Virus library updating method and system and virus detection method and device

By obtaining the current device configuration of the network device, determining the virus detection engine suitable for this configuration, and updating the virus database, the problem of poor applicability of virus database updates in the existing technology is solved, and the protection effect of virus detection rate and equipment performance is improved.

CN119938674APending Publication Date: 2025-05-06QI AN XIN TECHNOLOGY GROUP INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311459001.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-03
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, virus database updates rely on the subjective experience of the update personnel, resulting in poor applicability of selected virus detection engines to network devices and it is difficult to update a virus database suitable for virus detection.

Method used

By obtaining the current device configuration of the network device, the virus detection engine suitable for the configuration is determined from multiple virus detection engines, and the local virus database is updated based on its corresponding virus characteristics.

Benefits of technology

It improves the applicability of the virus database to network devices, enhances the virus detection rate, and reduces the impact of virus detection on network device performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119938674A_ABST
    Figure CN119938674A_ABST
Patent Text Reader

Abstract

The invention discloses a virus library updating method and system and a virus detection method and device, and mainly aims to update a virus library suitable for virus detection on network equipment. According to the main technical scheme, the method comprises the following steps: in response to determining to update a local virus library of network equipment, obtaining current equipment configuration of the network equipment; a first virus detection engine suitable for conducting virus detection on the network device with the current network device configuration is determined from a plurality of virus detection engines, and each virus detection engine has a corresponding virus feature; and updating the virus characteristics in the local virus library based on the first virus characteristics corresponding to the first virus detection engine.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a virus database updating method and system, and a virus detection method and device. Background Art

[0002] With the rapid development of computer technology and the Internet, viruses have become the main factor threatening network security. In order to ensure the network security of network devices, a virus detection engine is usually used to detect viruses on network devices, and the virus detection engine relies on the virus library deployed in the network devices. The virus library is used to store the virus features of the virus detection engine that detects viruses on network devices, so that the virus detection engine can detect viruses on network devices based on the corresponding virus features. In order to ensure the virus detection effect on network devices, the virus library needs to be updated.

[0003] At present, virus database updates are usually performed based on the subjective experience of the updater. When updating the virus database, the updater first needs to select a virus detection engine for virus detection on network devices from a large number of virus detection engines, and then update the virus signature of the selected virus detection engine into the virus database. However, due to the large number of virus detection engines, their performance varies, and the limited subjective experience of the updater, the selected virus detection engine often has poor applicability to network devices, making it difficult to update a virus database suitable for virus detection on network devices. Summary of the invention

[0004] In view of this, the present application proposes a virus library updating method and system, a virus detection method and device, the main purpose of which is to update a virus library suitable for performing virus detection on network devices.

[0005] In order to achieve the above objectives, this application mainly provides the following technical solutions:

[0006] In a first aspect, the present application provides a virus database updating method, the virus database updating method comprising:

[0007] In response to determining to update the local virus database of the network device, obtaining a current device configuration of the network device;

[0008] Determining, from a plurality of virus detection engines, a first virus detection engine suitable for performing virus detection on a network device having the current network device configuration, each of the virus detection engines having a corresponding virus feature;

[0009] Based on the first virus feature corresponding to the first virus detection engine, the virus feature in the local virus database is updated.

[0010] The virus library updating method provided by the present application, when determining to update the local virus library in the network device, determines the first virus detection engine suitable for virus detection on the network device with the current network device configuration from multiple virus detection engines based on the current device configuration of the network device, and then updates the virus features in the local virus library based on the first virus features corresponding to the first virus detection engine. It can be seen that the scheme provided by the present application is no longer based on the subjective experience of the update personnel when updating the local virus library, but selects the virus detection engine suitable for virus detection on the network device through the current device configuration of the network device, and then updates the virus library based on the virus features of the selected virus detection engine, so that the updated local virus library has strong applicability to the network device, and the virus detection rate of the network device can be improved based on such a virus library. In addition, the virus features in the local virus library limit the virus detection engine suitable for virus detection on the network device with the current device configuration, so that the network device can be virus detected. Therefore, the device configuration of the network device can support the virus detection of these virus detection engines, thereby reducing the impact of virus detection on the performance of the network device itself.

[0011] In a second aspect, the present application provides a virus detection method, which comprises:

[0012] In response to determining to perform virus detection on the network device, obtaining a current device configuration of the network device;

[0013] Determining, from a plurality of virus detection engines, a second virus detection engine suitable for performing virus detection on a network device having the current network device configuration, each of the virus detection engines having a corresponding virus feature;

[0014] The second virus feature corresponding to the second virus detection engine is called to perform virus detection on the network device.

[0015] The virus detection method provided by the present application, when determining to perform virus detection on a network device, determines a second virus detection engine suitable for performing virus detection on a network device having the current network device configuration from multiple virus detection engines based on the current device configuration of the network device, and then calls the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device. It can be seen that the solution provided by the present application uses a virus detection engine suitable for performing virus detection on a network device having the current device configuration to perform virus detection on the network device. Performing virus detection on the network device based on these virus detection engines can not only improve the virus detection rate, but also the device configuration of the network device can support the virus detection of these virus detection engines, thereby reducing the impact of virus detection on the performance of the network device itself.

[0016] In a third aspect, the present application provides a virus database update system, the virus database update system comprising:

[0017] The processing device is used for obtaining the current device configuration of the network device in response to determining to update the local virus library of the network device; determining a first virus detection engine suitable for performing virus detection on the network device having the current network device configuration from a plurality of virus detection engines, each of the virus detection engines having a corresponding virus feature;

[0018] The updating device is used to update the virus features in the local virus database based on the first virus features corresponding to the first virus detection engine.

[0019] The beneficial effects of the virus database update system provided in the present application are substantially the same as the beneficial effects of the above-mentioned virus database update method, and therefore will not be described in detail here. Please refer to the beneficial effects of the virus database update method in the above-mentioned first aspect.

[0020] In a fourth aspect, the present application provides a virus detection device, the virus detection device comprising:

[0021] An acquisition module, configured to acquire a current device configuration of the network device in response to determining to perform virus detection on the network device;

[0022] A determination module, configured to determine, from a plurality of virus detection engines, a second virus detection engine suitable for performing virus detection on a network device having the current network device configuration, each of the virus detection engines having a corresponding virus feature;

[0023] The detection module is used to call the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device.

[0024] The beneficial effects of the virus detection device provided in the present application are substantially the same as the beneficial effects of the above-mentioned virus detection method, and therefore will not be described in detail here. Please refer to the beneficial effects of the virus update method in the above-mentioned second aspect.

[0025] In a fifth aspect, the present application provides a computer-readable storage medium, which includes a stored program, wherein when the program is running, the device where the storage medium is located is controlled to execute the virus database update method of the first aspect, and / or execute the virus detection method of the second aspect.

[0026] In a sixth aspect, the present application provides an electronic device, comprising: a memory for storing programs; a processor, coupled to the memory, for running the programs to execute the virus database updating method described in the first aspect, and / or, to execute the virus detection method described in the second aspect.

[0027] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0029] Figure 1 A flowchart of a virus database updating method provided by an embodiment of the present application is shown;

[0030] Figure 2 A flow chart of a virus detection method provided by an embodiment of the present application is shown;

[0031] Figure 3 A schematic diagram of an implementation process of virus detection provided by an embodiment of the present application is shown;

[0032] Figure 4 A schematic diagram of the structure of a virus database updating system provided by an embodiment of the present application is shown;

[0033] Figure 5 A schematic diagram of the structure of a virus database updating system provided by another embodiment of the present application is shown;

[0034] Figure 6 A schematic diagram of the structure of a virus detection device provided by an embodiment of the present application is shown;

[0035] Figure 7 A schematic structural diagram of a virus detection device provided in another embodiment of the present application is shown. DETAILED DESCRIPTION

[0036] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0037] A local virus database is deployed in the network device, and the local virus database is used to store virus features of a virus detection engine that performs virus detection on the network device, so that the virus detection engine can perform virus detection on the network device based on the corresponding virus features.

[0038] At present, the update of local virus database is usually carried out based on the subjective experience of the update personnel. However, due to the large number of virus detection engines, different performances, and limited subjective experience of the update personnel, it is often the case that the selected virus detection engine is not suitable for virus detection of network devices, or the selected virus detection engine has poor applicability for virus detection of network devices. In this way, after the local virus database is updated based on the virus characteristics of the selected virus detection engine, the updated local virus database has poor applicability for network devices. Virus detection of network devices based on such a local virus database will reduce the virus detection rate.

[0039] After research, the inventors found that different virus detection engines are applicable to different device configurations. The virus detection engine performs virus detection on network devices with its applicable device configuration, which can not only give full play to its virus detection capabilities and improve the virus detection rate, but also has less impact on the performance of the network device itself, and can reduce the impact of virus detection on the business of the network element device itself. Therefore, the inventors propose that when updating the virus library of the network device, it is no longer based on the subjective experience of the update personnel, but the current device configuration of the network device is used to select a virus detection engine suitable for the network device, and then the local virus library is updated based on the virus characteristics of the selected virus detection engine. In this way, the updated local virus library is more applicable to the network device, and virus detection on the network device based on such a virus library can not only improve the virus detection rate, but also reduce the impact of virus detection on the performance of the network device itself.

[0040] Based on the above findings, the embodiment of the present application specifically provides a technical solution for updating the virus database. Specifically, in response to determining to update the local virus database of the network device, the current device configuration of the network device is obtained; from multiple virus detection engines, a first virus detection engine suitable for performing virus detection on the network device with the current network device configuration is determined, and each virus detection engine has a corresponding virus feature; based on the first virus feature corresponding to the first virus detection engine, the virus feature in the local virus database is updated.

[0041] In practical applications, the technical solution for updating the virus database provided in this embodiment can update the local virus database of any network device to update a local virus database suitable for virus detection of the network device. This embodiment does not limit the specific type of network device, and the network device can be flexibly selected based on business needs. Exemplarily, the network device is a protective wall device.

[0042] The inventor considers that selecting a first virus detection engine suitable for performing virus detection on a network device with a current network device configuration and performing virus detection on the network device can not only improve the virus detection rate, but also reduce the impact of virus detection on the performance of the network device itself. Therefore, this embodiment also proposes a technical solution for virus detection. Specifically, in response to determining to perform virus detection on a network device, the current device configuration of the network device is obtained; from multiple virus detection engines, a second virus detection engine suitable for performing virus detection on a network device with a current network device configuration is determined, each virus detection engine having a corresponding virus feature; and the second virus feature corresponding to the second virus detection engine is called to perform virus detection on the network device.

[0043] Based on the above-mentioned technical solutions for virus database update and virus detection, the present application embodiment specifically proposes a virus database update method and system, and a virus detection method and device. The following specifically describes the virus database update method and system, and virus detection method and device provided in the present application embodiment.

[0044] The present application embodiment provides a virus database update method, such as Figure 1 As shown, the virus database updating method mainly includes the following steps 101 to 103:

[0045] 101. In response to determining to update a local virus database of a network device, obtain a current device configuration of the network device.

[0046] The virus database update method provided in this embodiment is mainly used to update the local virus database deployed in the network device. The local virus database is used to store the virus features of the virus detection engine applicable to the network device for virus detection, that is, all the virus features of the virus detection engine currently applicable to the network device for virus detection need to be stored in the local virus database, otherwise the selected virus detection engine will not be able to perform virus detection on the network device because there are no virus features available in the network device.

