A method and apparatus for detecting a virus
By using virus sandbox technology in a cloud environment, virus detection tasks are generated, executed, and then automatically destroyed, solving the problems of cumbersome and unstable virus detection and achieving fast and secure virus detection results.
Patent Information
- Application Number
- CN202411630115.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-14
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2044-11-14
AI Technical Summary
Existing virus detection methods involve cumbersome, insecure, and incomplete virus file creation, making them easily detectable by routine scanning and resulting in unstable detection.
By employing virus sandbox technology, a virus sandbox is generated in a secure, isolated area. Based on the target virus vector and the target execution script, multiple target virus files are generated, and virus detection tasks are performed within the virus sandbox. After the detection is completed, the sandbox is automatically destroyed to ensure the security and stability of the cloud host.
It enables rapid, safe, and reliable virus detection, avoids false alarms, simplifies the testing process, and improves resource reuse and detection stability.
Smart Images

Figure CN119848842B_ABST
Abstract
Description
[0001] The application relates to the technical field of cloud security virus detection, and particularly relates to a virus detection method and device. BACKGROUND
[0002] Cloud security virus detection refers to real-time monitoring and virus detection of a system in a cloud environment by using cloud computing technology and security strategies. The cloud security virus detection can effectively identify, isolate and remove various malicious viruses. With the continuous enrichment and improvement of functions of cloud security products, data needs to be re-created and regression testing needs to be performed after each change in demand to ensure the stability and security of the cloud environment.
[0003] In related technologies, when a user changes virus detection demand each time in a security guard virus detection test process, different types of virus files need to be temporarily constructed, and the virus files need to be deleted immediately after the test is completed, so that the test process is complicated and time-consuming. In addition, in a regular test scanning process of a cloud host, test data is detected by regular scanning for a long time, which causes false positives. If the test data is deleted after the test is completed, the test data needs to be re-uploaded for next time test. If the test is performed on multiple platforms and multiple servers, the virus files need to be repeatedly uploaded and destroyed, which is complicated and risky, and is not conducive to the reuse of resources and the stability evaluation of the test. At the same time, the virus files are not completely deleted by manual operation after the test is completed, which affects the regular scanning report result. SUMMARY
[0004] Therefore, the application provides a virus detection method to solve the problems of complicated virus file manufacturing, unsafe and incomplete virus detection, easy detection by regular scanning and unstable detection in related technologies.
[0005] According to a first aspect, the application provides a virus detection method, which comprises the following steps.
[0006] A virus sandbox generated in a security isolation area is acquired, wherein the virus sandbox is generated based on a target virus carrier and a target execution script;
[0007] A plurality of target virus files are generated in the virus sandbox based on the target virus carrier;
[0008] A virus detection task is performed on the plurality of target virus files in the virus sandbox based on detection execution instructions;
[0009] The virus sandbox is destroyed by the target execution script in response to the end of the virus detection task execution.
[0010] The embodiment of the present disclosure provides a portable virus sandbox on a cloud environment of any cloud host for virus detection. The virus sandbox contains a target virus carrier and a target execution script to realize the manufacturing and destruction process of a target virus file, thereby forming a convenient and safe detection environment. The virus sandbox can be transplanted to a server for detection, which can cover different types of target virus files. When detection is needed, the virus sandbox can be transplanted to the cloud host to be detected at any time, and the target execution script can automatically generate the target virus carrier in the virus sandbox and generate a large number of different types of target virus files. After the test is completed, the entire virus sandbox is destroyed, and finally a fast and safe and reliable detection method is formed.
[0011] In some optional embodiments, the virus sandbox is generated based on the target virus carrier and the target execution script, and includes:
[0012] Obtaining an original virus file and a target execution script;
[0013] Splitting the original virus file into a plurality of sub-files according to a preset rule; wherein the plurality of sub-files are sequentially numbered;
[0014] Selecting sub-files belonging to the same category from the plurality of sub-files; wherein the sub-files belonging to the same category use the same serial number;
[0015] Encrypting the plurality of sub-files according to a preset ciphertext respectively;
[0016] Loading the plurality of sub-files encrypted respectively into the target virus carrier according to the serial numbers corresponding thereto;
[0017] Generating the virus sandbox based on the target execution script and the target virus carrier encrypted respectively.
