Virus scanning processing method, apparatus, device, and storage medium

By reusing virus scan results from enterprise-level products through a global sharing mechanism, the problem of low virus scanning efficiency for products is solved, and a more efficient scanning process is achieved.

CN119577760BActive Publication Date: 2026-04-14CCB FINTECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CCB FINTECH CO LTD
Filing Date
2024-08-14
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing technologies for virus scanning of enterprise-level artifacts are inefficient, leading to duplicate scans and wasted resources, especially when there are widely reused files and technical components across multiple artifacts.

Method used

A global sharing mechanism is adopted to generate virus scan results by parsing the files and technical component information of artifacts, and reuse the same scan results in other artifacts to reduce duplicate scans.

Benefits of technology

It optimized the scanning efficiency of products, reduced the number of repeated scans, reduced resource consumption, and improved scanning efficiency and enterprise-level shared virus scanning effects.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119577760B_ABST
    Figure CN119577760B_ABST
Patent Text Reader

Abstract

The application provides a virus scanning processing method, device and equipment and a storage medium. It relates to the technical field of big data. The method comprises the following steps: obtaining a scanning request; the scanning request comprises event information of a to-be-scanned product, and the event information comprises directory information of the to-be-scanned product and files under the directory information. According to the scanning request, the event information of the to-be-scanned product is analyzed to generate product analysis results and technical component information of the to-be-scanned product. According to the product analysis results, product file version information is generated. Based on the product analysis results, the technical component information and the product file version information, the files and / or technical components of the to-be-scanned product are subjected to virus scanning processing to generate virus scanning results; the virus scanning results are used as scanning results of the same files and / or technical components in the virus scanning process of other products. The method of the application solves the problem of low efficiency of product virus scanning in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of big data technology, and in particular to a virus scanning and processing method, apparatus, device and storage medium. Background Technology

[0002] Currently, the governance of enterprise application architecture remains a highly complex and sophisticated topic in the field of computer science. Because architecture itself is a high-level abstraction, the concept of an enterprise-level computer architecture varies depending on the size of the organization and the analytical perspective. An enterprise-level architecture effectively guides business and computer teams in translating corporate strategic goals and business knowledge into enterprise computing capabilities and operational capabilities, and ensures the consistent integration of business operations and computer systems.

[0003] In existing technologies, when scanning enterprise artifacts for viruses, after the artifact is submitted, a siloed scanning method is usually used to perform a full analysis and scan of the files and / or technical components in the artifact, and return the overall results of a single artifact.

[0004] However, in existing technologies, because it is necessary to perform full analysis and one-by-one scanning of the documents and / or technical components in the artifacts, if an enterprise has multiple artifacts, each artifact includes a large number of documents and / or technical components, and because enterprise-level computer technology resources have extensive reusability across artifacts, each artifact may contain the same documents and / or technical components. However, each artifact needs to be scanned independently, which may lead to duplicate scanning, which takes a long time and causes a huge waste of resources and efficiency. Summary of the Invention

[0005] This application provides a virus scanning processing method, apparatus, device, and storage medium to solve the problem of low efficiency in virus scanning of existing products.

[0006] In a first aspect, this application provides a virus scanning and processing method, comprising:

[0007] Obtain a scan request; wherein the scan request includes event information of the product to be scanned, and the event information includes directory information of the product to be scanned and files under the directory information;

[0008] Based on the scanning request, the event information of the product to be scanned is parsed to generate product parsing results and technical component information of the product to be scanned;

[0009] Based on the product parsing results, product file version information is generated;

[0010] Based on the product parsing results, the technical component information, and the product file version information, a virus scan is performed on the files and / or technical components of the product to be scanned, generating a virus scan result; wherein, the virus scan result is used as the scan result for the same files and / or technical components during the virus scan of other products.

[0011] In one possible design, the step of performing virus scanning processing on the files and / or technical components of the artifact to be scanned based on the artifact parsing results, the technical component information, and the artifact file version information, and generating virus scan results, includes:

[0012] Based on the product analysis results, the technical component information, the product file version information, and the preset virus database, files and / or technical components of the product to be scanned that do not meet the virus version in the virus database are filtered out.

[0013] Perform virus scanning on the filtered files and / or technical components, and generate virus scan results.

[0014] In one possible design, the step of performing virus scanning on the filtered files and / or technical components to generate virus scan results includes:

[0015] Based on the product parsing results, product file version information, and preset virus database, if it is determined that the filtered files include files not scanned under the virus database version or modified files, then the files or modified files are output to the target scan space.

[0016] Read the technical component information and the historical detection information of the technical components contained in the technical component information;

[0017] Based on the historical scanning information of the technical component, if it is determined that the filtered technical component has no scanning record, or the previous scan result does not meet the latest preset scanning rule information, then the technical component is output to the target scanning space; wherein, the preset scanning rule information represents the scanning requirements of the technical component during the scanning process;

[0018] Virus scanning is performed on the target objects in the target scanning space to generate virus scan results.

