Trojan virus-based mail processing method, device and equipment and storage medium
By identifying the target account information and virus characteristics before Trojan virus emails are intercepted, and then using security linkage devices for coordinated handling, the problem of low efficiency in handling Trojan virus emails in existing technologies is solved, achieving more efficient automated processing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-29
- Publication Date
- 2026-04-14
AI Technical Summary
Current technologies for handling Trojan virus emails are inefficient, requiring manual periodic detection and removal, which leads to untimely and inefficient processing.
By identifying the target account information of the Trojan virus email, obtaining virus characteristic information, and using security linkage devices for coordinated handling, including virus blocking strategies and terminal host isolation.
It improves the efficiency of handling Trojan virus emails, reduces manual intervention, and enhances user experience and overall security capabilities.
Smart Images

Figure CN119232406B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of internet security technology, and in particular to a method, apparatus, device, and storage medium for handling emails based on Trojan viruses. Background Technology
[0002] Trojan viruses are disguised and lurking network viruses that are sent as email attachments and bundled with other programs. Once activated, a Trojan virus can set up a backdoor, periodically sending the user's private information to an address specified by the Trojan program, and can arbitrarily control the computer, performing illegal operations such as deleting, copying, and changing passwords. Current technology requires manual periodic detection of emails containing Trojan viruses, and manual removal is required when Trojan virus emails are detected, resulting in low efficiency in handling Trojan virus emails.
[0003] The above content is only used to help understand the technical solution of the present invention and does not represent an admission that the above content is prior art. Summary of the Invention
[0004] The main objective of this invention is to provide a method, apparatus, device, and storage medium for handling emails based on Trojan viruses, aiming to solve the technical problem of how to improve the efficiency of handling emails containing Trojan viruses.
[0005] To achieve the above objectives, the present invention provides an email handling method based on a Trojan virus, the method comprising the following steps:
[0006] When the Trojan virus email is not blocked, determine the target account information that received the Trojan virus email;
[0007] Obtain the virus signature information of the Trojan virus email based on the target account information;
[0008] Based on the virus characteristic information, determine the security linkage device;
[0009] The aforementioned security linkage device enables coordinated handling of the Trojan virus emails.
[0010] Optionally, before the step of determining the target account information for receiving the Trojan virus email when it is not intercepted, the method further includes:
[0011] Email alerts are obtained through security testing equipment;
[0012] The Trojan virus incident was identified based on the email alert information.
[0013] The Trojan virus event was analyzed to obtain Trojan virus infection information;
[0014] The Trojan virus email was identified based on the Trojan virus infection information.
[0015] Optionally, after the step of determining the Trojan virus email based on the Trojan virus infection information, the method further includes:
[0016] The emails containing the Trojan virus are intercepted through an email gateway device, and email interception information is obtained.
[0017] Determine whether the email blocking information meets the preset blocking conditions;
[0018] If the email interception information does not meet the preset interception conditions, it is determined that the Trojan virus email has not been intercepted.
[0019] Optionally, after the step of determining whether the email blocking information meets the preset blocking conditions, the method further includes:
[0020] When the email interception information meets the preset interception conditions, an interception alarm message is generated based on the email interception information;
[0021] The interception alarm information is sent to the corresponding target management terminal.
[0022] Optionally, before the step of determining the target account information for receiving the Trojan virus email, the method further includes:
[0023] Obtain the email handling information for the Trojan virus email;
[0024] Determine whether the email processing information meets the preset email receiving conditions;
[0025] When the email processing information meets the preset email receiving conditions, the step of determining the target account information for receiving the Trojan virus email is executed.
[0026] Optionally, after the step of determining whether the email processing information meets the preset email receiving conditions, the method further includes:
[0027] When the email processing information does not meet the preset email receiving conditions, the delivery account information of the Trojan virus email is determined;
[0028] The delivery account information is added to the email blacklist so that the email blocking device can block emails sent by the delivery account information based on the email blacklist.
[0029] Optionally, the step of obtaining the virus signature information of the Trojan virus email based on the target account information includes:
[0030] Extract virus sample information from the Trojan virus email based on the target account information;
[0031] The virus sample information is analyzed to obtain the virus characteristic information of the Trojan virus email.
[0032] Optionally, the step of analyzing the virus sample information to obtain the virus characteristic information of the Trojan virus email includes:
[0033] Obtain the login terminal information corresponding to the target account information;
[0034] The security detection device is determined based on the login terminal information;
[0035] The virus sample information is analyzed by the security detection device to obtain the virus characteristic information of the Trojan virus email.
[0036] Optionally, the step of determining the security linkage device based on the virus characteristic information includes:
[0037] The virus characteristic information is analyzed to obtain Trojan virus information;
[0038] The security linkage device is determined based on the Trojan virus information.
[0039] Optionally, the step of determining the security linkage device based on the Trojan virus information includes:
[0040] Determine whether the Trojan virus information meets the preset virus conditions;
[0041] When the Trojan virus information meets the preset virus conditions, the Trojan virus level is determined based on the Trojan virus information.
[0042] The security linkage device is determined based on the level of the Trojan virus.
[0043] Optionally, the step of coordinating the handling of the Trojan virus email through the security linkage device includes:
[0044] Determine the domain name and address information corresponding to the Trojan virus email;
[0045] A preset virus blocking strategy is determined based on the domain name information, the address information, and the security linkage device;
[0046] Based on the preset virus blocking strategy, the Trojan virus emails are handled in conjunction with the security linkage device.
