A virus killing drill method, device, equipment and storage medium
By conducting virus scanning drills in a one-way isolated data sandbox, the problem of the lack of isolation between the antivirus environment and the production environment was solved, thus achieving both the security of virus scanning and the protection of the production environment, and reducing economic losses.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- EISOO SOFTWARE
- Filing Date
- 2023-10-31
- Publication Date
- 2026-05-12
AI Technical Summary
In existing technologies, the virus removal environment is not isolated from the production environment, which may cause the virus removal process to affect the production environment and increase economic losses.
Virus scanning drills were conducted in a pre-built data sandbox with one-way isolation capabilities. Data recovery and virus scanning were performed by obtaining backup data from the disaster recovery system to ensure the security of the production environment.
This avoided the impact of the virus detection and removal process on the production environment, ensured the security of production data, and reduced economic losses.
Smart Images

Figure CN117251845B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, and in particular to a virus detection and removal drill method, apparatus, equipment, and storage medium. Background Technology
[0002] In recent years, computer viruses, especially ransomware, have had a significant impact on the availability of business systems and data security, and are becoming increasingly rampant.
[0003] To address the threats mentioned above, the main approach at the data level is to regularly back up necessary data to a disaster recovery system using backup or disaster recovery systems. If the data in the production environment is infected with a virus, the data in the disaster recovery system can be used to quickly restore the data and minimize losses. However, the above methods cannot solve all ransomware problems. If the production data has already been infected before the backup or if the files are in the incubation period of the virus infection during the backup process, then the backup will not be able to prevent the virus from infecting the data.
[0004] To address these issues, a common solution is to periodically restore backed-up data using a disaster recovery system, and then scan the restored data for viruses using antivirus software to ensure data security. This method is known as a virus scan drill. However, the risk of this process is that if the antivirus environment is not isolated from the production environment, each virus scan may affect the production environment, causing even greater and incalculable losses. Summary of the Invention
[0005] This invention provides a virus detection and removal drill method, apparatus, equipment, and storage medium, which solves the problem of the lack of isolation between the virus removal environment and the production environment, avoids the impact of the virus detection and removal process on the production environment, and ensures the security of production data in the production environment while achieving virus detection and removal, thereby reducing economic losses in production.
[0006] In a first aspect, embodiments of this disclosure provide a virus detection and removal drill method, including:
[0007] Upon receiving the workflow start command, retrieve backup data from the disaster recovery system;
[0008] Perform data recovery on the backup data and determine the target data to be recovered;
[0009] Virus detection and removal drills were conducted on the target recovered data in a pre-built data sandbox with one-way isolation function.
[0010] Secondly, embodiments of this disclosure provide a virus detection and removal drill device, comprising:
[0011] The backup data recovery module is used to obtain backup data from the disaster recovery system after receiving the workflow start command;
[0012] The data recovery determination module is used to perform data recovery on the backup data and determine the target data to be recovered.
[0013] The virus detection and removal drill module is used to conduct virus detection and removal drills on the target recovered data in a pre-built data sandbox with one-way isolation function.
[0014] Thirdly, embodiments of this disclosure provide an electronic device, including:
[0015] At least one processor; and
[0016] A memory that is communicatively connected to at least one processor; wherein,
[0017] The memory stores a computer program that can be executed by at least one processor, and the computer program is executed by at least one processor so that at least one processor can perform the virus detection and removal exercise method provided in the first aspect embodiment above.
[0018] Fourthly, embodiments of this disclosure provide a computer-readable storage medium storing computer instructions that are used to cause a processor to execute the virus detection and removal drill method provided in the first aspect of the embodiments described above.
[0019] This invention discloses a virus scanning and removal drill method, apparatus, device, and storage medium. Upon receiving a workflow start command, it retrieves backup data from a disaster recovery system; performs data recovery on the backup data and identifies target data to be recovered; and conducts a virus scanning and removal drill on the target recovered data within a pre-built data sandbox with one-way isolation functionality. This technical solution solves the problem of the lack of isolation between the antivirus environment and the production environment, avoids the impact of the virus scanning and removal process on the production environment, and ensures the security of production data in the production environment while achieving virus scanning and removal, thereby reducing economic losses in production.
[0020] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1This is a flowchart of a virus detection and removal drill method provided in Embodiment 1 of the present invention;
[0023] Figure 2 This is a schematic diagram of the data sandbox involved in a virus detection and elimination drill method provided in Embodiment 1 of the present invention;
[0024] Figure 3 This is a flowchart of the data sandbox construction involved in a virus detection and elimination drill method provided in Embodiment 1 of the present invention;
[0025] Figure 4 This is a flowchart of a virus detection and removal drill method provided in Embodiment 2 of the present invention;
[0026] Figure 5 This is a schematic diagram of a virus detection and removal drill provided in Embodiment 2 of the present invention;
[0027] Figure 6 This is a schematic diagram of the open integrated antivirus engine involved in a virus detection and removal drill method provided in Embodiment 2 of the present invention;
[0028] Figure 7 This is a schematic diagram of the structure of a virus detection and elimination drill device provided in Embodiment 3 of the present invention;
[0029] Figure 8 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. Detailed Implementation
[0030] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0031] It should be noted that the terms "first," "second," and "target," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0032] Example 1
[0033] Figure 1 This is a flowchart of a virus detection and removal drill method provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of conducting virus detection and removal drills in a data sandbox with one-way isolation function. The method can be executed by a virus detection and removal drill device, which can be implemented in hardware and / or software.
