A security detection method for abnormal startup of a computer

By reading and parsing the priority settings of the startup device, analyzing the boot sector data and startup delays, and evaluating and adjusting the startup sequence, it solves the abnormal problems that may occur during the startup process of the computer system, improves the reliability and efficiency of system startup, and enhances user experience and system security.

CN119475351BActive Publication Date: 2025-06-10JIANGXI MODERN POLYTECHNIC COLLEGE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411556606.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-04
Publication Date
2025-06-10
Estimated Expiration
2044-11-04

AI Technical Summary

Technical Problem

The computer system may have abnormal behavior or abnormal startup methods during startup, resulting in the system failure or the startup time becomes longer, affecting the user experience and system security.

Method used

Read and parse the priority settings of the startup device through the system API interface, analyze the corruption of the boot sector data and the delay of the startup process, evaluate the accuracy of the startup sequence, and adjust the startup sequence according to the evaluation results to ensure that the devices containing the operating system are started first.

Benefits of technology

It significantly improves the reliability and efficiency of system startup, reduces startup time, enhances user experience, prevents potential security threats, and ensures the integrity and security of the computer system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119475351B_ABST
    Figure CN119475351B_ABST
Patent Text Reader

Abstract

The present invention discloses a security detection method for abnormal startup of a computer, which relates to the field of computer technology; by reading the current startup device priority setting through the system API interface, parsing the startup sequence data, judging the damage condition of the boot sector data and the delay condition during the startup process, comprehensively evaluating the accuracy of the startup sequence, classifying and adjusting the startup sequence according to the evaluation result, so as to optimize the system startup sequence, ensure that the operating system device starts up first, and finally display the new startup sequence for the user to confirm by further analyzing and generating an adjustment strategy, which can not only significantly improve the reliability and efficiency of system startup, but also reduce the startup time, enhance the user experience, and prevent potential system startup problems at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and particularly to a security detection method for abnormal startup of a computer. Background Art

[0002] Security detection of abnormal startup of a computer refers to monitoring and identifying whether there are abnormal behaviors or abnormal startup methods during the startup process of a computer system through technical means. These abnormalities include, but are not limited to, unauthorized hardware or firmware modifications, changes in the startup sequence, tampering with the bootloader, and injection of malware. The detection aims to timely discover potential security threats, prevent malicious attackers from exploiting vulnerabilities during the startup process for intrusion, thereby protecting the integrity and security of the computer system. When monitoring the startup sequence, the system administrator or user can specify the startup sequence in the BIOS / UEFI settings, usually with the hard disk first, followed by the optical drive, USB device, etc. However, if the user sets the wrong startup device priority in the BIOS / UEFI, setting a USB device or optical drive without an operating system as the first startup device instead of the hard disk containing the operating system. The computer may attempt to start from the data hard disk instead of the operating system hard disk, resulting in a startup failure. At the same time, if the system configuration startup sequence is incorrect, it may cause the computer to attempt to start from multiple invalid devices each time it starts, and finally find the correct startup device. Each startup process will be significantly extended, resulting in a longer system startup time and a worse user experience. Summary of the Invention

[0003] The purpose of the present invention is to provide a security detection method for abnormal startup of a computer to solve the deficiencies in the background art.

[0004] To achieve the above purpose, the present invention provides the following technical solution: A security detection method for abnormal startup of a computer, comprising the following steps:

[0005] S1: Use the system API interface to read the current startup device priority settings, parse the read startup sequence data, and determine the type and priority of each device;

[0006] S2: Check the startup devices according to the preset rules and priorities, judge the damage condition of the boot sector data of the startup devices, evaluate the health degree of the boot sector; and analyze the delay situation during the startup process, evaluate the stability of the startup process;

[0007] S3: Comprehensively analyze the health degree of the boot sector and the stability of the startup process, and evaluate the accuracy of the startup sequence;

[0008] S4: Based on the evaluation result of the accuracy of the startup sequence, divide it into three cases: accurate startup sequence, possibly accurate startup sequence, and inaccurate startup sequence, and adjust the startup sequence according to the division result;

[0009] S5: For the case of a possibly accurate startup sequence, determine the device containing the operating system according to each startup device and its priority in the current startup sequence, and adjust its priority;

[0010] S6: Further analyze the accuracy of the adjusted startup sequence, generate an adjustment strategy according to the analysis result, and generate a new startup sequence through the adjustment strategy for display to the user for confirmation.

