Method and apparatus for upgrading virus library, electronic device, and storage medium
By sending broadcast messages and establishing different types of connections within a local area network (LAN), the problem of standalone antivirus software's virus database being unable to be updated in batches is solved, achieving efficient virus database updates that are applicable to terminal devices within a LAN.
Patent Information
- Application Number
- CN202211542948.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-02
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2042-12-02
AI Technical Summary
Standalone antivirus software cannot perform batch updates of its virus database, resulting in low update efficiency when there are a large number of terminal devices.
By sending broadcast messages to target terminal devices in a local area network, connections with other terminal devices are established, and virus definition update packages are sent based on different connection types (FTP, shared files, TCP, UDP) to achieve batch updates of the virus definition.
Without a centralized management server, efficient batch upgrades of virus databases for multiple terminal devices on a local area network were achieved, saving time and manpower.
Smart Images

Figure CN116418801B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, electronic device, and storage medium for upgrading a virus database. Background Technology
[0002] With the widespread application of computer technology in all aspects of social life, viruses, like their byproducts, have followed suit. To ensure the network security of terminal devices, antivirus software needs to be installed. The detection performance of antivirus software relies on its virus database. The virus database is a collection of virus characteristics that allows terminal devices to quickly detect viruses based on these characteristics. Therefore, it is necessary to update the virus database periodically.
[0003] However, for standalone antivirus software, since there is no server deployed for centralized management and the terminal devices are located on a local area network and cannot connect to the internet, the virus database of standalone antivirus software cannot be updated in batches. That is, the latest virus database needs to be imported individually for each terminal device. When the number of terminal devices requiring virus database updates is large, the efficiency of this method will be significantly reduced.
[0004] Therefore, there is an urgent need for a method, device, electronic equipment, and storage medium for upgrading virus databases to solve the above-mentioned technical problems. Summary of the Invention
[0005] In order to enable batch upgrades of multiple terminal devices in a local area network, embodiments of this specification provide a method, apparatus, electronic device, and storage medium for upgrading a virus database.
[0006] Firstly, embodiments of this specification provide a method for upgrading a virus database, applied to a target terminal device deployed in a local area network, the method comprising:
[0007] In response to importing the virus definition update package, a broadcast message is sent to other terminal devices deployed on the local area network;
[0008] Based on the broadcast message, a target connection is established between the target terminal device and the other terminal devices.
[0009] Based on the type of the target connection, the virus database update package is sent to the other terminal devices.
[0010] In one possible design, the step of sending a broadcast message to other terminal devices deployed in the local area network in response to importing the virus definition update package includes:
[0011] In response to the import of the virus definition update package, the FTP setup software on the target terminal device is launched to set up the target terminal device as an FTP server;
[0012] The configured FTP address is broadcast as a message and sent to other terminal devices deployed in the local area network; wherein, the FTP address includes the IP address, username, password and absolute path of the target terminal device where the virus database update package is located.
[0013] In one possible design, sending the virus database update package to the other terminal devices based on the type of the target connection includes:
[0014] When the target connection type is FTP, receive and verify the username and password sent by the other terminal device;
[0015] After successful verification, in response to a download command sent by the other terminal device, the virus database update package is sent to the other terminal device.
[0016] In one possible design, the type of the target connection is a shared file type;
[0017] The response to importing the virus definition update package includes sending a broadcast message to other terminal devices deployed in the local area network, including:
[0018] In response to the import of the virus definition update package, the folder containing the virus definition update package is configured as a shared folder;
[0019] The absolute path of the shared folder and the IP address of the target terminal device are used as a broadcast message, and the broadcast message is sent to other terminal devices deployed in the local area network.
[0020] In one possible design, the target connection is of type TCP;
[0021] The response to importing the virus definition update package includes sending a broadcast message to other terminal devices deployed in the local area network, including:
[0022] In response to the import of the virus definition update package, a TCP port is created;
[0023] The TCP port, the IP address of the target terminal device, and the TCP connection method are used as broadcast messages, and the broadcast messages are sent to other terminal devices deployed in the local area network.
[0024] In one possible design, the target connection is of type UDP;
[0025] The response to importing the virus definition update package includes sending a broadcast message to other terminal devices deployed in the local area network, including:
[0026] In response to importing the virus definition update package, the IP address and UDP connection method of the target terminal device are broadcast as a broadcast message, and the broadcast message is sent to other terminal devices deployed in the local area network.
