Methods and devices for detecting false alarms in network products, storage media, and computer equipment
By working together with the front-end page module, back-end processing module, and antivirus module, false alarms in network products are automatically detected, solving the problem of low efficiency caused by relying on manual methods in existing technologies, and achieving efficient false alarm detection and handling.
Patent Information
- Application Number
- CN202411769444.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-04
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-12-04
AI Technical Summary
In existing technologies, false alarms caused by updates to the virus signature database after software product release cannot be detected in a timely manner. Relying on manual methods is inefficient and burdensome, and cannot achieve real-time feedback.
Through the collaborative work of the front-end page module, back-end processing module, and anti-drug module, automated anti-drug detection is achieved. It integrates multiple anti-drug software, generates anti-drug result data, and stores it in the database. The front-end page module provides an intuitive display of the results.
It enables automated false alarm detection for network products, improves the ability to detect false alarms, reduces manual intervention, and enhances response speed and work efficiency.
Smart Images

Figure CN119865329B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet technology, and in particular to a method and apparatus for detecting false alarms in network products, a storage medium, and a computer device. Background Technology
[0002] In the current software development and operations environment, software companies and internet service providers face severe security challenges, especially in virus detection and prevention after product release. After product release, executable files (PE files) on the Windows platform, application packages (APK files) on the Android operating system, and various website resources may be falsely flagged as containing malicious code due to continuous updates to virus signature databases. These false positives are often delayed; they may go undetected initially, but as major security software vendors continuously update their virus signature databases, files or websites that were previously unmarked may later be mistakenly identified as carrying viruses.
[0003] Traditionally, to address this challenge, companies have relied on manual methods, periodically submitting product-related documents or website addresses to third-party services for review. While this approach can identify potential false alarms to some extent, its inherent limitations are obvious: First, it is highly dependent on manual operation, which is not only inefficient but also prone to human error leading to the failure to detect false alarms in a timely manner; second, with the accelerating pace of product iteration and the surge in the number of documents, this manual submission and monitoring method has gradually become a heavy human burden, seriously affecting the team's response speed and overall work efficiency; finally, for false alarms that require immediate response, manual monitoring often cannot provide timely feedback. Summary of the Invention
[0004] In view of this, this application provides a method and apparatus for detecting false alarms in network products, a storage medium, and a computer device. Through the collaborative work of a front-end page module, a back-end processing module, and a virus scanning module, it realizes automated virus scanning and detection of network products and provides intuitive result display, which helps to improve the ability to detect false alarms in network products and facilitates relevant personnel to discover and handle false alarm situations in a timely manner.
[0005] According to one aspect of this application, a method for detecting false alarms in a network product is provided, comprising:
[0006] The front-end page module responds to the anti-drug task creation instruction, outputs the anti-drug task creation interface, and determines the acquisition method information of at least one network product based on the anti-drug task creation interface, and creates the target anti-drug task according to the acquisition method information.
[0007] The backend processing module receives the target antivirus task and obtains the acquisition method information of each network product contained in the target antivirus task. Based on the acquisition method information, it obtains the target file of each network product.
[0008] The antivirus module sends each target file to the antivirus task execution object, so that the antivirus task execution object can determine whether there are virus characteristics in each network product based on the target file, and obtain antivirus result data based on the virus characteristic determination result. The antivirus task execution object integrates multiple antivirus software.
[0009] The anti-virus module receives anti-virus result data for each network product returned by the anti-virus task execution object, and stores the anti-virus result data in the target database;
[0010] The backend processing module retrieves the drug scan result data from the target database based on the drug scan result viewing instruction transmitted by the frontend page module, and feeds back the drug scan result data to the frontend page module;
[0011] The front-end page module determines the display content corresponding to each network product based on the anti-drug results data, so that relevant personnel can identify network products with false alarms based on the display content.
[0012] According to another aspect of this application, a false alarm detection device for a network product is provided, comprising:
[0013] The front-end page module is used to respond to the anti-drug task creation instruction, output the anti-drug task creation interface, and determine the acquisition method information of at least one network product based on the anti-drug task creation interface, and create the target anti-drug task according to the acquisition method information.
[0014] The backend processing module is used to receive the target anti-virus task, obtain the acquisition method information of each network product contained in the target anti-virus task, and obtain the target file of each network product based on the acquisition method information;
[0015] The anti-virus module is used to send each target file to the anti-virus task execution object, so that the anti-virus task execution object can determine whether there are virus characteristics in each network product based on the target file, and obtain anti-virus result data based on the judgment result of the virus characteristics. The anti-virus task execution object integrates multiple anti-virus software.