[0018] The embodiment of the present disclosure synthesizes the target virus carrier and the target execution script to generate the virus sandbox, which separates the normal working environment of the cloud host and the sandbox environment of the virus sandbox, thereby ensuring the normal working of the cloud host. In addition, the original virus file is split and encrypted in the virus sandbox, and cannot be detected by virus scanning before the target execution script is triggered, which greatly reduces the false alarm possibility of regular scanning and lays a foundation for the sustainability of virus detection.
[0019] In some optional embodiments, based on the target virus carrier, a plurality of target virus files are generated in the virus sandbox, including:
[0020] Decrypting the plurality of sub-files from the virus sandbox according to a preset ciphertext;
[0021] Selecting sub-files belonging to the same category from the plurality of sub-files; wherein the sub-files belonging to the same category use the same serial number;
[0022] The target execution script generates multiple target virus files in the virus sandbox based on sub-files belonging to the same category.
[0023] The virus sandbox is run in the cloud environment of the cloud host, and multiple target virus files of different types are decrypted from the virus sandbox, which avoids the problem that the user needs to temporarily construct virus files of different categories after changing the virus detection requirement each time, resulting in a tedious and time-consuming test process.
[0024] In some optional embodiments, based on the detection execution instruction, the virus detection task is performed on the multiple target virus files in the virus sandbox, including:
[0025] Based on the target execution script, a detection request instruction is sent to the virus detection service center;
[0026] The detection execution instruction issued by the virus detection service center is received;
[0027] The detection execution instruction is called from the virus detection interface through the target execution script;
[0028] Based on the detection execution instruction, the virus detection task is performed on the multiple target virus files in the virus sandbox.
[0029] The virus sandbox is run in the cloud environment of the cloud host based on the interaction instruction between the cloud host and the detection service center, and the virus detection task is performed under the premise that the detection service center allows detection, so as to ensure the safe operation of the cloud host, and to quickly and accurately complete the virus detection task by using the virus sandbox combined with user requirements.
[0030] In some optional embodiments, the virus detection method in the present disclosure further includes:
[0031] The virus detection result is obtained;
[0032] The virus detection result is uploaded to the virus detection service center.
[0033] The virus detection result is uploaded to the virus detection service center after the virus detection task is performed, which is beneficial for the virus detection service center to configure a virus killing strategy based on the virus detection result.
[0034] In some optional embodiments, during the execution of the virus detection task, the virus monitoring instruction is called from the virus detection interface in real time through the target execution script to poll the current progress of the multiple virus detection tasks in the virus sandbox.
[0035] The embodiments of the present disclosure monitor the current progress of multiple virus detection tasks in real time, and facilitate timely learning of the current detection state of the virus detection task at any time.
[0036] According to a second aspect, the embodiments of the present disclosure provide a virus detection device, the device comprising:
[0037] The acquisition module is configured to acquire a virus sandbox generated in the secure isolation area, wherein the virus sandbox is generated based on a target virus carrier and a target execution script;
[0038] The generation module is configured to generate a plurality of target virus files in the virus sandbox based on the target virus carrier;
[0039] The execution module is configured to execute a virus detection task on the plurality of target virus files in the virus sandbox based on a detection execution instruction;
[0040] The destruction module is configured to destroy the virus sandbox by the target execution script in response to the end of the virus detection task execution.
[0041] According to a third aspect, the present disclosure provides a computer device, comprising a memory and a processor, the memory and the processor are communicatively connected, the memory stores computer instructions, and the processor executes the computer instructions to perform the virus detection method of the first aspect or any of the corresponding embodiments.
[0042] According to a fourth aspect, the present disclosure provides a computer readable storage medium, the computer readable storage medium stores computer instructions, and the computer instructions are used to make a computer execute the virus detection method of the first aspect or any of the corresponding embodiments.
[0043] According to a fifth aspect, the present disclosure provides a computer program product, comprising computer instructions, and the computer instructions are used to make a computer execute the virus detection method of the first aspect or any of the corresponding embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0044] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings needed to be used in the specific embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.