[0047] The local virus database will be updated only when it is determined that the local virus database of the network device is updated. Therefore, the virus database update method may also include a step of determining whether the local virus database needs to be updated. The specific execution methods of this step may include at least the following three methods:

[0048] First, if a local virus database update instruction issued by a user is received, it is determined to update the local virus database of the network device.

[0049] In order to enable users to flexibly update the local virus database based on their own needs, users can update the local virus database by issuing local virus database update instructions. Therefore, if a local virus database update instruction issued by a user is received, it means that the user currently has a need to update the local virus database. In order to meet this need of the user, it is determined to update the local virus database of the network device.

[0050] The second method is to determine to update the local virus database of the network device if an update instruction for the local virus database is detected; wherein the update instruction is generated by the virus database update process in the network device when the update cycle of the local virus database is reached.

[0051] Considering that the device configuration of the network device may change over time, in order to ensure that the virus signatures in the local virus signature match the current device configuration of the network device in a timely manner, the local virus database needs to be updated regularly. In order to achieve regular updates, a virus update process is set in the network device, and the virus update process monitors whether the update cycle of the local virus database has been reached. Once the virus update process monitors that the update cycle of the local virus database has been reached, an update instruction for the local virus database is generated.

[0052] If an update instruction for the local virus database is detected, it means that the virus features in the local virus database may no longer be suitable for virus detection on the network device, so it is determined to update the local virus database of the network device.

[0053] The third method is to monitor the device configuration of the network device; if it is monitored that the device configuration of the network device has changed, it is determined to update the local virus database of the network device.

[0054] If the device configuration of the network device changes, the virus detection engine applicable to the network device for virus detection may change. Therefore, in order to timely discover whether the device configuration of the network device has changed, it is necessary to monitor the device configuration of the network device. If the device configuration of the network device is monitored to have changed, it means that the virus detection engine applicable to the network device for virus detection may have changed. Therefore, in order to update the virus signature of the virus detection engine currently applicable to the network device for virus detection to the local virus database, it is determined to update the local virus database of the network device.

[0055] The above three methods for determining whether the local virus database needs to be updated may be used alone, or any two or three of them may be used in combination, which is not specifically limited in this embodiment.

[0056] In the case of determining to update the local virus library of the network device, the current device configuration of the network device is obtained, so as to select a first virus detection engine suitable for performing virus detection on the network device with the current network device configuration based on the current device configuration, and update the virus features in the local virus library through the virus features corresponding to the first virus detection engine. The current device configuration in this embodiment may include at least one of the following: device serial number, current deployment system and corresponding system version, memory size, and number of CPUs. In actual applications, the specific parameters included in the current device configuration can be flexibly selected from one or more of the above.

[0057] 102. Determine, from a plurality of virus detection engines, a first virus detection engine suitable for performing virus detection on a network device having a current network device configuration, each virus detection engine having a corresponding virus feature.

[0058] In this embodiment, multiple virus detection engines are collected in advance so as to determine the first virus detection engine suitable for performing virus detection on the network device with the current network device configuration from the multiple virus detection engines. Each virus detection engine has a corresponding virus feature, and each virus detection engine performs virus detection based on its corresponding virus feature.

[0059] The method for collecting virus detection engines may be: continuously monitoring whether at least one engine manufacturer has newly released a virus detection engine, and once a newly released virus detection engine is monitored, the newly released virus detection engine is collected, and an associated device configuration is set for the virus detection engine, and the virus detection engine is suitable for performing virus detection on a network device with the associated device configuration. That is, the device configuration associated with the virus detection engine is used to instruct the virus detection engine to perform virus detection on a network device with the device configuration, and the virus detection process is stable, can give full play to virus detection, and improve the virus detection rate.

[0060] The specific process of determining the first virus detection engine suitable for performing virus detection on the network device with the current network device configuration from multiple virus detection engines may include the following steps: detecting whether there is a virus detection engine associated with the current device configuration among the multiple virus detection engines. If it is detected that there is, the virus detection engine associated with the current device configuration is determined to be the first virus detection engine suitable for performing virus detection on the network device with the current network device configuration. If it is detected that there is no virus detection engine, a prompt is issued, and the prompt is used to inform that there is no virus detection engine suitable for the current device configuration, so that the business personnel can perform corresponding processing based on the prompt.

[0061] 103. Update the virus feature in the local virus database based on the first virus feature corresponding to the first virus detection engine.

[0062] Each virus detection engine has a corresponding engine feature library, and the engine feature library is used to store the virus features of the corresponding virus detection engine. After determining the first virus detection engine suitable for performing virus detection on the network device with the current network device configuration, it is necessary to obtain the first virus feature from the engine feature library corresponding to the first virus detection engine, so as to update the virus features in the local virus library through the first virus feature. Therefore, before updating the virus features in the local virus library based on the first virus feature corresponding to the first virus detection engine, the virus library update method may also include a process of obtaining the first virus feature, which may be that the following steps 103A to 103C are performed for each virus detection engine:

[0063] 103A. Determine whether the existing virus features in the local virus database include the virus features corresponding to the first virus detection engine; if not, execute step 103B; if included, execute step 103C.

[0064] The intersection of the existing virus features in the local virus database and the virus features corresponding to the first virus detection engine determines which virus features of the first virus detection engine need to be obtained as the first virus features. Therefore, it is necessary to determine whether the existing virus features in the local virus database include the virus features corresponding to the first virus detection engine. The execution method of this step may include at least the following two methods:

[0065] The first one is to detect whether the first virus detection engine is determined to be a virus detection engine suitable for performing virus detection on the network device when the local virus database is last updated; if so, it is determined that the existing virus features of the local virus database include the virus features of the first virus detection engine; otherwise, it is determined that the existing virus features of the local virus database do not include the virus features of the first virus detection engine.

[0066] If it is detected that the first virus detection engine was determined to be a virus detection engine suitable for performing virus detection on network devices when the local virus database was last updated, it means that the virus characteristics of the first virus detection engine have been updated to the local virus database when the local virus database was last updated. The local virus database must contain the virus characteristics of the first virus detection engine. Therefore, it is determined that the existing virus characteristics of the local virus database include the virus characteristics of the first virus detection engine.

[0067] If it is detected that the first virus detection engine was not determined as a virus detection engine suitable for performing virus detection on network devices when the local virus database was last updated, it means that the virus features of the first virus detection engine were not updated to the local virus database when the local virus database was last updated, and the virus features corresponding to the first virus detection engine do not yet exist in the local virus database. Therefore, it is determined that the existing virus features of the local virus database do not include the virus features of the first virus detection engine.

[0068] The second method is to send a fourth inquiry message to the network device to inquire whether the virus features of the first virus detection engine exist in the local virus library; if the network device feedback confirms that the instruction exists, it is determined that the existing virus features of the local virus library include the virus features of the first virus detection engine; if the network device feedback confirms that the instruction does not exist, it is determined that the existing virus features of the local virus library do not include the virus features of the first virus detection engine.

[0069] In order to more accurately determine whether the virus features corresponding to the first virus detection engine exist in the local virus database, the second and fourth query messages are sent to the network device to inquire whether the virus features of the first virus detection engine exist in the local virus database.

[0070] If the network device feedback confirms that the instruction exists, it means that the local virus database contains the virus features of the first virus detection engine. Therefore, it is determined that the existing virus features of the local virus database include the virus features of the first virus detection engine.

[0071] If the network device feedback confirms that there is no instruction, it means that the first virus detection engine is the latest virus detection engine suitable for the current device configuration of the network device determined in this update, and its corresponding virus features do not yet exist in the local virus library. Therefore, it is determined that the existing virus features in the local virus library do not include the virus features of the first virus detection engine.

[0072] The above two methods for determining whether the existing virus features in the local virus database include the virus features corresponding to the first virus detection engine may be used alone or in combination, and this embodiment does not specifically limit this.

[0073] 103B. Acquire all virus features of the first virus detection engine from the corresponding engine feature library as first virus features.

[0074] If it is determined that the existing virus features of the local virus library do not include the virus features of the first virus detection engine, in order to ensure that the first virus detection engine can rely on the virus features in the local virus library to perform virus detection on the network device, all virus features of the first virus detection engine are obtained as first virus features from the engine feature library corresponding to the first virus detection engine, so that the virus features of the first virus detection engine are fully added to the local virus library.

[0075] 103C. Based on the feature type of the corresponding existing virus feature in the local virus database, obtain a first virus feature from the virus features stored in the corresponding engine feature database.

[0076] If it is determined that the existing virus features in the local virus library include the virus features of the first virus detection engine, in order to be able to perform effective incremental updates to the virus features of the first virus detection engine in the local virus library, the first virus features are obtained from the virus features stored in the corresponding engine feature library based on the feature types of the corresponding existing virus features in the local virus library, so as to incrementally update the virus features of the first virus detection engine in the local virus library based on the obtained first virus features.

[0077] The specific execution process of this step 103C for acquiring the first virus feature from the virus features stored in the corresponding engine feature library based on the feature type of the corresponding existing virus feature in the local virus library may include the following steps 103C1 to 103C3:

[0078] 103C1. Based on the feature types of the corresponding existing virus features in the local virus database, determine whether the corresponding existing virus features in the local virus database are all basic virus features; if so, execute step 103C2; otherwise, execute step 103C3.

[0079] The feature types of virus features include non-basic feature types and basic feature types. For any virus detection engine, its corresponding engine feature library includes the basic features of its corresponding non-basic feature types and basic features of its basic feature types. In other words, the basic features and non-basic features constitute all the virus features of the virus detection engine. Basic virus features are simplified virus features of the virus detection engine. Virus detection can be performed based on basic virus features, but compared with virus detection based on all virus features, the virus detection rate is relatively low.

[0080] Based on the feature types of the corresponding existing virus features in the local virus database, it is determined whether the corresponding existing virus features in the local virus database are all basic virus features. If it is determined that the corresponding existing virus features in the local virus database are all basic virus features, it means that the first virus detection engine performs virus detection based only on the basic virus features, so step 103C2 is executed. If it is determined that the corresponding existing virus features in the local virus database include both basic virus features and non-basic virus features, it means that the first virus detection engine needs to perform virus detection based on all corresponding virus features, so step 103C3 is executed.

[0081] 103C2. From the corresponding engine feature library, obtain the basic virus features in the new virus features of the first virus detection engine as the first virus features.

[0082] If it is determined that all existing virus features corresponding to the first virus detection engine in the local virus database are basic virus features, it means that the first virus detection engine performs virus detection based only on basic virus features, so it is only necessary to incrementally update the basic virus features of the first virus detection engine in the local virus database. Therefore, the basic virus features in the new virus features of the first virus detection engine are obtained as the first virus features from the corresponding engine feature database, so that the incremental update of the basic virus features can be realized in the local virus database based on the first virus features. The new virus features here are the virus features that are newly added or changed by the first virus detection engine after the last update of the local virus database.

[0083] 103C3. Acquire all new virus features of the first virus detection engine from the corresponding engine feature library as first virus features.

[0084] If it is determined that the existing virus features corresponding to the first virus detection engine in the local virus database include both basic virus features and non-basic virus features, it means that the first virus detection engine needs to perform virus detection based on all its corresponding virus features, so it is necessary to incrementally update all virus features of the first virus detection engine in the local virus database. Therefore, all new virus features of the first virus detection engine are obtained as first virus features from the corresponding engine feature database, so that the virus features of the first virus detection engine can be incrementally updated in the local virus database based on all new virus features of the first virus detection engine.