[0019] In one possible design, after performing virus scanning processing on the files and / or technical components of the artifact to be scanned based on the artifact parsing results, the technical component information, and the artifact file version information, and generating virus scan results, the method further includes:

[0020] Receive additional scanning requests for other products;

[0021] If, based on the other scan requests, it is determined that there are files and / or technical components in the other artifacts that are identical to the target object in the target scan space, then the virus scan results of the identical files and / or technical components in the target scan space are obtained, and the virus scan results of the identical files and / or technical components are used as the virus scan results of the files and / or technical components in the other artifacts.

[0022] In one possible design, the step of parsing the event information of the article to be scanned according to the scanning request, and generating an article parsing result and technical component information of the article to be scanned, includes:

[0023] Based on preset product rule information, and according to the scanning request, the catalog information of the product to be scanned and the files under the catalog information are scanned;

[0024] The files of the preset type in the directory information are decompressed to generate product parsing results;

[0025] The files of a preset type in the directory information are scanned for technical components to generate technical component information of the product to be scanned.

[0026] In one possible design, the artifact parsing result includes a list of internal file resources of the artifact, and the technical component information includes component dependency information and dependency version change information of the artifact to be scanned.

[0027] Secondly, this application provides a virus scanning and processing apparatus, comprising:

[0028] An acquisition module is used to acquire a scan request; wherein, the scan request includes event information of the product to be scanned, and the event information includes directory information of the product to be scanned and files under the directory information;

[0029] The parsing module is used to parse the event information of the product to be scanned according to the scanning request, and generate product parsing results and technical component information of the product to be scanned;

[0030] The generation module is used to generate product file version information based on the product parsing results;

[0031] The virus scanning module is used to perform virus scanning processing on the files and / or technical components of the product to be scanned based on the product parsing results, the technical component information, and the product file version information, and generate virus scanning results; wherein, the virus scanning results are used as the scanning results of the same files and / or technical components in the virus scanning process of other products.

[0032] In one possible design, the virus scanning module includes:

[0033] The filtering unit is used to filter files and / or technical components of the product to be scanned that do not meet the virus version in the virus database, based on the product parsing result, the technical component information, the product file version information, and the preset virus database.

[0034] The virus scanning unit is used to perform virus scanning on filtered files and / or technical components and generate virus scan results.

[0035] In one possible design, the virus scanning unit includes:

[0036] The first determining subunit is used to output the file or the modified file to the target scanning space if it is determined that the filtered file includes a file not scanned under the virus database version in the virus database or a modified file, based on the product parsing result, product file version information, and a preset virus database.

[0037] The reading subunit is used to read the technical component information and the historical detection information of the technical components contained in the technical component information;

[0038] The second determining subunit is used to output the technical component to the target scanning space if, based on the historical scanning information of the technical component, it is determined that the filtered technical component has no scanning record, or the previous scan result does not meet the latest preset scanning rule information; wherein, the preset scanning rule information represents the scanning requirements of the technical component during the scanning process.

[0039] The virus scanning subunit is used to perform virus scanning processing on target objects in the target scanning space and generate virus scanning results.

[0040] In one possible design, the device further includes:

[0041] The receiving module is configured to perform virus scanning processing on the files and / or technical components of the product to be scanned based on the product parsing results, the technical component information, and the product file version information, and after generating virus scanning results, receive other scanning requests for other products.

[0042] The determination module is configured to, if, based on the other scanning requests, it is determined that there are files and / or technical components in the other artifacts that are identical to the target object in the target scanning space, then obtain the virus scan results of the identical files and / or technical components in the target scanning space, and use the virus scan results of the identical files and / or technical components as the virus scan results of the files and / or technical components in the other artifacts.

[0043] In one possible design, the parsing module includes:

[0044] The first scanning unit is used to scan the catalog information of the product to be scanned and the files under the catalog information according to the scanning request, based on preset product rule information.

[0045] The decompression unit is used to decompress files of a preset type in the directory information and generate product parsing results;

[0046] The second scanning unit is used to scan the files of a preset type in the directory information for technical components and generate the technical component information of the product to be scanned.

[0047] In one possible design, the artifact parsing result includes a list of internal file resources of the artifact, and the technical component information includes component dependency information and dependency version change information of the artifact to be scanned.

[0048] Thirdly, embodiments of this application provide an electronic device, including: at least one processor and a memory; the memory stores computer execution instructions; the at least one processor executes the computer execution instructions stored in the memory, causing the at least one processor to perform the virus scanning processing method as described in the first aspect and various possible designs of the first aspect.