[0027] In one possible design, sending broadcast messages to other terminal devices deployed in the local area network includes:
[0028] Send a broadcast message to the broadcast listening port of other terminal devices deployed in the local area network; wherein the broadcast listening port is created after the antivirus software of the other terminal devices starts.
[0029] Secondly, embodiments of this specification also provide a virus database upgrade device, applied to a target terminal device deployed in a local area network, the device comprising:
[0030] The first sending module is used to send broadcast messages to other terminal devices deployed in the local area network in response to the import of the virus definition update package;
[0031] A connection establishment module is used to establish a target connection between the target terminal device and the other terminal devices based on the broadcast message;
[0032] The second sending module is used to send the virus database update package to the other terminal devices based on the type of the target connection.
[0033] Thirdly, embodiments of this specification also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the method described in any embodiment of this specification.
[0034] Fourthly, embodiments of this specification also provide a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the methods described in any embodiment of this specification.
[0035] This specification provides a method, apparatus, electronic device, and storage medium for upgrading a virus database. When importing a virus database upgrade package into a target terminal device, the target terminal device sends a broadcast message to other terminal devices deployed in the local area network (LAN). This establishes a target connection between the target terminal device and the other terminal devices based on the broadcast message, allowing the virus database upgrade package to be sent to the other terminal devices based on the type of target connection. Therefore, this solution enables batch upgrading of multiple terminal devices in a LAN without a centrally managed server. Attached Figure Description
[0036] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0037] Figure 1 This is a flowchart of a virus database upgrade method provided in one embodiment of this specification;
[0038] Figure 2 This is a hardware architecture diagram of an electronic device provided in one embodiment of this specification;
[0039] Figure 3 This is a structural diagram of a virus database upgrade device provided in one embodiment of this specification. Detailed Implementation
[0040] To make the objectives, technical solutions, and advantages of the embodiments in this specification clearer, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments in this specification without creative effort are within the scope of protection of this specification.
[0041] Please refer to Figure 1 This specification provides a method for updating a virus database, applied to a target terminal device deployed in a local area network. The method includes:
[0042] Step 100: In response to importing the virus definition update package, send a broadcast message to other terminal devices deployed on the local area network;
[0043] Step 102: Based on the broadcast message, establish a target connection between the target terminal device and other terminal devices;
[0044] Step 104: Based on the type of the target connection, send the virus definition update package to other terminal devices.
[0045] In this embodiment, when importing the virus definition update package to the target terminal device, the target terminal device sends a broadcast message to other terminal devices deployed in the local area network. This broadcast message establishes a target connection between the target terminal device and the other terminal devices, allowing the virus definition update package to be sent to the other terminal devices based on the type of target connection. Therefore, the above solution can upgrade multiple terminal devices in a local area network in batches.
[0046] In one embodiment of this specification, the step of "sending a broadcast message to other terminal devices deployed in the local area network" may specifically include:
[0047] Send broadcast messages to the broadcast listening ports of other terminal devices deployed on the local area network; the broadcast listening ports are created after the antivirus software on the other terminal devices starts.
[0048] In this embodiment, by creating a broadcast listening port, other terminal devices can receive broadcast messages sent by the target terminal device, and the creation of the broadcast listening port depends on the startup of the antivirus software on the other terminal devices.
[0049] Since broadcasting is a one-way broadcast, it can use UDP broadcasting.
[0050] For example, when antivirus software on other terminal devices starts up, it creates a broadcast listening port 1. The target terminal device sends a broadcast message to the designated port 1 of all other terminal devices on the local area network, and the other terminal devices can then receive the corresponding message content. Of course, for other terminal devices that do not want to update their virus definitions, a toggle switch can be set up. Users can control this switch to prevent their port 1 from receiving broadcast messages, thus preventing them from downloading the corresponding virus definition update package from the target terminal device.
[0051] It should be noted that after receiving a broadcast message, the broadcast listening port of other terminal devices parses it, thereby determining what type of broadcast message it is (e.g., FTP, TCP, UDP, or shared file), and thus enabling the target terminal device and other terminal devices to establish what type of target connection.