[0085] Considering that, as time goes by, the user may change from requiring the first virus detection engine to perform virus detection based on basic virus features to requiring the first virus detection engine to perform virus detection based on all basic virus features. Therefore, in order to adapt to the change of user needs, after determining in the above step 103C1 that the corresponding existing virus features in the local virus database are all basic virus features, the virus database update method may further include the following steps 103C4 to 103C6:

[0086] 103C4. Send a third inquiry message to the third review end to confirm whether it is necessary to update the non-basic virus feature increment of the first virus detection engine to the local virus database.

[0087] After determining that the corresponding existing virus features in the local virus database are all basic virus features, in order to confirm whether the user has changed to requiring the first virus detection engine to perform virus detection based on all virus features, a third inquiry message is sent to the third review end so that the user can confirm whether it is necessary to incrementally update the non-basic virus features of the first virus detection engine to the local virus database based on his own needs.

[0088] 103C5. If a confirmation instruction fed back by the third audit terminal is received, the non-basic virus features of the first virus detection engine and the basic virus features in the new virus features are obtained as the first virus features from the corresponding engine feature library.

[0089] If a confirmation instruction is received from the third audit terminal, it means that the user needs the first virus detection engine to perform virus detection based on all virus features. In order to meet this need of the user, the non-basic virus features of the first virus detection engine and the basic virus features in the new virus features are obtained as the first virus features from the corresponding engine feature library. After the local virus library is updated based on such first virus features, all virus features corresponding to the first virus detection engine exist in the local virus library, and the first virus detection engine can perform virus detection based on all its corresponding virus features.

[0090] 103C6. If a rejection instruction is received from the third audit terminal, execute the above step 103C2 to obtain the basic virus features in the new virus features of the first virus detection engine as the first virus features from the corresponding engine feature library.

[0091] If a rejection instruction is received from the third audit terminal, it means that the user still needs the first virus detection engine to perform virus detection based on the basic virus features. In order to meet this need of the user, the above step 103C2 is executed to obtain the basic virus features in the new virus features of the first virus detection engine from the corresponding engine feature library as the first virus features. After the local virus is updated based on such first virus features, only the basic virus features corresponding to the first virus detection engine still exist in the local virus library. When performing virus detection, the first virus detection engine can continue to perform based on its corresponding basic virus features.

[0092] Further, considering that the user may need the first virus detection engine to perform virus detection based on basic virus features, or may need the first virus detection engine to perform virus detection based on all virus features, in order to meet the needs of the user as much as possible, after determining in the above step 103A that the existing virus features of the local virus library do not include the virus features corresponding to the first virus detection engine, the virus library update method may also include the following steps to confirm whether all virus features of the first virus detection engine are obtained as first virus features from the corresponding engine feature library: sending a first inquiry message to the first audit terminal to confirm whether it is necessary to store the basic virus features of the first virus detection engine in the local virus library, and it is not necessary to store the non-basic virus features of the first virus detection engine in the local virus library, and the basic virus features and the non-basic virus features constitute all virus features of the first virus detection engine. If a confirmation instruction fed back by the first audit terminal is received, the basic virus features of the first virus detection engine are obtained as first virus features from the corresponding engine feature library. If a rejection instruction fed back by the first audit terminal is received, the above step 103B is executed to obtain all virus features of the first virus detection engine from the corresponding engine feature library as first virus features.

[0093] When the existing virus features in the local virus library do not include the virus features corresponding to the first virus detection engine, in order to update the virus features of the first virus detection engine to the local virus library according to the user's usage requirements for the first virus detection engine, a first inquiry message is sent to the first audit end, so that the user can determine based on the first inquiry message whether to update the basic virus features of the first virus detection engine to the local virus library, or to update all the virus features of the first virus detection engine to the local virus library.

[0094] If a confirmation instruction is received from the first audit end, it means that the user only needs the first virus detection engine to perform virus detection based on basic virus features. Therefore, the basic virus features of the first virus detection engine are obtained as the first virus features from the corresponding engine feature library to add the basic virus features of the first virus detection engine to the local virus library.

[0095] If a rejection instruction is received from the first audit end, it means that the user requires the first virus detection engine to perform virus detection based on all virus features, and both the basic virus features and non-basic virus features of the first virus detection engine need to be added to the local virus library. Therefore, the above step 103B is executed to obtain all virus features of the first virus detection engine as first virus features from the corresponding engine feature library, so as to add all the basic virus features and non-basic virus features of the first virus detection engine to the local virus library based on such first virus features.

[0096] In this embodiment, before sending the first inquiry information to the first audit end, the virus database update method may also include the following steps: determine whether the local virus database stores all virus features of the virus detection engine by default; if by default, execute the above step 103B to obtain all virus features of the first virus detection engine from the corresponding engine feature library as the first virus features; if not by default, execute the step of sending the first inquiry information to the first audit end.

[0097] If it is determined that the local virus library stores all virus features of the virus detection engine by default, it means that it can be determined that the user needs to add all virus features of the first virus detection engine to the local virus library. Therefore, the above step 103B is executed to obtain all virus features of the first virus detection engine as first virus features from the corresponding engine feature library.

[0098] If it is determined that the local virus library does not store all the virus features of the virus detection engine by default, it means that it is currently impossible to determine whether the user needs all the virus features of the first virus detection engine to be added to the local virus library. Therefore, it is necessary to execute the step of sending a first inquiry message to the first audit end to ask the user whether to obtain all the virus features of the first virus detection engine as the first virus features from the corresponding engine feature library.

[0099] Furthermore, considering that the user may change from requiring the first virus detection engine to perform virus detection based on basic virus features to requiring the first virus detection engine to perform virus detection based on all virus features, in order to meet the needs of the user as much as possible, after determining in the above step 103A that the existing virus features in the local virus library include the virus features corresponding to the first virus detection engine, the virus library update method may also include the following two technical solutions to confirm whether to obtain the first virus feature from the virus features stored in the corresponding engine feature library based on the feature type of the corresponding existing virus features in the local virus library.

[0100] The first method is to send a second inquiry message to the second audit terminal to confirm whether to fully update the virus features of the first virus detection engine in the local virus library. If a full update confirmation instruction fed back by the second audit terminal is received, all virus features of the first virus detection engine are obtained as first virus features from the corresponding engine feature library. If no full update confirmation instruction fed back by the second audit terminal is received, or a full update rejection confirmation instruction fed back by the second audit terminal is received, the above step 103C is executed to obtain the first virus feature from the virus features stored in the corresponding engine feature library based on the feature type of the corresponding existing virus features in the local virus library.

[0101] If a full update confirmation instruction fed back by the second audit end is received, it means that the user does not need to incrementally update the existing virus features of the first virus detection engine in the local virus library, but needs to fully update the existing virus features of the first virus detection engine in the local virus library. Therefore, all virus features of the first virus detection engine are obtained as first virus features from the corresponding engine feature library, so as to fully update the virus features of the first virus detection engine in the local virus library based on such first virus features. The full update here means that the existing virus features of the first virus detection engine in the local virus library are fully deleted, and the obtained first virus features are added to the local virus library. Further, after receiving the full update confirmation instruction fed back by the second audit end, if the user specifies to use the basic virus features of the first virus detection engine for full update, the basic virus features of the first virus detection engine are all obtained as first virus features from the corresponding engine feature library. After receiving the full update confirmation instruction fed back by the second audit end, if the user specifies to use the full update of all virus features of the first virus detection engine, the step of obtaining all virus features of the first virus detection engine as first virus features from the corresponding engine feature library is executed.

[0102] If no full update confirmation instruction is received from the second audit end, or if a full update rejection confirmation instruction is received from the second audit end, it means that the user needs to use incremental update to update the virus features of the first virus detection engine in the local virus library. Therefore, the above step 103C is executed to obtain the first virus feature from the virus features stored in the corresponding engine feature library based on the feature type of the corresponding existing virus features in the local virus library, so as to use such first virus features to incrementally update the virus features of the first virus detection engine in the local virus library.

[0103] The second method is to determine whether the local virus database is set to update the virus signature in full by default. If it is set by default, all virus signatures of the first virus detection engine are obtained as the first virus signature from the corresponding engine signature database. If it is not set by default, the above step 103C is executed to obtain the first virus signature from the virus signature stored in the corresponding engine signature database based on the signature type of the corresponding existing virus signature in the local virus database.

[0104] If it is determined that the local virus database fully updates the virus features by default, it means that the existing virus features of the first virus detection engine in the local virus database need to be fully updated. Therefore, all the virus features of the first virus detection engine are obtained as the first virus features from the corresponding engine feature library, so as to fully update the virus features of the first virus detection engine in the local virus database based on such first virus features. The full update here means that the existing virus features of the first virus detection engine in the local virus database are fully deleted, and the obtained first virus features are added to the local virus database. Further, if it is determined that the local virus database fully updates the virus features by default, and the user specifies to use the basic virus features of the first virus detection engine for full update, then the basic virus features of the first virus detection engine are obtained as the first virus features from the corresponding engine feature library. If it is determined that the local virus database fully updates the virus features by default, and the user specifies to use the full update of all the virus features of the first virus detection engine, then the step of obtaining all the virus features of the first virus detection engine as the first virus features from the corresponding engine feature library is executed.

[0105] If it is determined that the local virus database does not update the virus features in full by default, it means that the virus features of the first virus detection engine in the local virus database need to be updated by incremental update. Therefore, the above step 103C is executed to obtain the first virus feature from the virus features stored in the corresponding engine feature database based on the feature type of the corresponding existing virus features in the local virus database, so as to use such first virus features to incrementally update the virus features of the first virus detection engine in the local virus database.

[0106] After obtaining the first virus feature corresponding to the first virus detection engine from the engine feature library corresponding to the first virus detection engine in the above manner, the virus feature in the local virus library is updated based on the first virus feature corresponding to the first virus detection engine. The specific process of updating the virus feature in the local virus library based on the first virus feature corresponding to the first virus detection engine is that the following steps 103D to 103H can be performed for each first virus detection engine:

[0107] 103D. Check whether the local virus database already has the virus signature corresponding to the first virus detection engine. If not, execute step 103E; if already exists, execute step 103F.

[0108] The existence of the virus features corresponding to the first virus detection engine in the local virus database determines the specific update method to be adopted when updating the virus features corresponding to the first virus detection engine in the local virus database. Therefore, it is necessary to detect whether the virus features corresponding to the first virus detection engine already exist in the local virus database.

[0109] Usually, existing virus features in local viruses all have corresponding identifiers. The identifier is used to indicate the virus detection engine corresponding to the corresponding virus feature. Therefore, when detecting whether the virus feature corresponding to the first virus detection engine already exists in the local virus database, it is sufficient to use the identifier corresponding to the existing virus feature.

[0110] 103E. Add the first virus signature of the first virus detection engine to the local virus database.

[0111] If it is detected that the virus feature corresponding to the first virus detection engine does not exist in the local virus library, the first virus feature corresponding to the first virus detection engine can be added to the local virus library. In this way, if the first virus detection engine is required to perform virus detection on the network device, it can be performed based on the local virus library and the corresponding virus feature.

[0112] 103F. Determine whether the first virus feature corresponding to the first virus detection engine can fully cover the existing virus features of the first virus detection engine in the local virus database; if so, execute step 103G; if not, execute step 103H.