[0034] This invention proposes a method for conducting virus scanning drills in a data sandbox. The data sandbox is isolated from the production environment. By conducting virus scanning in the data sandbox, the security of the virus scanning drills is ensured. Furthermore, the virus scanning drill method proposed in this invention is open and supports the integration of multiple antivirus engines, which can effectively address different virus scanning needs.
[0035] like Figure 1 As shown, the method includes:
[0036] S101. After receiving the workflow start command, retrieve backup data from the disaster recovery system.
[0037] In this embodiment, the workflow start command can be understood as an instruction used to initiate the overall job process. The disaster recovery system can be understood as a backup system used to prevent disasters, used to back up production data in the production environment. Here, the production environment refers to the customer's business environment. Backup data can be understood as data generated by backing up production data from the production environment in the disaster recovery system.
[0038] Specifically, upon receiving the workflow start command, it can be determined that the current virus scanning exercise can be started and executed. Therefore, it is necessary to first obtain backup data from the disaster recovery system so that the virus scanning exercise can be carried out based on the backup data later.
[0039] S102. Perform data recovery on the backup data and determine the target data to be recovered.
[0040] In this embodiment, the target recovery data can be understood as recovery data used for virus detection and removal drills, and the data content of the target recovery data is the same as that of the production data.
[0041] Specifically, the backup data is restored to a resource directory within a pre-built data sandbox according to a preset data recovery algorithm. The preset data recovery algorithm can be determined based on actual needs; this embodiment does not impose any limitations on it. The data sandbox includes at least one recovery resource, and multiple resource directories exist on the recovery resource. The restored data, generated after data recovery of the backup data, is stored in the resource directories within the data sandbox.
[0042] S103. Conduct virus detection and removal drills on the target recovery data in a pre-built data sandbox with one-way isolation function.
[0043] In this embodiment, the data sandbox serves as a network security defense. All programs running within the sandbox are simulations and exercises, not real applications. The sandbox works by running programs in an isolated space, where they are readable but not writable, thus preventing permanent modifications or damage to other programs and data on the computer. An illustrative analogy is that a computer is like a piece of paper, and running and modifying a program is like writing on that paper. The sandbox is like a pane of glass placed on that paper; program operations and modifications can only be written on that glass, while the paper itself remains intact.
[0044] Specifically, a data sandbox with one-way isolation is pre-built. Except for specified data, the data sandbox cannot interact with the production environment. Therefore, to ensure the security of the production environment, virus scanning exercises are performed on the target recovery data restored to the resource directory in the data sandbox with one-way isolation, based on the pre-selected virus scanning engine.
[0045] This invention provides a virus scanning and removal drill method. Upon receiving a workflow start command, it retrieves backup data from a disaster recovery system; performs data recovery on the backup data and identifies the target data to be recovered; and conducts a virus scanning and removal drill on the target data in a pre-built data sandbox with one-way isolation functionality. In this technical solution, restoring the backup data to a network-isolated recovery resource for virus scanning avoids impacting the production environment. It ensures the security of the recovered data by performing virus scanning on data under a specified path on the recovery resource. This technical solution solves the problem of the antivirus environment not being isolated from the production environment, avoiding the impact of the virus scanning process on the production environment, achieving virus scanning while ensuring the security of production data in the production environment, and reducing economic losses in production.
[0046] As a first optional embodiment of the embodiments, based on the above embodiments, this first optional embodiment further optimizes and adds the following:
[0047] Generate a virus detection and removal exercise report and send the report back to the server.
[0048] In this embodiment, the virus detection and removal drill report can be understood as a report generated based on the results of the virus detection and removal drill. The server can be understood as a server. The server, the client, and the electronic device that serves as the execution subject of this embodiment are all remotely wirelessly connected, enabling data interaction between any two parties. The client can also interact with the user.
[0049] Specifically, after conducting a virus scanning and removal drill on the target recovery resources within the data sandbox, a corresponding virus scanning and removal drill report is generated based on the results of the drill. The virus scanning and removal drill report is then uploaded to the server. The server can send the virus scanning and removal drill report to the client for user query and display based on the client's request.