[0045] Figure 1 is a flowchart of the virus detection method according to the embodiments of the present application;
[0046] Figure 2 is a schematic diagram of the virus sandbox according to the embodiments of the present application;
[0047] Figure 3 is a flowchart of another virus detection method according to an embodiment of the present application;
[0048] Figure 4 is a flowchart of yet another virus detection method according to an embodiment of the present application;
[0049] Figure 5 is a flowchart of yet another virus detection method according to an embodiment of the present application;
[0050] Figure 6 is an interaction diagram between a virus detection service center and a cloud host according to an embodiment of the present application;
[0051] Figure 7 is a flowchart of still another virus detection method according to an embodiment of the present application;
[0052] Figure 8 is a diagram of a cloud host cluster equipped with a virus sandbox according to an embodiment of the present application;
[0053] Figure 9 is a structural block diagram of a virus detection device according to an embodiment of the present application;
[0054] Figure 10 is a hardware structure diagram of a computer device according to an embodiment of the present application. DETAILED DESCRIPTION
[0055] In order to make the objects, technical solutions and advantages of embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the protection scope of the present application.
[0056] According to an embodiment of the present application, a virus detection method embodiment is provided. It should be noted that the steps shown in the flowchart of the drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.
[0057] In the present embodiment, a virus detection method is provided, which can be used in cloud servers, mobile terminals such as mobile phones, tablet computers, etc. Figure 1 is a flowchart of a virus detection method according to an embodiment of the present application, as shown in Figure 1 the flowchart includes the following steps:
[0058] Step S101, acquire a virus sandbox generated in a security isolation area; wherein the virus sandbox is generated based on a target virus carrier and a target execution script.
[0059] Specifically, the embodiments of the present disclosure are applied in the scenario of executing virus detection on a cloud host in a cloud server, which can be virus detection of the cloud host in a starting state or a running state. The security isolation area is an isolation area specially used for detecting viruses, which is isolated from the normal working area. The virus detection in the security isolation area ensures the security of the cloud host performing other work tasks in the normal working area. The virus sandbox is formed in the security isolation area to detect virus files in the target virus carrier through the target execution script. Therefore, the virus sandbox is generated based on the target virus carrier and the target execution script. The target virus carrier is a medium capable of carrying virus components, which does not constitute a threat by itself, but can cause a butterfly effect through the triggering of other substances, thereby generating one or more virus files. The target execution script is some program execution code written by a user, which is mainly used for executing virus detection tasks and destroying virus files. If more functions are desired, program codes of corresponding functions are programmed in the target execution script. Figure 2 As shown in the figure, it is a schematic diagram of the virus sandbox in the embodiments of the present disclosure.
[0060] In addition, the virus sandbox is pre-generated and has portability, which is suitable for any cloud host, thereby improving the flexibility of virus reuse and making it more convenient and efficient to change test content using the pre-generated virus sandbox.
[0061] Step S102, generate a plurality of target virus files in the virus sandbox based on the target virus carrier.
[0062] Specifically, the target virus carrier carries a plurality of virus files, which are combined in the virus sandbox to generate a plurality of target virus files. The process of generating a plurality of target virus files is described below.
[0063] The embodiments of the present disclosure directly generate a batch of target virus files of multiple types in the virus sandbox through the target virus carrier, which avoids the problem that the user temporarily constructs different types of virus files after changing virus detection requirements each time, resulting in a tedious and time-consuming test process. Therefore, directly generating a batch of target virus files of multiple types in the virus sandbox not only meets the different detection requirements of users, but also significantly improves the virus detection efficiency and simplifies the detection process.
[0064] Step S103, execute a virus detection task on the plurality of target virus files in the virus sandbox based on a detection execution instruction.
[0065] Specifically, the detection execution instruction here can come from a virus detection service center. The virus detection task here can be one or more.
[0066] The embodiment of the disclosure runs a virus sandbox under a cloud environment of a cloud host to perform a virus detection task, ensuring safe work of the cloud host.
[0067] Step S104, in response to the end of the virus detection task execution, destroying the virus sandbox through the target execution script.