[0016] The anti-virus module is also used to receive anti-virus result data for each network product returned by the anti-virus task execution object, and store the anti-virus result data in the target database;
[0017] The backend processing module is also used to obtain the drug scan result data from the target database based on the drug scan result viewing instruction transmitted by the frontend page module, and to feed back the drug scan result data to the frontend page module;
[0018] The front-end page module is also used to determine the display content corresponding to each network product based on the anti-drug result data, so that relevant personnel can identify network products with false alarms based on the display content.
[0019] According to another aspect of this application, a storage medium is provided that stores a computer program thereon, which, when executed by a processor, implements the false alarm detection method of the network product described above.
[0020] According to another aspect of this application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor executes the program to implement the false alarm detection method of the network product described above.
[0021] Using the above technical solution, this application provides a method and apparatus, storage medium, and computer equipment for detecting false positives of network products. After receiving a virus scanning task creation instruction, the front-end page module can display an interface for creating a virus scanning task. Users input or select the acquisition method information for network products through the virus scanning task creation interface. Based on the user-input acquisition method information, the front-end page module can construct a target virus scanning task. The back-end processing module is responsible for receiving the target virus scanning task created by the front-end page module, determining the acquisition method information according to the target virus scanning task, and downloading, extracting, or accessing the target files of each network product according to each acquisition method information. Then, the virus scanning module sends the received target files to a virus scanning task execution object that integrates multiple virus scanning software, and receives the virus scanning result data returned by the virus scanning task execution object, storing it in a target database. Subsequently, after receiving a virus scanning result viewing instruction, the back-end processing module can retrieve the corresponding virus scanning result data from the target database and send the retrieved virus scanning result data to the front-end page module. Based on the received virus scanning result data, the front-end page module generates corresponding display content (such as status icons, text descriptions, etc.) for each network product, so that relevant personnel can quickly identify network products with false positives. This application embodiment achieves automated virus detection of network products through the collaborative work of the front-end page module, back-end processing module, and antivirus module, and provides intuitive result display, which helps to improve the ability to detect false alarms of network products and facilitates relevant personnel to discover and handle false alarms in a timely manner.
[0022] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0023] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0024] Figure 1 A flowchart illustrating a false alarm detection method for a network product provided in an embodiment of this application is shown.
[0025] Figure 2 This illustration shows a schematic diagram of the structure of a false alarm detection device for a network product provided in an embodiment of this application;
[0026] Figure 3 A schematic diagram of the device structure of a computer device provided in an embodiment of this application is shown. Detailed Implementation
[0027] The present application will be described in detail below with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in the embodiments of the present application can be combined with each other.
[0028] This embodiment provides a method for detecting false alarms in network products, such as... Figure 1 As shown, the method includes:
[0029] Step 101: The front-end page module responds to the anti-virus task creation instruction, outputs the anti-virus task creation interface, and determines the acquisition method information of at least one network product based on the anti-virus task creation interface, and creates the target anti-virus task according to the acquisition method information.
[0030] Step 102: The backend processing module receives the target antivirus task and obtains the acquisition method information of each network product contained in the target antivirus task. Based on the acquisition method information, it obtains the target file of each network product.
[0031] Step 103: The antivirus module sends each target file to the antivirus task execution object, so that the antivirus task execution object can determine whether there are virus characteristics in each network product based on the target file, and obtain antivirus result data based on the judgment result of the virus characteristics. The antivirus task execution object integrates multiple antivirus software.
[0032] Step 104: The anti-virus module receives anti-virus result data for each network product returned by the anti-virus task execution object, and stores the anti-virus result data in the target database.
[0033] Step 105: The backend processing module retrieves the anti-drug result data from the target database based on the anti-drug result viewing instruction transmitted by the frontend page module, and feeds back the anti-drug result data to the frontend page module.
[0034] Step 106: The front-end page module determines the display content corresponding to each network product based on the anti-drug result data, so that relevant personnel can identify network products with false alarms based on the display content.
[0035] This application provides a method for detecting false positives in network products, which is applied to a false positive detection device for network products. The false positive detection device for network products may specifically include a front-end page module, a back-end processing module, a virus scanning module, etc. This method can efficiently and accurately detect whether there are cases in network products that are falsely reported as viruses.