[0050] As a second optional embodiment, Figure 2 This is a schematic diagram of the data sandbox structure involved in a virus detection and elimination drill method provided in Embodiment 1 of the present invention. The data sandbox includes at least a proxy device and a virtual switch vSwitch2 without an uplink. The proxy device has one externally connected virtual network interface card (vNic1) and several internally connected virtual network interface cards (vNic2, vNic3, vNic4, etc.). The virtual switch vSwitch2 has several isolated network port groups. The internally connected virtual network interface cards and the isolated network port groups are connected one by one to construct the network. Based on the above embodiment, this second optional embodiment further optimizes and adds the data sandbox construction steps, including:
[0051] a1) Create a virtual switch without uplink on the target virtualization platform, and create a preset number of isolated network ports on the virtual switch.
[0052] In this embodiment, the target virtualization platform is determined based on the client user's selection. A virtual switch without an uplink can be understood as a switch with unidirectional isolated power supply. This virtual switch is the foundation for the data sandbox's isolation capabilities. Because it lacks an uplink, it is isolated from the external network. Therefore, any virtual machine connected to this virtual switch network is also isolated from the external network. An isolated network port can be understood as a network port used for networking. An isolated network is a mapping of the external production network; each production network can be mapped to an isolated network. Through mapping, the isolated networks within the data sandbox together form a network similar to the production network, the difference being that this network is inside the data sandbox, isolated from the outside world, and will not affect the external environment.
[0053] The virtualization platform selected for client-user interaction is defined as the target virtualization platform. A data sandbox is then built on the target virtualization platform based on the program. Specifically, a virtual switch without uplink is created on the target virtualization platform. A preset number of isolated network ports are then created on the created virtual switch without uplink. The preset number of isolated network ports is a mapping of the production network ports in the data sandbox. Therefore, the preset number can be the same as the number of production network ports in the production network, and under certain conditions, it can be less than the number of production network ports.
[0054] b1) Create a virtual machine with a preset operating system and enabled routing forwarding function on the target virtualization platform, and identify the virtual machine as the agent device.
[0055] In this embodiment, the default operating system can be understood as a Linux system. The proxy device can be understood as a device used for data relay. The proxy device is essentially a Linux virtual machine with routing forwarding enabled. It has multiple virtual network cards, one of which is connected to the external network, and the others are connected to the isolated network inside the data sandbox. The proxy device is both the only bridge for communication between the outside world and the inside of the data sandbox, and also acts as a router connecting the various isolated networks inside the data sandbox.
[0056] Specifically, a virtual machine with a Linux operating system is created on the target virtualization platform, and the routing forwarding function is enabled. This virtual machine is designated as a proxy device for relaying data between virtual machines within the data sandbox and between the data sandbox and the target virtualization platform.
[0057] c1) Establish connections between the proxy device and the isolated network port, as well as between the proxy device and the target virtualization platform.
[0058] In this embodiment, a virtual network interface card (NIC) is created on the proxy device. This virtual NIC is then connected to an external production network within the target virtualization platform, and an IP address is configured to establish a connection between the virtual NIC and the production network, thereby enabling the connection between the proxy device and the target virtualization platform. Several virtual NICs are created on the proxy device, with the number of virtual NICs matching the number of isolated network ports. These virtual NICs are configured with addresses corresponding to the isolated network ports, establishing connections between each virtual NIC and each isolated network, thereby enabling the connection between the proxy device and the isolated network ports.
[0059] Furthermore, establishing a connection between the proxy device and the isolated network port includes:
[0060] c11) Create a preset number of virtual network cards on the proxy device and connect each virtual network card to a corresponding isolated network port.
[0061] In this embodiment, a preset number of virtual network cards are created on the proxy device. The number of network cards is the same as the number of isolated network ports, and each virtual network card is connected to each isolated network port in a one-to-one correspondence.
[0062] c12) Determine the gateway address of the production network mapped to each isolated network as the address of the virtual network card corresponding to the isolated network.
[0063] In this embodiment, the production network mapped by the isolated network is determined, and the gateway address corresponding to the production network is determined. The gateway address of the production network is determined as the IP address of the virtual network card connected to the isolated network.
[0064] c13) Receive network configuration information from the client and configure the subnet mask and masquerading network segment of the virtual network card according to the network configuration information.
[0065] In this embodiment, network configuration information can be understood as the network address information entered by the user when the client interacts with the user.
[0066] Specifically, the system receives network configuration information from the client, including the subnet mask and masquerading network segment configuration for the virtual network interface card (NIC). Based on the network configuration information transmitted by the client, the system configures the subnet mask and masquerading network segment for the virtual NIC.
[0067] d1) Receive the firewall configuration information from the client and configure the corresponding firewall rules for the proxy device based on the firewall configuration information.
[0068] In this embodiment, the firewall configuration information can be understood as the configuration information of iptables (network filter).
[0069] Specifically, firewall configuration information is information configured by the user during the interaction between the client and the user. Therefore, the proxy device receives the firewall configuration information transmitted by the client and performs corresponding iptables configuration (firewall rule configuration) based on the firewall configuration information.