[0068] Specifically, after the virus detection task ends, the virus sandbox is automatically destroyed through the target execution script, avoiding incomplete manual destruction of the virus file and affecting the virus detection accuracy. Therefore, the automatic destruction of the virus sandbox is safe and residue-free, and even if attacked, it will not affect the normal business, ensuring the safety and stability of the detection environment.
[0069] In addition, the virus sandbox of the embodiment of the disclosure has portability and can be configured based on the target execution script and the target virus carrier in any cloud host. The configuration process is convenient and simple. Since the target virus file is loaded in the target virus carrier of the virus sandbox, even if the cloud host is in the process of regular test scanning, the test data will not be detected by the regular scanning due to long-term storage, thereby causing false positives. Furthermore, the virus sandbox is pre-generated and called at any time, avoiding the tedious process of repeatedly uploading batch test data. The virus detection task is performed in the virus sandbox, which not only has low risk but also is conducive to resource reuse and test stability evaluation.
[0070] In the embodiment, a virus detection method is provided, which can be used in cloud servers, mobile terminals such as mobile phones and tablet computers, Figure 3 is a flowchart of the virus detection method according to the embodiment of the disclosure, as Figure 3 shown, the virus sandbox is generated based on the target virus carrier and the target execution script, and includes:
[0071] Step S301, obtaining an original virus file and a target execution script.
[0072] Specifically, the original virus file is a virus file initially constructed, and the original virus file is uploaded to the cloud host by the user.
[0073] The target execution script is some program execution code written by the user. The target execution script is mainly used to execute the virus detection task and destroy the virus file. If more functions are desired, program codes of corresponding functions are programmed in the target execution script.
[0074] Step S302, splitting the original virus file into a plurality of sub-files according to a preset rule; wherein the plurality of sub-files are sequentially numbered.
[0075] Specifically, the original virus file is split into multiple parts according to a preset rule, each part is a sub-file, and the multiple sub-files are sequentially numbered in increasing order. The preset rule can be a rule set flexibly based on user demand, for example, the original virus file is split according to the data size. As shown in the figure, it is a schematic diagram of a virus sandbox running in a cloud host. Figure 3 As shown in the figure, it is a schematic diagram of a virus sandbox running in a cloud host. Figure 3 In the embodiment of the disclosure, the virus sandbox runs in the cloud host and is used for performing a virus detection task.
[0076] Step S303, selecting sub-files belonging to the same category from the multiple sub-files; wherein the sub-files belonging to the same category use the same serial number.
[0077] Specifically, the multiple sub-files are classified, and sub-files of the same category are identified using the same serial number. For example, the multiple sub-files using the serial number AL00S10 are sub-files numbered 1, 3, 5, 9, and 11.
[0078] Step S304, respectively encrypting the multiple sub-files according to a preset ciphertext.
[0079] Specifically, the preset ciphertext is a pre-set password, and the multiple sub-files are respectively encrypted using the preset ciphertext.
[0080] The embodiment of the disclosure splits and encrypts the original virus file in the virus sandbox, which cannot be detected by virus scanning before the target execution script is triggered, greatly reducing the false positive rate of regular scanning, and laying a foundation for the sustainability of virus detection.
[0081] Step S305, generating a virus sandbox based on the target execution script and the target virus carrier respectively encrypted.
[0082] The target virus carrier and the target execution text are synthesized at the same time, and then a virus sandbox is generated. The virus sandbox separates the normal working environment of the cloud host and the sandbox environment of the virus sandbox from each other, thereby ensuring that the cloud host can work normally.
[0083] The embodiment of the disclosure runs the virus sandbox in the cloud environment of the cloud host, and generates multiple target virus files of different types in the virus sandbox and loads them in the target virus carrier, avoiding the problem that the user needs to temporarily construct different types of virus files after changing the virus detection demand each time, resulting in a tedious and time-consuming test process. The embodiment of the disclosure pre-forms multiple types of target virus files in the virus sandbox to meet different detection needs of users, without the need to temporarily construct a batch of different types of virus files, simplifying the virus detection process and improving the virus detection efficiency.