[0011] Preferably, in S2, generate a boot sector data damage index according to the damage condition of the boot sector data of the startup device, and evaluate the health of the boot sector according to the boot sector data damage index. The method for obtaining the boot sector data damage index is as follows:

[0012] Divide the boot sector data into data blocks, each data block containing n bytes. Generate Reed-Solomon codes according to the boot sector data blocks, including data symbols and parity symbols. The generating polynomial G(x) is used for encoding. The generating polynomial of the boot sector data is expressed as: G(x) = (x - α1)(x - α2)...(x - α2t); where α is a primitive element of the finite field, and t is the number of corrected errors; the product of the boot sector data polynomial D(x) and the generating polynomial G(x) plus the parity symbol C(x) gives the encoded data polynomial E(x), and the expression is: E(x) = D(x) * x 2t + C(x); Calculate the parity polynomial S(x) of the received polynomial R(x) to obtain the parity value, and the expression is: S(x) = R(x) mod G(x). Calculate the error polynomial E(x) according to the parity value S(x), detect the error position and quantity, use the Berlekamp-Massey algorithm to correct the errors, calculate the number of uncorrectable errors e, and generate the boot sector data damage index. The expression is: In the formula, Dc is the boot sector data damage index.

[0013] Preferably, compare the obtained boot sector data damage index with a pre-set reference threshold of the boot sector data damage index. If the boot sector data damage index is greater than or equal to the pre-set reference threshold of the boot sector data damage index, the damage condition of the boot sector data is serious and the health of the boot sector is low. At this time, generate a boot sector abnormal signal; if the boot sector data damage index is less than the pre-set reference threshold of the boot sector data damage index, the damage condition of the boot sector data is slight and the health of the boot sector is high. At this time, generate a boot sector normal signal.

[0014] Preferably, in S2, analyze the delay situation during the startup process and generate a startup delay index, and evaluate the stability of the startup process according to the startup delay index. The method for obtaining the startup delay index is as follows:

[0015] Obtain the delay data and related features during the startup process and establish a data matrix as X, where each row represents a startup process and each column represents a feature. Perform standardization processing on the data. The standardized data matrix is Z, and calculate the covariance matrix: Among them, C is an m×m covariance matrix. Perform eigenvalue decomposition on the covariance matrix C to obtain eigenvalues λi and corresponding eigenvectors vi. Select the first k largest eigenvalues and their corresponding eigenvectors to form a principal component matrix W: Project the data into the principal component space, and the expression is: T = ZW; where W is the matrix of the first k selected eigenvectors. Calculate the startup delay index DQ according to the principal component scores, and the expression is: DQ = β*T; in the formula, β is the weight vector.

[0016] Preferably, compare the obtained startup delay index with a preset startup delay index reference threshold. If the startup delay index is greater than or equal to the preset startup delay index reference threshold, a startup delay signal is generated at this time; if the startup delay index is less than the preset startup delay index reference threshold, no startup delay signal is generated at this time.

[0017] Preferably, convert the boot sector data corruption index and the startup delay index into a first eigenvector, and use the first eigenvector as the input of a machine learning model. The machine learning model takes the accuracy value label of predicting the startup order for each group of the first eigenvectors as the prediction target, and takes minimizing the sum of the prediction errors of the accuracy value labels for all startup orders as the training target. Train the machine learning model until the sum of the prediction errors reaches convergence and then stop the model training. Determine the accuracy value of the startup order according to the model output result, where the machine learning model is a polynomial regression model.

[0018] Preferably, in S4, according to the accuracy evaluation result of the startup order, divide it into the situation where the startup order is accurate, the situation where the startup order may be accurate, and the situation where the startup order is inaccurate. Specifically:

[0019] Compare the obtained accuracy value of the startup order with a gradient standard threshold. The gradient standard threshold includes a first standard threshold and a second standard threshold, and the first standard threshold is less than the second standard threshold. Compare the accuracy value of the startup order with the first standard threshold and the second standard threshold respectively;

[0020] If the accuracy value of the startup sequence is greater than the second standard threshold, it indicates that the startup sequence has high accuracy. It is classified as an accurate startup sequence case, and an accurate startup sequence signal is generated. There is no need to adjust, and the existing startup sequence is maintained. The system startup sequence is reasonable and efficient, and no change is required;

[0021] If the accuracy value of the startup sequence is greater than or equal to the first standard threshold and less than or equal to the second standard threshold, the startup sequence accuracy is medium. It is classified as a possibly accurate startup sequence case, and a possibly accurate startup sequence signal is generated. The user manually checks the priority settings of the startup devices;

[0022] If the accuracy value of the startup sequence is less than the first standard threshold, the startup sequence accuracy is low. It is classified as an inaccurate startup sequence case, and an inaccurate startup sequence signal is generated to adjust the startup sequence.

[0023] Preferably, in S5, for the possibly accurate startup sequence case, according to each startup device and its priority in the current startup sequence, its priority is adjusted. Specifically:

[0024] Read the startup sequence in the BIOS / UEFI settings and list all devices and their current priorities. Check each device in the startup sequence to determine the device containing the operating system. Read the boot sector of each device, check the boot record, adjust the startup sequence to ensure that the device containing the operating system has the highest priority, and write the adjusted startup sequence back to the BIOS / UEFI settings.

