Virus identification methods, devices, computer equipment, and storage media
Patent Information
- Application Number
- CN202311611129.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-28
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2043-11-28
AI Technical Summary
[0004]有鉴于此,本发明提供了一种病毒识别方法、装置、计算机设备及存储介质,以解决无法及时发现病毒,造成数据丢失等问题
[0013]由于大部分病毒入侵计算机设备的主要目的是为了获取利益,例如,通过病毒对文件进行加密,要求用户支付钱财后再给用户解密文件,或者,直接盗取文件等。为了达到此目的,病毒会通过频繁的系统行为对文件进行操作,并通过频繁的网络交互对获取到的相关信息进行传输等,即行为混乱度变高、网络交互频率变高。因此,通过计算机设备实时的网络交互频率和系统行为熵,可以确定出实时的系统行为特点(行为复杂度),进一步,通过系统行为特点,可以准确识别是否有病毒侵入。另外,虽然病毒更新换代快,但是病毒入侵后的系统行为特点与正常工作状态下的系统行为特点差异较大,这一点是不变的。因此,本方案抓住这一要点设计方案,无需考虑病毒更新换代的问题。
Smart Images

Figure CN117786685B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and more specifically to virus identification methods, devices, computer equipment, and storage media. Background Technology
[0002] In the field of computer technology, antivirus software is generally used to monitor viruses, and when a virus is detected, it is removed.
[0003] However, antivirus software relies on virus databases to prevent virus attacks. Viruses are often updated very quickly, and it is difficult for the virus database to record updated viruses or virus characteristics in a timely manner, resulting in the inability to detect viruses in time and causing problems such as data loss. Summary of the Invention
[0004] In view of this, the present invention provides a virus identification method, apparatus, computer equipment, and storage medium to solve the problems of failure to detect viruses in a timely manner, resulting in data loss.
[0005] In a first aspect, the present invention provides a virus identification method, comprising:
[0006] Obtain the total number of occurrences of each system behavior among various system behaviors of the operating system;
[0007] In addition, the number of network interaction behaviors within the current period is obtained, wherein the network interaction behaviors are one of the various system behaviors;
[0008] The network interaction frequency of the operating system is determined based on the number of network interaction behaviors in the current period and a preset threshold number.
[0009] The system behavior entropy of the operating system is determined based on the total number of occurrences of each system behavior among various system behaviors, wherein the system behavior entropy is used to indicate the degree of behavioral disorder of the operating system;
[0010] The behavioral complexity of the operating system is determined based on the network interaction frequency and the system behavior entropy.
[0011] The presence of a virus in the operating system is identified based on the complexity of the behavior.
[0012] The virus identification method provided by this invention has the following advantages:
[0013] Since most viruses infiltrate computer devices primarily for profit—for example, encrypting files and demanding payment before decryption, or directly stealing files—viruses frequently manipulate files through system actions and transmit acquired information via frequent network interactions. This results in increased behavioral chaos and network interaction frequency. Therefore, by analyzing the real-time network interaction frequency and system behavioral entropy of the computer device, real-time system behavioral characteristics (behavioral complexity) can be determined. Furthermore, these system behavioral characteristics can accurately identify whether a virus has infiltrated the system. Additionally, although viruses evolve rapidly, the system behavioral characteristics after a virus intrusion differ significantly from those under normal operating conditions; this remains constant. Therefore, this solution addresses this key point in its design and does not need to consider the issue of virus updates.
[0014] In one optional implementation, determining the system behavior entropy of the operating system based on the total number of occurrences of each system behavior among multiple system behaviors includes:
[0015] The total number of system behaviors of the operating system is determined based on the total number of behaviors for each type of system behavior among various system behaviors, wherein the total number of system behaviors is: C(i) represents the total number of times the behavior corresponds to the i-th type of system behavior, where i is a positive integer greater than or equal to 1, and k is a positive integer greater than or equal to 2;
[0016] Based on the total number of each system behavior and the total number of system behaviors, the system call frequency corresponding to each system behavior is determined, wherein the system call frequency corresponding to the i-th system behavior is P(i) = Ci / C;
[0017] Based on the system call frequency corresponding to the first system behavior, the subsystem behavior entropy corresponding to the first system behavior is determined, wherein the first system behavior is any one of a variety of system behaviors, and the subsystem behavior entropy corresponding to the i-th system behavior is Si = P(i) * logP(i).
[0018] The system behavior entropy is determined based on the subsystem behavior entropy corresponding to various system behaviors, wherein the system behavior entropy is...
[0019] Specifically, since viruses infiltrate computer devices to obtain relevant information, they will frequently perform encryption / decryption, reading, and even modification operations on files, as well as frequent network connections, process creation, and network interactions to transmit information. At this time, the system behavior of the computer device is more chaotic than normal operation. Therefore, using system behavior entropy as one of the conditions for determining the presence of a virus can make virus identification results more accurate.