[0047] Optionally, after the step of coordinating the handling of the Trojan virus email through the security linkage device based on the preset virus blocking strategy, the method further includes:
[0048] A Trojan virus log is generated based on the coordinated handling results of the aforementioned Trojan virus emails;
[0049] The terminal host compromise information was determined based on the Trojan virus logs.
[0050] Determine a preset host handling strategy based on the terminal host loss information;
[0051] The terminal host is isolated and processed according to the preset host processing strategy.
[0052] Furthermore, to achieve the above objectives, the present invention also proposes an email processing device based on a Trojan virus, the email processing device based on a Trojan virus comprising:
[0053] The determination module is used to determine the target account information that receives the Trojan virus email when the Trojan virus email is not intercepted.
[0054] The acquisition module is used to acquire virus feature information of the Trojan virus email based on the target account information;
[0055] The determining module is also used to determine the security linkage device based on the virus characteristic information;
[0056] The processing module is used to process the Trojan virus emails in conjunction with the security linkage device.
[0057] Optionally, the email processing device based on Trojan viruses further includes a determination module;
[0058] The determination module is used to obtain the email handling information of the Trojan virus email;
[0059] The determination module is also used to determine whether the email processing information meets the preset email receiving conditions;
[0060] The determination module is also used to perform the operation of determining the target account information for receiving the Trojan virus email when the email processing information meets the preset email receiving conditions.
[0061] Optionally, the acquisition module is further configured to extract virus sample information from the Trojan virus email based on the target account information;
[0062] The acquisition module is also used to analyze the virus sample information to obtain the virus characteristic information of the Trojan virus email.
[0063] Optionally, the determining module is further configured to analyze the virus feature information to obtain Trojan virus information;
[0064] The determining module is also used to determine the security linkage device based on the Trojan virus information.
[0065] Optionally, the processing module is further configured to determine the domain name information and address information corresponding to the Trojan virus email;
[0066] The processing module is also used to determine a preset virus blocking strategy based on the domain name information, the address information, and the security linkage device;
[0067] The processing module is also used to process the Trojan virus emails in conjunction with the security linkage device based on the preset virus blocking strategy.
[0068] Optionally, the processing module is further configured to generate a Trojan virus log based on the linkage processing results of the Trojan virus email;
[0069] The processing module is also used to determine terminal host compromise information based on the Trojan virus log;
[0070] The processing module is also used to determine a preset host processing strategy based on the terminal host compromise information;
[0071] The processing module is also used to isolate and process the terminal host according to the preset host processing strategy.
[0072] Furthermore, to achieve the above objectives, the present invention also proposes an email processing device based on a Trojan virus, the device comprising: a memory, a processor, and an email processing program based on a Trojan virus stored in the memory and executable on the processor, the email processing program based on a Trojan virus being configured to implement the steps of the email processing method based on a Trojan virus as described above.
[0073] Furthermore, to achieve the above objectives, the present invention also proposes a storage medium storing a Trojan virus-based email handling program, which, when executed by a processor, implements the steps of the Trojan virus-based email handling method described above.
[0074] This invention, when a Trojan virus email is not intercepted, first identifies the target account information receiving the email, then obtains the virus signature information based on the target account information, and determines a security linkage device based on the virus signature information. Finally, the security linkage device is used to handle the Trojan virus email in a coordinated manner. Compared to existing technologies that require manual detection and handling of Trojan virus emails, this invention, upon detecting a Trojan virus email, determines a security linkage device based on the corresponding virus signature information and then uses that device to handle the email in a coordinated manner, thereby improving the efficiency of Trojan virus email handling and ultimately enhancing the user experience. Attached Figure Description
[0075] Figure 1 This is a schematic diagram of the structure of an email processing device based on a Trojan virus in the hardware operating environment involved in the embodiments of the present invention;
[0076] Figure 2 This is a flowchart illustrating the first embodiment of the email handling method based on Trojan viruses of the present invention.
[0077] Figure 3 This is a flowchart illustrating the second embodiment of the email handling method based on Trojan viruses of the present invention.
[0078] Figure 4 This is a flowchart illustrating the third embodiment of the email handling method based on Trojan viruses of the present invention.
[0079] Figure 5 This is a structural block diagram of the first embodiment of the email processing device based on Trojan viruses of the present invention.
[0080] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0081] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.
[0082] Reference Figure 1 , Figure 1 This is a schematic diagram of the structure of an email processing device based on a Trojan virus, which is part of the hardware operating environment involved in the embodiments of the present invention.
[0083] like Figure 1As shown, the email processing device based on a Trojan virus may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to establish communication between these components. The user interface 1003 may include a display screen and an input unit such as a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wireless-Fidelity (Wi-Fi) interface). The memory 1005 may be high-speed random access memory (RAM) or stable non-volatile memory (NVM), such as a disk drive. The memory 1005 may also optionally be a storage device independent of the aforementioned processor 1001.
[0084] Those skilled in the art will understand that Figure 1 The structure shown does not constitute a limitation on Trojan virus-based email processing devices, which may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0085] like Figure 1 As shown, the memory 1005, which serves as a storage medium, may include an operating system, a data storage module, a network communication module, a user interface module, and an email handling program based on a Trojan virus.