[0052] The following section introduces four virus database update strategies.
[0053] The first method is to access an FTP server:
[0054] In one embodiment of this specification, step 100 may specifically include:
[0055] In response to the import of the virus definition update package, the FTP setup software on the target terminal device is launched to set up the target terminal device as an FTP server;
[0056] The configured FTP address is broadcast as a broadcast message and sent to other terminal devices deployed on the local area network; the FTP address includes the target terminal device's IP address, username, password, and the absolute path to the virus definition update package.
[0057] In this embodiment, by launching FTP setup software (such as FileZilla) on the target terminal device when importing the virus definition update package, the target terminal device is set up as an FTP server. The target terminal device can then send the configured FTP address to other terminal devices deployed on the local area network. To ensure secure access to the FTP server, the FTP address must include the target terminal device's IP address, username, password, and the absolute path to the virus definition update package.
[0058] In one embodiment of this specification, step 104 may specifically include:
[0059] When the target connection type is FTP, receive and verify the username and password sent by other terminal devices;
[0060] After successful verification, in response to download instructions sent by other terminal devices, the virus definition update package is sent to those other terminal devices.
[0061] In this embodiment, in order to enable other terminal devices to securely access the target terminal device, it is necessary to first verify the access of the other terminal devices, that is, to verify the username and password sent by the other terminal devices; only after the verification is successful can the target terminal device be downloaded by other terminal devices to download the virus database update package.
[0062] The second method is to access a shared folder:
[0063] In one embodiment of this specification, the target connection is of type shared file.
[0064] Step 100 may specifically include:
[0065] In response to importing virus definition update packages, configure the folder containing the virus definition update packages as a shared folder;
[0066] The absolute path of the shared folder and the IP address of the target terminal device are broadcast as a broadcast message, and the broadcast message is sent to other terminal devices deployed in the local area network.
[0067] In this embodiment, by configuring the folder containing the virus definition update package as a shared folder when importing it, the target terminal device can send the absolute path of the shared folder and its IP address to other terminal devices deployed on the local area network. Upon receiving the broadcast message, other terminal devices will access the target terminal device's shared folder and download the virus definition update package.
[0068] The third method is to use a TCP connection:
[0069] In one embodiment of this specification, the target connection type is TCP.
[0070] Step 100 may specifically include:
[0071] In response to the import of the virus definition update package, a TCP port is created;
[0072] The TCP port, the IP address of the target terminal device, and the TCP connection method are broadcast as a message, and the broadcast message is sent to other terminal devices deployed on the local area network.
[0073] In this embodiment, a TCP port is created on the target terminal device when importing the virus definition update package. Then, the target terminal device can send the TCP port, the IP address of the target terminal device, and the TCP connection method to other terminal devices deployed in the local area network.
[0074] Understandably, after the TCP three-way handshake, the target terminal device and other terminal devices establish a TCP connection. In this way, other terminal devices can send requests to the target terminal device to obtain virus definition update packages, and the target terminal device can send the virus definition update packages to other terminal devices via a socket; alternatively, after establishing a TCP connection, the target terminal device can directly send virus definition update packages to other terminal devices.
[0075] The fourth method is to use a UDP connection:
[0076] In one embodiment of this specification, the target connection type is UDP;
[0077] Step 100 may specifically include:
[0078] In response to the import of the virus definition update package, the target terminal device's IP address and UDP connection method are broadcast as a broadcast message, and the broadcast message is sent to other terminal devices deployed on the local area network.
[0079] In this embodiment, since UDP is a one-way connection, when importing the virus definition update package, the target terminal device directly sends its IP address and UDP connection method to other terminal devices deployed on the local area network. Thus, after establishing the UDP connection, the target terminal device can directly send the virus definition update package to other terminal devices.
[0080] In summary, the above technical solution solves the inefficient method of upgrading the virus database on a standalone antivirus software terminal, which requires each terminal to operate and upgrade independently. Instead, it uses a more efficient synchronous batch upgrade method to free up manpower and save time.