[0049] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions. When a processor executes the computer-executable instructions, it implements the virus scanning and processing method described in the first aspect and various possible designs of the first aspect.

[0050] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the virus scanning and processing method described in the first aspect and various possible designs of the first aspect.

[0051] The virus scanning processing method, apparatus, device, and storage medium provided in this application obtain a scan request. The scan request includes event information of the document to be scanned, which includes directory information and files within that directory. Based on the scan request, the event information of the document to be scanned is parsed to generate a document parsing result and technical component information. Based on the document parsing result, document file version information is generated. Based on the document parsing result, technical component information, and document file version information, virus scanning processing is performed on the files and / or technical components of the document to be scanned, generating a virus scan result. This virus scan result is used as the scan result for the same files and / or technical components in other documents. In this solution, based on the document parsing result, technical component information, and document file version information, virus scanning processing is performed on the files and / or technical components of the document to be scanned to generate a virus scan result. In subsequent virus scans of other documents, the virus scan result for the files and / or technical components can be used as the scan result for the same files and / or technical components in those other documents. Therefore, the global sharing mechanism for scanning results of enterprise-level artifacts at the document and technical component levels proposed in this application, based on enterprise-level artifacts and technical components, enables the reuse of scanning results for the same documents and / or technical components, realizing an enterprise-level shared artifact virus scanning process and optimizing artifact scanning efficiency. Compared to siloed virus scanning methods, it can significantly reduce the number of times widely reused technical components are repeatedly scanned in different artifacts, and can reduce the scanning resource consumption of unchanged assets across multiple versions of the same artifact, greatly improving scanning efficiency, reducing scanning resource consumption, and solving the problem of low artifact virus scanning efficiency in existing technologies. Attached Figure Description

[0052] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0053] Figure 1 A schematic flowchart of a virus scanning and processing method provided in an embodiment of this application;

[0054] Figure 2 A schematic flowchart of another virus scanning and processing method provided in an embodiment of this application;

[0055] Figure 3 A schematic diagram of the architecture of a virus scanning and processing method provided in an embodiment of this application;

[0056] Figure 4 This is a schematic diagram of the structure of a virus scanning and processing device provided in an embodiment of this application;

[0057] Figure 5This is a schematic diagram of another virus scanning and processing device provided in an embodiment of this application;

[0058] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0059] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to specific embodiments. Detailed Implementation

[0060] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0061] It should be noted that the collection, storage, use, processing, transmission, provision, and disclosure of financial data or user data involved in the technical solution of this application all comply with relevant laws and regulations and do not violate public order and good morals. The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, and displayed data) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use, and processing of related data must comply with relevant laws, regulations, and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse. In addition, certain software, components, models, and other existing industry solutions may be mentioned in the embodiments of this application. These should be considered exemplary, and their purpose is merely to illustrate the feasibility of implementing the technical solution of this application, but does not mean that the applicant has already used or necessarily used such solutions.

[0062] Currently, the governance of enterprise application architecture remains a highly complex and sophisticated topic in the field of computer science. Because architecture itself is a high-level abstraction, the concept of an enterprise-level computer architecture varies depending on the size of the organization and the analytical perspective. An enterprise-level architecture effectively guides business and computer teams in translating corporate strategic goals and business knowledge into enterprise computing capabilities and operational capabilities, and ensures the consistent integration of business operations and computer systems.

[0063] From the perspective of most application developers or small businesses, technology components or component framework collections such as Spring Cloud, Dubbo, and Spring Framework constitute enterprise-level architecture. Distributed service strategies and end-to-end monitoring are typically the responsibility of the architect. However, within some large financial enterprises, based on industry-leading architectural perspectives and concepts, we scientifically and systematically divide enterprise-level architecture according to corporate strategic goals. For example, a large bank has defined enterprise-level architecture as follows:

[0064] Enterprise architecture describes the framework for an enterprise's business operations and computing support, encompassing business architecture and computing architecture. Computing architecture includes application architecture, data architecture, technology architecture, and security architecture. The above description scientifically and comprehensively outlines the scope and hierarchical division of enterprise architecture. Furthermore, it effectively guides business and computing teams in translating corporate strategic goals and business knowledge into enterprise computing capabilities and operational capabilities, and ensures the consistent integration of business operations and computing systems.

[0065] Within traditional large banks, whose primary business is banking, employees typically possess a strong understanding of banking operations and a clear governance approach. Consequently, they often demonstrate excellent capabilities and management skills in defining and managing business and application architectures within computer systems. However, in other areas of computer architecture, such as technical architecture, due to the specialized nature of these fields, clear hierarchical divisions and effective governance structures are lacking. In practice, while companies may have defined architectural layers and governance domains, they often lack truly effective management methods and tools for implementation.