[0070] Figure 3This is a flowchart illustrating the data sandbox construction involved in a virus detection and elimination drill method provided in Embodiment 1 of the present invention. The data sandbox constructed based on this flowchart possesses three functions: one-way external connectivity, internal interconnection, and support for proactive requests from within the data sandbox to the outside based on specified IP addresses and ports. The one-way external connectivity function allows active access from outside the data sandbox to the inside, and allows internal responses to be sent out, but does not allow active access from inside the data sandbox to the outside. Since the proxy device is the only bridge between the inside and outside of the data sandbox, one-way isolation is mainly achieved by configuring corresponding iptables rules on the proxy device. The internal interconnection function allows the various networks within the data sandbox to communicate with each other. Internal interconnection is mainly achieved by marking traffic within the isolated network on the proxy device and setting corresponding routing policies. Support for proactive requests from within the data sandbox to the outside based on specified IP addresses and ports is a special case of the one-way external connectivity function. Depending on actual needs, requests from inside the data sandbox to actively access specified IP addresses and ports can be allowed. This function is also implemented on the proxy device by configuring corresponding iptables rules.
[0071] like Figure 3 As shown, the configuration process for the data sandbox is as follows:
[0072] S10. Select a virtualization platform: Select a virtualization platform (for deploying the data sandbox).
[0073] S11. Create a virtual switch without uplink: Create a virtual switch without uplink on this virtualization platform.
[0074] S12. Create a proxy device and enable routing forwarding: Create a Linux operating system virtual machine on the virtualization platform and enable the routing forwarding function.
[0075] S13. Add a virtual network interface card (NIC) to the proxy device, connect it to a production network external to the virtualization platform, and configure its IP address: Add a virtual NIC to the proxy device, connect it to a production network external to the virtualization platform, and configure its IP address.
[0076] S14. Create N port groups on the previously created virtual switch, where N is the number of production networks to be mapped: Create several isolated network port groups on the virtual switch according to the number of production networks to be mapped. The number of isolated network port groups is the same as the number of production networks to be mapped.
[0077] S15. Add N virtual network cards to the proxy device and connect them to the port groups created in the previous step. Configure the IP address, subnet mask, and masquerading network segment: Create several more virtual network cards on the proxy device and connect them to the isolated network one by one. Set the IP address, subnet mask, and masquerading network segment of the virtual network cards created on the proxy device. The IP address needs to be set to the gateway address of the production network mapped by the isolated network corresponding to the virtual network card.
[0078] S16. Configure iptables and arptables rules on the proxy device: Configure the corresponding iptables and arptables rules on the proxy device. The basic idea of arptables rules is the same as that of iptables, but arptables handles packets related to the ARP protocol.
[0079] S17. Determine whether the isolated network is interconnected: If the isolated network is interconnected, proceed to step S18; if the isolated network is not interconnected, proceed to step S19.
[0080] S18. Tag internal traffic and set routing policies on the proxy device: If internal communication within the isolated network is enabled, continue to configure the proxy device to tag packets that match the characteristics of the isolated network and specify the corresponding routing policies.
[0081] S19. Determine whether the specified IP and port are open: If the specified IP and port are open, proceed to step S20; if the specified IP and port are not open, end the data sandbox construction process and complete the construction of the data sandbox.
[0082] S20. Configure iptables rules on the proxy device: If you specify that traffic to a certain IP address and port should be allowed to be accessed externally, continue to configure the corresponding iptables rules on the proxy device. After the configuration is completed, end the data sandbox construction process and complete the construction of the data sandbox.
[0083] Example 2
[0084] Figure 4 This is a flowchart of a virus detection and elimination drill method provided in Embodiment 2 of the present invention. This embodiment is a further optimization of any of the above embodiments and can be applied to the situation of conducting virus detection and elimination drills in a data sandbox with one-way isolation function. The method can be executed by a virus detection and elimination drill device, which can be implemented in hardware and / or software.
[0085] like Figure 4 As shown, the method includes:
[0086] S201. After receiving the workflow start command, retrieve backup data from the disaster recovery system.
[0087] S202. Restore the backup data to the recovery resources in the data sandbox to form initial recovery data and verify it.
[0088] In this embodiment, the initial recovery data can be understood as unverified data that is directly restored from the backup data to the recovery resource.
[0089] Specifically, abandoning traditional data recovery methods, a mount-based recovery approach is adopted. Mount-based recovery refers to mounting backup data to recovery resources using protocols such as NFS (Network File System), iSCSI (Internet Small Computer System Interface), FC SAN (Fibre Channel Storage Area Network), S3, HDFS (Hadoop Distributed File System), and CSI. Initial recovery data is then generated on the recovery resources, enabling rapid business recovery. This method does not require the storage of recovery resources, improving data recovery efficiency and saving costs. After the backup data is restored to the recovery resources in the data sandbox to form initial recovery data, a preset verification method is used to verify whether the initial recovery data matches the production data backed up by the backup data. If they match, the initial recovery data verification is successful; otherwise, it fails.