[0081] like Figure 2 , Figure 3As shown, this specification provides a virus database update device. The device can be implemented in software, hardware, or a combination of both. From a hardware perspective, as... Figure 2 The diagram shown is a hardware architecture diagram of an electronic device containing a virus database upgrade device provided in an embodiment of this specification. Except for... Figure 2 In addition to the processor, memory, network interface, and non-volatile memory shown, the electronic device in the embodiment may also include other hardware, such as a forwarding chip responsible for processing packets. Taking software implementation as an example, such as... Figure 3 As shown, a device in a logical sense is formed by the CPU of the electronic device in which it is located reading the corresponding computer program from the non-volatile memory into the memory for execution.
[0082] like Figure 3 As shown, this embodiment provides a virus database upgrade device, applied to a target terminal device deployed in a local area network. The device includes:
[0083] The first sending module 300 is used to send broadcast messages to other terminal devices deployed in the local area network in response to the import of the virus database upgrade package;
[0084] The connection establishment module 302 is used to establish a target connection between the target terminal device and the other terminal devices based on the broadcast message;
[0085] The second sending module 304 is used to send the virus database update package to the other terminal devices based on the type of the target connection.
[0086] In the embodiments described in this specification, the first sending module 300 can be used to execute step 100 in the above method embodiments, the connection establishment module 302 can be used to execute step 102 in the above method embodiments, and the second sending module 304 can be used to execute step 104 in the above method embodiments.
[0087] In one embodiment of this specification, the first sending module is configured to perform the following operations:
[0088] In response to the import of the virus definition update package, the FTP setup software on the target terminal device is launched to set up the target terminal device as an FTP server;
[0089] The configured FTP address is broadcast as a message and sent to other terminal devices deployed in the local area network; wherein, the FTP address includes the IP address, username, password and absolute path of the target terminal device where the virus database update package is located.
[0090] In one embodiment of this specification, the second transmitting module is configured to perform the following operations:
[0091] When the target connection type is FTP, receive and verify the username and password sent by the other terminal device;
[0092] After successful verification, in response to a download command sent by the other terminal device, the virus database update package is sent to the other terminal device.
[0093] In one embodiment of this specification, the target connection is of the shared file type;
[0094] The first sending module is configured to perform the following operations:
[0095] In response to the import of the virus definition update package, the folder containing the virus definition update package is configured as a shared folder;
[0096] The absolute path of the shared folder and the IP address of the target terminal device are used as a broadcast message, and the broadcast message is sent to other terminal devices deployed in the local area network.
[0097] In one embodiment of this specification, the target connection is of type TCP;
[0098] The first sending module is configured to perform the following operations:
[0099] In response to the import of the virus definition update package, a TCP port is created;
[0100] The TCP port, the IP address of the target terminal device, and the TCP connection method are used as broadcast messages, and the broadcast messages are sent to other terminal devices deployed in the local area network.
[0101] In one embodiment of this specification, the target connection is of type UDP;
[0102] The first sending module is configured to perform the following operations:
[0103] In response to importing the virus definition update package, the IP address and UDP connection method of the target terminal device are broadcast as a broadcast message, and the broadcast message is sent to other terminal devices deployed in the local area network.
[0104] In one embodiment of this specification, when the first sending module performs the action of sending a broadcast message to other terminal devices deployed in the local area network, it performs the following operations:
[0105] Send a broadcast message to the broadcast listening port of other terminal devices deployed in the local area network; wherein the broadcast listening port is created after the antivirus software of the other terminal devices starts.
[0106] It is understood that the structures illustrated in the embodiments of this specification do not constitute a specific limitation on a virus database upgrade device. In other embodiments of this specification, a virus database upgrade device may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0107] The information interaction and execution process between the modules in the above-mentioned device are based on the same concept as the method embodiments in this specification, and the specific details can be found in the descriptions in the method embodiments in this specification, so they will not be repeated here.
[0108] This specification also provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements a virus database upgrade method according to any embodiment of this specification.
[0109] This specification also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform a virus database upgrade method according to any embodiment of this specification.
[0110] Specifically, a system or apparatus equipped with a storage medium may be provided, on which software program code implementing the functions of any of the embodiments described above is stored, and the computer (or CPU or MPU) of the system or apparatus may read and execute the program code stored in the storage medium.
[0111] In this case, the program code read from the storage medium can itself implement the function of any of the above embodiments, and therefore the program code and the storage medium storing the program code constitute a part of this specification.