[0020] In one optional implementation, determining the behavioral complexity of the operating system based on the network interaction frequency and the system behavioral entropy includes:
[0021] The operating system's behavior pattern indicators are determined based on the network interaction frequency and the system behavior entropy.
[0022] The behavioral complexity is determined based on the behavioral pattern index and the system behavioral entropy.
[0023] Specifically, while different viruses manipulate data on computer devices in slightly different ways, network interaction will be extremely frequent regardless of the type of virus. Furthermore, network interaction frequency reflects the operating system's network interaction pattern, and system behavior entropy reflects the operating system's overall current behavior pattern. Therefore, by analyzing the essential network interaction characteristics and overall system behavior characteristics among various system behaviors, the operating system's behavior pattern can be accurately represented. Moreover, using behavior pattern as one of the conditions for determining the presence of a virus can make virus identification results more accurate.
[0024] In one optional implementation, identifying the presence of a virus in the operating system based on the behavioral complexity includes:
[0025] Determine whether the behavior complexity is greater than or equal to a preset behavior complexity threshold;
[0026] When the behavior complexity is determined to be greater than or equal to a preset behavior complexity threshold, a virus is identified in the operating system.
[0027] or,
[0028] When the complexity of the behavior is determined to be less than a preset behavior complexity threshold, it is determined that there is no virus in the operating system.
[0029] Specifically, after most viruses infiltrate computer devices, they frequently manipulate files through system actions and transmit acquired information via frequent network interactions, resulting in increased behavioral chaos and network interaction frequency. This differs significantly from the system behavior characteristics of a computer device under normal operating conditions. Therefore, by analyzing the real-time network interaction frequency and system behavior entropy of the computer device, real-time system behavior characteristics (behavioral complexity) can be determined. Furthermore, comparing the calculated behavioral complexity with a preset behavioral complexity threshold can identify whether the operating system contains a virus.
[0030] In one optional implementation, the network interaction frequency of the operating system is determined based on the number of network interaction behaviors in the current period and a preset threshold number, using the following expression:
[0031] NFI=ΔN / N……(1)
[0032] Wherein, NFI is the network interaction frequency, ΔN is the number of network interaction behaviors in the current period, and N is the preset number threshold.
[0033] Specifically, after a virus infiltrates a computer device, it engages in frequent network interactions with the target (the virus initiator) to obtain relevant information. In other words, the frequency of these network interactions increases after a virus infiltrates a computer device. Therefore, using network interaction frequency as one of the criteria for determining the presence of a virus can make virus identification more accurate.
[0034] In one optional implementation, the step of determining the operating system's behavioral pattern indicators based on the network interaction frequency and the system behavior entropy...
[0035] Use the following expression:
[0036] NBD=α*NFI+β*S……(2)
[0037] Wherein, NBD is the behavior pattern index, α is the first preset coefficient, NFI is the network interaction frequency, β is the second preset coefficient, and S is the behavior entropy.
[0038] Specifically, while different viruses manipulate data on computer devices in slightly different ways, network interaction will be extremely frequent regardless of the type of virus. Furthermore, network interaction frequency reflects the operating system's network interaction pattern, and system behavior entropy reflects the operating system's overall current behavior pattern. Therefore, by analyzing the essential network interaction characteristics and overall system behavior characteristics among various system behaviors, the operating system's behavior pattern can be accurately represented. Moreover, using behavior pattern as one of the conditions for determining the presence of a virus can make virus identification results more accurate.
[0039] In one optional implementation, the determination of the behavioral complexity is based on the behavioral pattern index and the system behavioral entropy.
[0040] Use the following expression:
[0041] RVAS=NBD+γ*NBD*S……(3)
[0042] Wherein, RVAS is the behavioral complexity, γ is the third preset coefficient, NBD is the behavioral pattern index, and S is the system behavioral entropy.
[0043] Specifically, in the above formula, behavioral complexity is mainly composed of the independent influence (NBD) of network interaction frequency and system behavioral entropy, as well as the mutual influence (γ*NBD*S) between these two indicators. Therefore, by combining the independent influence of each indicator and the mutual influence between them, the behavioral characteristics of the operating system can be determined more accurately.
[0044] Secondly, the present invention provides a virus identification device, comprising:
[0045] The acquisition module is used to acquire the total number of times each system behavior is performed among various system behaviors of the operating system; and to acquire the number of times network interaction behavior is performed in the current period, wherein the network interaction behavior is one of the various system behaviors.