[0113] If it is detected that the virus signature corresponding to the first virus detection engine exists in the local virus database, it is necessary to clarify whether the first virus signature is used to fully update the existing virus signature of the first virus detection engine in the local virus database, or to incrementally update the existing virus signature of the first virus detection engine in the local virus database. Therefore, it is necessary to determine whether the first virus signature corresponding to the first virus detection engine can fully cover the existing virus signature of the first virus detection engine in the local virus database.

[0114] 103G. Replace all relevant existing virus features with the first virus feature.

[0115] If it is determined that the first virus feature corresponding to the first virus detection engine can fully cover the existing virus features of the first virus detection engine in the local virus database, all existing virus features related to the first virus detection engine in the local virus database will be deleted and completely replaced with the first virus feature corresponding to the first virus detection engine.

[0116] 103H. Incrementally update the relevant existing virus features based on the first virus feature.

[0117] If it is determined that the first virus feature corresponding to the first virus detection engine cannot fully cover the existing virus features of the first virus detection engine in the local virus database, it means that the first virus feature is only used to incrementally update the local virus database. Therefore, the existing virus features related to the first virus detection engine are incrementally updated based on the first virus feature.

[0118] The specific process of incrementally updating the relevant existing virus features based on the first virus feature may include the following steps as required: for each first virus feature, detecting whether the first virus feature has a corresponding virus feature in the relevant existing virus features; if so, replacing the corresponding virus feature with the first virus feature; if not, adding the first virus feature to the local virus library.

[0119] If it is detected that the first virus feature has a corresponding virus feature in the existing virus features related to the first virus detection engine, it means that the first virus feature is a virus feature formed by modifying the related existing virus features. Therefore, the existing virus feature corresponding to the first virus feature is deleted, and the first virus feature is added to the local virus library to replace the existing virus feature corresponding to the first virus feature with the first virus feature.

[0120] If it is detected that the first virus feature does not have a corresponding virus feature in the existing virus features related to the first virus detection engine, it means that the first virus feature is a newly added virus feature, so the first virus feature is directly added to the local virus library.

[0121] Based on the first virus feature corresponding to the first virus detection engine, the virus features in the updated local virus library are all virus features of the virus detection engine that is suitable for performing virus detection on the network device with the current network device configuration. Therefore, performing virus detection on the network device based on the updated local virus library can at least achieve the following two effects: First, the virus detection engine that is suitable for performing virus detection on the network device with the current device configuration can perform virus detection on the network device based on the virus features in the local virus library, so that the virus detection rate can be improved. Second, the virus features in the local virus library limit the virus detection engine that is suitable for performing virus detection on the network device with the current device configuration to perform virus detection on the network device, so the device configuration of the network device can support the virus detection of these virus detection engines, thereby ensuring the stability of the virus detection on the network device and reducing the possibility of performance damage when the virus detection engine performs virus detection on the network device.

[0122] The virus library updating method provided by the embodiment of the present application, when determining to update the local virus library in the network device, based on the current device configuration of the network device, from multiple virus detection engines, determine the first virus detection engine suitable for virus detection on the network device with the current network device configuration, and then update the virus features in the local virus library based on the first virus feature corresponding to the first virus detection engine. It can be seen that the scheme provided by the embodiment of the present application is no longer based on the subjective experience of the update personnel when updating the local virus library, but selects the virus detection engine suitable for virus detection on the network device through the current device configuration of the network device, and then updates the virus library based on the virus feature of the selected virus detection engine, so that the updated local virus library has strong applicability to the network device, and the virus detection rate of the network device can be improved based on such a virus library. In addition, the virus features in the local virus library limit the virus detection engine suitable for virus detection on the network device with the current device configuration, so that the network device can be virus detected. Therefore, the device configuration of the network device can support the virus detection of these virus detection engines, thereby reducing the impact of virus detection on the performance of the network device itself.

[0123] In some embodiments of the present application, the network device allocates limited storage space for the local virus library. If the local virus library is updated based on the first virus feature corresponding to the first virus detection engine and the current actual storage space of the local virus library is exceeded, not only will the update fail, but it will also make it difficult to detect viruses on the network device. Therefore, in order to avoid this situation, the virus library update method may also include the following steps: determining whether the expected storage space of the local virus library required to update the virus features in the local virus library based on the first virus feature corresponding to the first virus detection engine exceeds the current actual storage space of the local virus library; if not, executing the step of updating the virus features in the local virus library based on the first virus feature corresponding to the first virus detection engine; if exceeded, expanding the current actual storage space of the local virus library to be not less than the expected storage space, and then executing the above step 103 to update the virus features in the local virus library based on the first virus feature corresponding to the first virus detection engine, or issuing a prompt that the existing storage space of the local virus library is insufficient.

[0124] In order to avoid the local virus database exceeding the current actual storage space after the local virus database is updated based on the first virus feature corresponding to the first virus detection engine, the expected storage space of the local virus database required to update the virus feature in the local virus database based on the first virus feature corresponding to the first virus detection engine is estimated before the above step 103. The estimation process can be carried out with reference to the specific detailed description of the above step 103, which is only an estimation, but does not actually update the local virus database.

[0125] After estimating the expected storage space, the expected storage space is compared with the current actual storage space of the local virus library. If the expected storage space does not exceed the current actual storage space, it means that the current actual storage space meets the update requirements, so the above step 103 is performed to update the virus features in the local virus library based on the first virus feature corresponding to the first virus detection engine. If the expected storage space exceeds the current actual storage space, it means that if the virus features in the local virus library are updated based on the first virus feature corresponding to the first virus detection engine, the virus features will overflow from the corresponding current actual storage space, resulting in an exception. For this exceeding situation, the following two methods can be used to handle it: First, the current actual storage space of the local virus library is expanded to be not less than the expected storage space, so that the storage space of the local virus library can support the update of the local virus library. Second, a prompt is issued that the existing storage space of the local virus library is insufficient, so that the user can handle the exception based on the prompt. For example, further filter out the virus detection engine that meets the current actual storage space from the first virus detection engine, and update the local virus library only based on the first virus feature of the filtered virus detection engine, so that it can be ensured that the current actual storage space of the local virus library will not overflow after the update.

[0126] In some embodiments of the present application, after the virus features in the local virus database are updated based on the first virus features corresponding to the first virus detection engine in the above step 103, if there are virus features other than those of the first virus detection engine in the local virus database, these virus features are deleted to avoid them occupying the storage space corresponding to the local virus.

[0127] In some embodiments of the present application, further, after the virus features in the local virus library are updated based on the first virus features corresponding to the first virus detection engine in the above step 103, a virus feature directory can also be formed for the virus features in the updated local virus library. The virus feature directory records each virus feature in the local virus library and the virus detection engine corresponding to each virus feature. In this way, when the virus detection engine involved in the local virus library is called to perform virus detection on the network device, the virus detection engine can perform virus detection on the network device based on the correspondence between the virus detection engine and the virus features in the virus directory and rely on its own corresponding virus features.

[0128] In some embodiments of the present application, in order to quickly detect and kill viruses, the virus database update method may also include the following steps: adding the virus md5 value of the known virus to the network device. And / or, when there is data to be detected by the virus in the network device, the target md5 value of the data to be detected by the virus is compared with the virus md5 value of the known virus pre-stored in the network device; if the target md5 value does not exist in the virus md5 value, the local virus database is called to perform virus detection on the data to be detected by the virus.

[0129] When there is data to be detected by viruses in the network device, in order to quickly determine whether it is a virus, the target md5 value of the data to be detected is first compared with the virus md5 value of the known virus pre-stored in the network device. If it is determined after the comparison that the target md5 value does not exist in the virus md5 value, it means that it is not clear whether the data to be detected is a virus at present, so the local virus library is further called to perform virus detection on the data to be detected to determine whether the data is a virus. If it is determined after the comparison that the target md5 value exists in the virus md5 value, it means that the data can be clearly identified as a virus, and the data is processed such as interception and deletion.

[0130] In some embodiments of the present application, the first virus feature corresponding to the first virus detection engine can be obtained from the engine feature library of the first virus detection engine located on the server. After the acquisition, the first virus feature needs to be transmitted to the network device through the server for local virus library update. Therefore, in order to ensure the security of the first virus feature and prevent the first virus feature from being maliciously tampered with during the transmission between the server and the network device, the virus library update method may also include the following steps: performing a first target processing on the first virus feature, and obtaining feature data after pushing the first target processing to the network device, wherein the first target processing includes compression processing and / or encryption processing. After the network device receives the feature data, it performs a corresponding second target processing on the feature data to obtain the target virus feature.

[0131] The first target processing can flexibly select one or both of compression processing and encryption processing. When both are selected, the order of using compression processing and encryption processing can be flexibly set based on business requirements. After pushing the feature data obtained after the first target processing to the network device, the network device uses the second target processing corresponding to the first target processing to process the feature data in order to obtain the first virus feature included in the feature data. Specifically, when the first target processing includes compression processing, the second target processing includes corresponding decompression processing. When the first target processing includes encryption processing, the second target processing includes corresponding decryption processing.

[0132] The present application also provides a virus detection method, such as Figure 2 As shown, the virus detection method mainly includes the following steps 201 to 202:

[0133] 201. In response to determining to perform virus detection on a network device, obtain a current device configuration of the network device.

[0134] The virus detection method provided in this embodiment is applied to network devices, and is mainly used to perform virus detection on data to be detected in network devices. When determining to perform virus detection on a network device, it is first necessary to obtain the current network device of the network device, so that a virus detection engine suitable for performing virus detection on a network device with the current network device configuration can be selected based on the current network device, and virus detection can be performed on the network device. The current device configuration includes at least one of the following: device serial number, current deployment system and corresponding system version, memory size, and CPU number.

[0135] The method of determining whether to perform virus detection on a network device may include at least the following two methods: first, detecting whether the data of the CPU in the network device is stored in the shared memory. For example, when the network device is a firewall device, detecting whether the CPU of the firewall device stores the data through the wall in the shared memory. If it is detected that it is stored in the shared memory, it is determined to perform virus detection on the network device; second, detecting whether a virus detection instruction is received. If received, it is determined to perform virus detection on the network device. Users can issue virus detection instructions at an appropriate time based on the business.

[0136] 202. Determine, from a plurality of virus detection engines, a second virus detection engine suitable for performing virus detection on a network device having a current network device configuration, each virus detection engine having a corresponding virus feature.

[0137] In this embodiment, multiple virus detection engines are preset, and each virus detection engine has corresponding virus features and device configurations. The device configuration is used to instruct the corresponding virus detection engine to perform virus detection on the network device with the device configuration, and the virus detection process is stable, which can play a role in virus detection and improve the virus detection rate.

[0138] After obtaining the current network device configuration, the current network device configuration is matched with the device configuration corresponding to each virus detection engine. If the match is successful, the virus detection engine corresponding to the successfully matched device configuration is determined as the second virus detection engine. If the match fails, a match failure prompt is issued so that the business personnel can take corresponding measures based on the prompt.

[0139] 203. Call the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device.

[0140] Each virus detection engine has a corresponding engine feature library. The engine feature library is used to store the virus features corresponding to the corresponding virus detection engine. The virus detection engine implements virus detection based on the corresponding virus features. Therefore, the specific process of calling the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device may include the following steps 203A to 203B:

[0141] 203A. Load the second virus signature corresponding to each second virus detection engine from the engine signature library corresponding to each second virus detection engine.