[0066] In one example, regarding virus scanning of enterprise artifacts, after artifact submission, a siloed scanning method is typically used to perform a full analysis and individual scan of the files and / or technical components within the artifact, returning the overall results for a single artifact. However, in existing technologies, because a full analysis and individual scan of the files and / or technical components within an artifact is required, if an enterprise has multiple artifacts, each containing a large number of files and / or technical components, and given the extensive reusability of enterprise-level computer technology resources across artifacts, each artifact may contain the same files and / or technical components. However, each artifact requires independent scanning, potentially leading to duplicate scans, consuming significant time, and resulting in substantial waste of resources and efficiency.

[0067] To address the aforementioned technical problems, this application proposes the following technical concept: Virus scanning is performed on the files and / or technical components of the document to be scanned, and the resulting virus scan results are shared globally, meaning that virus scan results for the same files and / or technical components can be reused. This solves the problem of low efficiency in virus scanning of documents in existing technologies.

[0068] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.

[0069] Figure 1 This is a flowchart illustrating a virus scanning and processing method provided in an embodiment of this application, as shown below. Figure 1 As shown, the method includes:

[0070] Step 101: Obtain a scan request; wherein, the scan request includes event information of the product to be scanned, and the event information includes the directory information of the product to be scanned and the files under the directory information.

[0071] For example, the executing entity of this embodiment can be an electronic device, a terminal device, a virus scanning and processing device, or other device or equipment capable of executing this embodiment, and there is no limitation thereto. In this embodiment, the executing entity is described as an electronic device.

[0072] First, obtain a scan request. The scan request can be initiated by the computer management platform, which contains key business information about the products. This key business information includes the product's directory structure and the standard files under that directory structure. Relevant personnel can upload multiple products and initiate scan requests for product inspection on the computer management platform based on this key business information. The scan request includes event information about the product to be scanned, which includes the product's directory information and the recorded files under that directory information.

[0073] Step 102: Based on the scanning request, parse the event information of the product to be scanned, and generate the product parsing result and the technical component information of the product to be scanned.

[0074] For example, based on the scanning request and the directory structure of the key business information of the artifacts provided by the computer management platform, and according to the preset artifact rule information, the directory information in the event information of the artifact to be scanned is scanned, and the files of preset types under the directory information are decompressed to form artifact parsing results. The artifact parsing results include the artifact's internal file (document) resource details. The event information of the artifact to be scanned is then parsed to generate the technical component information of the artifact to be scanned. The technical component information includes component dependency information and dependency version change information. Further, an enterprise-level component dependency view can be formed based on the technical component information.

[0075] Step 103: Generate the product file version information based on the product parsing results.

[0076] For example, based on the details of the internal documents (resources) of the product in the product parsing results, product document (resource) version information can be generated.

[0077] Step 104: Based on the artifact parsing results, technical component information, and artifact file version information, perform virus scanning on the files and / or technical components of the artifact to be scanned, and generate virus scan results; wherein, the virus scan results are used as the scan results of the same files and / or technical components in the virus scanning process of other artifacts.

[0078] For example, artifacts are composed of files and / or technical components. Based on the artifact parsing results, technical component information, and artifact file version information, the files and / or technical components of the artifact to be scanned are subjected to virus scanning processing to generate virus scan results. During the virus scanning process of other artifacts, if other artifacts include the same files and / or technical components, the same files and / or technical components do not need to be scanned repeatedly. The virus scan results of the files and / or technical components of the artifact to be scanned can be directly used as the scan results of the same files and / or technical components.

[0079] In this embodiment, a scan request is obtained; the scan request includes event information of the document to be scanned, and the event information includes directory information and files under the directory information of the document to be scanned. Based on the scan request, the event information of the document to be scanned is parsed to generate a document parsing result and technical component information of the document to be scanned. Based on the document parsing result, document file version information is generated. Based on the document parsing result, technical component information, and document file version information, virus scanning processing is performed on the files and / or technical components of the document to be scanned, generating virus scan results; wherein, the virus scan results are used as scan results for the same files and / or technical components in the virus scanning process of other documents. In this solution, based on the document parsing result, technical component information, and document file version information, virus scanning processing is performed on the files and / or technical components of the document to be scanned to generate virus scan results. In subsequent virus scanning processes of other documents, the virus scan results of the files and / or technical components can be used as scan results for the same files and / or technical components in other documents. Therefore, the global sharing mechanism for scanning results of enterprise-level artifacts at the document and technical component levels proposed in this application, based on enterprise-level artifacts and technical components, enables the reuse of scanning results for the same documents and / or technical components, realizing an enterprise-level shared artifact virus scanning process and optimizing artifact scanning efficiency. Compared to siloed virus scanning methods, it can significantly reduce the number of times widely reused technical components are repeatedly scanned in different artifacts, and can reduce the scanning resource consumption of unchanged assets across multiple versions of the same artifact, greatly improving scanning efficiency, reducing scanning resource consumption, and solving the problem of low artifact virus scanning efficiency in existing technologies.