[0090] S203. The verified initial recovery data is determined as the target recovery data.
[0091] In this embodiment, the target recovery data can be understood as recovery data consistent with the production data, which can be used for virus detection and removal drills.
[0092] Specifically, the initial recovery data passed verification, indicating that the data content is consistent with the production data, and can be used for virus detection and removal drills. Therefore, the verified initial recovery data was determined as the target recovery data for virus detection and removal drills.
[0093] S204. Send the virus scanning engine option to the client and receive the target virus scanning engine from the client.
[0094] In this embodiment, the virus scanning engine option can be understood as the virus scanning engine that the client user can choose, including antivirus software such as SDK (Software Development Kit), license, and virus database. The target virus scanning engine can be understood as the virus scanning engine selected by the client user.
[0095] Specifically, several virus scanning engines are sent as options to the client. The client user selects one or more desired virus scanning engines from the options, and the client transmits this selection information back to the electronic device that executes this invention. The virus scanning engine selected by the user is then designated as the target virus scanning engine.
[0096] S205. In a pre-built data sandbox with one-way isolation function, a virus scanning exercise is performed on the target recovered data according to the target virus scanning engine. The data sandbox includes at least one recovery resource, and each recovery resource includes at least one resource directory. The target recovered data is located in the resource directory.
[0097] In this embodiment, the data sandbox with one-way isolation includes at least one recovery resource, and each recovery resource includes at least one resource directory, on which the target recovery data resides. Multiple virus scanning engine instances (target virus scanning engines) are simultaneously launched on the recovery resource to perform parallel scanning of the target path on that resource. To better control the resource usage of the recovery resource, the configurable concurrency of the recovery resource and the concurrency configured for a single virus scanning task are managed as a resource pool. A parallel scanning limit can be configured based on the actual situation of the recovery resource, and a desired concurrency can be configured for each virus scanning task. During actual task execution, the actual number of concurrent scans for each scanning task needs to be controlled based on the maximum concurrency of the recovery resource and the actual concurrency used by the scanning task. This method not only fully utilizes the recovery resource but also ensures virus scanning efficiency. The resource pool is a configuration mechanism for the recovery resource, used to manage the number of concurrent virus scanning engines that can be used by the recovery resource and the number of concurrent virus scanning engines that can be used by a single virus scanning task.
[0098] Figure 5 This is a schematic diagram of a virus detection and removal drill provided in Embodiment 2 of the present invention. Figure 5As shown, a virus scanning exercise is performed on the target recovery data on the recovery resources in the data sandbox. In the diagram, the production environment is the client business environment; distributed storage is the backup medium used to store backup data; virus scanning configuration refers to the target recovery resource and the configuration related to the scanning path. This configuration can be connected with other different types of configurations according to a certain topology to form a specific task flow. Through this flow, a series of functions such as data recovery, virus scanning, recovery data verification, recovery resource cleanup, and email notification can be realized sequentially; the antivirus engine refers to the antivirus software including the virus scanning SDK, license, and virus database; the recovery resource refers to the destination used for data recovery. This resource can be the production environment or other environments that communicate with the production environment, and virus scanning is also performed on this resource.
[0099] Specifically, such as Figure 5 As shown, a virus scanning and removal drill was conducted in isolation from the production network, including: S21, creating a data sandbox and deploying recovery resources and an antivirus engine client within it. The data sandbox was configured to expose the registration port of the antivirus engine client to the virus scanning and removal drill server; S22, configuring the task flow, where the virtualization platform where the data sandbox was deployed was selected as the recovery resource in the disaster recovery configuration; S23, configuring the virus scanning and removal, selecting one or more paths on the recovery resource as the paths to be scanned and removed, and selecting the antivirus engine client within the data sandbox as the antivirus client, followed by configuring the scanning and removal processes; S24, configuring other nodes in the task flow; S25, initiating the task flow.
[0100] Furthermore, Figure 5 It includes both a built-in virus scanning engine and a third-party virus scanning engine, with the aim of supporting different types of antivirus engines and enabling open access to multiple virus scanning engines. Figure 6 This is a schematic diagram of the open integrated antivirus engine involved in a virus detection and removal drill method provided in Embodiment 2 of the present invention, as shown below. Figure 6As shown, the open integrated antivirus engine includes a virus scanning scheduling layer, a virus scanning adaptation layer, and a virus scanning engine. The virus scanning scheduling layer primarily provides a set of common virus scanning interface definitions. These interfaces are implemented by various virus scanning engine adapters. When initiating a virus scan, the adapters directly call the public interface of the specified virus scanning engine, without concern for the engine's specific functionality. The virus scanning adaptation layer mainly stores adapters. These adapters provide a unified encapsulation for different types of antivirus engines. Different virus scanning engines only need to implement the interface defined by the upper-level scheduling layer. The specific scheduling and usage of the virus scanning engine are implemented within these interface implementations. The virus scanning engine includes a virus scanning SDK, a license, and a virus database file. The SDK contains a series of interfaces required for virus scanning, the license file authorizes the calls to these interfaces, and the virus database records virus characteristics.