[0142] The virus detection capability of the second virus detection engine depends on its corresponding virus feature implementation. Therefore, it is necessary to load the second virus features corresponding to each second virus detection engine from the engine feature library corresponding to each second virus detection engine, so that each second virus detection engine has the corresponding second virus available.

[0143] Furthermore, in order to facilitate virus detection on the network device, a local virus library is deployed in the network device, and the local virus library is used to store virus features corresponding to multiple virus detection engines. Therefore, the virus detection method may also include executing the following steps for each second virus detection engine: determining whether the local virus library includes the second virus feature corresponding to the second virus detection engine; if included, loading the second virus feature corresponding to the second virus detection engine from the local virus library; if not included, executing the above step 203A to load the second virus feature corresponding to the second virus detection engine from the corresponding engine feature library.

[0144] The local virus library is deployed in the network device, so loading the second virus feature of the second virus detection engine from the local virus library is more convenient than loading the second virus feature from the engine virus library. Therefore, when loading the second virus feature corresponding to the second virus detection engine, it is possible to first determine whether the local virus library includes the second virus feature corresponding to the second virus detection engine. In the case where it is determined that the local virus library includes the second virus feature corresponding to the second virus detection engine, in order to improve the loading efficiency of the second virus feature, the second virus feature corresponding to the second virus detection engine is loaded from the local virus library. In the case where it is determined that the local virus library does not include the second virus feature corresponding to the second virus detection engine, in order to ensure that the second virus detection engine has the second virus to rely on, the above step 203A is executed to load the second virus feature corresponding to the second virus detection engine from the corresponding engine feature library.

[0145] 203B. Call each second virus detection engine through a preset virus detection process, and perform virus detection on the network device based on the loaded corresponding second virus signature.

[0146] The second virus detection engine can only exert its virus detection capability after being called, so each second virus detection engine can be called through a preset virus detection process to perform virus detection on the network device based on the loaded corresponding second virus features.

[0147] The preset virus detection process includes at least one virus detection thread, and each virus detection thread has a corresponding source CPU in the network device. The virus detection thread is used to call the corresponding second virus detection engine, and perform virus detection on the virus detection data to be generated by the corresponding source CPU based on the loaded corresponding second virus features. Therefore, the specific process of calling each second virus detection engine through the preset virus detection process and performing virus detection on the network device based on the loaded corresponding second virus features may include the following steps 203B1 to 203B2:

[0148] 203B1. Determine the source CPU of the data to be detected for viruses in the network device.

[0149] In this embodiment, the purpose of setting a corresponding virus detection thread for each source CPU in the network device is to disperse the virus detection operation through the virus detection thread. When there is data to be detected by virus in the network device, the second virus detection engine is called through the virus detection thread corresponding to the source CPU of the data to be detected by virus, and virus detection is performed on the data to be detected based on the corresponding second virus features loaded. In this way, each virus detection thread is only responsible for the virus detection of the corresponding source CPU, thereby reducing the impact of virus detection on the performance of network element equipment.

[0150] Furthermore, a shared memory divided into at least one cache area is provided in the network device. Each cache area has a corresponding source CPU in the network device and is used to store the virus detection data of the corresponding source CPU. It can be seen that in this embodiment, the virus detection data of the source CPU in the network device will be cached in the shared memory, so that when the second virus detection engine is called to perform virus detection on the virus detection data, the virus detection can be performed directly in the shared memory, thereby reducing data copying.

[0151] Since each cache area is used to store the virus detection data of the corresponding source CPU, the specific process of determining the source CPU of the virus detection data in the network device in step 203B1 may include the following steps: determining the target cache area where the virus detection data is located. Determine the source CPU corresponding to the target cache area as the source CPU of the virus detection data.

[0152] Furthermore, each source CPU issues a virus detection request after caching the data to be detected for viruses into the shared memory. Therefore, the virus detection method may also include the following monitoring process to determine when to execute the above 203B1 to determine the source CPU of the data to be detected for viruses in the network device. The monitoring process may include the following steps: monitoring whether the source CPU in the network device issues a virus detection request. If monitored, the data to be detected for viruses is read from the cache area corresponding to the source CPU that issued the virus detection request, and the step of determining the source CPU of the data to be detected for viruses in the network device is executed.

[0153] If a virus detection request is monitored, it means that there must be data to be detected in the shared memory. Therefore, the data to be detected is read from the cache area corresponding to the source CPU that issued the virus detection request, and the above 203B1 is executed to determine the source CPU of the data to be detected in the network device, so as to call the second virus detection engine through the virus detection thread corresponding to the source CPU, and perform virus detection on the data to be detected based on the loaded corresponding second virus features.

[0154] 203B2. Call the second virus detection engine through the virus detection thread corresponding to the source CPU, and perform virus detection on the data to be detected based on the loaded corresponding second virus features.

[0155] In order to find a virus detection thread suitable for virus detection on the virus detection data, the virus detection method may further include the following steps: finding out whether there is a virus detection thread corresponding to the source CPU in the at least one virus detection thread. If there is, calling the second virus detection engine through the virus detection thread corresponding to the source CPU, and performing virus detection on the virus detection data based on the loaded corresponding second virus features. If there is not, creating a virus detection thread corresponding to the source CPU, and calling the second virus detection engine through the created virus detection thread, and performing virus detection on the virus detection data based on the loaded corresponding second virus features.

[0156] If it is found that there is a virus detection thread corresponding to the source CPU in the at least one virus detection thread, it means that there is an available virus detection thread currently, then the step of calling the second virus detection engine through the virus detection thread corresponding to the source CPU and performing virus detection on the data to be detected based on the loaded corresponding second virus features is executed.

[0157] If it is found that there is no virus detection thread corresponding to the source CPU in the at least one virus detection thread, it means that there is no corresponding virus detection thread currently in the source CPU, then a virus detection thread corresponding to the source CPU is created, and the second virus detection engine is called through the created virus detection thread to perform virus detection on the virus detection data based on the loaded corresponding second virus feature. In this way, the threads can be expanded as the CPU is added, so that each CPU has a corresponding virus detection thread, which is responsible for performing virus detection on the target data corresponding to the CPU.

[0158] It can be seen that the virus detection method provided in the embodiment of the present application, when determining to perform virus detection on a network device, determines, based on the current device configuration of the network device, from multiple virus detection engines, a second virus detection engine suitable for performing virus detection on a network device with the current network device configuration, and then calls the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device. It can be seen that the scheme provided in the embodiment of the present application adopts a virus detection engine suitable for performing virus detection on a network device with the current device configuration to perform virus detection on the network device. Performing virus detection on the network device based on these virus detection engines can not only improve the virus detection rate, but also the device configuration of the network device can support the virus detection of these virus detection engines, thereby reducing the impact of virus detection on the performance of the network device itself.

[0159] In some embodiments of the present application, after the second virus feature corresponding to the second virus detection engine is called to perform virus detection on the network device in the above step 203, the second virus detection engine feeds back the corresponding virus detection result. Therefore, the virus detection method may also include the following steps: if any second virus detection engine is monitored to feed back a virus detection result, and it is determined that the virus detection result indicates that the data to be detected has a virus, a disposal instruction is issued to the source CPU corresponding to the data to be detected through a preset virus detection process, so that the source CPU performs corresponding virus protection disposal on the data to be detected based on the disposal instruction.

[0160] The purpose of virus detection is to prevent viruses from endangering the security of network devices. Therefore, if any second virus detection engine is monitored to feedback virus detection results, and it is determined that the virus detection results indicate that the data to be detected by the virus has a virus, then in order to reduce the harm of the virus to the network device, a disposal instruction is issued to the source CPU corresponding to the data to be detected by the virus through the preset virus detection process, so that the source CPU performs corresponding virus protection disposal on the data to be detected by the virus based on the disposal instruction. The specific disposal method of virus disposal can be flexibly selected based on business needs. For example, the disposal method of virus disposal is to delete the corresponding data to be detected by the virus.

[0161] Furthermore, if any second virus detection engine is monitored to feedback a virus detection result, and it is determined that the virus detection result indicates that there is no virus in the data to be detected, a release instruction is issued to the source CPU corresponding to the data to be detected through a preset virus detection process, so that the source CPU releases the corresponding business of the data to be detected based on the release instruction, so that the corresponding business can be executed smoothly.

[0162] In some embodiments of the present application, after the above step 203 calls the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device, the virus detection method may also include the following steps: if it is determined that the second virus detection engine has completed virus detection on the data to be detected, the data to be detected is transferred to a designated location.

[0163] Transferring the data to be detected for viruses to a designated location can prevent the same data to be detected for viruses from being detected repeatedly, thereby avoiding additional virus detection consumption. The designated location can be flexibly selected based on business needs. For example, the designated location is a cache space of a network device.

[0164] In some embodiments of the present application, the virus detection method may further include the following steps: monitoring whether a preset virus detection process has any operational abnormalities; if an operational abnormality is monitored and it is determined that the number of consecutive occurrences of the operational abnormality is less than a target threshold, restarting the preset virus detection process; if an operational abnormality is monitored and it is determined that the number of consecutive occurrences of the operational abnormality is not less than the target threshold, issuing a process abnormality prompt.

[0165] During the operation of the preset virus detection process, abnormal conditions such as stopping operation may occur. When the above abnormal conditions occur, the second virus detection engine will interrupt the virus detection of the network device, and the interruption of virus detection will affect the network security of the network device. Therefore, in order to timely discover and troubleshoot abnormal conditions of the preset virus detection process, it is necessary to monitor whether the preset virus detection process has abnormal operation.

[0166] If an operation abnormality is monitored and it is determined that the number of consecutive operation abnormalities is less than the target threshold, it means that the abnormality can be eliminated with a high probability by restarting the preset virus detection process, so the preset virus detection process is restarted.

[0167] If an operation abnormality is monitored and it is determined that the number of consecutive operation abnormalities is not less than the target threshold, it means that the abnormality of the preset virus detection process is difficult to eliminate by restarting. Therefore, the user is prompted by issuing a process abnormality prompt so that the user can intervene in the abnormality elimination in time based on the prompt.

[0168] In some embodiments of the present application, in order to improve the virus detection effect of the virus detection engine, the engine virus library is usually updated at a set period. The virus features in the updated engine virus library are more suitable for virus detection of network devices. Therefore, in order to improve the virus detection effect, the virus detection method may also include the following steps: monitoring whether the engine virus library is updated; if updated, reloading the second virus features of the corresponding second virus detection engine from the updated engine virus library.

[0169] If the engine virus database is monitored to be updated, it means that the virus signatures in the engine virus database may have changed, and the currently loaded virus signatures are no longer the most suitable virus signatures for virus detection on network devices. Therefore, in order to improve the virus detection effect, it is necessary to reload the second virus signatures of the corresponding second virus detection engine to perform virus detection on the network device based on the reloaded virus signatures that are currently most suitable for virus detection on the network device.

[0170] In some embodiments of the present application, the preset virus detection process is different from the network device's own service process. In other words, the preset virus detection process is independent of the network device's own service process, and is an independent process, which can reduce the interference of virus detection on the network device's own service.

[0171] In some embodiments of the present application, the following Figure 3 The implementation process of virus detection based on the virus detection method of this embodiment is described as an example. Figure 3 In the embodiment, the preset virus detection process includes a parent process and a child process. The parent process is responsible for monitoring the child process, and the child process includes multiple virus detection threads. The network device includes multiple source CPUs, which are CPU1 to CPUn, and each source CPU has its own data transmission interface DP, and stores its own data to be detected by viruses to the shared memory through the corresponding data transmission interface. Each source CPU has a corresponding virus detection thread. For example, CPU1 corresponds to virus detection thread 1, and CPU2 corresponds to virus detection thread 2. The shared memory is divided into multiple cache areas, and each source CPU has a corresponding cache area, which is used to store the corresponding source CPU's data to be detected by viruses.