[0080] Figure 2 A schematic flowchart of another virus scanning and processing method provided in this application embodiment is shown below. Figure 2 As shown, the method includes:

[0081] Step 201: Obtain a scan request; wherein, the scan request includes event information of the product to be scanned, and the event information includes the directory information of the product to be scanned and the files under the directory information.

[0082] For example, this step can be referred to Figure 1 Step 101 in the text will not be repeated here.

[0083] Step 202: Based on the preset product rule information, scan the catalog information of the product to be scanned and the files under the catalog information according to the scanning request.

[0084] For example, the product rule information represents the internal structure of the product, namely the product's catalog information and the files under the catalog information. Based on the preset product rule information, the catalog information of the product to be scanned and the files under the catalog information are scanned according to the scanning request.

[0085] Step 203: Decompress the files of the preset types in the directory information to generate the product parsing results.

[0086] In one example, the artifact parsing result includes details of the artifact's internal file resources.

[0087] For example, the catalog information includes multiple types of files. The multiple types of files are identified, a preset type of file is determined, and the preset type of file is decompressed to generate the product parsing result.

[0088] Step 204: Perform technical component scanning on the files of the preset types in the catalog information to generate technical component information of the product to be scanned.

[0089] In one example, the technical component information includes component dependency information and dependency version change information of the artifact to be scanned.

[0090] For example, an electronic device can scan files of a preset type in the catalog information for technical components, and generate technical component information of the product to be scanned. The technical component information includes component dependency information and dependency version change information of the product to be scanned.

[0091] Step 205: Generate the product file version information based on the product parsing results.

[0092] For example, the electronic device generates product document version information based on the product parsing results. The product document version information can also be represented as product document (document) version information.

[0093] Step 206: Based on the artifact parsing results, technical component information, artifact file version information, and the preset virus database, filter the files and / or technical components of the artifact to be scanned that do not meet the virus version in the virus database.

[0094] In one example, step 206 includes: based on the artifact parsing results, artifact file version information, and a preset virus database, if it is determined that the filtered files include files not scanned under the virus database version or modified files, then the files or modified files are output to the target scan space; reading the technical component information and the historical scanning information of the technical components contained in the technical component information; based on the historical scanning information of the technical components, if it is determined that the filtered technical components have no scanning records, or that the previous scan result does not meet the latest preset scanning rule information, then the technical components are output to the target scan space; wherein, the preset scanning rule information represents the scanning requirements of the technical components during the scanning process; performing virus scanning processing on the target objects in the target scan space to generate virus scan results.

[0095] For example, for files in a document to be scanned, the electronic device reads the document parsing results and matches each file one by one according to the document file version information and the update status of the virus database version in the preset virus database. If it is determined that there is a file that has not been scanned under the virus database version or a modified file, then that file or modified file is output to the target scan space. Other scanned files that match the virus database version are ignored and do not need to be output to the target scan space for re-scanning.

[0096] For the technical components in the product to be scanned, the system reads the component information, including component dependencies and version change information. Based on the component's historical scanning information, such as scan records and virus database versions, it determines whether the component needs to be re-scanned. If there are no scan records or the previous scan results no longer meet the latest preset scanning rules, the component is re-included in the target scan scope. The preset scanning rules define the scanning requirements for the component during the scanning process and can be updated at any time.

[0097] Step 207: Perform virus scanning on the filtered files and / or technical components to generate virus scan results; wherein, the virus scan results are used as the scan results of the same files and / or technical components during the virus scanning process of other artifacts.

[0098] For example, after filtering files and / or technical components, electronic devices perform virus scans on the filtered files and / or technical components that enter the target scan space, obtaining virus scan results. It is important to note that an enterprise may have multiple artifacts. Within the same artifact, or within the same artifact in different versions, or across different artifacts, there are many reused files and technical components. When performing a global virus scan on any artifact, that is, once a resource (file, technical component) has been scanned once, the generated virus scan results can be reused across all artifacts, meaning there is no need to repeatedly perform virus scans.

[0099] Step 208: Receive other scanning requests for other products.

[0100] For example, since the computer management platform has multiple artifacts in its memory, it can receive additional scan requests for other artifacts.

[0101] Step 209: If, based on other scan requests, it is determined that files and / or technical components in other artifacts contain the same files and / or technical components as the target object in the target scan space, then obtain the virus scan results of the same files and / or technical components in the target scan space, and use the virus scan results of the same files and / or technical components as the virus scan results of the files and / or technical components in other artifacts.