[0025] Preferably, in S6, further analyze the accuracy of the adjusted startup sequence, and generate an adjustment strategy according to the analysis result. Specifically:

[0026] Further analyze the accuracy of the adjusted startup sequence. When the startup sequence is a possibly accurate case, that is, the accuracy value of the startup sequence generated within a fixed time period is greater than or equal to the first standard threshold and less than or equal to the second standard threshold, collect the accuracy values of the startup sequences generated within the subsequent fixed time period that are greater than or equal to the first standard threshold and less than or equal to the second standard threshold, and establish a data set. Calculate the mean and standard deviation of the data set, analyze it to generate an adjustment strategy, and display a new startup sequence generated by the adjustment strategy to the user for confirmation.

[0027] Preferably, if the mean of the accuracy values in the data set is greater than or equal to the reference threshold of the mean of the accuracy values, and the standard deviation of the accuracy values is less than the reference threshold of the standard deviation of the accuracy values, no warning signal is generated at this time, and the current startup sequence is maintained, and the user is prompted that the current startup sequence is stable and accurate;

[0028] If the mean value of the accuracy value is greater than or equal to the reference threshold of the mean value of the accuracy value, and the standard deviation of the accuracy value is greater than or equal to the reference threshold of the standard deviation of the accuracy value, a third-level warning signal is generated at this time, and it is recommended that the user make minor adjustments to reduce the fluctuation of the startup sequence and improve stability;

[0029] If the mean value of the accuracy value is less than the reference threshold of the mean value of the accuracy value, and the standard deviation of the accuracy value is greater than or equal to the reference threshold of the standard deviation of the accuracy value, a second-level warning signal is generated at this time, and the user makes significant adjustments to improve the accuracy of the startup sequence;

[0030] If the mean value of the accuracy value is less than the reference threshold of the mean value of the accuracy value, and the standard deviation of the accuracy value is less than the reference threshold of the standard deviation of the accuracy value, a first-level warning signal is generated at this time, and the user conducts a comprehensive inspection and adjustment to improve the accuracy of the startup sequence.

[0031] In the above technical solution, the technical effects and advantages provided by the present invention are as follows:

[0032] 1. By using the system API interface to read and analyze the startup device priority settings, the present invention comprehensively analyzes the boot sector data of the startup device and the delay situation during the startup process, and evaluates the accuracy of the startup sequence. Through the comprehensive evaluation of the health of the boot sector and the stability of the startup process, a scientific adjustment strategy is formulated to ensure that the device containing the operating system in the startup device starts first. It can not only significantly improve the reliability and efficiency of system startup, reduce startup time, improve the user experience, but also prevent and detect potential security threats, and ensure the integrity and security of the computer system.

[0033] 2. By introducing advanced algorithms such as Reed-Solomon coding and principal component analysis (PCA), the present invention realizes the precise quantification of the damage of the boot sector data and the startup delay, generates the accuracy value of the startup sequence, and classifies and optimizes the startup sequence according to the set threshold. The possible accurate startup sequence is refined and analyzed and optimized to further improve the stability of system startup. Finally, the adjusted startup sequence is displayed through an intuitive user interface for the user to confirm, ensuring the transparency and controllability of the adjustment process. It not only optimizes the system startup process, but also improves the user's trust and satisfaction. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings.

[0035] Figure 1 This is the flowchart of the method of the present invention. Specific embodiments

[0036] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0037] Embodiment, please refer to Figure 1 As shown, a security detection method for abnormal startup of a computer in this embodiment includes the following steps:

[0038] S1: Use the system API interface to read the current startup device priority settings, parse the read startup sequence data, and determine the type and priority of each device;

[0039] S2: Check the startup devices according to the preset rules and priorities, judge the damage condition of the boot sector data of the startup devices, and evaluate the health degree of the boot sector; and analyze the delay condition during the startup process to evaluate the stability of the startup process;

[0040] S3: Comprehensively analyze the health degree of the boot sector and the stability of the startup process to evaluate the accuracy of the startup sequence;

[0041] S4: According to the evaluation result of the accuracy of the startup sequence, divide it into the case where the startup sequence is accurate, the case where the startup sequence may be accurate, and the case where the startup sequence is inaccurate, and adjust the startup sequence according to the division result;

[0042] S5: For the case where the startup sequence may be accurate, determine the device containing the operating system according to each startup device and its priority in the current startup sequence, and adjust its priority;

[0043] S6: Further analyze the accuracy of the adjusted startup sequence, generate an adjustment strategy according to the analysis result, and generate a new startup sequence through the adjustment strategy to display to the user for the user to confirm.

[0044] Among them, in S1, using the system API interface to read the current startup device priority settings, parsing the read startup sequence data, and determining the type and priority of each device mainly includes:

[0045] First, the user needs to restart the computer and press a specific key (usually F2, F10, Delete, or Esc) during the startup process to enter the BIOS or UEFI setup interface. This step is to ensure that the system can read the boot order data from the BIOS / UEFI.

[0046] Use the API interface provided by the system to read the current boot device priority settings. For example, in the Windows system, the WMI (Windows Management Instrumentation) interface can be used to obtain the boot order data; while in the Linux system, the efibootmgr tool can be used to obtain the EFI boot entries. The data read is usually a list or string representing the order of boot devices.