[0084] In addition, the virus sandbox of the embodiment of the present disclosure has the characteristic of portability, and can be equipped based on a target execution script and a target virus carrier in any cloud host. The equipping process is convenient and simple. Since the target virus file is loaded in the target virus carrier of the virus sandbox, even if the cloud host is in the process of regular test scanning, the test data will not be detected by the regular scanning due to long-term storage, thereby causing false alarm. In addition, the virus sandbox is pre-generated and called at any time, thereby avoiding the tedious process of repeatedly uploading batch test data. The virus detection task is performed in the virus sandbox, which is not only low-risk but also conducive to the reuse of resources and the stability evaluation of the test.
[0085] In the embodiment, a virus detection method is provided, which can be used in a cloud server, a mobile terminal such as a mobile phone, a tablet computer, etc. Figure 4 The flowchart of the virus detection method according to the embodiment of the present disclosure is shown in FIG. 1. Figure 4 As shown in FIG. 1, based on a target virus carrier, a plurality of target virus files are generated in a virus sandbox. The flowchart includes the following steps:
[0086] In step S401, a plurality of sub-files are decrypted from the virus sandbox according to a preset ciphertext.
[0087] Specifically, the decryption process here is the inverse process of the encryption process described above, and a plurality of sub-files are decrypted from the virus sandbox according to a preset ciphertext.
[0088] In step S402, sub-files belonging to the same category are selected from the plurality of sub-files, wherein the sub-files belonging to the same category use the same serial number.
[0089] Specifically, the sub-files belonging to the same category are selected, and specific reference can be made to the examples described above, which will not be described here again.
[0090] In step S403, based on the sub-files belonging to the same category, a plurality of target virus files are generated in the virus sandbox by a target execution script.
[0091] Specifically, the target execution file is triggered, and a plurality of target virus files are generated in the virus sandbox according to the same serial number of the same sub-files.
[0092] In the embodiment, a virus detection method is provided, which can be used in a cloud server, a mobile terminal such as a mobile phone, a tablet computer, etc.
[0093] In the embodiment, a virus detection method is provided, which can be used in a cloud server, a mobile terminal such as a mobile phone, a tablet computer, etc. Figure 5 The flowchart of the virus detection method according to the embodiment of the present disclosure is shown in FIG. 1. Figure 5As shown, based on the detection execution instruction, the virus detection task is performed on the plurality of target virus files in the virus sandbox, and the process includes the following steps:
[0094] In step S501, based on the target execution script, a detection request instruction is sent to the virus detection service center.
[0095] In step S502, the detection execution instruction issued by the virus detection service center is received.
[0096] Specifically, the interaction scenario between the virus detection service center and the cloud host is involved here. Figure 6 As shown, the cloud host issues a detection request instruction to the detection service center based on the target execution script, the user's detection requirements are written on the target execution script, and the virus detection service center issues a detection execution instruction to the cloud host based on the detection request instruction. Therefore, the cloud host receives the detection execution instruction issued by the detection service center.
[0097] In step S503, the detection execution instruction is called from the virus detection interface through the target execution script.
[0098] In step S504, based on the detection execution instruction, the virus detection task is performed on the plurality of target virus files in the virus sandbox.
[0099] Specifically, after the target virus file is manufactured, the detection execution instruction from the virus detection service center is called from the virus detection interface of the cloud host through the target execution script, and the virus detection task is performed on the plurality of virus files in the virus sandbox.
[0100] The embodiments of the present disclosure are based on the interaction instruction between the cloud host and the detection service center. Under the premise that the detection service center allows detection, the virus sandbox is run in the cloud environment of the cloud host to perform the virus detection task, which ensures the safe operation of the cloud host, and uses the virus sandbox to quickly and accurately complete the virus detection task combined with user requirements.
[0101] In the present embodiment, a virus detection method is provided, which can be used in cloud servers, mobile terminals such as mobile phones, tablet computers, etc. Figure 7 The flowchart of the virus detection method according to the embodiments of the present application is shown in FIG. 1, which further includes: Figure 7
[0102] In step S105, the virus detection result is obtained.
[0103] In step S106, the virus detection result is uploaded to the virus detection service center.
[0104] Specifically, referring to Figure 6 After the virus detection task is executed, the virus detection result is uploaded to the virus detection service center, so that the virus detection service center configures a virus killing strategy based on the virus detection result.
