, obtain the existing detection policy in the configuration background server.

8. The system according to claim 5, wherein After determining that there is a target encrypted storage space in the electronic device, the detection module is further configured to perform the following method: Store the sample virus file in the target encrypted storage space.

9. The system according to claim 1, characterized in that, The detection policy corresponding to the encrypted storage space includes not performing file detection on the files in the encrypted storage space.

Citation Information

Patent Citations

  • Detection method, detection device and detection system based on virus sample characteristics

    CN103559447A

  • Method and device for storing files

    CN108133154A