[0036] In this embodiment, when a user or system administrator wants to initiate a new antivirus scan task, they can trigger the task creation instruction by clicking a button or similar method. Upon receiving this instruction, the front-end page module can display an interface for creating an antivirus scan task. This interface can include various necessary input fields, such as the acquisition method of the network product and its associated project. The user inputs or selects the acquisition method information of the network product through the antivirus scan task creation interface, such as URL links, file paths, cloud storage locations, etc., thereby identifying the network product that needs to be scanned. Here, the network product can be a website, software, etc. Based on the acquisition method information input by the user, the front-end page module can construct a target antivirus scan task, which contains relevant information about the network product to be detected. Here, a single target antivirus scan task can include acquisition method information for multiple network products simultaneously, allowing multiple network products to be scanned at the same time.
[0037] The backend processing module is responsible for receiving target antivirus tasks created by the frontend page module, determining the acquisition method information based on the target antivirus task, and downloading, extracting, or accessing the target files of each network product according to each acquisition method. Here, when the network product is software, the target files can be the software's executable file or related resource files. These files are necessary for the software to run and contain the software's code, data, configuration information, etc. When the network product is a website, the target files can be source code files (such as .html, .css, .js, etc.), compiled files (such as compressed or optimized JavaScript files), static resource files (such as images, videos, etc.), as well as server configuration files and database files. These files together constitute the complete system of the website.
[0038] Next, the antivirus module sends the received target files to an antivirus task execution object that integrates multiple antivirus software programs. This antivirus task execution object can be a local service, a remote server, or a cloud service. The antivirus task execution object uses the integrated antivirus software to scan the target files, determine whether each target file contains virus characteristics, and generate corresponding antivirus result data. The antivirus module receives the antivirus result data returned by the antivirus task execution object and stores it in a target database for subsequent querying and analysis. It is important to note that since the virus databases of each antivirus software integrated in the antivirus task execution object are constantly updated, the antivirus task can be repeatedly executed for each network product to periodically check whether the target files of each network product have been hit by the new virus database.
[0039] When a user or system administrator wants to view the antivirus scan results, they can send a command to view the scan results through the front-end page module. Upon receiving the command, the back-end processing module retrieves the corresponding antivirus scan result data from the target database and sends the retrieved data back to the front-end page module. Specifically, after a user or system administrator logs into the front-end page module, a command to view the antivirus scan results can be automatically generated. The back-end processing module can then automatically retrieve unviewed antivirus scan result data from the target database and send all of this data back to the front-end page module.
[0040] The front-end page module generates corresponding display content (such as status icons, text descriptions, etc.) for each network product based on the received antivirus scan results, so that relevant personnel can quickly identify network products that have been falsely flagged. In this embodiment, the target files are all normal files that do not contain viruses. If the antivirus scan results for a certain network product indicate that antivirus software has flagged its target file as malicious, then it is considered that the network product has been falsely flagged.
[0041] By applying the technical solution of this embodiment, after receiving the anti-virus task creation instruction, the front-end page module can display an interface for creating an anti-virus task. Users input or select the acquisition method information for network products through the anti-virus task creation interface. Based on the user-input acquisition method information, the front-end page module can construct the target anti-virus task. The back-end processing module is responsible for receiving the target anti-virus task created by the front-end page module, determining the acquisition method information according to the target anti-virus task, and downloading, extracting, or accessing the target files of each network product according to each acquisition method information. Then, the anti-virus module sends the received target files to the anti-virus task execution object that integrates multiple anti-virus software, and receives the anti-virus result data returned by the anti-virus task execution object, storing it in the target database. Subsequently, after receiving the anti-virus result viewing instruction, the back-end processing module can retrieve the corresponding anti-virus result data from the target database and send the retrieved anti-virus result data to the front-end page module. Based on the received anti-virus result data, the front-end page module generates corresponding display content (such as status icons, text descriptions, etc.) for each network product, so that relevant personnel can quickly identify network products with false positives. This application embodiment achieves automated virus detection of network products through the collaborative work of the front-end page module, back-end processing module, and antivirus module, and provides intuitive result display, which helps to improve the ability to detect false alarms of network products and facilitates relevant personnel to discover and handle false alarms in a timely manner.
[0042] Optionally, in this embodiment of the application, the method further includes: a message distribution module determining whether there is any undistributed latest anti-drug result data in the target database according to a preset polling rule, and when there is, distributing the latest anti-drug result data to the target receiving address of the corresponding network product, wherein the target receiving address is extracted from the anti-drug task creation interface and / or determined based on the default binding address of the network product.