[0086] exist Figure 1 In the Trojan virus-based email processing device shown, the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and memory 1005 in the Trojan virus-based email processing device of the present invention can be set in the Trojan virus-based email processing device, and the Trojan virus-based email processing device calls the Trojan virus-based email processing program stored in the memory 1005 through the processor 1001 and executes the Trojan virus-based email processing method provided in the embodiment of the present invention.
[0087] This invention provides a method for handling emails based on Trojan viruses, referring to... Figure 2 , Figure 2 This is a flowchart illustrating the first embodiment of the email handling method based on Trojan viruses of the present invention.
[0088] In this embodiment, the email handling method based on Trojan viruses includes the following steps:
[0089] Step S10: If the Trojan virus email is not intercepted, determine the target account information that received the Trojan virus email.
[0090] It is easy to understand that the execution subject of this embodiment can be a Trojan virus-based email processing device with functions such as data processing, network communication and program execution, or other computer devices with similar functions. This embodiment does not limit it.
[0091] Understandably, a Trojan virus email is an email that carries a Trojan virus. Once a user opens this Trojan virus email, the terminal will be infected by the Trojan virus, which can then arbitrarily control the computer and perform illegal operations such as deleting, copying, and changing passwords.
[0092] It should be noted that the target account information of Trojan virus emails includes the email account information of the recipient of the Trojan virus email.
[0093] Furthermore, in order to accurately identify Trojan virus emails, before determining the target account information for receiving Trojan virus emails if they are not intercepted, it is necessary to obtain email alert information through security detection equipment. Then, based on the email alert information, the Trojan virus event is determined. After that, the Trojan virus event is analyzed to obtain Trojan virus infection information, and the Trojan virus email is identified based on the Trojan virus infection information.
[0094] It should also be understood that email alerts are virus alerts generated by security devices, which may include the discovery of Trojan virus delivery events or the discovery of other virus delivery events.
[0095] In practice, when a Trojan virus delivery event is discovered, it is necessary to analyze the event to obtain Trojan virus infection information. This information includes the specific delivery method of the Trojan virus, such as delivery via link or email. Based on this infection information, the Trojan virus email or link can then be identified.
[0096] In this embodiment, the security device generates an alarm, enabling it to perform advanced threat detection and malicious analysis on Trojan virus emails, identifying events that deliver Trojan virus emails. The Trojan virus event needs to be sent to the email gateway, which can intercept the Trojan virus email, obtain email interception information, and determine whether the email interception information meets preset interception conditions. If the email interception information does not meet the preset interception conditions, it is determined that the Trojan virus email has not been intercepted; if the email interception information meets the preset interception conditions, an interception alarm is generated based on the email interception information and sent to the corresponding target management terminal.
[0097] It should be understood that the preset blocking condition is that the Trojan virus email is blocked. The email blocking information includes whether the email was blocked or not. The target management terminal can be a terminal managed by the person in charge of the Trojan virus, or it can be a terminal associated with the target account information.
[0098] In practical implementation, when the Trojan virus email is not intercepted by the email gateway, the email handling information of the Trojan virus email is also needed to determine whether the email handling information meets the preset email receiving conditions. If the email handling information does not meet the preset email receiving conditions, the delivery account information of the Trojan virus email is determined and added to the email blacklist so that the email interception device can intercept emails sent by the delivery account information according to the email blacklist. If the email handling information meets the preset email receiving conditions, the target account information for receiving the Trojan virus email is determined.
[0099] It should also be noted that the email handling information can include the current status of the malware email, such as whether the email has been received or not. The default email reception condition is that the user has already received the malware email.
[0100] In this embodiment, an alarm generated by the security device detects an event where a virus / Trojan email is delivered. First, it is determined whether the email gateway has blocked it. If the email gateway has already blocked it, no action is needed; otherwise, the relevant email account is identified based on the alarm. Then, based on the alarm information, the relevant virus / Trojan email is identified, and it is determined whether the user has accepted the email. If the user has not accepted it, it is confirmed that the user is not harmed, and the user is notified not to open the email. If the user has accepted the email, they are asked whether it has been opened. If not, the user is notified not to open the email. If the user has opened the email, the host processing procedure is initiated. The host processing procedure includes isolating the host, notifying technical personnel to perform on-site processing, deleting the email, removing the Trojan, and restoring services.
[0101] Step S20: Obtain the virus signature information of the Trojan virus email based on the target account information.
[0102] Furthermore, in order to accurately obtain virus feature information, the processing method for obtaining virus feature information of Trojan virus emails based on target account information can be to extract virus sample information from Trojan virus emails based on target account information, and then analyze the virus sample information to obtain the virus feature information of Trojan virus emails.
[0103] It should also be understood that virus sample information can be part of the Trojan virus information in the Trojan virus email, and virus feature information can be information related to the Trojan virus, such as Trojan virus toxicity information, related domain names or Internet Protocol (IP) addresses, etc.
[0104] In practice, the steps to analyze virus sample information and obtain virus characteristic information of Trojan virus emails can be as follows: obtain the login terminal information corresponding to the target account information, then determine the security detection device based on the login terminal information, and analyze the virus sample information through the security detection device to obtain the virus characteristic information of Trojan virus emails.
[0105] It should be noted that the login terminal information refers to the terminal device that is logged in when receiving the Trojan virus email, and the security detection device refers to the security devices present on the currently logged-in terminal device, such as intrusion detection systems or sandbox devices.