[0112] Examples of storage media used to provide program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Alternatively, program code can be downloaded from a server computer via a communication network.
[0113] Furthermore, it should be clear that not only can the program code read by the computer be executed, but also the operating system or other components operating on the computer can be instructed based on the program code to perform some or all of the actual operations, thereby realizing the function of any of the embodiments described above.
[0114] Furthermore, it is understood that the program code read from the storage medium is written to the memory set in the expansion board inserted into the computer or to the memory set in the expansion module connected to the computer. Then, based on the instructions of the program code, the CPU or other components installed on the expansion board or expansion module execute some and all of the actual operations, thereby realizing the function of any of the above embodiments.
[0115] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0116] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as ROM, RAM, magnetic disk, or optical disk.
[0117] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this specification, and are not intended to limit them. Although this specification has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this specification.
Claims
1. A method for upgrading a virus database, characterized in that, The method, applied to a target terminal device deployed in a local area network, includes: In response to importing the virus definition update package of the standalone antivirus software, a broadcast message is sent to the broadcast listening port of other terminal devices deployed in the local area network; wherein, the terminal devices located in the local area network cannot be connected to the Internet, and the broadcast listening port is created after the antivirus software on the other terminal devices starts. Based on the broadcast message, a target connection is established between the target terminal device and the other terminal devices; wherein, the type of the target connection includes FTP, shared file, TCP, and UDP. Based on the type of the target connection, the virus database update package is sent to the other terminal devices; The response to importing the virus definition update package includes sending a broadcast message to other terminal devices deployed in the local area network, including: When the type of the target connection is FTP, in response to importing the virus definition update package, the FTP setup software in the target terminal device is started to set up the target terminal device as an FTP server; The configured FTP address is broadcast as a broadcast message and sent to other terminal devices deployed in the local area network; wherein, the FTP address includes the IP address, username, password and absolute path of the target terminal device where the virus definition update package is located; The step of sending the virus database update package to the other terminal devices based on the type of the target connection includes: Receive and verify the username and password sent by the other terminal devices; After successful verification, in response to a download command sent by the other terminal device, the virus database update package is sent to the other terminal device. When the target connection is a shared file type, the step of responding to importing the virus definition update package and sending a broadcast message to other terminal devices deployed on the local area network includes: In response to the import of the virus definition update package, the folder containing the virus definition update package is configured as a shared folder; The absolute path of the shared folder and the IP address of the target terminal device are used as a broadcast message, and the broadcast message is sent to other terminal devices deployed in the local area network. When the target connection is of type TCP, the step of sending a broadcast message to other terminal devices deployed on the local area network in response to importing the virus definition update package includes: In response to the import of the virus definition update package, a TCP port is created; The TCP port, the IP address of the target terminal device, and the TCP connection method are used as broadcast messages, and the broadcast messages are sent to other terminal devices deployed in the local area network. When the target connection is of type UDP, the step of sending a broadcast message to other terminal devices deployed on the local area network in response to importing the virus definition update package includes: In response to importing the virus definition update package, the IP address and UDP connection method of the target terminal device are broadcast as a broadcast message, and the broadcast message is sent to other terminal devices deployed in the local area network.
2. A virus database upgrade device, characterized in that, For performing the method as described in claim 1, applied to a target terminal device deployed in a local area network, the apparatus includes: The first sending module is used to send broadcast messages to the broadcast listening ports of other terminal devices deployed in the local area network in response to the import of the virus definition update package of the standalone antivirus software; wherein, the terminal devices located in the local area network cannot be connected to the Internet, and the broadcast listening ports are created after the antivirus software on the other terminal devices starts. A connection establishment module is used to establish a target connection between the target terminal device and the other terminal devices based on the broadcast message; wherein, the type of the target connection includes FTP type, shared file type, TCP type and UDP type; The second sending module is used to send the virus database update package to the other terminal devices based on the type of the target connection.
3. An electronic device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the method as described in claim 1.
4. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed in a computer, causes the computer to perform the method of claim 1.
Citation Information
Patent Citations
Local area network virus library upgrading system and method based on P2P technology
CN101795295A
Method and device for sharing file modification in real time in local area network
CN107612979A
Charging pile software upgrading method, charging pile and control equipment
CN109922145A
Data upgrading method and device
CN112532664A