[0102] For example, an electronic device can determine whether reused files and / or technical components exist in other artifacts based on other scan requests. If it is determined that the files and / or technical components in other artifacts are the same as the target objects in the target scan space, then the virus scan results of the same files and / or technical components in the target scan space are obtained, and the virus scan results of the same files and / or technical components are used as the virus scan results of the files and / or technical components in other artifacts. Therefore, reused files and / or technical components in other artifacts do not need to be scanned repeatedly; where the target object refers to the files and / or technical components in the target scan space.

[0103] In this embodiment, a scan request is obtained; the scan request includes event information of the document to be scanned, and the event information includes directory information of the document to be scanned and files under the directory information. Based on preset document rule information, the directory information of the document to be scanned and the files under the directory information are scanned according to the scan request. Files of preset types in the directory information are decompressed to generate document parsing results. Technical component scanning is performed on files of preset types in the directory information to generate technical component information of the document to be scanned. Document file version information is generated based on the document parsing results. Based on the document parsing results, technical component information, document file version information, and a preset virus database, files and / or technical components of the document to be scanned that do not meet the virus versions in the virus database are filtered. Virus scanning processing is performed on the filtered files and / or technical components to generate virus scan results; wherein, the virus scan results are used as scan results for the same files and / or technical components during virus scanning of other documents. Other scan requests for other documents are received. If, based on other scan requests, it is determined that files and / or technical components in other artifacts contain the same files and / or technical components as the target objects in the target scan space, then the virus scan results of the same files and / or technical components in the target scan space are obtained, and these virus scan results are used as the virus scan results of files and / or technical components in other artifacts. Therefore, the global sharing mechanism for scan results at the file (document) and technical component levels proposed in this application, based on enterprise-level artifacts and technical components, enables the reuse of scan results for the same files and / or technical components, realizing an enterprise-level shared artifact virus scanning process and optimizing artifact scanning efficiency. Compared to siloed virus scanning methods, it can significantly reduce the number of times widely reused technical components are repeatedly scanned in different artifacts, and can reduce the scanning resource consumption of unchanged assets across multiple versions of a unified artifact, greatly improving scanning efficiency and reducing scanning resource consumption, thus solving the problem of low artifact virus scanning efficiency in existing technologies. Simultaneously, it also achieves enterprise-level global virus risk control for technical components and artifact files (documents).

[0104] In one example, Figure 3 A schematic diagram of the architecture of a virus scanning and processing method provided in this application embodiment is shown below. Figure 3 As shown, this device is used for virus scanning of enterprise-level products and includes: an enterprise computer management platform, a product parsing module, a product scanning module, a file (document) management module, a technical component management module, and a virus scanning module. Among them,

[0105] Based on a computer management platform: Establish key business information for products, including product catalog structure and standard content information. Provide relevant personnel with processes for uploading products and initiating product inspections.

[0106] Product Analysis Module: Based on the internal structure of the product provided by the computer management platform, and according to specific rules, scans the directory structure, decompresses files of preset types, and generates product analysis results, including details of the product's internal file (document) resources. Based on the product analysis results, it generates product file (document) version information.

[0107] Technical Component Management Module: Scans files of preset types for technical components to obtain the technical component information of the artifact. The technical component information includes component dependency information and dependency version changes, forming an enterprise-level component dependency view.

[0108] Virus Scanning Module: Based on the artifact parsing results, artifact file (document) version information, and artifact technical component information, the antivirus engine scans the artifact content for viruses. Specifically, this includes: reading the artifact parsing results, matching them against file (document) change information and virus database updates; outputting files not scanned under a matching virus database version or modified files to the scan target space; ignoring other scanned files that meet the rules; and reading the artifact's technical component information, determining whether the component needs rescanning based on its historical scan information (including scan records and virus database versions). If there are no scan records or the previous scan results no longer meet the current scan rules, the component is re-included in the scan scope.

[0109] Virus detection module: After filtering based on the above-mentioned file and technical components, it performs virus scans on files entering the target scan space and obtains the virus scan results.

[0110] File (document) management module: Records virus information in specific files (documents) from virus scan results.

[0111] poison

[0112] Scan Results. Technical Component Management Module: Records the virus scan results for technical components within the virus scan results. These virus scan results can be shared across multiple artifacts in this version.

[0113] Figure 4 This is a schematic diagram of the structure of a virus scanning and processing device provided in an embodiment of this application, as shown below. Figure 4 As shown, the device includes:

[0114] The acquisition module 31 is used to acquire a scan request; wherein the scan request includes event information of the product to be scanned, and the event information includes the directory information of the product to be scanned and the files under the directory information.

[0115] The parsing module 32 is used to parse the event information of the product to be scanned according to the scanning request, and generate the product parsing result and the technical component information of the product to be scanned.

[0116] The generation module 33 is used to generate product file version information based on the product parsing results.

[0117] The virus scanning module 34 is used to perform virus scanning on the files and / or technical components of the work to be scanned based on the work parsing results, technical component information, and work file version information, and generate virus scanning results; wherein, the virus scanning results are used as the scanning results of the same files and / or technical components in the virus scanning process of other work.