[0101] Accordingly, virus scanning drills are conducted on the recovered target data based on the target virus scanning engine, including:
[0102] a2) Call the adapter corresponding to the target virus scanning engine through the preset virus scanning interface.
[0103] In this embodiment, the preset virus scanning interface can be understood as a public virus scanning interface definition provided by the virus scanning scheduling layer, which can correspond to various types of virus scanning adapters.
[0104] Specifically, the virus scanning scheduling layer calls a preset virus scanning interface to connect with the virus scanning adaptation layer. Through the preset virus scanning interface, the virus scanning adaptation layer calls the virus scanning adapter corresponding to the target virus scanning engine.
[0105] b2) Based on the adapter corresponding to the target virus scanning engine, call the target virus scanning engine to perform virus scanning drills on the target recovered data.
[0106] In this embodiment, after the virus scanning scheduling layer calls the adapter of the virus scanning adaptation layer, the corresponding target virus scanning engine is called according to each adapter, and the target virus scanning engine performs parallel virus scanning exercises on the target recovered data.
[0107] This embodiment provides a virus scanning and removal drill method. Upon receiving a workflow start command, it retrieves backup data from the disaster recovery system; restores the backup data to recovery resources in a data sandbox to form initial recovery data and verifies it; determines the verified initial recovery data as the target recovery data; sends virus scanning engine options to the client and receives the target virus scanning engine from the client; and performs a virus scanning and removal drill on the target recovery data in a pre-built data sandbox with one-way isolation functionality, based on the target virus scanning and removal engine. The data sandbox includes at least one recovery resource, and each recovery resource includes at least one resource directory, on which the target recovery data resides. This technical solution, through the open integration of different antivirus engines via an adaptation layer and a virus scanning and removal scheduling layer, resolves the differences between various types of virus scanning and removal engines, providing a technical foundation for future integration of other virus scanning and removal engines. Users can freely configure virus scanning and removal, making the virus scanning and removal function more complete. By mounting recovery, it quickly provides scanning targets and resource pools to fully utilize recovery resources. These two mechanisms achieve efficient and parallel scanning and removal. The above technical solution solves the problem of the lack of isolation between the antivirus environment and the production environment, avoids the impact of the virus scanning process on the production environment, and ensures the security of production data in the production environment while achieving virus scanning, thereby reducing economic losses in production.
[0108] For example, to more clearly explain the content of the embodiments of the present invention, an example is given here: the present invention includes constructing a data sandbox with one-way isolation function, and performing virus scanning and killing drills on the recovery resources of the data sandbox.
[0109] Specifically, such as Figure 2 and Figure 5 As shown, the method includes:
[0110] 1. Select a virtualization platform A for deploying a data sandbox;
[0111] 2. Create a virtual switch vSwitch2 on A without an uplink;
[0112] 3. Create a Linux operating system virtual machine, appliance proxy, on A and enable route forwarding;
[0113] 4. Add a virtual network interface card (vNic1) to the appliance proxy, connect vNic1 to one of A's external production networks, and configure its IP address;
[0114] 5. Create a port group IsolatedVM Network1 on vSwitch2. Add a virtual network adapter vNic2 on the appliance proxy and connect vNic2 to IsolatedVM Network1. Assume the virtual machine to be restored is vm1 (IP address 192.168.125.100), and vm1 is connected to the production network VM Network1. The gateway address of VM Network1 is 192.168.125.254. Then configure the IP address of vNic2 to 192.168.125.254, and configure the subnet mask to be the same as the subnet mask of VMNetwork1. Set the masquerading network of IsolatedVM Network1 to 192.168.225.0 / 24.
[0115] 6. Assuming the IP address of the virus scanning and removal exercise server is 192.168.10.100, and the antivirus engine client registers with the server on port 9614, then configure the data sandbox to specify the open IP address as 192.168.10.100 and the port as 9614 for packets.
[0116] 7. Configure the corresponding iptables rules on the appliance proxy;
[0117] 8. Deploy a virtual machine (let's call it client1) with the antivirus engine client installed on Isolated VM Network1;
[0118] 9. Create a task flow where, in the disaster recovery configuration, select virtualization platform A for the resource recovery section, select vm1 for the virtual machine to be recovered in the application configuration section, select A for the recovery destination, name the recovered virtual machine vm2, and select Isolated VM Network1 for the network connection.