[0046] The determination module is used to determine the network interaction frequency of the operating system based on the number of network interaction behaviors in the current period and a preset threshold number of behaviors; determine the system behavior entropy of the operating system based on the total number of behaviors of each type of system behavior among multiple system behaviors, wherein the system behavior entropy is used to indicate the behavior disorder of the operating system; and determine the behavior complexity of the operating system based on the network interaction frequency and the system behavior entropy.
[0047] The identification module is used to identify whether a virus exists in the operating system based on the complexity of the behavior.
[0048] Thirdly, the present invention provides a computer device, comprising: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the virus identification method of the first aspect or any corresponding embodiment described above.
[0049] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions for causing a computer to perform the virus identification method of the first aspect or any corresponding embodiment thereof. Attached Figure Description
[0050] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0051] Figure 1 This is a schematic diagram of the structure of an operating system according to an embodiment of the present invention;
[0052] Figure 2 This is a flowchart illustrating a virus identification method according to an embodiment of the present invention;
[0053] Figure 3 This is a flowchart illustrating another virus identification method according to an embodiment of the present invention;
[0054] Figure 4 This is a schematic diagram of the structure of an apparatus for a virus identification method according to an embodiment of the present invention;
[0055] Figure 5 This is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. Detailed Implementation
[0056] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0057] In the field of computer technology, computer devices typically have an operating system installed, such as Linux or Windows. A Linux system can include an application layer and a kernel layer, such as... Figure 1As shown. The kernel layer can be used to control the hardware resources of the computer device, such as allocating memory resources and coordinating the processing resources of the Central Processing Unit (CPU). The application layer can be used to respond to user operation commands and directly process them. The application layer and the kernel layer interact through system call functions. The method provided in this embodiment is mainly executed by the Linux system kernel layer.
[0058] Viruses typically encrypt or steal files stored in data centers, leading to data breaches and loss. Therefore, computer equipment needs to be monitored for viruses in real time and intercepted promptly upon detection.
[0059] This invention provides a virus identification method that determines the presence of a virus by analyzing the behavioral characteristics of the operating system, thereby accurately identifying viruses and preventing data loss.
[0060] According to an embodiment of the present invention, a virus identification method embodiment is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0061] This embodiment provides a virus identification method that can be used in the aforementioned computer devices, such as servers and terminals. Figure 2 This is a flowchart of a virus identification method according to an embodiment of the present invention, such as... Figure 2 As shown, the process includes the following steps:
[0062] Step S201: Obtain the total number of occurrences of each system behavior among the various system behaviors of the operating system.
[0063] Among these, various system behaviors can include opening, reading, modifying, and deleting files stored on computer devices, as well as network connection behaviors, process creation behaviors, and network interaction behaviors.
[0064] Specifically, technicians can pre-add hooks to relevant system behavior functions in the operating system. Hooks are Hook functions in the kernel code that can capture event information.
[0065] For example, regarding network interaction behavior, all network packets are sent sequentially through the `ndo_start_xmit()` and `dev_queue_xmit()` functions, while all network packets are received through the `napi_gro_receive()` function. Therefore, technicians can add hooks to these functions to capture network interaction behavior. For file opening behavior, technicians can add a hook in the `sys_open()` function within `entry_SYSCALL_64` of the `arch / x86 / entry / common.c` file; for network connection behavior, technicians can add a hook in the `sys_connect()` function within `entry_SYSCALL_64` of the `arch / x86 / entry / common.c` file; and for process creation behavior, technicians can add a hook in the `do_fork()` function within `entry_SYSCALL_64` of the `arch / x86 / entry / common.c` file.
[0066] Additionally, technicians can set multiple global variables in the operating system kernel layer, each of which records the number of times a specific system behavior occurs. Alternatively, technicians can set a global array in the operating system kernel layer to record the correspondence between system behaviors and their counts. Whenever the computer device captures a system behavior through a hook in the system behavior function, it increments the count of that behavior by one. For example, corresponding to the network interaction behavior example above, whenever the computer device captures a network interaction behavior through any of the three functions mentioned above, the global variable corresponding to that network interaction behavior is incremented by one.
[0067] Each time the computer device is turned on, it can update global variables or global arrays to their initial state (i.e., reset the number of actions to zero).
[0068] In this way, for each system behavior, whenever a periodic triggering time is reached, the computer device can obtain the total number of times the corresponding system behavior occurs from the global variable for that system behavior. Alternatively, whenever a periodic triggering time is reached, the computer device can obtain the total number of times each system behavior occurs from a global array.
[0069] Step S202: Obtain the number of network interaction behaviors within the current period.
[0070] Specifically, for network interaction behavior, technicians can set a timer to trigger once every first preset duration, for example, one minute. The computer device can record the number of network interaction behaviors from the trigger time within the first preset duration.