[0047] Parse the read boot order data and convert it into a usable list format. During the parsing process, it is necessary to determine the identifier of each device and its corresponding boot priority. For example, each device in the list may contain the device ID and its position (priority) in the boot order.

[0048] Based on the device ID or name, identify and determine the type of each device, such as hard disk, USB device, or optical drive, etc. Pre-defined mappings or rules can be used to identify the device type. For example, a device ID starting with "HD" may indicate a hard disk, and a device ID starting with "USB" indicates a USB device. Identifying the device type helps to understand the role of each device during the startup process.

[0049] After parsing the boot order data, the result can be printed for inspection or saved to a file for subsequent analysis and reference. The parsing result usually includes information such as the ID, type, and priority of each device, and this information is very important for subsequent boot order adjustment and optimization.

[0050] S2: Check the boot devices according to the preset rules and priorities, judge the damage condition of the boot sector data of the boot devices, evaluate the health of the boot sector; and analyze the delay situation during the startup process to evaluate the stability of the startup process.

[0051] The steps for checking the startup device according to preset rules and priorities include: First, read and parse the current startup sequence data to determine the type and priority of each device; Second, perform checks according to the preset rules, including verifying the existence and validity of each startup device, ensuring that the boot sector is healthy, the boot files are complete, and the device type meets expectations; Finally, analyze whether there are redundant configurations in the startup sequence and delays during the startup process, and evaluate the stability and efficiency of the startup process. This process is implemented through the system API interface or command-line tools to ensure accurate and comprehensive startup sequence data. It can not only effectively improve the reliability and efficiency of system startup. By verifying the validity and priority configuration of the startup device, startup failures, system delays, and poor user experience caused by incorrect settings can be avoided. Detect and exclude redundant device configurations to ensure that the operating system device starts first, thereby shortening the system startup time. In addition, identifying and fixing problems with the boot sector or boot files in advance helps prevent potential system crashes and data loss, ensuring the security and stability of the system.

[0052] Generate a boot sector data corruption index based on the corruption situation of the boot sector data of the startup device, and evaluate the health of the boot sector according to the boot sector data corruption index. The method for obtaining the boot sector data corruption index is as follows:

[0053] Divide the boot sector data into data blocks, each data block containing n bytes. Generate Reed-Solomon codes based on the boot sector data blocks, including data symbols and parity symbols. The generating polynomial G(x) is used for encoding. The generating polynomial of the boot sector data is expressed as: G(x) = (x - α1)(x - α2)...(x - α2t); where α is a primitive element of the finite field, and t is the number of errors to be corrected;

[0054] The product of the boot sector data polynomial D(x) and the generating polynomial G(x) plus the parity symbol C(x) gives the encoded data polynomial E(x), and the expression is: E(x) = D(x) * x 2t + C(x); Calculate the parity polynomial S(x) of the received polynomial R(x) to obtain the parity value, and the expression is: S(x) = R(x) mod G(x). Calculate the error polynomial E(x) according to the parity value S(x), detect the error position and quantity, use the Berlekamp-Massey algorithm to correct the errors, calculate the number of errors e that cannot be corrected, and generate the boot sector data corruption index. The expression is: In the formula, Dc is the boot sector data corruption index.

[0055] Compare the obtained boot sector data corruption index with the pre-set reference threshold of the boot sector data corruption index. If the boot sector data corruption index is greater than or equal to the pre-set reference threshold of the boot sector data corruption index, it indicates that the corruption of the boot sector data is serious and the health of the boot sector is low. At this time, a boot sector anomaly signal is generated. If the boot sector data corruption index is less than the pre-set reference threshold of the boot sector data corruption index, it indicates that the corruption of the boot sector data is minor and the health of the boot sector is high. At this time, a boot sector normal signal is generated.

[0056] The larger the boot sector data corruption index, the more serious the corruption of the boot sector data. This index quantifies the degree of data corruption and can intuitively reflect the proportion of the boot sector damaged by evaluating the number of uncorrectable errors. If the corruption index is close to 100%, it means that most of the boot sector data has been damaged and cannot be repaired.

[0057] The larger the boot sector data corruption index, the worse the health of the boot sector. A healthy boot sector should have no or very few uncorrectable errors. If the corruption index is low (close to 0%), it indicates that the boot sector data is relatively intact, with only a small amount or no data errors, indicating that the health of the boot sector is good.

[0058] By monitoring and calculating the boot sector data corruption index, the health status of the boot sector can be identified and evaluated in a timely manner, and appropriate repair or preventive measures can be taken to ensure the stable operation of the system. If the corruption index is high, it is recommended to perform data backup, boot sector repair, or replace the storage device to avoid problems such as system startup failure or data loss.