[0106] In this embodiment, virus sample information can be obtained through an intrusion detection system, and then the virus sample information can be analyzed in conjunction with a sandbox to obtain virus feature information, including Trojan virus information, related domain names or IP addresses, etc.
[0107] Step S30: Determine the security linkage device based on the virus characteristic information.
[0108] Furthermore, in order to improve the processing efficiency of Trojan virus emails, the processing method for determining security linkage devices based on virus feature information can be as follows: analyze the virus feature information to obtain Trojan virus information, determine whether the Trojan virus information meets the preset virus conditions, and when the Trojan virus information meets the preset virus conditions, determine the Trojan virus level based on the Trojan virus information, and then determine the security linkage device based on the Trojan virus level.
[0109] It should also be understood that the preset virus conditions are that Trojan virus emails are malicious emails, and the Trojan virus information includes information about whether the Trojan virus is malicious or not. The security linkage device can be a firewall or other security device.
[0110] In practice, if the Trojan virus email is not malicious, the process ends; if the Trojan virus email is malicious, the security linkage device can be a firewall, etc.
[0111] Step S40: The Trojan virus email is handled in conjunction with the security linkage device.
[0112] Furthermore, in order to improve the efficiency of handling Trojan virus emails, the processing method of handling Trojan virus emails in conjunction with security linkage devices can be as follows: determine the domain name information and address information corresponding to the Trojan virus email, then determine the preset virus blocking policy based on the domain name information, address information and security linkage devices, and then handle the Trojan virus emails in conjunction with the security linkage devices based on the preset virus blocking policy.
[0113] It should also be noted that the preset virus blocking policy can be customized by the user, such as linking with the firewall to block related domains and IPs.
[0114] In this embodiment, based on a preset virus blocking strategy, the security linkage device is used to handle Trojan virus emails in a coordinated manner. A Trojan virus log is generated based on the results of the coordinated handling of the Trojan virus emails. The Trojan virus log is used to determine the terminal host compromise information. Based on the terminal host compromise information, a preset host handling strategy is determined. The terminal host is then isolated and handled according to the preset host handling strategy.
[0115] In the specific implementation, the analysis of host compromise is based on the results of the coordinated handling of Trojan virus emails, combined with traffic, alarms, and Endpoint Detection and Response (EDR) logs. Host compromise analysis strategies include identifying communication traffic from domains or IPs that match those analyzed in the sandbox analysis, abnormal security operation alarms generated by the endpoint EDR, and actions consistent with the sandbox virus analysis results. Following this, a preset host handling strategy is determined based on the host compromise analysis results. This strategy may include isolating the host and notifying technical personnel to perform on-site processing, delete emails, remove Trojans, and restore services. Finally, the endpoint host is handled according to the preset host handling strategy, and the reasons for the intrusion and shortcomings in data / service recovery are summarized and reviewed to improve overall security capabilities.
[0116] In this embodiment, when a Trojan virus email is not intercepted, the target account information receiving the email is first determined. Then, the virus signature information of the email is obtained based on the target account information, and a security linkage device is determined based on the virus signature information. The email is then handled in a coordinated manner through this security linkage device. Compared to existing technologies that require manual detection and handling of Trojan virus emails, this embodiment determines a security linkage device based on the corresponding virus signature information when a Trojan virus email is detected, and then handles the email in a coordinated manner through this device, thereby improving the efficiency of Trojan virus email handling.
[0117] refer to Figure 3 , Figure 3 This is a flowchart illustrating the second embodiment of the email handling method based on Trojan viruses of the present invention.
[0118] Based on the first embodiment described above, in this embodiment, step S10 includes:
[0119] Step S101: If the Trojan virus email is not intercepted, obtain the email handling information of the Trojan virus email.
[0120] Understandably, a Trojan virus email is an email that carries a Trojan virus. Once a user opens this Trojan virus email, the terminal will be infected by the Trojan virus, which can then arbitrarily control the computer and perform illegal operations such as deleting, copying, and changing passwords.
[0121] Furthermore, in order to quickly process Trojan virus emails, before obtaining the email handling information of the Trojan virus emails when they are not intercepted, it is necessary to obtain email alarm information through security detection equipment, then determine the Trojan virus event based on the email alarm information, analyze the Trojan virus event to obtain Trojan virus infection information, and then determine the Trojan virus email based on the Trojan virus infection information.
[0122] It should also be understood that email alerts are virus alerts generated by security devices, which may include the discovery of Trojan virus delivery events or the discovery of other virus delivery events.
[0123] In practice, when a Trojan virus delivery event is discovered, it is necessary to analyze the event to obtain Trojan virus infection information. This information includes the specific delivery method of the Trojan virus, such as delivery via link or email. Based on this infection information, the Trojan virus email or link can then be identified.
[0124] In this embodiment, an event involving the delivery of a virus / Trojan email is detected through an alarm generated by a security device. The Trojan / Trojan event needs to be sent to the email gateway, which can intercept the email, obtain email interception information, and determine whether the email interception information meets preset interception conditions. If the email interception information does not meet the preset interception conditions, it is determined that the Trojan / Trojan email has not been intercepted; if the email interception information meets the preset interception conditions, an interception alarm is generated based on the email interception information and sent to the corresponding target management terminal.
[0125] It should be understood that the preset blocking condition is that the Trojan virus email is blocked. The email blocking information includes whether the email was blocked or not. The target management terminal can be a terminal managed by the person in charge of the Trojan virus, or it can be a terminal associated with the target account information.