[0071] Step S203: Determine the network interaction frequency of the operating system based on the number of network interaction behaviors in the current period and a preset threshold number of behaviors.
[0072] Specifically, the preset frequency threshold can be the number of normal network interactions of the installed computer device within a second preset duration. The second preset duration is longer than the first preset duration. For example, the second preset duration can be one hour. Furthermore, the ratio of the number of network interaction behaviors in the current period to the preset frequency threshold is determined as the network interaction frequency of the operating system.
[0073] Furthermore, the frequency of network interactions under normal operating conditions varies depending on factors such as different time periods, different computer models, different network connection states (e.g., connected to a subnet, connected to the internet), and different operating systems; that is, the preset threshold values differ. Therefore, technicians need to conduct testing to determine the correspondence between time periods, computer models, network connection states, operating system types, and preset threshold values. When executing this method, the computer device can select the corresponding preset threshold value from the corresponding relationship based on its current time period, model, network connection state, and operating system type. In this way, by selecting the appropriate preset threshold value based on the computer device's characteristics and real-time conditions, the network interaction frequency of the operating system can be determined more accurately.
[0074] Step S204: Determine the system behavior entropy of the operating system based on the total number of occurrences of each system behavior among various system behaviors.
[0075] System behavior entropy is used to indicate the degree of disorder in the operating system's behavior.
[0076] Specifically, the computer device can first determine the proportion of each system behavior among all system behaviors based on the total number of such behaviors. Further, based on the proportion of each system behavior, the system behavior entropy of the operating system can be determined.
[0077] Step S205: Determine the behavioral complexity of the operating system based on the network interaction frequency and system behavior entropy.
[0078] Specifically, computer devices can directly sum the network interaction frequency and system behavior entropy to obtain the operating system's behavioral complexity.
[0079] Step S206: Identify whether a virus exists in the operating system based on behavioral complexity.
[0080] Specifically, after calculating the complexity of the behavior, the computer device can determine whether the complexity is within a preset range. If it is, it indicates that the operating system contains a virus, and the computer device will perform a virus interception operation. This interception operation may include interrupting network connections and other ongoing processes, as well as performing a full scan of the computer's data to find and delete virus-infected files. If not, it indicates that the operating system is virus-free. Additionally, after performing a virus interception, the computer device can display a pop-up window to notify the user that the virus has been intercepted.
[0081] The virus identification method provided in this embodiment addresses the issue that most viruses infiltrate computer devices primarily for profit. For example, they might encrypt files and demand payment before decrypting them, or directly steal files. To achieve this, viruses frequently manipulate files through system actions and transmit acquired information via frequent network interactions, resulting in increased behavioral complexity and network interaction frequency. Therefore, by analyzing the real-time network interaction frequency and system behavior entropy of the computer device, real-time system behavior characteristics (behavioral complexity) can be determined. Furthermore, these system behavior characteristics can accurately identify whether a virus has infiltrated the system. Additionally, although viruses evolve rapidly, the system behavior characteristics after a virus intrusion differ significantly from those under normal operating conditions. This remains constant. Therefore, this solution addresses this key point in its design and does not need to consider the issue of virus updates.
[0082] This embodiment provides a virus identification method that can be used in the aforementioned computer devices, such as servers and terminals. Figure 3 This is a flowchart of a virus identification method according to an embodiment of the present invention, such as... Figure 3 As shown, the process includes the following steps:
[0083] Step S301: Obtain the total number of occurrences of each system behavior among the various system behaviors of the operating system.
[0084] Step S302: Obtain the number of network interaction behaviors within the current period.
[0085] The specific processing of steps S301 to S302 can be similar to that of steps S201 to S202, and will not be repeated here.
[0086] Step S303: Determine the network interaction frequency of the operating system based on the number of network interaction behaviors in the current period and a preset threshold number of behaviors.
[0087] Specifically, step S303 above can be expressed as follows:
[0088] NFI=ΔN / N……(1)
[0089] Wherein, NFI is the network interaction frequency, ΔN is the number of network interaction behaviors in the current period, and N is the preset threshold number of behaviors.
[0090] After a virus infiltrates a computer device, it engages in frequent network interactions with the target (the virus initiator) to obtain relevant information. In other words, the frequency of these network interactions increases after a virus infiltrates a computer device. Therefore, the frequency of network interactions can be used as one of the criteria for determining whether a computer device is infected with a virus.
[0091] Step S304: Determine the system behavior entropy of the operating system based on the total number of occurrences of each system behavior among various system behaviors.
[0092] Specifically, step S304 includes:
[0093] Step S3041: Determine the total number of system behaviors of the operating system based on the total number of behaviors of each type of system behavior among the various system behaviors.
[0094] Specifically, the computer device can sum the total number of times each system action corresponds to a single action to obtain the total number of system actions.