[0059] Analyze the delay situation during the startup process and generate a startup delay index. Evaluate the stability of the startup process based on the startup delay index. The method for obtaining the startup delay index is as follows:

[0060] Obtain the delay data and related features (such as the startup time of each device, device type, priority, etc.) during the startup process and establish a data matrix as X, where each row represents a startup process and each column represents a feature. Standardize the data so that the mean of each feature is 0 and the variance is 1. The standardized data matrix is Z, and the expression is: where μj and σj are the mean and standard deviation of the jth feature respectively, and calculate the covariance matrix: Among them, C is an m×m covariance matrix, which reflects the linear relationship between various features. The eigenvalue decomposition of the covariance matrix C is performed to obtain the eigenvalues λi and the corresponding eigenvectors vi. The decomposition expression is: Cvi = λivi; where λi is the i-th eigenvalue and vi is the corresponding eigenvector. The first k largest eigenvalues and their corresponding eigenvectors are selected to form the principal component matrix W: The data is projected onto the principal component space, and the expression is: T = ZW; where W is the matrix of the first k selected eigenvectors. The startup delay index DQ is calculated based on the principal component scores, and the expression is: DQ = β*T; β is the weight vector, which can be determined according to the variance contribution rate of the principal components or through a regression model.

[0061] The obtained startup delay index is compared with a pre-set startup delay index reference threshold. If the startup delay index is greater than or equal to the pre-set startup delay index reference threshold, it indicates that the delay situation during startup is relatively obvious, and at this time, a startup delay signal is generated; if the startup delay index is less than the pre-set startup delay index reference threshold, it indicates that the delay situation during startup is not obvious, and at this time, no startup delay signal is generated.

[0062] The larger the startup delay index, the more serious the delay situation during startup. The startup delay index is a quantitative indicator obtained by analyzing various delay factors during startup. A higher startup delay index indicates that the system encounters more delay problems during startup, such as a long recognition time for startup devices, an overly long system initialization time, or too much time for loading programs.

[0063] When the startup delay index increases, users will experience a significantly longer system startup time. This may be caused by improper startup sequence settings, a decline in the performance of hardware devices, or non-optimized system configurations. Such delays not only affect the user experience but may also cause inconvenience and frustration to users while waiting for the system to start up.

[0064] By monitoring and analyzing the startup delay index, system administrators can timely discover and diagnose problems during startup, and take corresponding optimization measures, such as adjusting the startup sequence, replacing aging devices, or optimizing system configurations, so as to improve the system startup speed and enhance the overall user experience and system performance.

[0065] Here, it should be noted that through the principal component analysis method, it is possible to effectively reduce the dimension and extract the main features affecting the delay during the startup process, and generate a startup delay index. First, standardize the collected startup delay data, then calculate the covariance matrix of the data and perform eigenvalue decomposition, and select the first few main eigenvectors as the principal components. Next, project the standardized data into the principal component space to obtain the principal component scores. Finally, calculate the startup delay index based on the principal component scores and the weight vector. This method can not only reduce the data dimension and improve the calculation efficiency, but also accurately evaluate the startup delay situation by selecting the most representative principal components. The generated startup delay index can quantify the delay degree of the startup process and help evaluate the stability of the startup process.

[0066] S3: Comprehensively analyze the health of the boot sector and the stability of the startup process to evaluate the accuracy of the startup sequence.

[0067] Convert the boot sector data corruption index and the startup delay index into the first eigenvector, and use the first eigenvector as the input of the machine learning model. The machine learning model takes predicting the accuracy value label of the startup sequence for each group of the first eigenvectors as the prediction target, and takes minimizing the sum of the prediction errors of the accuracy value labels of all startup sequences as the training target. Train the machine learning model until the sum of the prediction errors reaches convergence and then stop the model training. Determine the accuracy value of the startup sequence according to the model output result, where the machine learning model is a polynomial regression model.

[0068] The method for obtaining the accuracy value of the startup sequence is: obtain the corresponding function expression from the first eigenvector training data of the trained machine learning model: CR = f 1 (D c , QD); in the formula, f 1 is the output function of the model, Dc is the boot sector data corruption index, QD is the startup delay index, and CR is the accuracy value of the startup sequence.

[0069] S4: According to the evaluation result of the accuracy of the startup sequence, divide it into the situation where the startup sequence is accurate, the situation where the startup sequence may be accurate, and the situation where the startup sequence is inaccurate, and adjust the startup sequence according to the division result.

[0070] Compare the obtained accuracy value of the startup sequence with the gradient standard thresholds. The gradient standard thresholds include the first standard threshold and the second standard threshold, and the first standard threshold is less than the second standard threshold. Compare the accuracy value of the startup sequence with the first standard threshold and the second standard threshold respectively;

[0071] If the accuracy value of the startup sequence is greater than the second standard threshold, it indicates a high accuracy of the startup sequence. It is classified as a case of accurate startup sequence and an accurate startup sequence signal is generated. No adjustment is required, and the existing startup sequence is maintained. The system startup sequence is reasonable and efficient and does not need to be changed;

[0072] If the accuracy value of the startup sequence is greater than or equal to the first standard threshold and less than or equal to the second standard threshold, it indicates a medium accuracy of the startup sequence. It is classified as a case of possibly accurate startup sequence and a possibly accurate startup sequence signal is generated. It is recommended that the user perform a manual check or provide optimization suggestions. The startup sequence is basically reasonable, but there may be room for optimization. It is recommended that the user check the priority settings of the startup devices to ensure that key devices (such as the hard disk containing the operating system) are in the front row and secondary devices (such as USB, optical drive) are in the back row;

[0073] If the accuracy value of the startup sequence is less than the first standard threshold, it indicates a low accuracy of the startup sequence. It is classified as a case of inaccurate startup sequence and an inaccurate startup sequence signal is generated, and manual and automatic adjustments are made to it.