[0126] In practical implementation, when the Trojan virus email is not intercepted by the email gateway, the email handling information of the Trojan virus email is also required. The email handling information can be the current status information of the Trojan virus email, such as the email receiving status or the email not being received status.
[0127] Step S102: Determine whether the email processing information meets the preset email receiving conditions.
[0128] It should also be noted that the default email receiving condition is that the user has already received emails containing Trojan viruses, etc.
[0129] Step S103: When the email processing information meets the preset email receiving conditions, determine the target account information for receiving the Trojan virus email.
[0130] It should be noted that the target account information of Trojan virus emails includes the email account information of the recipient of the Trojan virus email.
[0131] In this embodiment, when the email processing information does not meet the preset email receiving conditions, the delivery account information of the Trojan virus email is determined and the delivery account information is added to the email blacklist so that the email interception device can intercept the email sent by the delivery account information according to the email blacklist; when the email processing information meets the preset email receiving conditions, the target account information for receiving the Trojan virus email is determined.
[0132] In practical implementation, alerts generated by security devices detect the delivery of malware-infected emails. The system first checks if the email gateway has blocked the email. If it has, no action is needed; otherwise, the relevant email account is identified based on the alert. Then, the malware-infected email is identified based on the alert information, and it's determined whether the user accepted the email. If not, the user is confirmed unharmed and notified not to open the email. If the email has been accepted, the user is asked if it has been opened. If not, the user is notified not to open the email. If the email has been opened, the system initiates a host handling process, which includes isolating the host, notifying technical personnel to perform on-site processing, deleting the email, removing the malware, and restoring service.
[0133] In this embodiment, when a Trojan virus email is not intercepted, the email handling information of the Trojan virus email is first obtained, and it is determined whether the email handling information meets the preset email receiving conditions. If the email handling information meets the preset email receiving conditions, the target account information for receiving the Trojan virus email is determined. Compared with the prior art, which does not process Trojan virus emails, this embodiment determines the target account information of the Trojan virus email when it is not intercepted and is received, thereby achieving accurate acquisition of the account information of the Trojan virus email and thus speeding up the handling efficiency of Trojan virus emails.
[0134] refer to Figure 4 , Figure 4 This is a flowchart illustrating the third embodiment of the email handling method based on Trojan viruses of the present invention.
[0135] Based on the first embodiment described above, in this embodiment, after step S40, the method further includes:
[0136] Step S401: Determine the domain name information and address information corresponding to the Trojan virus email.
[0137] In this embodiment, virus sample information can be obtained through an intrusion detection system, and then the virus sample information can be analyzed in conjunction with a sandbox to obtain virus feature information, including Trojan virus information, related domain names or IP addresses, etc.
[0138] Step S402: Determine a preset virus blocking strategy based on the domain name information, the address information, and the security linkage device.
[0139] It should also be noted that the preset virus blocking policy can be customized by the user, such as linking with the firewall to block related domains and IPs.
[0140] Step S403: Based on the preset virus blocking strategy, the Trojan virus email is handled in conjunction with the security linkage device.
[0141] It should be noted that, based on the preset virus blocking policy, the system uses security linkage devices to handle Trojan virus emails in a coordinated manner, generates Trojan virus logs based on the results of the coordinated handling of Trojan virus emails, determines the terminal host compromise information based on the Trojan virus logs, determines the preset host handling policy based on the terminal host compromise information, and isolates the terminal host according to the preset host handling policy.
[0142] In the specific implementation, the analysis of host compromise is based on the results of the coordinated handling of Trojan virus emails, combined with traffic, alarms, and terminal EDR logs. Host compromise analysis strategies include identifying communication traffic from domains or IPs that match those analyzed in the sandbox analysis, abnormal security operation alarms generated by the terminal EDR, and actions consistent with the sandbox virus analysis results. Following this, a preset host handling strategy is determined based on the host compromise analysis results. This strategy may include isolating the host and notifying technical personnel to perform on-site processing, delete emails, remove Trojans, and restore services. Finally, the terminal host is handled according to the preset host handling strategy, and the causes of the intrusion and shortcomings in data / service recovery are summarized and reviewed to improve overall security capabilities.
[0143] In this embodiment, the domain name and address information corresponding to the Trojan virus email are first determined. Then, a preset virus blocking strategy is determined based on the domain name, address information, and security linkage devices. Finally, the Trojan virus email is handled in conjunction with the security linkage devices based on the preset virus blocking strategy. Compared with the prior art, which can only manually handle Trojan virus emails, this embodiment can handle Trojan virus emails in conjunction with the preset virus blocking strategy and security linkage devices, thereby improving the processing efficiency of Trojan virus emails and enhancing the overall security capability.
[0144] Reference Figure 5 , Figure 5 This is a structural block diagram of the first embodiment of the email processing device based on Trojan viruses of the present invention.
[0145] like Figure 5 As shown, the email processing device based on Trojan viruses proposed in this embodiment of the invention includes:
[0146] The determination module 5001 is used to determine the target account information that receives the Trojan virus email when the Trojan virus email is not intercepted.
[0147] Understandably, a Trojan virus email is an email that carries a Trojan virus. Once a user opens this Trojan virus email, the terminal will be infected by the Trojan virus, which can then arbitrarily control the computer and perform illegal operations such as deleting, copying, and changing passwords.
[0148] It should be noted that the target account information of Trojan virus emails includes the email account information of the recipient of the Trojan virus email.