[0095] Step S3042: Determine the system call frequency corresponding to each system behavior based on the total number of behaviors and the total number of system behaviors for each type of system behavior.
[0096] Specifically, for each system behavior, the computer device can determine the system call frequency corresponding to that system behavior as the ratio of the total number of behaviors corresponding to that system behavior to the total number of system behaviors.
[0097] Step S3043: Determine the subsystem behavior entropy corresponding to the first system behavior based on the system call frequency corresponding to the first system behavior.
[0098] The first type of system behavior is any one of the multiple system behaviors.
[0099] Specifically, for each system behavior, the computer device can first calculate the logarithm of the system call frequency corresponding to the system behavior, and then determine the subsystem behavior entropy corresponding to the system behavior by multiplying the logarithm by the system call frequency.
[0100] Step S3044: Determine the system behavior entropy based on the subsystem behavior entropy corresponding to the various system behaviors.
[0101] Specifically, a computer device can sum the entropy of the subsystem behaviors corresponding to all system behaviors to obtain the system behavior entropy of the operating system.
[0102] The above step S304 can be expressed as follows:
[0103]
[0104] P(i)=Ci / C…… (3)
[0105] Si=P(i)*logP(i)……(4)
[0106]
[0107] Where C is the total number of system behaviors, C(i) is the total number of behaviors corresponding to the i-th system behavior, i is a positive integer greater than or equal to 1, k is a positive integer greater than or equal to 2, P(i) is the system call frequency corresponding to the i-th system behavior, S is the system behavior entropy, and Si is the subsystem behavior entropy corresponding to the i-th system behavior.
[0108] For example, for a set of data including three system behaviors, the three system behaviors are A, B and C, and the total number of behaviors corresponding to system behavior A is 20, the total number of behaviors corresponding to system behavior B is 30, the total number of behaviors corresponding to system behavior C is 50, and the total number of system behaviors is 100, substituting into formula (2), we can get: S=-(20 / 100)*log(20 / 100)-(30 / 100)*log(30 / 100)-(50 / 100)*log(50 / 100)=1.52.
[0109] Since viruses infiltrate computer devices to obtain relevant information, they frequently perform encryption / decryption, reading, and even modification operations on files, as well as frequent network connections, process creation, and network interactions to transmit information. At this point, the computer device's system behavior is significantly more chaotic than normal operation. Therefore, the degree of chaos in the operating system's system behavior can be used as one of the criteria for determining whether a computer device is infected with a virus.
[0110] Step S305: Determine the behavioral complexity of the operating system based on the network interaction frequency and system behavior entropy.
[0111] Specifically, step S305 includes:
[0112] Step S3051: Determine the operating system's behavior pattern indicators based on network interaction frequency and system behavior entropy.
[0113] In some possible implementations, step S3051 above can be expressed as follows:
[0114] NBD=α*NFI+β*S……(6)
[0115] Wherein, NBD is the behavior pattern index, α is the first preset coefficient, NFI is the network interaction frequency, β is the second preset coefficient, and S is the system behavior entropy.
[0116] While different viruses manipulate data on computer devices in slightly different ways, network interaction is invariably frequent regardless of the type of virus. Furthermore, network interaction frequency reflects the operating system's network interaction patterns, and system behavior entropy reflects the operating system's overall current behavior pattern. Therefore, by analyzing the essential network interaction characteristics and overall system behavior characteristics among various system behaviors, the operating system's behavior pattern can be accurately represented. Moreover, using behavior pattern as one of the criteria for determining the presence of a virus can make virus identification results more accurate.
[0117] Because different computer devices exhibit varying behavioral characteristics during business processing, technicians can determine specific first and second preset coefficients tailored to the unique characteristics of different computer models through multiple tests. Therefore, employing different first and second preset coefficients for different situations allows for a more accurate representation of the operating system's behavioral characteristics.
[0118] Step S3052: Determine the behavioral complexity based on the behavioral pattern indicators and system behavioral entropy.
[0119] In some possible implementations, step S3052 above can be expressed as follows:
[0120] RVAS=NBD+γ*NBD*S……(7)
[0121] Where RVAS is the behavioral complexity, γ is the third preset coefficient, NBD is the behavioral pattern index, and S is the system behavioral entropy.
[0122] In the above formula (7), the behavioral complexity is mainly composed of the independent influence of the two indicators, network interaction frequency and system behavioral entropy (NBD, see formula (6)) and the mutual influence of the two indicators (γ*NBD*S). Therefore, by combining the independent influence of each indicator and the mutual influence between indicators, the behavioral characteristics of the operating system can be determined more accurately.