[0172] In this embodiment, when determining to perform virus detection on a network device, the current device configuration of the network device is obtained, and a second virus detection engine suitable for performing virus detection on a network device having the current network device configuration is determined from multiple virus detection engines. The second virus features corresponding to each second virus detection engine are loaded from the engine feature library corresponding to each second virus detection engine through a subprocess in a preset virus detection process.

[0173] In this embodiment, after any source CPU caches the data to be detected by the virus in the shared memory, it can send a virus detection request to the sub-process in the preset virus detection process through the transmission channel 1. Then, the sub-process in the preset virus detection process determines the target cache area where the data to be detected by the virus is located based on the virus detection request, and determines the source CPU corresponding to the target cache area as the source CPU of the data to be detected by the virus. The second virus detection engine is called through the virus detection thread corresponding to the source CPU of the data to be detected by the virus, and the virus detection is performed on the data to be detected by the virus based on the corresponding second virus features loaded. For example, Figure 3 As shown, it is determined that the target cache area where the data to be detected for virus is located is cache area 1, then the source CPU "CPU1" corresponding to the target cache area is determined as the source CPU of the data to be detected for virus, and then the second virus detection engine is called through the virus detection thread "Thread 1" corresponding to the source CPU "CPU1", and virus detection is performed on the data to be detected for virus based on the loaded corresponding second virus features.

[0174] After the second virus detection engine is called through the virus detection thread corresponding to the source CPU, and the data to be detected for viruses is detected based on the corresponding second virus features loaded, the second virus detection engine feeds back the corresponding virus detection results, which will be fed back to the corresponding source CPU through transmission channel 2, so that the source CPU can perform corresponding disposal operations. For example, the second virus detection engine is called through the virus detection thread "Thread 1" corresponding to the source CPU "CPU1", and after the data to be detected for viruses is detected based on the corresponding second virus features loaded, Thread 1 feeds back virus detection result 1, and determines that virus detection result 1 indicates that the data to be detected for viruses has viruses, then the preset virus detection process sends disposal instructions to the source CPU "CPU1" corresponding to the data to be detected for viruses through transmission channel 2, so that "CPU1" performs corresponding virus protection disposal on the data to be detected for viruses based on the disposal instructions, so as to prevent the data to be detected for viruses from endangering the network security of the network device.

[0175] Furthermore, the parent process monitors whether the child process has an abnormal operation. If an abnormal operation is monitored and it is determined that the number of consecutive abnormal operation occurrences is less than the target threshold, the child process is restarted. If an abnormal operation is monitored and it is determined that the number of consecutive abnormal operation occurrences is not less than the target threshold, a process abnormality prompt is issued.

[0176] Furthermore, an embodiment of the present application also provides a virus database update system, such as Figure 4 As shown, the virus database update system includes:

[0177] The processing device 31 is used for obtaining the current device configuration of the network device in response to determining to update the local virus library of the network device; determining a first virus detection engine suitable for performing virus detection on the network device having the current network device configuration from a plurality of virus detection engines, each of the virus detection engines having a corresponding virus feature;

[0178] The updating device 32 is used to update the virus feature in the local virus database based on the first virus feature corresponding to the first virus detection engine.

[0179] In this embodiment, the processing device 31 can be a server, a cloud platform, etc. The updating device 32 is deployed in a network device. The local virus database in the network device is updated through the interaction between the processing device 31 and the updating device 32.

[0180] The virus library updating system provided by the embodiment of the present application, when determining to update the local virus library in the network device, determines the first virus detection engine suitable for performing virus detection on the network device with the current network device configuration from multiple virus detection engines based on the current device configuration of the network device, and then updates the virus features in the local virus library based on the first virus feature corresponding to the first virus detection engine. It can be seen that the scheme provided by the embodiment of the present application is no longer updated by the subjective experience of the update personnel when updating the local virus library, but selects the virus detection engine suitable for performing virus detection on the network device through the current device configuration of the network device, and then updates the virus library based on the virus feature of the selected virus detection engine, so that the updated local virus library has strong applicability to the network device, and performing virus detection on the network device based on such a virus library can improve the virus detection rate. In addition, the virus features in the local virus library limit the virus detection engine suitable for performing virus detection on the network device with the current device configuration, so that the network device can perform virus detection on the network device, so the device configuration of the network device can support the virus detection of these virus detection engines, thereby reducing the impact of virus detection on the performance of the network device itself.

[0181] In some embodiments of the present application, Figure 5 As shown, each of the virus detection engines has a corresponding engine feature library, and the engine feature library is used to store the virus features of the corresponding virus detection engine; then, the processing device 31 includes:

[0182] The first judgment module 311 is used to determine, for each of the first virus detection engines, whether the existing virus features in the local virus library include the virus features corresponding to the first virus detection engine before the network device 32 updates the virus features in the local virus library based on the first virus features corresponding to the first virus detection engine; if not, trigger the first acquisition module 312 to acquire all the virus features of the first virus detection engine as the first virus features from the corresponding engine feature library; if included, trigger the second acquisition module 313 to acquire the first virus features from the virus features stored in the corresponding engine feature library based on the feature type of the corresponding existing virus features in the local virus library.

[0183] In some embodiments of the present application, Figure 5 As shown, the processing device 31 also includes:

[0184] The first confirmation module 314 is used to send a first inquiry message to the first audit end after the first judgment module 311 determines that the existing virus features of the local virus library do not include the virus features corresponding to the first virus detection engine, so as to confirm whether it is necessary to store the basic virus features of the first virus detection engine in the local virus library, and whether it is not necessary to store the non-basic virus features of the first virus detection engine in the local virus library, wherein the basic virus features and the non-basic virus features constitute all the virus features of the first virus detection engine; if a confirmation instruction fed back by the first audit end is received, the third acquisition module 315 is triggered to acquire the basic virus features of the first virus detection engine as the first virus features from the corresponding engine feature library; if a rejection instruction fed back by the first audit end is received, the first acquisition module 312 is triggered to execute the step of acquiring all the virus features of the first virus detection engine as the first virus features from the corresponding engine feature library.

[0185] In some embodiments of the present application, Figure 5 As shown, the processing device 31 also includes:

[0186] The second judgment module 316 is used to judge whether the local virus library stores all virus features of the virus detection engine by default; if it does so by default, the first acquisition module 312 is triggered to execute the step of acquiring all virus features of the first virus detection engine as first virus features from the corresponding engine feature library; if it does not by default, the first confirmation module 314 is triggered to execute the step of sending a first inquiry message to the first audit end.

[0187] In some embodiments of the present application, Figure 5 As shown, the processing device 31 also includes:

[0188] The second confirmation module 317 is used to send a second inquiry message to the second audit end to confirm whether to fully update the virus features of the first virus detection engine in the local virus library after the first judgment module 311 determines that the existing virus features of the local virus library include the virus features corresponding to the first virus detection engine; if a full update confirmation instruction fed back by the second audit end is received, the first acquisition module 312 is triggered to acquire all the virus features of the first virus detection engine from the corresponding engine feature library as the first virus features; if the full update confirmation instruction fed back by the second audit end is not received, or if a full update rejection confirmation instruction fed back by the second audit end is received, the second acquisition module 313 is triggered to execute the step of acquiring the first virus features from the virus features stored in the corresponding engine feature library based on the feature type of the corresponding existing virus features in the local virus library.

[0189] In some embodiments of the present application, Figure 5 As shown, the processing device 31 also includes:

[0190] The third confirmation module 318 is used to determine whether the local virus library updates all virus features by default after the first judgment module 311 determines that the existing virus features of the local virus library include the virus features corresponding to the first virus detection engine; if by default, trigger the first acquisition module 312 to acquire all virus features of the first virus detection engine from the corresponding engine feature library as the first virus feature; if not by default, trigger the second acquisition module 313 to execute the step of acquiring the first virus feature from the virus features stored in the corresponding engine feature library based on the feature type of the corresponding existing virus features in the local virus library.

[0191] In some embodiments of the present application, Figure 5 As shown, the second acquisition module 313 is specifically used to determine whether the corresponding existing virus features in the local virus library are all basic virus features based on the feature types of the corresponding existing virus features in the local virus library; if so, the basic virus features in the new virus features of the first virus detection engine are acquired as the first virus features from the corresponding engine feature library; the new virus features are the virus features that are newly added or changed by the first virus detection engine after the local virus library was last updated; if not, all the new virus features of the first virus detection engine are acquired as the first virus features from the corresponding engine feature library.

[0192] In some embodiments of the present application, Figure 5As shown, the second acquisition module 313 is also used to send a third inquiry message to the third review end to confirm whether it is necessary to incrementally update the non-basic virus features of the first virus detection engine to the local virus library after determining that the corresponding existing virus features in the local virus library are all basic virus features; if a confirmation instruction is received from the third review end, the non-basic virus features of the first virus detection engine and the basic virus features in the new virus features are acquired as the first virus features from the corresponding engine feature library; if a rejection instruction is received from the third review end, the step of acquiring the basic virus features in the new virus features of the first virus detection engine as the first virus features from the corresponding engine feature library is executed.

[0193] In some embodiments of the present application, Figure 5 As shown, the first judgment module 311 is specifically used to detect whether the first virus detection engine is determined as a virus detection engine suitable for performing virus detection on the network device when the local virus database is last updated; if so, it is determined that the existing virus features of the local virus database include the virus features of the first virus detection engine; otherwise, it is determined that the existing virus features of the local virus database do not include the virus features of the first virus detection engine.

[0194] In some embodiments of the present application, Figure 5 As shown, the first judgment module 311 is specifically used to send a fourth inquiry message to the network device to inquire the network device whether the virus features of the first virus detection engine exist in the local virus library; if the network device feedback confirms that there is an instruction, it is determined that the existing virus features of the local virus library include the virus features of the first virus detection engine; if the network device feedback confirms that there is no instruction, it is determined that the existing virus features of the local virus library do not include the virus features of the first virus detection engine.

[0195] In some embodiments of the present application, Figure 5 As shown, the updating device 22 is specifically used to detect whether the virus feature corresponding to the first virus detection engine already exists in the local virus library for each of the first virus detection engines; if not, add the first virus feature of the first virus detection engine to the local virus library; if already exists, determine whether the first virus feature corresponding to the first virus detection engine can fully cover the existing virus features of the first virus detection engine in the local virus library; if it can fully cover, fully replace the relevant existing virus features with the first virus features; if it cannot fully cover, incrementally update the relevant existing virus features based on the first virus features.

[0196] In some embodiments of the present application, Figure 5 As shown, the updating device 22 is specifically used to detect whether there is a corresponding virus feature in the relevant existing virus features for each of the first virus features; if so, replace the corresponding virus feature with the first virus feature; if not, add the first virus feature to the local virus library.

[0197] In some embodiments of the present application, Figure 5 As shown, the updating device 22 is also used to add the virus md5 value of the known virus to the network device; and / or, when there is data to be detected by the virus in the network device, the target md5 value of the data to be detected by the virus is compared with the virus md5 value of the known virus pre-stored in the network device; if the target md5 value does not exist in the virus md5 value, the local virus library is called to perform virus detection on the data to be detected by the virus.