[0074] Automatic adjustment: The startup sequence or prompt the user to make manual adjustments. Rearrange the priorities of the startup devices to ensure that the most important device (such as the operating system hard disk) starts first, and remove or lower the priorities of invalid or redundant devices.

[0075] Manual adjustment: Provide specific adjustment suggestions, such as setting the hard disk as the first startup device in the BIOS to ensure that the priorities of USB devices and optical drives are lower. The current startup sequence seriously affects the system startup efficiency and needs to be adjusted immediately to improve the startup speed and stability.

[0076] S5: For the case of possibly accurate startup sequence, determine the device containing the operating system according to each startup device and its priority in the current startup sequence, and adjust its priority.

[0077] Read the startup sequence in the BIOS / UEFI settings and list all devices and their current priorities. Obtain the startup sequence list through the system API or command line tool and display the device ID and priority.

[0078] Check each device in the startup sequence to determine which devices contain the operating system. Read the boot sector of each device and check the boot record (such as MBR, GPT). Query the identifier and description of the device (such as the operating system marker on the hard disk).

[0079] Adjust the startup sequence to ensure that the device containing the operating system has the highest priority. Adjust the priority of the startup device so that the operating system device is at the front of the startup sequence.

[0080] Write the adjusted boot order back to the BIOS / UEFI settings. Use system APIs or command-line tools to update the BIOS / UEFI boot order settings.

[0081] For example: Assume the current boot order is: Device A (USB device): Priority 1; Device B (Hard Disk 1, containing the operating system): Priority 2; Device C (Optical drive): Priority 3.

[0082] Adjustment steps: Identify the boot devices and priorities: The current boot order is: A > B > C; Determine the device containing the operating system: By checking the devices, determine that Device B contains the operating system.

[0083] Adjust the boot order: Modify the priorities so that Device B has the highest priority: The adjusted boot order is: B > A > C;

[0084] Update the boot order: Use system tools to write the adjusted order back to the BIOS / UEFI.

[0085] S6: Further analyze the accuracy of the adjusted boot order, generate an adjustment strategy based on the analysis results, and generate a new boot order through the adjustment strategy for the user to view and confirm.

[0086] Further analyze the accuracy of the adjusted boot order. When the boot order is in a possibly accurate situation, that is, the accuracy value of the boot order generated within a fixed time period is greater than or equal to the first standard threshold and less than or equal to the second standard threshold, collect the accuracy values of the boot orders generated within subsequent fixed time periods that are greater than or equal to the first standard threshold and less than or equal to the second standard threshold, establish a data set, calculate the mean and standard deviation of the data set, generate an adjustment strategy after analyzing it, and generate a new boot order through the adjustment strategy for the user to view and confirm.

[0087] If the mean of the accuracy values in the data set is greater than or equal to the reference threshold of the mean of the accuracy values, and the standard deviation of the accuracy values is less than the reference threshold of the standard deviation of the accuracy values, no warning signal is generated at this time, the current boot order is maintained, and the user is prompted that the current boot order is stable and accurate;

[0088] If the mean of the accuracy values is greater than or equal to the reference threshold of the mean of the accuracy values, and the standard deviation of the accuracy values is greater than or equal to the reference threshold of the standard deviation of the accuracy values, a level 3 warning signal is generated at this time, and it is recommended that the user make minor adjustments to reduce the fluctuations in the boot order and improve stability;

[0089] If the mean of the accuracy values is less than the reference threshold of the mean of the accuracy values, and the standard deviation of the accuracy values is greater than or equal to the reference threshold of the standard deviation of the accuracy values, a secondary warning signal is generated at this time, and it is recommended that the user make significant adjustments to improve the accuracy of the startup sequence.

[0090] If the mean of the accuracy values is less than the reference threshold of the mean of the accuracy values, and the standard deviation of the accuracy values is less than the reference threshold of the standard deviation of the accuracy values, a primary warning signal is generated at this time, and it is recommended that the user conduct a comprehensive inspection and adjustment to significantly improve the accuracy of the startup sequence.

[0091] According to the generated adjustment strategy, a new startup sequence is generated. The priorities of the startup devices are adjusted according to the strategy to generate an optimized startup sequence. The new startup sequence is displayed to the user, and a confirmation option is provided. The adjusted startup sequence is displayed, and the user is prompted to confirm whether to apply the new sequence.

[0092] Here, it should be noted that the management level of the primary warning signal is higher than that of the secondary warning signal, and the management level of the secondary warning signal is higher than that of the tertiary warning signal. Relevant personnel can carry out corresponding management according to the level of the warning signal.