[0123] Because different computer devices exhibit varying behavioral characteristics during business processing, technicians can determine a third preset coefficient that suits the specific characteristics of each computer model through multiple tests. Therefore, using different third preset coefficients for different situations can more accurately represent the behavioral characteristics of the operating system.
[0124] Step S306: Identify whether a virus exists in the operating system based on behavioral complexity.
[0125] Specifically, step S306 includes:
[0126] Step S3061: Determine whether the behavior complexity is greater than or equal to the preset behavior complexity threshold.
[0127] The preset behavioral complexity can be the lowest behavioral complexity of the operating system determined during the virus intrusion test.
[0128] Specifically, computer devices can compare the behavioral complexity calculated by the above process with a preset behavioral complexity threshold to determine whether the operating system contains a virus.
[0129] Because different computer models exhibit varying behavioral characteristics during business processing, technicians can determine preset behavioral complexity thresholds tailored to the specific characteristics of each computer through multiple tests. Therefore, employing different preset behavioral complexity thresholds for different situations allows for a more accurate determination of the presence of viruses in the operating system.
[0130] Step S3062: When the behavior complexity is determined to be greater than or equal to a preset behavior complexity threshold, a virus is identified in the operating system.
[0131] Specifically, when the calculated behavioral complexity is greater than or equal to a preset behavioral complexity threshold, it indicates a significant difference between the current operating system's behavior and its normal operating state, which is highly likely a manifestation of a virus intrusion. In this case, the presence of a virus in the operating system can be confirmed, and virus interception can be performed. Virus interception may include interrupting network connections and other ongoing processes, as well as performing a full scan of the computer's data to identify and delete virus files.
[0132] Step S3063: When the behavior complexity is determined to be less than the preset behavior complexity threshold, it is determined that there is no virus in the operating system.
[0133] Specifically, when the calculated behavioral complexity is less than a preset behavioral complexity threshold, it indicates that the current operating system's behavioral characteristics are similar to those under normal operating conditions, meaning the operating system is functioning normally. In this case, it can be determined that the operating system is free of viruses. The virus identification method provided in this embodiment addresses this by recognizing that most viruses, after invading a computer device, frequently manipulate files through system actions and transmit acquired information via frequent network interactions, resulting in increased behavioral disorder and network interaction frequency. This differs significantly from the system behavior characteristics of a computer device under normal operating conditions. Therefore, by analyzing the real-time network interaction frequency and system behavioral entropy of the computer device, the real-time system behavioral characteristics (behavioral complexity) can be determined. Furthermore, comparing the calculated behavioral complexity with a preset behavioral complexity threshold allows for the identification of whether a virus exists in the operating system.
[0134] In some possible implementations, the specific procedures for identifying whether an operating system is infected with a virus may also include:
[0135] Multiple virus intrusion tests are conducted on identical computer devices, operating systems, and network connections. During each test, the computer device calculates the behavioral complexity based on the steps outlined above. Furthermore, the computer device model, operating system type, network connection status, network interaction frequency, system behavioral entropy, and behavioral complexity for each test are treated as a single data point. This yields multiple data points. These multiple data points are then input into a feature extraction model to obtain the behavioral characteristics of the operating system after a virus intrusion, under the same computer device model, operating system type, and network connection status. Different computer devices, operating system types, and network connections will correspond to different behavioral characteristics. A behavioral feature library is generated during the testing process. This library can include the correspondence between computer device model, operating system type, network connection status, and behavioral characteristics.
[0136] During the execution of this scheme, the computer device collects real-time data (including the computer device model, operating system type, network status, network interaction frequency, system behavior entropy, and behavior complexity), and obtains real-time behavioral features based on the feature extraction model. Additionally, the computer device can select corresponding behavioral features from the behavioral feature library based on its own model, operating system type, and real-time network status. Finally, the computer device can calculate the similarity between the behavioral features corresponding to the real-time data and the selected behavioral features. When the similarity is greater than or equal to a preset similarity threshold, the operating system is identified as containing a virus; when the similarity is less than or equal to the preset similarity threshold, the operating system is identified as not containing a virus.
[0137] This embodiment also provides a virus identification device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0138] This embodiment provides a virus identification device, such as... Figure 4 As shown, it includes:
[0139] The acquisition module 401 is used to acquire the total number of times each system behavior is performed among various system behaviors of the operating system; and to acquire the number of times network interaction behavior is performed in the current period, wherein network interaction behavior is one of the various system behaviors.
[0140] The determination module 402 is used to determine the network interaction frequency of the operating system based on the number of network interaction behaviors in the current period and a preset threshold number of behaviors; to determine the system behavior entropy of the operating system based on the total number of behaviors of each type of system behavior among various system behaviors, wherein the system behavior entropy is used to indicate the behavior disorder of the operating system; and to determine the behavior complexity of the operating system based on the network interaction frequency and the system behavior entropy.