[0118] The apparatus in this embodiment can execute the technical solutions in the above method. Its specific implementation process and technical principles are the same, and will not be repeated here.

[0119] Figure 5 This is a schematic diagram of another virus scanning and processing device provided in an embodiment of this application. Figure 4 Based on the illustrated embodiments, as Figure 5 As shown, the virus scanning module 34 includes:

[0120] The filtering unit 341 is used to filter files and / or technical components of the artifact to be scanned that do not meet the virus version in the virus database, based on the artifact parsing results, technical component information, artifact file version information, and a preset virus database.

[0121] Virus scanning unit 342 is used to perform virus scanning processing on filtered files and / or technical components and generate virus scan results.

[0122] In one example, virus scanning unit 342 includes:

[0123] The first determining subunit 3421 is used to output the file or the modified file to the target scan space if it is determined that the filtered file includes a file that has not been scanned under the virus database version or a modified file, based on the product parsing result, product file version information and the preset virus database.

[0124] Read subunit 3422 is used to read technical component information and historical detection information of technical components contained in the technical component information.

[0125] The second determining subunit 3423 is used to output the technical component to the target scanning space if, based on the historical scanning information of the technical component, it is determined that the filtered technical component has no scanning record, or the previous scan result does not meet the latest preset scanning rule information; wherein, the preset scanning rule information represents the scanning requirements of the technical component during the scanning process.

[0126] The virus scanning subunit 3424 is used to perform virus scanning processing on target objects in the target scanning space and generate virus scanning results.

[0127] In one example, the device also includes:

[0128] The receiving module 41 is used to perform virus scanning processing on the files and / or technical components of the work to be scanned based on the work parsing results, technical component information and work file version information, and after generating virus scanning results, receive other scanning requests for other work.

[0129] The determination module 42 is used to, if, based on other scanning requests, it is determined that there are files and / or technical components in other artifacts that are the same as the target object in the target scanning space, then obtain the virus scanning results of the same files and / or technical components in the target scanning space, and use the virus scanning results of the same files and / or technical components as the virus scanning results of the files and / or technical components in other artifacts.

[0130] In one example, parsing module 32 includes:

[0131] The first scanning unit 321 is used to scan the catalog information of the product to be scanned and the files under the catalog information according to the scanning request, based on the preset product rule information.

[0132] The decompression unit 322 is used to decompress files of a preset type in the directory information and generate product parsing results.

[0133] The second scanning unit 323 is used to scan the technical components of files of a preset type in the catalog information and generate technical component information of the product to be scanned.

[0134] In one example, the artifact parsing results include details of the artifact's internal file resources, and the technical component information includes component dependency information and dependency version change information of the artifact to be scanned.

[0135] The apparatus in this embodiment can execute the technical solutions in the above method. Its specific implementation process and technical principles are the same, and will not be repeated here.

[0136] It should be noted that the division of the various modules in the above device is merely a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. These modules can be implemented entirely in software via processing element calls; they can be fully implemented in hardware; or some modules can be implemented in software via processing element calls, while others are implemented in hardware. Each module can be a separate processing element, or it can be integrated into a chip within the device. Alternatively, it can be stored as program code in the device's memory, and its functions can be called and executed by a processing element. Furthermore, these modules can be fully or partially integrated together, or they can be implemented independently. The processing element here can be an integrated circuit with signal processing capabilities. During implementation, each step of the above method or each of the above modules can be completed through integrated logic circuits in the processor element or through software instructions.

[0137] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 6 As shown, the electronic device may include: transceiver 121, processor 122, and memory 123.

[0138] Processor 122 executes computer execution instructions stored in memory, causing processor 122 to perform the scheme in the above embodiments. Processor 122 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0139] The memory 123 is connected to the processor 122 via the system bus and completes communication between them. The memory 123 is used to store computer program instructions.

[0140] Transceiver 121 can be used to obtain the task to be run and its configuration information.

[0141] The system bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The system bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in the diagram, but this does not indicate that there is only one bus or one type of bus. Transceivers are used to enable communication between database access devices and other computers (e.g., clients, read-write libraries, and read-only libraries). Memory may include random access memory (RAM) and may also include non-volatile memory.

[0142] The electronic device provided in this application embodiment can be the terminal device described in the above embodiments.

[0143] This application also provides a chip for executing instructions, which is used to execute the virus scanning and processing method described in the above embodiments.

[0144] This application also provides a computer-readable storage medium storing computer instructions that, when executed on a computer, cause the computer to perform the virus scanning processing method described in the above embodiments.

[0145] This application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when the at least one processor executes the computer program, it can implement the technical solution of the virus scanning and processing method in the above embodiments.