[0149] Furthermore, in order to accurately identify Trojan virus emails, before determining the target account information for receiving Trojan virus emails if they are not intercepted, it is necessary to obtain email alert information through security detection equipment. Then, based on the email alert information, the Trojan virus event is determined. After that, the Trojan virus event is analyzed to obtain Trojan virus infection information, and the Trojan virus email is identified based on the Trojan virus infection information.
[0150] It should also be understood that email alerts are virus alerts generated by security devices, which may include the discovery of Trojan virus delivery events or the discovery of other virus delivery events.
[0151] In practice, when a Trojan virus delivery event is discovered, it is necessary to analyze the event to obtain Trojan virus infection information. This information includes the specific delivery method of the Trojan virus, such as delivery via link or email. Based on this infection information, the Trojan virus email or link can then be identified.
[0152] In this embodiment, an event involving the delivery of a virus / Trojan email is detected through an alarm generated by a security device. The Trojan / Trojan event needs to be sent to the email gateway, which can intercept the email, obtain email interception information, and determine whether the email interception information meets preset interception conditions. If the email interception information does not meet the preset interception conditions, it is determined that the Trojan / Trojan email has not been intercepted; if the email interception information meets the preset interception conditions, an interception alarm is generated based on the email interception information and sent to the corresponding target management terminal.
[0153] It should be understood that the preset blocking condition is that the Trojan virus email is blocked. The email blocking information includes whether the email was blocked or not. The target management terminal can be a terminal managed by the person in charge of the Trojan virus, or it can be a terminal associated with the target account information.
[0154] In practical implementation, when the Trojan virus email is not intercepted by the email gateway, the email handling information of the Trojan virus email is also needed to determine whether the email handling information meets the preset email receiving conditions. If the email handling information does not meet the preset email receiving conditions, the delivery account information of the Trojan virus email is determined and added to the email blacklist so that the email interception device can intercept emails sent by the delivery account information according to the email blacklist. If the email handling information meets the preset email receiving conditions, the target account information for receiving the Trojan virus email is determined.
[0155] It should also be noted that the email handling information can include the current status of the malware email, such as whether the email has been received or not. The default email reception condition is that the user has already received the malware email.
[0156] In this embodiment, an alarm generated by the security device detects an event where a virus / Trojan email is delivered. First, it is determined whether the email gateway has blocked it. If the email gateway has already blocked it, no action is needed; otherwise, the relevant email account is identified based on the alarm. Then, based on the alarm information, the relevant virus / Trojan email is identified, and it is determined whether the user has accepted the email. If the user has not accepted it, it is confirmed that the user is not harmed, and the user is notified not to open the email. If the user has accepted the email, they are asked whether it has been opened. If not, the user is notified not to open the email. If the user has opened the email, the host processing procedure is initiated. The host processing procedure includes isolating the host, notifying technical personnel to perform on-site processing, deleting the email, removing the Trojan, and restoring services.
[0157] The acquisition module 5002 is used to acquire the virus characteristic information of the Trojan virus email based on the target account information.
[0158] Furthermore, in order to accurately obtain virus feature information, the processing method for obtaining virus feature information of Trojan virus emails based on target account information can be to extract virus sample information from Trojan virus emails based on target account information, and then analyze the virus sample information to obtain the virus feature information of Trojan virus emails.
[0159] It should also be understood that virus sample information can be part of the Trojan virus information in the Trojan virus email, and virus feature information can be information related to the Trojan virus, such as Trojan virus toxicity information, related domain names or IP addresses, etc.
[0160] In practice, the steps to analyze virus sample information and obtain virus characteristic information of Trojan virus emails can be as follows: obtain the login terminal information corresponding to the target account information, then determine the security detection device based on the login terminal information, and analyze the virus sample information through the security detection device to obtain the virus characteristic information of Trojan virus emails.
[0161] It should be noted that the login terminal information refers to the terminal device that is logged in when receiving the Trojan virus email, and the security detection device refers to the security devices present on the currently logged-in terminal device, such as intrusion detection systems or sandbox devices.
[0162] In this embodiment, virus sample information can be obtained through an intrusion detection system, and then the virus sample information can be analyzed in conjunction with a sandbox to obtain virus feature information, including Trojan virus information, related domain names or IP addresses, etc.
[0163] The determining module 5001 is also used to determine the security linkage device based on the virus characteristic information.
[0164] Furthermore, in order to improve the processing efficiency of Trojan virus emails, the processing method for determining security linkage devices based on virus feature information can be as follows: analyze the virus feature information to obtain Trojan virus information, determine whether the Trojan virus information meets the preset virus conditions, and when the Trojan virus information meets the preset virus conditions, determine the Trojan virus level based on the Trojan virus information, and then determine the security linkage device based on the Trojan virus level.
[0165] It should also be understood that the preset virus conditions are that Trojan virus emails are malicious emails, and the Trojan virus information includes information about whether the Trojan virus is malicious or not. The security linkage device can be a firewall or other security device.
[0166] In practice, if the Trojan virus email is not malicious, the process ends; if the Trojan virus email is malicious, the security linkage device can be a firewall, etc.
[0167] The processing module 5003 is used to perform coordinated processing of the Trojan virus email through the security linkage device.