[0093] In this embodiment, the system API interface is used to read the current startup device priority settings, the read startup sequence data is parsed to determine the type and priority of each device; the startup devices are checked according to the preset rules and priorities to judge the damage condition of the boot sector data of the startup devices and evaluate the health of the boot sector; and the delay situation during the startup process is analyzed to evaluate the stability of the startup process; the health of the boot sector and the stability of the startup process are comprehensively analyzed to evaluate the accuracy of the startup sequence; according to the evaluation result of the accuracy of the startup sequence, it is divided into the situation where the startup sequence is accurate, the situation where the startup sequence may be accurate, and the situation where the startup sequence is inaccurate, and the startup sequence is adjusted according to the division result; for the situation where the startup sequence may be accurate, according to each startup device and its priority in the current startup sequence, the device containing the operating system is determined and its priority is adjusted; the accuracy of the adjusted startup sequence is further analyzed, an adjustment strategy is generated according to the analysis result, and a new startup sequence is generated through the adjustment strategy and displayed to the user for confirmation. It can not only significantly improve the reliability and efficiency of system startup, but also reduce the startup time, enhance the user experience, and prevent potential system startup problems at the same time.

[0094] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the real situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0095] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0096] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood by referring to the context.

[0097] In the present application, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0098] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0099] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0100] If the described functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs.

[0101] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application.

Claims

1. A safety detection method for abnormal startup of a computer, characterized in that: The following steps are involved: S1: Use the system API interface to read the current boot device priority setting, parse the read boot sequence data, and determine the type and priority of each device; S2: Check the boot device according to the preset rules and priorities, determine the damage of the boot sector data of the boot device, and evaluate the health of the boot sector; and analyze the delay in the boot process and evaluate the stability of the boot process, specifically: The delay in the startup process is analyzed and a startup delay index is generated. The stability of the startup process is evaluated based on the startup delay index. The startup delay index is obtained by obtaining the delay data and related features in the startup process and establishing a data matrix X, where each row represents a startup process and each column represents a feature. The data is standardized and the standardized data matrix is ​​Z. The covariance matrix is ​​calculated: Where C is an m×m covariance matrix. The covariance matrix C is decomposed by eigenvalue to obtain the eigenvalue λi and the corresponding eigenvector vi. The first k largest eigenvalues ​​and their corresponding eigenvectors are selected to form the principal component matrix W: The data is projected into the principal component space, and the expression is: T = ZW; Where W is the first k eigenvector matrix selected. The start delay index DQ is calculated according to the principal component score, and the expression is: DQ = β*T; Where β is the weight vector; The acquired startup delay index is compared with a preset startup delay index reference threshold value. If the startup delay index is greater than or equal to the preset startup delay index reference threshold value, a startup delay signal is generated at this time; if the startup delay index is less than the preset startup delay index reference threshold value, no startup delay signal is generated at this time; S3: Comprehensively analyze the health of the boot sector and the stability of the boot process to evaluate the accuracy of the boot sequence; S4: according to the accuracy evaluation result of the startup sequence, the startup sequence is divided into a startup sequence accurate situation, a startup sequence possibly accurate situation and a startup sequence inaccurate situation, and the startup sequence is adjusted according to the division result; S5: For a possible accurate boot sequence, determine the device containing the operating system according to each boot device and its priority in the current boot sequence, and adjust its priority; S6: further analyzing the accuracy of the adjusted startup sequence, generating an adjustment strategy according to the analysis result, and generating a new startup sequence through the adjustment strategy and displaying it to the user for confirmation.

2. A computer abnormal startup safety detection method according to claim 1, characterized in that: In S2, a boot sector data damage index is generated according to the damage of the boot sector data of the boot device, and the health of the boot sector is evaluated according to the boot sector data damage index. The method for obtaining the boot sector data damage index is: The boot sector data is divided into data blocks, each data block contains n bytes, and a Reed-Solomon code is generated according to the boot sector data block, which includes data symbols and check symbols. The generating polynomial G(x) is used for encoding. The generating polynomial of the boot sector data is expressed as: G(x) = (x-α1)(x-α2)...(x-α2t); where α is a primitive element of the finite field, and t is the number of errors corrected; the product of the boot sector data polynomial D(x) and the generating polynomial G(x) plus the check symbol C(x) obtains the coded data polynomial E(x), which is expressed as: E(x) = D(x)*x 2t +C(x); calculate the check polynomial S(x) of the received polynomial R(x) to obtain the check value, which is expressed as: S(x)=R(x)modG(x) Calculate the error polynomial E(x) according to the check value S(x), detect the error position and number, use the Berlekamp-Massey algorithm to correct the error, calculate the number of errors that cannot be corrected e, and generate the boot sector data damage index, which is expressed as: Where Dc is the boot sector data damage index.