[0043] In this embodiment, the false alarm detection device for the network product may further include a message distribution module. The main task of the message distribution module is to check for new, undistributed antivirus results and send this data to the correct location. Specifically, a polling rule can be preset, and the message distribution module can repeatedly check the target database for new antivirus results according to the preset polling rule at certain time intervals or conditions. Once the latest undistributed antivirus results are found, the message distribution module can send this data to the target receiving address of the corresponding network product. Each network product may correspond to one or more target receiving addresses, which can be email, SMS, WeChat, DingTalk, etc.
[0044] Here, the target receiving address mainly comes from the following two sources:
[0045] The first method is to extract the address from the antivirus task creation interface. That is, when creating an antivirus task, users can enter the target receiving address for each network product in the antivirus task creation interface, and then extract the address directly from that interface later.
[0046] The second method is based on determining the default binding address of the network product. The message distribution module can also find the default binding address of each network product as the target receiving address. These default binding addresses can be pre-configured.
[0047] Alternatively, the target receiving addresses determined by the two methods can be merged, and the merged target receiving address can be used as the final target receiving address corresponding to the network product.
[0048] In this embodiment of the application, the message distribution module can periodically check whether there is new antivirus result data in the target database through a preset polling rule, and distribute this data to the target receiving address of the corresponding network product in a timely and accurate manner, thereby ensuring the timely transmission of antivirus result data.
[0049] In this embodiment of the application, optionally, after "outputting the anti-virus task creation interface" in step 101, the method further includes: determining multiple application programming interface keys to be added based on the anti-virus task creation interface; "creating a target anti-virus task according to each acquisition method information" in step 101 includes: creating a target anti-virus task according to each acquisition method information and the multiple application programming interface keys; "sending each target file to the anti-virus task execution object" in step 103 includes: the anti-virus module sending each target file and an application programming interface key to the anti-virus task execution object, and after receiving the error information returned by the anti-virus task execution object, sending the remaining target files for which anti-virus result data was not successfully obtained, and the next application programming interface key, to the anti-virus task execution object again, until the anti-virus result data of each target file is successfully obtained.
[0050] In this embodiment, after the antivirus task creation interface is displayed, the user or system administrator can enter or select multiple Application Programming Interface Keys (APIKEYs) on this interface. These APIKEYs are authentication information used to access the objects to be executed by the antivirus task. Each APIKEY can only successfully scan a fixed number of target files; therefore, multiple APIKEYs can be pre-entered for backup.
[0051] When creating a target antivirus task, in addition to considering the acquisition method information of the network product, the previously determined Application Programming Interface (API) key can also be included. When the antivirus module initially executes the target antivirus task, it not only sends all target files to the antivirus task execution object but can also attach an API key. Once the antivirus task execution object successfully verifies the API key, it can begin scanning the target files. If the API key becomes invalid after processing a fixed number of target files, the antivirus task execution object can return an error message to the antivirus module.
[0052] Upon receiving an error message, the antivirus module can resend the remaining target files from which antivirus results were not obtained, along with the next unused application programming interface (API) key, to the antivirus task execution object. This process can be repeated until antivirus results for each target file are successfully obtained. This embodiment of the application programming interface (API) key and retry mechanism enhance the security and reliability of the antivirus task execution.
[0053] In this embodiment of the application, optionally, the anti-virus module sends each target file to the anti-virus task execution object according to a timed schedule. The timed schedule is determined based on the following methods: the timed schedule is determined based on the default anti-virus time configured by the front-end page module; or, based on the current time, a target time interval is determined, and the resource usage data of the server where the anti-virus module is located within the target time interval is obtained. Based on the resource usage data, the idle time corresponding to the server is determined, and the timed schedule is determined based on the idle time.
[0054] In this embodiment, the anti-virus module can send target files to the anti-virus task execution object at scheduled intervals. The methods for determining the scheduled intervals can include the following two approaches, aimed at optimizing the execution efficiency of the anti-virus task and effectively utilizing server resources.
[0055] The first method involves determining the scheduled scan time based on the default scan time configured in the front-end page module. Specifically, users or administrators can set a default scan time through the front-end page module. This time can be a fixed point in time daily, weekly, or monthly. The scan module can read this default scan time configured by the front-end page module and automatically schedule the target scan task according to this time. This method is simple and intuitive, allowing users to flexibly set the scan time according to their needs, avoiding the impact on server performance by executing scan tasks during peak periods.