[0141] The identification module 403 is used to identify whether a virus exists in the operating system based on the complexity of its behavior.
[0142] In one alternative implementation, the determining module 402 is configured to:
[0143] The total number of system behaviors in the operating system is determined based on the total number of behaviors for each type of system behavior among various system behaviors. The total number of system behaviors is: C(i) represents the total number of behaviors corresponding to the i-th type of system behavior, where i is a positive integer greater than or equal to 1, and k is a positive integer greater than or equal to 2;
[0144] Based on the total number of behaviors and the total number of system behaviors for each type of system behavior, the system call frequency corresponding to each type of system behavior is determined, where the system call frequency corresponding to the i-th type of system behavior is P(i) = Ci / C;
[0145] Based on the system call frequency corresponding to the first system behavior, determine the subsystem behavior entropy corresponding to the first system behavior. The first system behavior is any one of the multiple system behaviors, and the subsystem behavior entropy corresponding to the i-th system behavior is Si = P(i) * logP(i).
[0146] The system behavior entropy is determined based on the subsystem behavior entropy corresponding to various system behaviors, where the system behavior entropy is:
[0147] In one alternative implementation, the determining module 402 is configured to:
[0148] Determine the operating system's behavioral pattern indicators based on network interaction frequency and system behavior entropy;
[0149] Determine the behavioral complexity based on behavioral pattern indicators and system behavioral entropy.
[0150] In one alternative implementation, the identification module 403 is used for:
[0151] Determine whether the behavior complexity is greater than or equal to a preset behavior complexity threshold;
[0152] When the behavior complexity is determined to be greater than or equal to a preset behavior complexity threshold, a virus is identified in the operating system.
[0153] or,
[0154] When the behavior complexity is determined to be less than a preset behavior complexity threshold, it is determined that there is no virus in the operating system.
[0155] In one optional implementation, the network interaction frequency of the operating system is determined based on the number of network interaction behaviors in the current period and a preset threshold, using the following expression:
[0156] NFI=ΔN / N……(1)
[0157] Wherein, NFI is the network interaction frequency, ΔN is the number of network interaction behaviors in the current period, and N is the preset threshold number of behaviors.
[0158] In one alternative implementation, operating system behavior pattern indicators are determined based on network interaction frequency and system behavior entropy.
[0159] Use the following expression:
[0160] NBD=α*NFI+β*S……(2)
[0161] Wherein, NBD is the behavioral pattern index, α is the first preset coefficient, NFI is the network interaction frequency, β is the second preset coefficient, and S is the behavioral entropy.
[0162] In one alternative implementation, behavioral complexity is determined based on behavioral pattern indicators and system behavioral entropy.
[0163] Use the following expression:
[0164] RVAS=NBD+γ*NBD*S……(3)
[0165] Wherein, RVAS represents behavioral complexity, γ is the third preset coefficient, NBD is the behavioral pattern index, and S is the system behavioral entropy. Further functional descriptions of the above modules and units are the same as in the corresponding embodiments described above, and will not be repeated here.
[0166] The virus identification device in this embodiment is presented in the form of a functional unit. Here, a unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.
[0167] This invention also provides a computer device having the above-described features. Figure 4 The virus identification device shown.
[0168] Please see Figure 5 , Figure 5 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 5 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 5 Take a processor 10 as an example.
[0169] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.
[0170] The memory 20 stores instructions executable by at least one processor 10 to cause the at least one processor 10 to perform the method shown in the above embodiments.
[0171] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computer device. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, which can be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0172] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0173] The computer device also includes an input device 30 and an output device 40. The processor 10, memory 20, input device 30, and output device 40 can be connected via a bus or other means. Figure 5 Taking the example of a connection between China and Israel via a bus.
[0174] Input device 30 can receive input numerical or character information, and generate key signal inputs related to user settings and function control of the computer device, such as a touchscreen, keypad, mouse, touchpad, pointer, etc. Output device 40 may include display devices, etc. The aforementioned display devices include, but are not limited to, liquid crystal displays, light-emitting diodes, displays, and plasma displays. In some optional embodiments, the display device may be a touchscreen.
[0175] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.