[0198] In some embodiments of the present application, Figure 5 As shown, the updating device 22 includes:

[0199] The first detection module 221 is used to determine to update the local virus database of the network device if an update instruction for the local virus database is detected; wherein the update instruction is generated by the virus database update process in the network device when monitoring reaches the update cycle of the local virus database.

[0200] In some embodiments of the present application, Figure 5 As shown, the updating device 22 includes:

[0201] The second detection module 222 is used to monitor the device configuration of the network device; if it is monitored that the device configuration of the network device has changed, it is determined to update the local virus database of the network device.

[0202] In some embodiments of the present application, Figure 5 As shown, the updating device 22 also includes:

[0203] The prediction module 223 is used to determine whether the expected storage space of the local virus library required to update the virus features in the local virus library based on the first virus feature corresponding to the first virus detection engine exceeds the current actual storage space of the local virus library; if not, the step of updating the virus features in the local virus library based on the first virus feature corresponding to the first virus detection engine is executed; if exceeded, the current actual storage space of the local virus library is expanded to be not less than the expected storage space, and then the step of updating the virus features in the local virus library based on the first virus feature corresponding to the first virus detection engine is executed, or a prompt is issued that the existing storage space of the local virus library is insufficient.

[0204] In some embodiments of the present application, Figure 5 As shown, the current device configuration includes at least one of the following: device serial number, current deployment system and corresponding system version, memory size, and CPU quantity.

[0205] In the virus database updating system provided in the embodiment of the present application, the detailed descriptions used in the operation of each functional module can be found in the corresponding detailed descriptions of the above-mentioned virus database updating method embodiment, which will not be repeated here.

[0206] Furthermore, an embodiment of the present application also provides a virus detection device, such as Figure 6 As shown, the virus detection device comprises:

[0207] An acquisition module 41, configured to acquire a current device configuration of the network device in response to determining to perform virus detection on the network device;

[0208] A determination module 42, configured to determine, from a plurality of virus detection engines, a second virus detection engine suitable for performing virus detection on a network device having the current network device configuration, each of the virus detection engines having a corresponding virus feature;

[0209] The detection module 43 is used to call the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device.

[0210] The virus detection method provided in the embodiment of the present application, when determining to perform virus detection on a network device, determines a second virus detection engine suitable for performing virus detection on a network device having the current network device configuration from multiple virus detection engines based on the current device configuration of the network device, and then calls the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device. It can be seen that the scheme provided in the embodiment of the present application adopts a virus detection engine suitable for performing virus detection on a network device having the current device configuration to perform virus detection on the network device. Performing virus detection on the network device based on these virus detection engines can not only improve the virus detection rate, but also the device configuration of the network device can support the virus detection of these virus detection engines, thereby reducing the impact of virus detection on the performance of the network device itself.

[0211] In some embodiments of the present application, Figure 7 As shown, each of the virus detection engines has a corresponding engine feature library, and the engine feature library is used to store virus features corresponding to the corresponding virus detection engine; then, the detection module 43 includes:

[0212] A loading unit 430, configured to load the second virus signature corresponding to each of the second virus detection engines from an engine signature library corresponding to each of the second virus detection engines;

[0213] The detection unit 431 is used to call each of the second virus detection engines through the preset virus detection process, and perform virus detection on the network device based on the loaded corresponding second virus features.

[0214] In some embodiments of the present application, Figure 7 As shown, a local virus library is deployed in the network device; then, the detection module 43 also includes:

[0215] The judgment unit 432 is used to judge, for each of the second virus detection engines, whether the local virus library includes the second virus feature corresponding to the second virus detection engine; if so, load the second virus feature corresponding to the second virus detection engine from the local virus library; if not, trigger the loading unit 430 to execute the step of loading the second virus feature corresponding to the second virus detection engine from the corresponding engine feature library.

[0216] In some embodiments of the present application, Figure 7 As shown, the preset virus detection process includes at least one virus detection thread, and each of the virus detection threads has a corresponding source CPU in the network device; then, the detection unit 431 is specifically used to determine the source CPU of the data to be detected by the virus in the network device; call the second virus detection engine through the virus detection thread corresponding to the source CPU, and perform virus detection on the data to be detected by the virus based on the loaded corresponding second virus features.

[0217] In some embodiments of the present application, Figure 7 As shown, the detection module 43 also includes:

[0218] The searching unit 433 is used to search whether there is a virus detection thread corresponding to the source CPU in the at least one virus detection thread; if so, the detecting unit 431 is triggered to execute the step of calling the second virus detection engine through the virus detection thread corresponding to the source CPU, and performing virus detection on the data to be detected based on the loaded corresponding second virus features; if not, the creating unit 434 is triggered to create a virus detection thread corresponding to the source CPU, and the second virus detection engine is called through the created virus detection thread, and the data to be detected based on the loaded corresponding second virus features is detected.

[0219] In some embodiments of the present application, Figure 7As shown, the network device is provided with a shared memory divided into at least one cache area; each of the cache areas has a corresponding source CPU in the network device and is used to store the virus detection data to be detected by the corresponding source CPU; then, the detection unit 431 is specifically used to determine the target cache area where the virus detection data to be detected is located; and the source CPU corresponding to the target cache area is determined as the source CPU of the virus detection data to be detected.

[0220] In some embodiments of the present application, Figure 7 As shown, the network device is provided with a shared memory divided into at least one cache area; each of the cache areas has a corresponding source CPU in the network device and is used to store the virus detection data to be detected by the corresponding source CPU; each of the source CPUs issues a virus detection request after caching the virus detection data to be detected in the shared memory, then, the detection module 43 also includes:

[0221] The first monitoring unit 435 is used to monitor whether the source CPU in the network device issues a virus detection request; if monitored, the data to be detected by the virus is read from the cache area corresponding to the source CPU that issues the virus detection request, and the detection unit 431 is triggered to execute the step of determining the source CPU of the data to be detected by the virus in the network device.

[0222] In some embodiments of the present application, Figure 7 As shown, after calling the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device, the second virus detection engine feeds back the corresponding virus detection result, then the detection module 43 further includes:

[0223] The feedback unit 436 is used to send a processing instruction to the source CPU corresponding to the data to be detected through the preset virus detection process if any of the second virus detection engines is monitored to feedback a virus detection result, and it is determined that the virus detection result indicates that the data to be detected contains a virus, so that the source CPU can perform corresponding virus protection processing on the data to be detected based on the processing instruction.

[0224] In some embodiments of the present application, Figure 7 As shown, the detection module 43 also includes:

[0225] The moving unit 437 is configured to transfer the data to be detected by viruses to a designated location if it is determined that the second virus detection engine has completed the virus detection on the data to be detected by viruses.

[0226] In some embodiments of the present application, Figure 7 As shown, the detection module 43 also includes:

[0227] The second monitoring unit 438 is used to monitor whether the preset virus detection process has any operation abnormalities; if an operation abnormality is monitored and it is determined that the number of consecutive operation abnormalities is less than the target threshold, the preset virus detection process is restarted; if an operation abnormality is monitored and it is determined that the number of consecutive operation abnormalities is not less than the target threshold, a process abnormality prompt is issued.

[0228] In some embodiments of the present application, Figure 7 As shown, the detection module 43 also includes:

[0229] The third monitoring unit 439 is used to monitor whether the engine virus library is updated; if updated, reload the second virus signature of the corresponding second virus detection engine from the updated engine virus library.

[0230] In some embodiments of the present application, Figure 7 As shown, the preset virus detection process involved in the detection module 43 is different from the service process of the network device itself.

[0231] In the virus detection device provided in the embodiment of the present application, the detailed description used in the operation process of each functional module can be referred to the corresponding detailed description of the above-mentioned virus detection method embodiment, which will not be repeated here.

[0232] Furthermore, an embodiment of the present application also provides a computer-readable storage medium, which includes a stored program, wherein when the program is running, the device where the storage medium is located is controlled to execute the above-mentioned virus database update method and / or execute the above-mentioned virus detection method.

[0233] Furthermore, an embodiment of the present application also provides an electronic device, comprising: a memory for storing programs; a processor, coupled to the memory, for running the programs to execute the above-mentioned virus database updating method, and / or, to execute the above-mentioned virus detection method.

[0234] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0235] It is understandable that the related features in the above methods and devices can be referenced to each other. In addition, the "first", "second" and the like in the above embodiments are used to distinguish the embodiments, but do not represent the advantages and disadvantages of the embodiments.

[0236] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0237] The algorithm and display provided herein are not inherently related to any particular computer, virtual system or other device. Various general purpose systems can also be used together with the teachings based on this. According to the above description, it is obvious to construct the structure required for this type of system. In addition, the application is not directed to any specific programming language either. It should be understood that various programming languages ​​can be utilized to realize the content of the application described herein, and the description of the above specific language is to disclose the preferred embodiment of the application.

[0238] In addition, the memory may include a non-permanent memory in a computer-readable medium, a random access memory (RAM) and / or a non-volatile memory, such as a read-only memory (ROM) or a flash memory (flash RAM), and the memory includes at least one memory chip. It should be understood by those skilled in the art that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing a computer-usable program code.

[0239] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data cutover device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data cutover device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0240] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data switching device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0241] These computer program instructions can also be loaded onto a computer or other programmable data transfer device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps of the functions specified in the box or multiple boxes. In a typical configuration, the computing device includes one or more processors (CPU), input / output interfaces, network interfaces and memory. The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0242] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves. It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0243] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0244] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.

Claims

1. A virus database updating method, characterized in that: The method comprises: In response to determining to update the local virus database of the network device, obtaining a current device configuration of the network device; Determining, from a plurality of virus detection engines, a first virus detection engine suitable for performing virus detection on a network device having the current network device configuration, each of the virus detection engines having a corresponding virus feature; Based on the first virus feature corresponding to the first virus detection engine, the virus feature in the local virus database is updated.

2. The method according to claim 1, characterized in that Each of the virus detection engines has a corresponding engine feature library, and the engine feature library is used to store the virus features of the corresponding virus detection engine; then, before updating the virus features in the local virus library based on the first virus features corresponding to the first virus detection engine, the method further includes: For each of the first virus detection engines, determine whether the existing virus features in the local virus library include the virus features corresponding to the first virus detection engine; if not, obtain all the virus features of the first virus detection engine as first virus features from the corresponding engine feature library; if included, obtain the first virus feature from the virus features stored in the corresponding engine feature library based on the feature type of the corresponding existing virus features in the local virus library.

3. The method according to claim 2, characterized in that After determining that the existing virus features in the local virus database do not include the virus features corresponding to the first virus detection engine, the method further includes: Sending a first inquiry message to the first audit terminal to confirm whether it is necessary to store basic virus features of the first virus detection engine in the local virus database, and it is not necessary to store non-basic virus features of the first virus detection engine in the local virus database, wherein the basic virus features and the non-basic virus features constitute all virus features of the first virus detection engine; If a confirmation instruction fed back by the first audit terminal is received, the basic virus feature of the first virus detection engine is obtained from the corresponding engine feature library as a first virus feature; If a rejection instruction fed back by the first audit end is received, a step of acquiring all virus features of the first virus detection engine as first virus features from a corresponding engine feature library is executed.

4. The method according to claim 3, characterized in that The method further comprises: Determine whether the local virus database stores all virus features of the virus detection engine by default; If by default, the step of acquiring all virus features of the first virus detection engine as first virus features from the corresponding engine feature library is performed; If not, the step of sending the first inquiry information to the first audit terminal is executed.