[0056] The second method dynamically determines the timing based on server resource usage. Specifically, the antivirus module can determine a target time interval (e.g., within a week) before the current time, and then statistically analyze server resource usage data (such as CPU usage and memory usage) within this target time interval. Based on the statistical results, the server's idle time can be determined. For example, if statistical analysis reveals that server resource usage is lowest between 2:00 AM and 5:00 AM each day, a timing interval can be determined within this timeframe. This method allows for more flexible adaptation to changes in server resource usage, ensuring that antivirus tasks are performed when server resources are relatively idle, reducing the impact on server performance. A time interval, such as a week, can be preset, and then the target time interval can be determined based on the current time and the preset time interval.
[0057] Optionally, in this embodiment, step 106, "the front-end page module determines the display content corresponding to each network product based on the antivirus scan result data," includes: for each network product, the front-end page module determines the type icon corresponding to the network product based on the product type of the network product, obtains the product information corresponding to the network product, and determines the antivirus report results of each antivirus software for the network product based on the antivirus scan result data corresponding to the network product, wherein the product information includes at least one of MD5 information, version information, signature information, and file description; the front-end page module displays the type icon, product information, and antivirus report results corresponding to each network product according to preset display rules.
[0058] In this embodiment, the front-end page module can also determine and display relevant content for each network product based on the antivirus scan results. Specifically, the front-end page module can determine a corresponding type icon for each network product based on its product type (such as application, document, media file, etc.). The type icon can be a pre-designed series of icons, each representing a product type. Furthermore, the front-end page module can also obtain product information corresponding to each network product. Here, product information includes MD5 information (a unique identifier for the file), version information (the product's version number), signature information (a digital signature used to verify the file's integrity and authenticity), and file description (a brief description of the file), etc. This information can be collected during the antivirus scan process or provided during network product registration. In addition, for each network product, the front-end page module can also determine the antivirus reports from multiple antivirus software programs based on the antivirus scan results. Here, the antivirus scan results can include the detection results of each antivirus software program on the target file, including whether a virus was detected, the type of virus detected, the threat level, etc. The front-end page module can parse this data and generate an antivirus report for each antivirus software program.
[0059] After determining the above information, the front-end page module can also display the information according to preset display rules. These preset display rules can include the order of information arrangement, display format, etc. These rules aim to ensure that the information is clear, intuitive, and easy to understand. Specifically, the front-end page module can display the type icons of network products, product information, and the detection results of various antivirus software to the user in a prescribed manner according to the preset display rules. This embodiment of the application, through the intelligent processing and display of the front-end page module, enables users to easily view the type and information of each network product, as well as the detection results of multiple antivirus software. This helps users quickly understand the security status of network products and take corresponding security measures. At the same time, the application of preset display rules also improves the readability and usability of the information.
[0060] Optionally, after the step of "determining the antivirus detection results of each antivirus software for the network product based on the antivirus detection result data corresponding to the network product", the method further includes: based on the antivirus detection results of each antivirus software for the network product, counting the number of antivirus software and the number of antivirus software corresponding to the network product, and calculating the antivirus detection rate of the network product based on the number of antivirus software and the number of antivirus software, and determining the display color corresponding to the network product based on the preset antivirus detection range to which the antivirus detection rate belongs; the step of "the front-end page module displays the type icon, product information and antivirus detection results of each antivirus software corresponding to each network product according to preset display rules" includes: the front-end page module displays the type icon, product information, antivirus detection results of each antivirus software and the antivirus detection rate of each network product according to preset display rules, and controls at least one of the type icon, product information, antivirus detection results of each antivirus software and the antivirus detection rate to be displayed according to the display color based on the display color corresponding to each network product.
[0061] In this embodiment, for each network product, the front-end page module can also calculate the number of antivirus software reporting the product as malicious and the total number of antivirus software participating in the scan based on its corresponding antivirus results data. Then, by calculating the ratio of the number of antivirus software reports to the number of antivirus software scans, the detection rate of the network product is obtained. Afterwards, a display color is assigned to each network product according to the preset detection range to which the detection rate belongs. This color can intuitively reflect the security status of the network product. The preset detection range can be set based on security policies or experience; for example, a preset detection range of 0%-10% is green (safe), a preset detection range of 11%-30% is yellow (warning), and a preset detection range of over 31% is red (dangerous). Then, a corresponding display color is assigned to the network product according to the preset detection range to which its detection rate belongs.
[0062] The front-end page module displays the type icon, product information, antivirus detection results from various antivirus software, and newly added detection rates for each network product according to preset display rules. Furthermore, based on the display color corresponding to each network product, it controls at least one of the following: type icon, product information, antivirus detection results from various antivirus software, and detection rate, to be displayed according to a specific color. This can be achieved by changing text color, background color, border color, etc., to intuitively reflect the security status of the network product.