[0176] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A method for virus identification, characterized in that, The method includes: Obtain the total number of occurrences of each system behavior among various system behaviors of the operating system; In addition, the number of network interaction behaviors within the current period is obtained, wherein the network interaction behaviors are one of the various system behaviors; The network interaction frequency of the operating system is determined based on the number of network interaction behaviors in the current period and a preset threshold number. The system behavior entropy of the operating system is determined based on the total number of occurrences of each system behavior among various system behaviors, wherein the system behavior entropy is used to indicate the degree of behavioral disorder of the operating system; The operating system's behavior pattern indicators are determined based on the network interaction frequency and the system behavior entropy. The behavioral complexity is determined based on the behavioral pattern index and the system behavioral entropy. The presence of a virus in the operating system is identified based on the described behavioral complexity. The network interaction frequency of the operating system is determined based on the number of network interaction behaviors in the current period and a preset threshold number, using the following expression: NFI = ΔN / N (1) Wherein, NFI is the network interaction frequency, ΔN is the number of network interaction behaviors in the current period, and N is the preset number threshold. The behavioral pattern index of the operating system is determined based on the network interaction frequency and the system behavior entropy, using the following expression: NBD = α × NFI + β × S (2) Wherein, NBD is the behavior pattern index, α is the first preset coefficient, NFI is the network interaction frequency, β is the second preset coefficient, and S is the behavior entropy; The behavioral complexity is determined based on the behavioral pattern index and the system behavioral entropy, using the following expression: RVAS = NBD + γ × NBD × S (3) Wherein, RVAS is the behavioral complexity, γ is the third preset coefficient, NBD is the behavioral pattern index, and S is the system behavioral entropy.
2. The method according to claim 1, characterized in that, The step of determining the system behavior entropy of the operating system based on the total number of occurrences of each system behavior among multiple system behaviors includes: The total number of system behaviors of the operating system is determined based on the total number of behaviors for each type of system behavior among various system behaviors, wherein the total number of system behaviors is C= C(i) represents the total number of times the behavior corresponds to the i-th type of system behavior, where i is a positive integer greater than or equal to 1, and k is a positive integer greater than or equal to 2; Based on the total number of each system behavior and the total number of system behaviors, the system call frequency corresponding to each system behavior is determined, wherein the system call frequency corresponding to the i-th system behavior is P(i) = Ci / C; Based on the system call frequency corresponding to the first system behavior, determine the subsystem behavior entropy corresponding to the first system behavior, where the first system behavior is any one of multiple system behaviors, and the subsystem behavior entropy corresponding to the i-th system behavior is Si= ; The system behavior entropy is determined based on the subsystem behavior entropy corresponding to various system behaviors, wherein the system behavior entropy is... .
3. The method according to claim 1 or 2, characterized in that, The step of identifying whether a virus exists in the operating system based on the behavioral complexity includes: Determine whether the behavior complexity is greater than or equal to a preset behavior complexity threshold; When the behavior complexity is determined to be greater than or equal to a preset behavior complexity threshold, a virus is identified in the operating system. or, When the complexity of the behavior is determined to be less than a preset behavior complexity threshold, it is determined that there is no virus in the operating system.
4. A virus identification device, characterized in that, The device includes: The acquisition module is used to acquire the total number of times each system behavior is performed among various system behaviors of the operating system; and to acquire the number of times network interaction behavior is performed in the current period, wherein the network interaction behavior is one of the various system behaviors. A determination module is configured to: determine the behavior pattern index of the operating system based on the network interaction frequency and the system behavior entropy; determine the behavior complexity based on the behavior pattern index and the system behavior entropy; determine the system behavior entropy of the operating system based on the total number of behaviors of each type of system behavior among multiple system behaviors, wherein the system behavior entropy is used to indicate the behavior disorder of the operating system; and determine the behavior complexity of the operating system based on the network interaction frequency and the system behavior entropy. The identification module is used to identify whether a virus exists in the operating system based on the complexity of the behavior. The network interaction frequency of the operating system is determined based on the number of network interaction behaviors in the current period and a preset threshold number, using the following expression: NFI = ΔN / N (1) Wherein, NFI is the network interaction frequency, ΔN is the number of network interaction behaviors in the current period, and N is the preset number threshold. The behavioral pattern index of the operating system is determined based on the network interaction frequency and the system behavior entropy, using the following expression: NBD = α × NFI + β × S (2) Wherein, NBD is the behavior pattern index, α is the first preset coefficient, NFI is the network interaction frequency, β is the second preset coefficient, and S is the behavior entropy; The behavioral complexity is determined based on the behavioral pattern index and the system behavioral entropy, using the following expression: RVAS = NBD + γ × NBD × S (3) Wherein, RVAS is the behavioral complexity, γ is the third preset coefficient, NBD is the behavioral pattern index, and S is the system behavioral entropy.
5. A computer device, characterized in that, include: A memory and a processor are communicatively connected, the memory stores computer instructions, and the processor executes the computer instructions to perform the virus identification method according to any one of claims 1 to 3.
6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to perform the virus identification method according to any one of claims 1 to 3.
Citation Information
Patent Citations
Detecting method and system for malicious codes
CN102360408A
Method and device for monitoring operation times of user system and computer storage medium
CN109918278A