[0105] In some optional embodiments, during the execution of the virus detection task, the virus monitoring instruction is called from the virus detection interface in real time by the target execution script to poll the current progress of the plurality of virus detection tasks in the virus sandbox.
[0106] Specifically, after the target virus file is manufactured, the virus detection interface is called by the target execution script, and the virus monitoring instruction is called in real time to poll the current progress of the plurality of virus detection tasks in the virus sandbox.
[0107] The embodiments of the present disclosure monitor the current progress of the plurality of virus detection tasks in real time, so that the current detection state of the virus detection task can be learned at any time.
[0108] Therefore, as Figure 8 shown, the embodiments of the present disclosure provide a virus sandbox with portability on the cloud environment of any cloud host for virus detection. The virus sandbox contains a target virus carrier cooperating with a target execution script to implement the manufacturing and destruction process of a target virus file, and thus a convenient and safe detection environment can be formed. The virus sandbox can be transplanted as a whole to a server to be detected for detection, and can cover different types of target virus files. When detection is needed, the virus sandbox can be transplanted to a cloud host to be detected at any time, and the target execution script can be executed to automatically generate a target virus carrier in the virus sandbox, and a large number of different types of target virus files can be generated. After the test is completed, the entire virus sandbox is destroyed, and finally a fast and safe and reliable detection method is formed.
[0109] In the embodiments, a virus detection device is also provided, which is used to implement the above embodiments and preferred embodiments, and will not be described again. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware, or a combination of software and hardware can also be implemented and conceived.
[0110] The embodiments provide a virus detection device, as Figure 9 shown, comprising:
[0111] The acquisition module 91 is configured to acquire a virus sandbox generated in a secure isolation area; wherein the virus sandbox is generated based on a target virus carrier and a target execution script;
[0112] The generation module 92 is configured to generate a plurality of target virus files in the virus sandbox based on the target virus carrier;
[0113] The execution module 93 is configured to execute a virus detection task on the target virus files in the virus sandbox based on the detection execution instruction.
[0114] The destruction module 94 is configured to destroy the virus sandbox through the target execution script in response to the end of the virus detection task execution.
[0115] In some optional embodiments, the acquisition module 91 comprises a sandbox generation submodule, which comprises:
[0116] The acquisition unit is configured to acquire the original virus file and the target execution script.
[0117] The splitting unit is configured to split the original virus file into a plurality of subfiles according to a preset rule; wherein the plurality of subfiles are sequentially numbered.
[0118] The selection unit is configured to select subfiles belonging to the same category from the plurality of subfiles; wherein the subfiles belonging to the same category use the same serial number.
[0119] The encryption unit is configured to encrypt the plurality of subfiles according to a preset ciphertext respectively.
[0120] The loading unit is configured to load the plurality of subfiles encrypted respectively into the target virus carrier according to the serial numbers corresponding thereto.
[0121] The generation unit is configured to generate the virus sandbox based on the target execution script and the target virus carrier encrypted respectively.
[0122] In some optional embodiments, the generation module 92 comprises:
[0123] The decryption submodule is configured to decrypt the plurality of subfiles from the virus sandbox according to a preset ciphertext.
[0124] The selection submodule is configured to select subfiles belonging to the same category from the plurality of subfiles; wherein the subfiles belonging to the same category use the same serial number.
[0125] The generation submodule is configured to generate a plurality of target virus files in the virus sandbox through the target execution script based on the subfiles belonging to the same category.
[0126] In some optional embodiments, the execution module 93 comprises:
[0127] The sending submodule is configured to send a detection request instruction to a virus detection service center based on the target execution script.
[0128] The receiving submodule is configured to receive a detection request instruction issued by the virus detection service center.
[0129] The calling submodule is configured to call the detection execution instruction from the virus detection interface through the target execution script;
[0130] The execution submodule is configured to execute the virus detection task on the plurality of target virus files in the virus sandbox based on the detection execution instruction.
[0131] In some optional embodiments, the virus detection device further comprises:
[0132] The detection result output module is configured to obtain the virus detection result.
[0133] The detection result uploading module is configured to upload the virus detection result to a virus detection service center.