[0063] This application embodiment calculates the detection rate by statistically analyzing the number of antivirus software reports and scanning software, and determines the display color based on the detection rate, further enhancing the front-end page module's ability to display the security status of network products. Users can quickly understand the security status of network products by viewing the detection rate and display color, and take corresponding security measures. At the same time, this intuitive display method also helps to improve users' security awareness and vigilance.
[0064] Optionally, in this embodiment, the front-end page module further displays a report retrieval icon corresponding to each network product; the method further includes: the front-end page module responding to a trigger instruction of any report retrieval icon, generating a report retrieval request, and sending the report retrieval request to the back-end processing module; the back-end processing module retrieving corresponding anti-virus result data from the target database according to the report retrieval request, generating a target report based on the anti-virus result data, and feeding the target report back to the front-end page module; the front-end page module receiving the target report and storing the target report in local storage space.
[0065] In this embodiment, the front-end page module displays information about each network product, along with a corresponding report retrieval icon. This icon can be a button or a link, which the user can click to obtain a more detailed antivirus scan report. The report retrieval icon can be a pre-designed graphic element, such as a button with the text "View Report" or "Download Report." The front-end page module can display it along with other information about the network product (such as type icons, product information, and antivirus reports) on the page.
[0066] When a user clicks the report retrieval icon corresponding to a network product, the front-end page module receives and responds to a trigger command, generating a report retrieval request and sending it to the back-end processing module. Upon receiving the request, the back-end processing module retrieves the corresponding antivirus scan results from the target database based on the information carried in the request (such as the network product's identifier). Then, the back-end processing module generates a target report based on this scan results. This target report can be a detailed text file, PDF file, or other format document containing detailed information such as the network product's antivirus results, detected virus information, and threat level. The back-end processing module then sends this report back to the front-end page module. Upon receiving the target report, the front-end page module can store it in its local storage space for the user to view or download at any time.
[0067] This application embodiment provides users with a convenient way to obtain detailed antivirus scan results reports for network products through a report retrieval icon displayed on the front-end page module. Users simply click the icon to trigger a series of background processing steps, ultimately obtaining a report containing detailed antivirus information. This design not only improves the user experience but also enhances the system's interactivity and usability. Furthermore, storing the report in local storage space facilitates subsequent viewing and management by the user.
[0068] Furthermore, as Figure 1 In terms of specific implementation, this application provides a false alarm detection device for network products, such as... Figure 2 As shown, the device includes:
[0069] The front-end page module is used to respond to the anti-drug task creation instruction, output the anti-drug task creation interface, and determine the acquisition method information of at least one network product based on the anti-drug task creation interface, and create the target anti-drug task according to the acquisition method information.
[0070] The backend processing module is used to receive the target anti-virus task, obtain the acquisition method information of each network product contained in the target anti-virus task, and obtain the target file of each network product based on the acquisition method information;
[0071] The anti-virus module is used to send each target file to the anti-virus task execution object, so that the anti-virus task execution object can determine whether there are virus characteristics in each network product based on the target file, and obtain anti-virus result data based on the judgment result of the virus characteristics. The anti-virus task execution object integrates multiple anti-virus software.
[0072] The anti-virus module is also used to receive anti-virus result data for each network product returned by the anti-virus task execution object, and store the anti-virus result data in the target database;
[0073] The backend processing module is also used to obtain the drug scan result data from the target database based on the drug scan result viewing instruction transmitted by the frontend page module, and to feed back the drug scan result data to the frontend page module;
[0074] The front-end page module is also used to determine the display content corresponding to each network product based on the anti-drug result data, so that relevant personnel can identify network products with false alarms based on the display content.
[0075] Optionally, the device further includes:
[0076] The message distribution module is used to determine whether there is any undistributed latest anti-virus result data in the target database according to a preset polling rule, and when it exists, to distribute the latest anti-virus result data to the target receiving address of the corresponding network product. The target receiving address is extracted from the anti-virus task creation interface and / or determined based on the default binding address of the network product.
[0077] Optionally, the front-end interface module is further used for:
[0078] After the output of the anti-drug task creation interface, the multiple application programming interface keys to be added are determined based on the anti-drug task creation interface.
[0079] The front-end interface module is also used for:
[0080] Based on the information obtained through each method and the multiple application programming interface keys, a target anti-drug task is created.