[0119] 10. In the verification configuration, select ping as the verification method for the virtual machine, and the target IP address is 192.168.225.100 (the masquerading IP of vm1);
[0120] 11. In the virus scan configuration, select client1 as the antivirus engine client (because port 9614 of 192.168.10.100 is open, the virus scan drill server can find client1), select the / home path of the restored virtual machine vm2 as the scan path, and select scan and remove viruses;
[0121] 12. In the cleanup configuration, select script cleanup and specify the virtual machine to be cleaned as vm2;
[0122] 13. After configuration, execute the task process.
[0123] In this embodiment, following the previously configured task flow, during task execution, VM1 will be restored to virtualization platform A where the data sandbox resides. The restored virtual machine will be named VM2 and connected to Isolated VM Network1. During the verification phase, the restoration of VM2 will be verified from outside the data sandbox by pinging 192.168.225.100. After verification, a virus scan will be performed on the / home path of VM2. Since both the antivirus engine client and VM2 are connected to Isolated VM Network1, and Isolated VM Network1 is inside the data sandbox and isolated from the outside world, the security of the virus scan process can be ensured. Finally, a report of this virus scan exercise will be generated.
[0124] Example 3
[0125] Figure 7 This is a schematic diagram of the structure of a virus detection and elimination drill device provided in Embodiment 3 of the present invention. Figure 7 As shown, the device includes:
[0126] The backup data recovery module 31 is used to obtain backup data from the disaster recovery system after receiving the workflow start command;
[0127] The data recovery determination module 32 is used to perform data recovery on the backup data and determine the target data to be recovered;
[0128] The virus detection and removal exercise module 33 is used to conduct virus detection and removal exercises on the target recovered data in a pre-built data sandbox with one-way isolation function.
[0129] The virus scanning and removal training device used in this technical solution solves the problem of the lack of isolation between the virus scanning environment and the production environment, avoids the impact of the virus scanning and removal process on the production environment, and ensures the security of production data in the production environment while achieving virus scanning and removal, thereby reducing economic losses in production.
[0130] Optionally, the data recovery determination module 32 is specifically used for:
[0131] The backup data is restored to the recovery resources in the data sandbox to form initial recovery data, which is then verified.
[0132] The verified initial recovery data is determined as the target recovery data.
[0133] Optional, virus detection and removal drill module 33 includes:
[0134] The target engine determination unit is used to send virus scanning engine options to the client and receive the target virus scanning engine fed back by the client.
[0135] The virus detection and removal drill unit is used to perform virus detection and removal drills on the target recovered data in a pre-built data sandbox with one-way isolation function, according to the target virus detection and removal engine. The data sandbox includes at least one recovery resource, each recovery resource includes at least one resource directory, and the target recovered data is located in the resource directory.
[0136] Optional, virus detection and removal drill unit, specifically used for:
[0137] The adapter corresponding to the target virus scanning engine is called through the preset virus scanning interface;
[0138] The target virus scanning engine is invoked according to the adapter corresponding to the target virus scanning engine to perform a virus scanning exercise on the target recovered data.
[0139] Optionally, the device may also include:
[0140] The exercise report generation module is used to generate a virus detection and removal exercise report and send the report back to the server.
[0141] Optionally, the device also includes a data sandbox creation module, comprising:
[0142] An isolated network creation unit is used to create a virtual switch without uplink on a target virtualization platform, and to create a preset number of isolated network ports on the virtual switch;
[0143] The agent device determination unit is used to create a virtual machine with a preset operating system and enabled routing forwarding function on the target virtualization platform, and determine the virtual machine as an agent device.
[0144] A proxy connection establishment unit is used to establish a connection between the proxy device and the isolated network port, and a connection between the proxy device and the target virtualization platform;
[0145] The rule configuration unit is used to receive firewall configuration information from the client and configure corresponding firewall rules for the proxy device according to the firewall configuration information.
[0146] Optional, the proxy connection establishment unit is specifically used for:
[0147] A preset number of virtual network interface cards (NICs) are created on the proxy device, and each virtual NIC is connected to a corresponding isolated network port.
[0148] The gateway address of the production network mapped by each isolated network is determined as the address of the virtual network card corresponding to the isolated network;
[0149] Receive network configuration information from the client and configure the subnet mask and masquerading network segment of the virtual network card according to the network configuration information.
[0150] The virus detection and elimination training device provided in this embodiment of the invention can execute the virus detection and elimination training method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method.
[0151] Example 4
[0152] Figure 8 A schematic diagram of an electronic device 40 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0153] like Figure 8 As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42 or a random access memory (RAM) 43, communicatively connected to the at least one processor 41. The memory stores computer programs executable by the at least one processor. The processor 41 can perform various appropriate actions and processes based on the computer program stored in the ROM 42 or loaded into the RAM 43 from storage unit 48. The RAM 43 may also store various programs and data required for the operation of the electronic device 40. The processor 41, ROM 42, and RAM 43 are interconnected via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.