[0134] In some optional embodiments, the execution module 93 is further configured to call the virus monitoring instruction from the virus detection interface through the target execution script in real time to poll and monitor the current progress of the plurality of virus detection tasks in the virus sandbox during the execution of the virus detection task.
[0135] Further function descriptions of the above-mentioned modules and units are the same as those of the corresponding embodiments, and will not be described here again.
[0136] The virus detection device in the embodiment is presented in the form of a functional unit. The unit herein refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and a memory that execute one or more software or fixed programs, and / or other devices that can provide the above-mentioned functions.
[0137] The embodiment of the present application further provides a computer device with the above-mentioned virus detection device.
[0138] Please refer to Figure 10 , Figure 10 is a structural schematic diagram of a computer device provided by an optional embodiment of the present application, as Figure 10As shown, the computer device includes one or more processors 10, memory 20, and interfaces 30 for the various components to communicate with one another. The various components communicate through the use of the various buses, and can be mounted on a common motherboard or in other manners as appropriate. The processor 10 can process instructions for execution within the computer device, including instructions stored in the memory 20 or elsewhere within the computer device. In some optional embodiments, multiple processors 10 and / or multiple buses can be employed as appropriate. Also, various components of the computer device can be used in combination, located in various physical locations, coupled directly or indirectly, and / or distributed throughout one or more networks. Figure 10 The processor 10 is taken as an example.
[0139] The processor 10 can be a central processing unit, a network processor, or a combination thereof. The processor 10 can further include a hardware chip. The hardware chip can be an application specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device can be a complex programmable logic device, a field programmable logic device, a general array logic, or any combination thereof.
[0140] The memory 20 stores instructions that can be executed by the at least one processor 10, so that the at least one processor 10 implements the method shown in the above embodiments.
[0141] The memory 20 can include a program region and a data region. The program region can store an operating system and an application program required by at least one function. The data region can store data created according to the use of the computer device, and the like. In addition, the memory 20 can include a high-speed random access memory, and can further include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some optional embodiments, the memory 20 can optionally include a memory disposed remotely with respect to the processor 10, and these remote memories can be connected to the computer device through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0142] The memory 20 can include a volatile memory, such as a random access memory, and can also include a non-volatile memory, such as a flash memory, a hard disk, or a solid state disk. The memory 20 can further include a combination of the above-mentioned kinds of memories.
[0143] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or communication networks.
[0144] The embodiments of the present application further provide a computer readable storage medium, and the method according to the embodiments of the present application can be implemented in hardware, firmware, or recorded in a storage medium, or stored in a remote storage medium or a non-transitory machine readable storage medium and downloaded to a local storage medium through network, so that the method described herein can be processed by such software on a storage medium using a general purpose computer, a special purpose processor, or programmable or special hardware. The storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid state disk, etc. Further, the storage medium can also include a combination of the above-mentioned memories. It can be understood that the computer, the processor, the microprocessor controller, or the programmable hardware includes a storage component that can store or receive software or computer code, when the software or computer code is accessed and executed by the computer, the processor, or the hardware, the method shown in the above embodiments is implemented.
[0145] Part of the present application can be applied as a computer program product, for example, computer program instructions, when executed by a computer, the operation of the computer can invoke or provide the method and / or technical solutions according to the present application. Those skilled in the art should understand that the form of computer program instructions in computer readable medium includes but is not limited to source file, executable file, installation package file, etc. Correspondingly, the way of computer program instructions executed by computer includes but is not limited to: the computer directly executes the instructions, or the computer compiles the instructions and then executes the corresponding compiled program, or the computer reads and executes the instructions, or the computer reads and installs the instructions and then executes the corresponding installed program. Here, the computer readable medium can be any available computer readable storage medium or communication medium accessible to the computer.
[0146] Although the embodiments of the present application are described in conjunction with the accompanying drawings, various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present application, and such modifications and changes fall within the scope defined by the appended claims.