[0081] The anti-virus module is also used to send the target file and an application programming interface key to the anti-virus task execution object, and after receiving the error information returned by the anti-virus task execution object, send the remaining target files for which anti-virus results data were not successfully obtained, as well as the next application programming interface key, to the anti-virus task execution object again, until the anti-virus results data of each target file is successfully obtained.
[0082] Optionally, the anti-virus module is further configured to send each target file to the anti-virus task execution object according to a scheduled time, wherein the scheduled time is determined based on the following method:
[0083] The timing time is determined based on the default antivirus scanning time configured in the front-end page module; or,
[0084] Based on the current time, a target time interval is determined, and the resource usage data of the server where the anti-drug module is located within the target time interval is obtained. Based on the resource usage data, the idle time corresponding to the server is determined, and the timing time is determined according to the idle time.
[0085] Optionally, for each network product, the front-end page module is further configured to determine the type icon corresponding to the network product based on the product type of the network product, obtain the product information corresponding to the network product, and determine the virus detection results of each antivirus software for the network product based on the antivirus detection result data corresponding to the network product, wherein the product information includes at least one of MD5 information, version information, signature information and file description;
[0086] The front-end page module is also used to display the type icon, product information, and virus detection results of each network product according to preset display rules.
[0087] Optionally, the front-end page module is further used for:
[0088] After determining the antivirus detection results of each antivirus software for the network product based on the antivirus detection results data corresponding to the network product, the number of antivirus detection software and the number of antivirus software corresponding to the network product are counted based on the antivirus detection results of each antivirus software for the network product, and the detection rate of the network product is calculated based on the number of antivirus detection software and the number of antivirus software, and the display color corresponding to the network product is determined based on the preset detection range to which the detection rate belongs.
[0089] The front-end page module is also used to display the type icon, product information, antivirus detection results and detection rate of each network product according to preset display rules, and control at least one of the type icon, product information, antivirus detection results and detection rate to be displayed according to the display color based on the display color of each network product.
[0090] Optionally, the front-end page module also displays a report retrieval icon for each network product;
[0091] The front-end page module is also used to generate a report retrieval request in response to any trigger command of the report retrieval icon, and send the report retrieval request to the back-end processing module;
[0092] The backend processing module is also used to obtain the corresponding drug detection result data from the target database according to the report acquisition request, generate a target report based on the drug detection result data, and feed the target report back to the frontend page module;
[0093] The front-end page module is also used to receive the target report and store the target report in local storage space.
[0094] It should be noted that other corresponding descriptions of the functional units involved in the false alarm detection device for a network product provided in this application embodiment can be found in the following references. Figure 1 The corresponding descriptions in the method will not be repeated here.
[0095] This application also provides a computer device, which may specifically be a personal computer, a server, a network device, etc. Figure 3As shown, the computer device includes a bus, a processor, memory, and a communication interface, and may also include an input / output interface and a display device. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database stores location information. The network interface allows communication with external terminals via a network connection. When the computer program is executed by the processor, it implements the steps in the various method embodiments.
[0096] Those skilled in the art will understand that Figure 3 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0097] In one embodiment, a computer-readable storage medium is provided, which may be non-volatile or volatile, having stored thereon a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0098] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0099] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0100] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0101] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0102] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for detecting false alarms in a network product, characterized in that, include: The front-end page module responds to the anti-drug task creation instruction, outputs the anti-drug task creation interface, and determines the acquisition method information of at least one network product based on the anti-drug task creation interface, and creates the target anti-drug task according to the acquisition method information. The backend processing module receives the target antivirus task and obtains the acquisition method information of each network product contained in the target antivirus task. Based on the acquisition method information, it obtains the target file of each network product. The antivirus module sends each target file to the antivirus task execution object, so that the antivirus task execution object can determine whether there are virus characteristics in each network product based on the target file, and obtain antivirus result data based on the virus characteristic determination result. The antivirus task execution object integrates multiple antivirus software. The anti-virus module receives anti-virus result data for each network product returned by the anti-virus task execution object, and stores the anti-virus result data in the target database; The backend processing module retrieves the drug scan result data from the target database based on the drug scan result viewing instruction transmitted by the frontend page module, and feeds back the drug scan result data to the frontend page module; The front-end page module determines the display content corresponding to each network product based on the anti-drug results data, so that relevant personnel can identify network products with false alarms based on the display content.