[0168] Furthermore, in order to improve the efficiency of handling Trojan virus emails, the method of handling Trojan virus emails in conjunction with security linkage devices can be as follows: determine the domain name information and address information corresponding to the Trojan virus email, then determine the preset virus blocking policy based on the domain name information, address information and security linkage devices, and then handle the Trojan virus emails in conjunction with the security linkage devices based on the preset virus blocking policy.
[0169] It should also be noted that the preset virus blocking policy can be customized by the user, such as linking with the firewall to block related domains and IPs.
[0170] In this embodiment, based on a preset virus blocking strategy, the security linkage device is used to handle Trojan virus emails in a coordinated manner. A Trojan virus log is generated based on the results of the coordinated handling of the Trojan virus emails. The Trojan virus log is used to determine the terminal host compromise information. Based on the terminal host compromise information, a preset host handling strategy is determined. The terminal host is then isolated and handled according to the preset host handling strategy.
[0171] In the specific implementation, the analysis of host compromise is based on the results of the coordinated handling of Trojan virus emails, combined with traffic, alarms, and terminal EDR logs. Host compromise analysis strategies include identifying communication traffic from domains or IPs that match those analyzed in the sandbox analysis, abnormal security operation alarms generated by the terminal EDR, and actions consistent with the sandbox virus analysis results. Following this, a preset host handling strategy is determined based on the host compromise analysis results. This strategy may include isolating the host and notifying technical personnel to perform on-site processing, delete emails, remove Trojans, and restore services. Finally, the terminal host is handled according to the preset host handling strategy, and the causes of the intrusion and shortcomings in data / service recovery are summarized and reviewed to improve overall security capabilities.
[0172] In this embodiment, when a Trojan virus email is not intercepted, the target account information receiving the email is first determined. Then, the virus signature information of the email is obtained based on the target account information, and a security linkage device is determined based on the virus signature information. The email is then handled in a coordinated manner through this security linkage device. Compared to existing technologies that require manual detection and handling of Trojan virus emails, this embodiment determines a security linkage device based on the corresponding virus signature information when a Trojan virus email is detected, and then handles the email in a coordinated manner through this device, thereby improving the efficiency of Trojan virus email handling.
[0173] Furthermore, the email processing device based on Trojan viruses also includes a determination module;
[0174] The determination module is used to obtain the email handling information of the Trojan virus email;
[0175] The determination module is also used to determine whether the email processing information meets the preset email receiving conditions;
[0176] The determination module is also used to perform the operation of determining the target account information for receiving the Trojan virus email when the email processing information meets the preset email receiving conditions.
[0177] Furthermore, the acquisition module 5002 is also used to extract virus sample information from the Trojan virus email based on the target account information;
[0178] The acquisition module 5002 is also used to analyze the virus sample information to obtain the virus characteristic information of the Trojan virus email.
[0179] Furthermore, the determining module 5001 is also used to analyze the virus feature information to obtain Trojan virus information;
[0180] The determining module 5001 is also used to determine the security linkage device based on the Trojan virus information.
[0181] Furthermore, the processing module 5003 is also used to determine the domain name information and address information corresponding to the Trojan virus email;
[0182] The processing module 5003 is also used to determine a preset virus blocking strategy based on the domain name information, the address information and the security linkage device;
[0183] The processing module 5003 is also used to perform coordinated processing of the Trojan virus emails through the security linkage device based on the preset virus blocking strategy.
[0184] Furthermore, the processing module 5003 is also used to generate a Trojan virus log based on the linkage processing result of the Trojan virus email;
[0185] The processing module 5003 is also used to determine terminal host compromise information based on the Trojan virus log;
[0186] The processing module 5003 is also used to determine a preset host processing strategy based on the terminal host compromise information;
[0187] The processing module 5003 is also used to isolate and process the terminal host according to the preset host processing strategy.
[0188] Other embodiments or specific implementations of the email processing device based on Trojan viruses of the present invention can be referred to the above-described method embodiments, and will not be repeated here.
[0189] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.
[0190] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0191] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as read-only memory / random access memory, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0192] The above are merely preferred embodiments of the present invention and do not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A method for handling emails based on Trojan viruses, characterized in that, The method for handling emails based on Trojan viruses includes the following steps: When the Trojan virus email is not blocked, determine the target account information that received the Trojan virus email; Obtain the virus signature information of the Trojan virus email based on the target account information; The security linkage device is determined based on the virus feature information. The security linkage device is determined based on the Trojan virus level when the Trojan virus information in the virus feature information meets the preset virus conditions. The aforementioned security linkage device enables coordinated handling of the Trojan virus emails.
2. The method as described in claim 1, characterized in that, Before the step of determining the target account information for receiving the Trojan virus email when it is not intercepted, the method further includes: Email alerts are obtained through security testing equipment; The Trojan virus incident was identified based on the email alert information. The Trojan virus event was analyzed to obtain Trojan virus infection information; The Trojan virus email was identified based on the Trojan virus infection information.
3. The method as described in claim 2, characterized in that, After the step of determining the Trojan virus email based on the Trojan virus infection information, the method further includes: The emails containing the Trojan virus are intercepted through an email gateway device, and email interception information is obtained. Determine whether the email blocking information meets the preset blocking conditions; If the email interception information does not meet the preset interception conditions, it is determined that the Trojan virus email has not been intercepted.
4. The method as described in claim 3, characterized in that, After the step of determining whether the email blocking information meets the preset blocking conditions, the method further includes: When the email interception information meets the preset interception conditions, an interception alarm message is generated based on the email interception information; The interception alarm information is sent to the corresponding target management terminal.