5. The method according to claim 2, characterized in that: After determining that the existing virus features in the local virus database include the virus features corresponding to the first virus detection engine, the method further includes: Sending a second inquiry message to the second audit terminal to confirm whether to fully update the virus features of the first virus detection engine in the local virus database; If a full update confirmation instruction fed back by the second audit terminal is received, all virus features of the first virus detection engine are obtained as first virus features from the corresponding engine feature library; If no full update confirmation instruction is received from the second audit end, or if a full update rejection confirmation instruction is received from the second audit end, the step of obtaining the first virus feature from the virus features stored in the corresponding engine feature library based on the feature type of the corresponding existing virus feature in the local virus library is executed.

6. The method according to claim 2, characterized in that After determining that the existing virus features in the local virus database include the virus features corresponding to the first virus detection engine, the method further includes: Determine whether the local virus database fully updates virus signatures by default; If by default, all virus features of the first virus detection engine are obtained from the corresponding engine feature library as first virus features; If not, a step of acquiring a first virus feature from virus features stored in a corresponding engine feature library is performed based on the feature type of the corresponding existing virus feature in the local virus library.

7. The method according to any one of claims 2, 5 and 6, characterized in that: Based on the feature type of the corresponding existing virus feature in the local virus database, obtaining a first virus feature from the virus features stored in the corresponding engine feature database includes: Based on the feature types of the corresponding existing virus features in the local virus database, determining whether the corresponding existing virus features in the local virus database are all basic virus features; If yes, then obtaining the basic virus features in the new virus features of the first virus detection engine as the first virus features from the corresponding engine feature library; the new virus features are virus features that are newly added or changed by the first virus detection engine after the local virus library was last updated; If not, all new virus features of the first virus detection engine are acquired from the corresponding engine feature library as first virus features.

8. The method according to claim 7, characterized in that After determining that the corresponding existing virus features in the local virus database are all basic virus features, the method includes: Sending a third inquiry message to a third review end to confirm whether it is necessary to incrementally update the non-basic virus features of the first virus detection engine to the local virus database; If a confirmation instruction fed back by the third audit terminal is received, the non-basic virus features of the first virus detection engine and the basic virus features in the new virus features are obtained as first virus features from the corresponding engine feature library; If a rejection instruction fed back by the third audit terminal is received, a step of acquiring the basic virus features in the new virus features of the first virus detection engine as the first virus features from the corresponding engine feature library is executed.

9. The method according to claim 2, characterized in that: Determining whether the existing virus features in the local virus database include the virus features corresponding to the first virus detection engine includes: detecting whether the first virus detection engine is determined as a virus detection engine suitable for performing virus detection on the network device when the local virus database is last updated; If yes, determining that the existing virus features in the local virus database include the virus features of the first virus detection engine; Otherwise, it is determined that the existing virus features of the local virus database do not include the virus features of the first virus detection engine; and / or, A fourth inquiry message is sent to the network device to inquire whether the virus features of the first virus detection engine exist in the local virus library; if the network device feedback confirms that there are instructions, it is determined that the existing virus features of the local virus library include the virus features of the first virus detection engine; if the network device feedback confirms that there are no instructions, it is determined that the existing virus features of the local virus library do not include the virus features of the first virus detection engine.

10. The method according to any one of claims 2-6, 8-9, characterized in that: Updating the virus feature in the local virus database based on the first virus feature corresponding to the first virus detection engine includes: For each of the first virus detection engines, check whether the virus feature corresponding to the first virus detection engine already exists in the local virus library; if not, add the first virus feature of the first virus detection engine to the local virus library; if already exists, determine whether the first virus feature corresponding to the first virus detection engine can fully cover the existing virus features of the first virus detection engine in the local virus library; if it can, replace the relevant existing virus features with the first virus features; if it cannot, incrementally update the relevant existing virus features based on the first virus features.

11. The method according to claim 10, characterized in that Incrementally updating the relevant existing virus features based on the first virus feature includes: For each of the first virus features, detect whether the first virus feature has a corresponding virus feature in the relevant existing virus features; if so, replace the corresponding virus feature with the first virus feature; if not, add the first virus feature to the local virus library.

12. The method according to any one of claims 2-6, 8-9, and 11, characterized in that: The method further comprises: Adding the virus md5 value of a known virus to the network device; and / or, When there is data to be detected for viruses in the network device, the target md5 value of the data to be detected for viruses is compared with the virus md5 value of a known virus pre-stored in the network device; If the target md5 value does not exist in the virus md5 value, the local virus library is called to perform virus detection on the data to be detected.

13. The method according to any one of claims 2-6, 8-9, and 11, characterized in that: The method further comprises: If an update instruction for the local virus database is detected, it is determined to update the local virus database of the network device; wherein the update instruction is generated by the virus database update process in the network device when the update cycle of the local virus database is reached; and / or, Monitoring device configuration of the network device; If it is monitored that the device configuration of the network device is changed, it is determined to update the local virus database of the network device.

14. The method according to any one of claims 2-6, 8-9, and 11, characterized in that: The method further comprises: determining whether an expected storage space of the local virus database required to update the virus signature in the local virus database based on the first virus signature corresponding to the first virus detection engine exceeds a current actual storage space of the local virus database; If not, executing the step of updating the virus signature in the local virus database based on the first virus signature corresponding to the first virus detection engine; If it exceeds, the current actual storage space of the local virus database is expanded to be no less than the expected storage space, and then the step of updating the virus features in the local virus database based on the first virus feature corresponding to the first virus detection engine is executed, or a prompt is issued that the existing storage space of the local virus database is insufficient.

15. The method according to any one of claims 2-6, 8-9, and 11, characterized in that: The current device configuration includes at least one of the following: device serial number, current deployment system and corresponding system version, memory size, and CPU quantity.

16. A virus detection method, characterized in that: The method comprises: In response to determining to perform virus detection on the network device, obtaining a current device configuration of the network device; Determining, from a plurality of virus detection engines, a second virus detection engine suitable for performing virus detection on a network device having the current network device configuration, each of the virus detection engines having a corresponding virus feature; The second virus feature corresponding to the second virus detection engine is called to perform virus detection on the network device.

17. The method according to claim 16, characterized in that Each of the virus detection engines has a corresponding engine feature library, and the engine feature library is used to store virus features corresponding to the corresponding virus detection engine. Then, calling the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device includes: Loading the second virus features corresponding to each of the second virus detection engines from the engine feature library corresponding to each of the second virus detection engines; Each of the second virus detection engines is called through the preset virus detection process to perform virus detection on the network device based on the loaded corresponding second virus features.

18. The method according to claim 17, characterized in that If a local virus database is deployed in the network device, the method further includes: For each of the second virus detection engines: determine whether the local virus library includes the second virus features corresponding to the second virus detection engine; if so, load the second virus features corresponding to the second virus detection engine from the local virus library; if not, execute the step of loading the second virus features corresponding to the second virus detection engine from the corresponding engine feature library.

19. The method according to claim 17, characterized in that The preset virus detection process includes at least one virus detection thread, and each of the virus detection threads has a corresponding source CPU in the network device; then, calling each of the second virus detection engines through the preset virus detection process to perform virus detection on the network device based on the loaded corresponding second virus features includes: Determine a source CPU of the data to be detected for viruses in the network device; The second virus detection engine is called through the virus detection thread corresponding to the source CPU, and virus detection is performed on the data to be virus-detected based on the loaded corresponding second virus features.

20. The method according to claim 19, characterized in that The method further comprises: Searching whether there is a virus detection thread corresponding to the source CPU in the at least one virus detection thread; If so, executing the step of calling the second virus detection engine through the virus detection thread corresponding to the source CPU, and performing virus detection on the data to be detected based on the loaded corresponding second virus feature; If it does not exist, a virus detection thread corresponding to the source CPU is created, and the second virus detection engine is called through the created virus detection thread to perform virus detection on the data to be detected based on the loaded corresponding second virus feature.

21. The method according to claim 19, characterized in that The network device is provided with a shared memory divided into at least one cache area; each cache area has a corresponding source CPU in the network device and is used to store the virus detection data to be detected by the corresponding source CPU; then, determining the source CPU of the virus detection data to be detected by the network device includes: Determine a target cache area where the data to be detected for viruses is located; The source CPU corresponding to the target cache area is determined as the source CPU of the data to be detected for viruses.

22. The method according to claim 19, characterized in that The network device is provided with a shared memory divided into at least one cache area; each of the cache areas has a corresponding source CPU in the network device and is used to store the virus detection data to be detected by the corresponding source CPU; each of the source CPUs issues a virus detection request after caching the virus detection data to be detected in the shared memory, then, the method further includes: Monitoring whether a source CPU in the network device issues a virus detection request; If detected, the data to be detected by the virus is read from the cache area corresponding to the source CPU that issues the virus detection request, and the step of determining the source CPU of the data to be detected by the virus in the network device is performed.

23. The method according to any one of claims 19 to 22, characterized in that After calling the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device, the second virus detection engine feeds back a corresponding virus detection result, and the method further includes: If any of the second virus detection engines is monitored to feedback a virus detection result, and it is determined that the virus detection result indicates that the data to be detected for virus exists a virus, a processing instruction is issued to a source CPU corresponding to the data to be detected for virus through the preset virus detection process, so that the source CPU performs corresponding virus protection processing on the data to be detected for virus based on the processing instruction; and / or, If it is determined that the second virus detection engine completes the virus detection on the data to be detected, the data to be detected is transferred to a designated location.

24. The method according to any one of claims 17 to 22, characterized in that The method further comprises: Monitor whether the preset virus detection process has an operation abnormality; if an operation abnormality is monitored and it is determined that the number of consecutive operation abnormalities is less than the target threshold, restart the preset virus detection process; if an operation abnormality is monitored and it is determined that the number of consecutive operation abnormalities is not less than the target threshold, issue a process abnormality prompt; and / or, Monitoring whether the engine virus library is updated; if updated, reloading the second virus signature of the corresponding second virus detection engine from the updated engine virus library; and / or, The preset virus detection process and the service process of the network device itself are different processes.

25. A virus database updating system, characterized in that: The system comprises: The processing device is used for obtaining the current device configuration of the network device in response to determining to update the local virus library of the network device; determining a first virus detection engine suitable for performing virus detection on the network device having the current network device configuration from a plurality of virus detection engines, each of the virus detection engines having a corresponding virus feature; The updating device is used to update the virus features in the local virus database based on the first virus features corresponding to the first virus detection engine.

26. A virus detection device, characterized in that: The device comprises: An acquisition module, configured to acquire a current device configuration of the network device in response to determining to perform virus detection on the network device; A loading module, used to determine, from a plurality of virus detection engines, a second virus detection engine suitable for performing virus detection on a network device having the current network device configuration, each of the virus detection engines having a corresponding virus feature; The detection module is used to call the second virus feature corresponding to the second virus detection engine to perform virus detection on the network device.

27. A computer-readable storage medium, characterized in that: The storage medium includes a stored program, wherein when the program is running, the device where the storage medium is located is controlled to execute the virus database updating method described in any one of claims 1 to claim 15, and / or execute the virus detection method described in any one of claims 16 to claim 24.

28. An electronic device, characterized in that: The electronic device comprises: Memory, used to store programs; A processor, coupled to the memory, is used to run the program to execute the virus database updating method described in any one of claims 1 to 15, and / or to execute the virus detection method described in any one of claims 16 to 24.