2. The method according to claim 1, characterized in that, The method further includes: The message distribution module determines whether there is any undistributed latest antivirus result data in the target database according to a preset polling rule, and when it does exist, it distributes the latest antivirus result data to the target receiving address of the corresponding network product. The target receiving address is extracted from the antivirus task creation interface and / or determined based on the default binding address of the network product.
3. The method according to claim 1, characterized in that, After the output of the anti-drug task creation interface, the method further includes: Based on the drug sweep task creation interface, determine the multiple application programming interface keys to be added; The step of creating a target anti-drug task based on information obtained from various methods includes: Based on the information obtained through each method and the multiple application programming interface keys, a target anti-drug task is created. The anti-virus module sends each target file to the anti-virus task execution object, including: The antivirus module sends each target file and an application programming interface (API) key to the antivirus task execution object. After receiving the error message returned by the antivirus task execution object, it sends the remaining target files for which antivirus results were not successfully obtained, as well as the next API key, to the antivirus task execution object again, until the antivirus results for each target file are successfully obtained.
4. The method according to claim 1, characterized in that, The anti-virus module sends each target file to the anti-virus task execution object at a set time, and the set time is determined based on the following method: The timing time is determined based on the default antivirus scanning time configured in the front-end page module; or, Based on the current time, a target time interval is determined, and the resource usage data of the server where the anti-drug module is located within the target time interval is obtained. Based on the resource usage data, the idle time corresponding to the server is determined, and the timing time is determined according to the idle time.
5. The method according to claim 1, characterized in that, The front-end page module determines the display content corresponding to each network product based on the antivirus results data, including: For each network product, the front-end page module determines the type icon corresponding to the network product based on the product type of the network product, obtains the product information corresponding to the network product, and determines the virus detection results of each antivirus software for the network product based on the antivirus detection result data corresponding to the network product. The product information includes at least one of MD5 information, version information, signature information, and file description. The front-end page module displays the type icon, product information, and virus detection results of each network product according to preset display rules.
6. The method according to claim 5, characterized in that, After determining the antivirus detection results of each antivirus software for the network product based on the antivirus detection data corresponding to the network product, the method further includes: Based on the antivirus detection results of each antivirus software for the network product, the number of antivirus software and the number of antivirus software corresponding to the network product are counted. Based on the number of antivirus software and the number of antivirus software, the detection rate of the network product is calculated. Based on the preset detection range to which the detection rate belongs, the display color corresponding to the network product is determined. The front-end page module displays the type icon, product information, and antivirus detection results for each network product according to preset display rules, including: The front-end page module displays the type icon, product information, antivirus detection results, and detection rate of each network product according to preset display rules. Based on the display color of each network product, it controls at least one of the type icon, product information, antivirus detection results, and detection rate to be displayed according to the specified color.
7. The method according to claim 6, characterized in that, The front-end page module also displays a report retrieval icon for each network product; the method further includes: The front-end page module responds to any report retrieval icon trigger command by generating a report retrieval request and sending the report retrieval request to the back-end processing module; The backend processing module retrieves the corresponding drug detection result data from the target database according to the report retrieval request, generates a target report based on the drug detection result data, and feeds the target report back to the frontend page module; The front-end page module receives the target report and stores it in local storage space.
8. A false alarm detection device for a network product, characterized in that, include: The front-end page module is used to respond to the anti-drug task creation instruction, output the anti-drug task creation interface, and determine the acquisition method information of at least one network product based on the anti-drug task creation interface, and create the target anti-drug task according to the acquisition method information. The backend processing module is used to receive the target anti-virus task, obtain the acquisition method information of each network product contained in the target anti-virus task, and obtain the target file of each network product based on the acquisition method information; The anti-virus module is used to send each target file to the anti-virus task execution object, so that the anti-virus task execution object can determine whether there are virus characteristics in each network product based on the target file, and obtain anti-virus result data based on the judgment result of the virus characteristics. The anti-virus task execution object integrates multiple anti-virus software. The anti-virus module is also used to receive anti-virus result data for each network product returned by the anti-virus task execution object, and store the anti-virus result data in the target database; The backend processing module is also used to obtain the drug scan result data from the target database based on the drug scan result viewing instruction transmitted by the frontend page module, and to feed back the drug scan result data to the frontend page module; The front-end page module is also used to determine the display content corresponding to each network product based on the anti-drug result data, so that relevant personnel can identify network products with false alarms based on the display content.
9. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 7.
10. A computer device, comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 7.
Citation Information
Patent Citations
Distributed vulnerability scanning system, vulnerability scanning method and storage medium
CN115499206A
Virus scanning method and system, scanner and storage medium
CN118036007A