Claims
1. A method of detecting a virus, characterized by, The method comprises: acquiring a virus sandbox generated in a secure isolation area; wherein the virus sandbox is generated based on a target virus carrier and a target execution script; generating a plurality of target virus files in the virus sandbox based on the target virus carrier; performing a virus detection task on the plurality of target virus files in the virus sandbox based on a detection execution instruction; destroying the virus sandbox through the target execution script in response to the end of the virus detection task execution; The virus sandbox is generated based on a target virus carrier and a target execution script, comprising: acquiring an original virus file and a target execution script; splitting the original virus file into a plurality of sub-files according to a preset rule; wherein the plurality of sub-files are sequentially numbered in order; selecting sub-files belonging to the same category from the plurality of sub-files; wherein sub-files belonging to the same category use the same serial number; encrypting the plurality of sub-files according to a preset ciphertext respectively; loading the plurality of sub-files encrypted respectively into the target virus carrier according to the serial numbers corresponding thereto; generating the virus sandbox based on the target execution script and the target virus carrier encrypted respectively; Generating a plurality of target virus files in the virus sandbox based on the target virus carrier, comprising: decrypting the plurality of sub-files from the virus sandbox according to the preset ciphertext; selecting sub-files belonging to the same category from the plurality of sub-files; wherein sub-files belonging to the same category use the same serial number; generating the plurality of target virus files in the virus sandbox through the target execution script based on the sub-files belonging to the same category.
2. The method of claim 1, wherein, Performing a virus detection task on the plurality of target virus files in the virus sandbox based on a detection execution instruction, comprising: sending a detection request instruction to a virus detection service center based on the target execution script; receiving a detection execution instruction issued by the virus detection service center; calling the detection execution instruction from a virus detection interface through the target execution script; performing a virus detection task on the plurality of target virus files in the virus sandbox based on the detection execution instruction.
3. The method of claim 1, wherein, Further comprising: acquiring a virus detection result; uploading the virus detection result to a virus detection service center.
4. The method according to any one of claims 1 to 3, characterized in that, In the process of performing a virus detection task, a virus monitoring instruction is called from a virus detection interface in real time through the target execution script to poll and monitor the current progress of a plurality of virus detection tasks in the virus sandbox.
5. A viral detection device, characterized in that, The device comprises: an acquisition module for acquiring a virus sandbox generated in a secure isolation area; wherein the virus sandbox is generated based on a target virus carrier and a target execution script; a generation module for generating a plurality of target virus files in the virus sandbox based on the target virus carrier; an execution module for performing a virus detection task on the plurality of target virus files in the virus sandbox based on a detection execution instruction; a destruction module for destroying the virus sandbox through the target execution script in response to the end of the virus detection task execution; The acquisition module comprises a sandbox generation submodule, which comprises: An acquisition unit is configured to acquire an original virus file and a target execution script. A splitting unit is configured to split the original virus file into a plurality of sub-files according to a preset rule; the plurality of sub-files are sequentially numbered. A selection unit is configured to select sub-files belonging to the same category from the plurality of sub-files; the sub-files belonging to the same category use the same serial number. An encryption unit is configured to encrypt the plurality of sub-files according to a preset cipher text. A loading unit is configured to load the plurality of sub-files encrypted respectively into a target virus carrier according to the serial numbers corresponding thereto. A generation unit is configured to generate a virus sandbox based on the target execution script and the target virus carrier encrypted respectively. A generation module includes: A decryption sub-module is configured to decrypt the plurality of sub-files from the virus sandbox according to the preset cipher text. A selection sub-module is configured to select sub-files belonging to the same category from the plurality of sub-files; the sub-files belonging to the same category use the same serial number. A generation sub-module is configured to generate a plurality of target virus files in the virus sandbox through the target execution script based on the sub-files belonging to the same category.
6. A computer device, comprising: A memory and a processor are communicatively connected, and the memory stores computer instructions; the processor executes the computer instructions to perform the virus detection method of any one of claims 1 to 4. The computer readable storage medium stores computer instructions for causing a computer to perform the virus detection method of any one of claims 1 to 4.
7. A computer readable storage medium characterized in that, The computer instructions are configured to cause a computer to perform the virus detection method of any one of claims 1 to 4.
8. A computer program product, characterised in that,
Citation Information
Patent Citations
Virus detection method and device
CN115495740A
Virus searching and killing drill method, device and equipment and storage medium
CN117251845A