[0146] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or modules, and may be electrical, mechanical, or other forms.

[0147] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to implement the solution of this embodiment according to actual needs.

[0148] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing unit, or each module can exist physically separately, or two or more modules can be integrated into one unit. The unit composed of the above modules can be implemented in hardware or in the form of hardware plus software functional units.

[0149] The integrated modules described above, implemented as software functional modules, can be stored in a computer-readable storage medium. These software functional modules, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods of the various embodiments of this application.

[0150] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly manifested as execution by a hardware processor, or execution by a combination of hardware and software modules within the processor.

[0151] The memory may include high-speed RAM, and may also include non-volatile storage (NVM), such as at least one disk storage device, and may also be a USB flash drive, external hard drive, read-only memory, disk or optical disc, etc.

[0152] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0153] The aforementioned storage medium can be implemented from any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium accessible to general-purpose or special-purpose computers.

[0154] An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Alternatively, the storage medium can be an integral part of the processor. The processor and storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and storage medium can exist as discrete components in an electronic control unit or main control device.

[0155] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0156] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. A virus scanning and processing method, characterized in that, include: Obtain a scan request; wherein the scan request includes event information of the product to be scanned, and the event information includes directory information of the product to be scanned and files under the directory information; Based on the scanning request, the event information of the product to be scanned is parsed to generate product parsing results and technical component information of the product to be scanned; Based on the product parsing results, product file version information is generated; the product file version information is used to represent the version information of the product file. Based on the product file version information and the virus database version in the preset virus database, determine whether there are any files in the product file version information that have not been scanned under the virus database version or have been modified; if so, output the files that have not been scanned under the virus database version or have been modified to the target scan space. Based on the technical component information and the historical scanning information of the technical component, determine whether the technical component in the technical component information has no scanning record or whether the previous scan result does not meet the latest preset scanning rule information; if the technical component has no scanning record or the previous scan result does not meet the latest preset scanning rule information, then output the technical component to the target scanning space; The files and / or technical components in the target scan space are subjected to virus scanning processing to generate virus scan results; wherein, the virus scan results are used as the scan results of the same files and / or technical components in the virus scanning process of other artifacts.

2. The method according to claim 1, characterized in that, The preset scanning rule information represents the scanning requirements of the technical component during the scanning process.

3. The method according to claim 1, characterized in that, After performing virus scanning processing on the files and / or technical components of the product to be scanned based on the product parsing results, the technical component information, and the product file version information, and generating virus scan results, the method further includes: Receive additional scanning requests for other products; If, based on the other scan requests, it is determined that there are files and / or technical components in the other artifacts that are identical to the target object in the target scan space, then the virus scan results of the identical files and / or technical components in the target scan space are obtained, and the virus scan results of the identical files and / or technical components are used as the virus scan results of the files and / or technical components in the other artifacts.

4. The method according to any one of claims 1-3, characterized in that, The step of parsing the event information of the product to be scanned according to the scanning request, and generating product parsing results and technical component information of the product to be scanned, includes: Based on preset product rule information, and according to the scanning request, the catalog information of the product to be scanned and the files under the catalog information are scanned; The files of the preset type in the directory information are decompressed to generate product parsing results; The files of a preset type in the directory information are scanned for technical components to generate technical component information of the product to be scanned.

5. The method according to claim 4, characterized in that, The product parsing results include details of the product's internal file resources, and the technical component information includes component dependency information and dependency version change information of the product to be scanned.

6. A virus scanning and processing device, characterized in that, include: An acquisition module is used to acquire a scan request; wherein, the scan request includes event information of the product to be scanned, and the event information includes directory information of the product to be scanned and files under the directory information; The parsing module is used to parse the event information of the product to be scanned according to the scanning request, and generate product parsing results and technical component information of the product to be scanned; The generation module is used to generate product file version information based on the product parsing results; the product file version information is used to represent the version information of the product file. The virus scanning module is used to determine whether there are any files in the product file version information that have not been scanned under the virus database version or have been modified, based on the product file version information and the virus database version in the preset virus database. If so, the files that have not been scanned under the virus database version or have been modified are output to the target scanning space. Based on the technical component information and the historical scanning information of the technical components, the module determines whether the technical components in the technical component information have no scanning records or whether the previous scan result does not meet the latest preset scanning rule information. If the technical component has no scanning records or the previous scan result does not meet the latest preset scanning rule information, the technical component is output to the target scanning space. The module performs virus scanning processing on the files and / or technical components in the target scanning space to generate virus scanning results. The virus scanning results are used as the scanning results for the same files and / or technical components during the virus scanning process of other products.

7. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-5.

9. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-5.

Citation Information

Patent Citations

  • Rapid virus scanning and killing method and apparatus

    CN105718800A

  • Virus searching and killing method and device and storage medium

    CN111191232A