[0154] Multiple components in electronic device 40 are connected to I / O interface 45, including: input unit 46, such as keyboard, mouse, etc.; output unit 47, such as various types of monitors, speakers, etc.; storage unit 48, such as disk, optical disk, etc.; and communication unit 49, such as network card, modem, wireless transceiver, etc. Communication unit 49 allows electronic device 40 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0155] Processor 41 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 41 performs the various methods and processes described above, such as virus scanning drills.
[0156] In some embodiments, the virus scanning and elimination drill method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 40 via ROM 42 and / or communication unit 49. When the computer program is loaded into RAM 43 and executed by processor 41, one or more steps of the virus scanning and elimination drill method described above may be performed. Alternatively, in other embodiments, processor 41 may be configured to execute the virus scanning and elimination drill method by any other suitable means (e.g., by means of firmware).
[0157] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0158] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0159] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0160] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0161] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0162] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0163] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0164] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for virus detection and removal drills, characterized in that, include: Upon receiving the workflow start command, retrieve backup data from the disaster recovery system; Perform data recovery on the backup data and determine the target data to be recovered; Virus detection and removal drills were conducted on the target recovered data in a pre-built data sandbox with one-way isolation function; The construction of the data sandbox includes: Create a virtual switch without uplink on the target virtualization platform, and create a preset number of isolated network ports on the virtual switch; wherein the virtual switch without uplink is isolated from the external network, and any virtual machine connected to the virtual switch network is also isolated from the external network; A virtual machine with a preset operating system and routing forwarding function is created on the target virtualization platform, and the virtual machine is identified as a proxy device; Establish a connection between the proxy device and the isolated network port, and a connection between the proxy device and the target virtualization platform; The system receives firewall configuration information from the client and configures corresponding firewall rules on the proxy device based on the firewall configuration information. The firewall configuration information is network filter configuration information, and the data sandbox's outward one-way connectivity function is achieved by configuring corresponding network filter rules on the proxy device.
2. The method according to claim 1, characterized in that, The process of restoring the backup data and determining the target data to be restored includes: The backup data is restored to the recovery resources in the data sandbox to form initial recovery data, which is then verified. The verified initial recovery data is determined as the target recovery data.
3. The method according to claim 1, characterized in that, The exercise of virus scanning and removal on the target recovered data in a pre-built data sandbox with one-way isolation function includes: Send virus scanning engine options to the client and receive the target virus scanning engine from the client; In a pre-built data sandbox with one-way isolation function, a virus scanning exercise is performed on the target recovered data according to the target virus scanning engine. The data sandbox includes at least one recovery resource, and each recovery resource includes at least one resource directory. The target recovered data is located in the resource directory.
4. The method according to claim 3, characterized in that, The step of performing a virus scanning exercise on the target recovered data based on the target virus scanning engine includes: The adapter corresponding to the target virus scanning engine is called through the preset virus scanning interface; The target virus scanning engine is invoked according to the adapter corresponding to the target virus scanning engine to perform a virus scanning exercise on the target recovered data.
5. The method according to claim 1, characterized in that, Also includes: Generate a virus detection and removal exercise report and send the report back to the server.
6. The method according to claim 1, characterized in that, Establishing the connection between the proxy device and the isolated network port includes: A preset number of virtual network interface cards (NICs) are created on the proxy device, and each virtual NIC is connected to a corresponding isolated network port. The gateway address of the production network mapped by each isolated network is determined as the address of the virtual network card corresponding to the isolated network; Receive network configuration information from the client and configure the subnet mask and masquerading network segment of the virtual network card according to the network configuration information.
7. A virus detection and removal drill device, characterized in that, include: The backup data recovery module is used to obtain backup data from the disaster recovery system after receiving the workflow start command; The data recovery determination module is used to perform data recovery on the backup data and determine the target data to be recovered. The virus detection and removal drill module is used to conduct virus detection and removal drills on the target recovered data in a pre-built data sandbox with one-way isolation function; The device further includes a data sandbox creation module, which includes: An isolated network creation unit is used to create a virtual switch without uplink on a target virtualization platform and to create a preset number of isolated network ports on the virtual switch; wherein the virtual switch without uplink is isolated from the external network, and any virtual machine connected to the virtual switch network is also isolated from the external network. The agent device determination unit is used to create a virtual machine with a preset operating system and enabled routing forwarding function on the target virtualization platform, and determine the virtual machine as an agent device. A proxy connection establishment unit is used to establish a connection between the proxy device and the isolated network port, and a connection between the proxy device and the target virtualization platform; The rule configuration unit is used to receive firewall configuration information from the client and configure corresponding firewall rules for the proxy device according to the firewall configuration information; wherein, the firewall configuration information is network filter configuration information, and the outward one-way connectivity function of the data sandbox is implemented by configuring corresponding network filter rules on the proxy device.
8. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform a virus detection and removal drill method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause a processor to execute a virus detection and removal drill method according to any one of claims 1-6.