3. A computer abnormal startup safety detection method according to claim 2, characterized in that: The obtained boot sector data damage index is compared with the preset boot sector data damage index reference threshold. If the boot sector data damage index is greater than or equal to the preset boot sector data damage index reference threshold, the boot sector data is severely damaged and the health of the boot sector is low. In this case, a boot sector abnormal signal is generated. If the boot sector data damage index is less than the preset boot sector data damage index reference threshold, the boot sector data is slightly damaged and the health of the boot sector is high. In this case, a boot sector normal signal is generated.

4. A computer abnormal startup safety detection method according to claim 3, characterized in that: The boot sector data damage index and the startup delay index are converted into a first eigenvector, and the first eigenvector is used as the input of a machine learning model. The machine learning model uses the accuracy value label of the startup sequence predicted by each group of first eigenvectors as a prediction target, and minimizes the sum of prediction errors of the accuracy value labels of all startup sequences as a training target. The machine learning model is trained until the sum of prediction errors converges, and the model training is stopped. The accuracy value of the startup sequence is determined according to the model output results, wherein the machine learning model is a polynomial regression model.

5. A computer abnormal startup safety detection method according to claim 4, characterized in that: In S4, according to the accuracy evaluation result of the startup sequence, it is divided into the startup sequence accurate situation, the startup sequence possibly accurate situation and the startup sequence inaccurate situation, specifically: Comparing the acquired accuracy value of the startup sequence with a gradient standard threshold, the gradient standard threshold includes a first standard threshold and a second standard threshold, and the first standard threshold is less than the second standard threshold, and comparing the accuracy value of the startup sequence with the first standard threshold and the second standard threshold respectively; If the accuracy value of the startup sequence is greater than the second standard threshold, it indicates that the startup sequence accuracy is high, and it is classified as the startup sequence accuracy situation, and a startup sequence accuracy signal is generated, and no adjustment is required, and the existing startup sequence is maintained. The system startup sequence is reasonable and efficient and does not need to be changed; If the accuracy value of the boot sequence is greater than or equal to the first standard threshold and less than or equal to the second standard threshold, the boot sequence accuracy is medium, and it is classified as a boot sequence that may be accurate, and a boot sequence that may be accurate signal is generated, and the user manually checks the priority setting of the boot device; If the accuracy value of the startup sequence is less than the first standard threshold, the startup sequence accuracy is low, it is classified as an inaccurate startup sequence situation, and an inaccurate startup sequence signal is generated to adjust the startup sequence.

6. A computer abnormal startup safety detection method according to claim 1, characterized in that: In S5, for the possible accurate boot sequence, the priority of each boot device in the current boot sequence and its priority is adjusted, specifically: Read the boot order in the BIOS / UEFI setup and list all devices and their current priority, check each device in the boot order, determine the device that contains the operating system, read the boot sector of each device, check the boot record, adjust the boot order to ensure that the device containing the operating system has the highest priority, and write the adjusted boot order back to the BIOS / UEFI setup.

7. A computer abnormal startup safety detection method according to claim 1, characterized in that: In S6, the accuracy of the adjusted startup sequence is further analyzed, and an adjustment strategy is generated according to the analysis result, specifically: The accuracy of the adjusted startup sequence is further analyzed. When the startup sequence is possibly accurate, that is, the accuracy value of the startup sequence generated within a fixed time period is greater than or equal to the first standard threshold and less than or equal to the second standard threshold, the accuracy values ​​of the startup sequences generated within a subsequent fixed time period that are greater than or equal to the first standard threshold and less than or equal to the second standard threshold are collected, and a data set is established. The mean and standard deviation of the data set are calculated, and an adjustment strategy is generated after analysis. The new startup sequence generated by the adjustment strategy is displayed to the user for confirmation.

8. A computer abnormal startup safety detection method according to claim 7, characterized in that: If the mean of the accuracy values ​​in the data set is greater than or equal to the reference threshold of the mean of the accuracy values, and the standard deviation of the accuracy values ​​is less than the reference threshold of the standard deviation of the accuracy values, then no warning signal is generated, the current startup sequence is maintained, and the user is prompted that the current startup sequence is stable and accurate; If the mean of the accuracy values ​​is greater than or equal to the reference threshold of the mean of the accuracy values, and the standard deviation of the accuracy values ​​is greater than or equal to the reference threshold of the standard deviation of the accuracy values, a level 3 warning signal is generated, and the user is advised to make slight adjustments to reduce fluctuations in the startup sequence and improve stability; If the mean of the accuracy values ​​is less than the reference threshold of the mean of the accuracy values, and the standard deviation of the accuracy values ​​is greater than or equal to the reference threshold of the standard deviation of the accuracy values, a secondary warning signal is generated, and the user makes substantial adjustments to improve the accuracy of the startup sequence; If the mean of the accuracy values ​​is less than the reference threshold of the mean of the accuracy values, and the standard deviation of the accuracy values ​​is less than the reference threshold of the standard deviation of the accuracy values, a first-level warning signal is generated and the user conducts a comprehensive inspection and adjustment to improve the accuracy of the startup sequence.

Citation Information

Patent Citations

  • Computer starting sequence adjusting method and device

    CN110888677A

  • System starting method based on intelligent analysis and DMA technology

    CN118193066A