5. The method as described in claim 1, characterized in that, Before the step of determining the target account information for receiving the Trojan virus email, the method further includes: Obtain the email handling information for the Trojan virus email; Determine whether the email processing information meets the preset email receiving conditions; When the email processing information meets the preset email receiving conditions, the step of determining the target account information for receiving the Trojan virus email is executed.
6. The method as described in claim 5, characterized in that, After the step of determining whether the email processing information meets the preset email receiving conditions, the method further includes: When the email processing information does not meet the preset email receiving conditions, the delivery account information of the Trojan virus email is determined; The delivery account information is added to the email blacklist so that the email blocking device can block emails sent by the delivery account information based on the email blacklist.
7. The method as described in claim 1, characterized in that, The step of obtaining the virus signature information of the Trojan virus email based on the target account information includes: Extract virus sample information from the Trojan virus email based on the target account information; The virus sample information is analyzed to obtain the virus characteristic information of the Trojan virus email.
8. The method as described in claim 7, characterized in that, The step of analyzing the virus sample information to obtain the virus characteristic information of the Trojan virus email includes: Obtain the login terminal information corresponding to the target account information; The security detection device is determined based on the login terminal information; The virus sample information is analyzed by the security detection device to obtain the virus characteristic information of the Trojan virus email.
9. The method according to any one of claims 1-8, characterized in that, The step of determining the security linkage device according to the virus characteristic information includes: Analyze the virus characteristic information to obtain Trojan virus information; Determine the security linkage device according to the Trojan virus information.
10. The method as described in claim 9, characterized in that, The step of determining the security linkage device according to the Trojan virus information includes: Judge whether the Trojan virus information meets the preset virus conditions; When the Trojan virus information meets the preset virus conditions, determine the Trojan virus level according to the Trojan virus information; Determine the security linkage device according to the Trojan virus level.
11. The method according to any one of claims 1-8, characterized in that, The step of performing linkage disposal on the Trojan virus email through the security linkage device includes: Determine the domain name information and address information corresponding to the Trojan virus email; Determine the preset virus blocking policy according to the domain name information, the address information and the security linkage device; Perform linkage disposal on the Trojan virus email through the security linkage device based on the preset virus blocking policy.
12. The method of claim 11, characterized in that, After the step of performing linkage disposal on the Trojan virus email through the security linkage device based on the preset virus blocking policy, it further includes: Generate a Trojan virus log according to the linkage disposal result of the Trojan virus email; Determine the information on the compromised terminal host according to the Trojan virus log; Determine the preset host disposal policy according to the information on the compromised terminal host; Isolate the terminal host according to the preset host disposal policy.
13. An email processing device based on a Trojan virus, characterized in that, The email disposal device based on Trojan virus includes: A determination module, configured to determine the target account information for receiving the Trojan virus email when the Trojan virus email is not intercepted; An acquisition module, configured to obtain the virus characteristic information of the Trojan virus email according to the target account information; The determination module is further configured to determine the security linkage device according to the virus characteristic information, and the security linkage device is determined according to the Trojan virus level when the Trojan virus information in the virus characteristic information meets the preset virus conditions; A disposal module, configured to perform linkage disposal on the Trojan virus email through the security linkage device.
14. The apparatus as claimed in claim 13, characterized in that, The email disposal device based on Trojan virus further includes a determination module; The determination module is configured to obtain the email disposal information of the Trojan virus email; The determination module is further configured to judge whether the email disposal information meets the preset email receiving conditions; The determination module is further configured to perform the operation of determining the target account information for receiving the Trojan virus email when the email disposal information meets the preset email receiving conditions.
15. The apparatus as claimed in claim 13, characterized in that, The acquisition module is further configured to extract virus sample information from the Trojan virus email according to the target account information; The acquisition module is further configured to analyze the virus sample information to obtain the virus characteristic information of the Trojan virus email.
16. The apparatus according to any one of claims 13-15, characterized in that, The determination module is further configured to analyze the virus characteristic information to obtain Trojan virus information; The determination module is further configured to determine the security linkage device according to the Trojan virus information.
17. The apparatus according to any one of claims 13-15, characterized in that, The disposal module is further configured to determine the domain name information and address information corresponding to the Trojan virus email; The processing module is also used to determine a preset virus blocking strategy based on the domain name information, the address information, and the security linkage device; The processing module is also used to process the Trojan virus emails in conjunction with the security linkage device based on the preset virus blocking strategy.
18. The apparatus as claimed in claim 17, characterized in that, The processing module is also used to generate a Trojan virus log based on the linkage processing results of the Trojan virus email; The processing module is also used to determine terminal host compromise information based on the Trojan virus log; The processing module is also used to determine a preset host processing strategy based on the terminal host compromise information; The processing module is also used to isolate and process the terminal host according to the preset host processing strategy.
19. An email processing device based on a Trojan virus, characterized in that, The Trojan virus-based email processing device includes: a memory, a processor, and a Trojan virus-based email processing program stored in the memory and executable on the processor, wherein the Trojan virus-based email processing program is configured to implement the Trojan virus-based email processing method as described in any one of claims 1 to 12.
20. A storage medium, characterized in that, The storage medium stores an email handling program based on a Trojan virus, which, when executed by a processor, implements the steps of the email handling method based on a Trojan virus as described in any one of claims 1 to 12.
Citation Information
Patent Citations
Security arrangement and automatic response method
CN115208699A