Method and device for carrying out virus processing on vehicle system based on mobile terminal

By detecting and comparing files in the mobile storage device connected to the vehicle system at the mobile terminal, generating target threat values ​​and sending them to the vehicle system for processing, the problem of virus scanning difficulties caused by insufficient computing power in the vehicle system is solved, and effective virus processing is achieved without affecting the operation of other applications of the vehicle.

CN119989351AInactive Publication Date: 2025-05-13BEIJING YUNCHI FUTURE TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510480170.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When the vehicle system connects to external mobile storage devices, the equipment has insufficient computing power and limited storage resources, resulting in the inability to effectively scan viruses, affecting the operation of other applications of the vehicle and posing safety hazards.

Method used

When the mobile terminal remains connected to the control terminal of the vehicle system, it detects that the mobile storage device is accessed, and obtains the scanning information of the file to be scanned, and compares it according to the virus database of the mobile terminal, generates a target threat value, and sends it to the control terminal for processing.

Benefits of technology

Without using the computing power of the vehicle system, virus scanning is performed through mobile terminals to avoid affecting the operation of other vehicle applications, greatly reduce safety risks, and keep the virus database up-to-date through cloud updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989351A_ABST
    Figure CN119989351A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a virus processing method and device for a vehicle system based on a mobile terminal, and the method comprises the steps: carrying out the virus processing of the vehicle system based on the mobile terminal under the condition of keeping connection with a control terminal of a target vehicle, and when the access of a mobile storage device for the control terminal is detected, carrying out the virus processing of the vehicle system based on the mobile terminal; acquiring scanning information of a to-be-scanned file in the mobile storage device; comparing the scanning information with a current first virus database of the mobile terminal to obtain a target threat value of each to-be-scanned file; and threat information including the target threat value is sent to the control terminal, so that the control terminal carries out corresponding processing. According to the embodiment of the invention, the mobile terminal is used for scanning under the condition that the computing power of a vehicle system is not used, so that the operation of other applications of the vehicle is not influenced, and potential safety hazards caused by the operation are greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this specification relate to the field of virus processing technology, and more particularly to a method and device for processing viruses on a vehicle system based on a mobile terminal. Background Art

[0002] With the development of technology, software systems in cars are becoming more and more common. When connecting to external mobile storage devices, the vehicle's own device computing power is low and storage resources are limited, which is insufficient to support local virus scanning. Even if the computing power of some vehicles is improved, the virus scanning process consumes a lot of device computing power, which can easily affect the operation of other applications in the vehicle, thus causing safety hazards. Summary of the invention

[0003] In view of this, the embodiments of this specification provide a method for processing viruses in a vehicle system based on a mobile terminal. One or more embodiments of this specification also relate to a device for processing viruses in a vehicle system based on a mobile terminal, a computing device, a computer-readable storage medium, and a computer program to solve the technical defects existing in the prior art.

[0004] According to a first aspect of an embodiment of this specification, a method for processing viruses in a vehicle system based on a mobile terminal is provided, comprising: In the case of maintaining connection with the control terminal of the target vehicle, when detecting access to a mobile storage device for the control terminal, obtaining scanning information of the file to be scanned in the mobile storage device, wherein the scanning information includes basic attribute information, metadata information, content structure information and behavior feature information; Compare each scan information with the first virus database currently in the mobile terminal to obtain a target threat value for each file to be scanned; Threat information including the target threat value is sent to the control terminal so that the control terminal performs corresponding processing, wherein the threat information includes the target threat value, and processing instructions and scanning information corresponding to the target threat value.

[0005] In some embodiments, the target threat value is obtained by comparing each scanning information with the current first virus database of the mobile terminal, including: Perform static feature comparison on basic attribute information, metadata information, and content structure information in the scanned information to obtain a static threat value; Perform dynamic feature comparison on the behavioral feature information in the scan information to obtain a dynamic threat value; A target threat value is generated according to the static threat value and the dynamic threat value.

[0006] In some embodiments, static feature comparison is performed on basic attribute information, metadata information, and content structure information to obtain a static threat value, including: Determine the whitelist attenuation factor and whitelist probability confidence of each file to be scanned based on the basic attribute information and metadata information; Comparing the content structure information, obtaining the hit count and discreteness for each virus feature in the first virus database; The static threat value of each file to be scanned is calculated based on the whitelist attenuation factor, whitelist probability confidence, hit count and dispersion.

[0007] In some embodiments, the static threat value of each file to be scanned is calculated according to the whitelist attenuation factor, the whitelist probability confidence, the number of hits and the discreteness, including: Get the first weight of each virus feature; According to a preset first calculation formula, a first weight, a whitelist attenuation factor, a whitelist probability confidence, a hit count, and a discreteness, a static threat value of each file to be scanned is calculated, wherein the first calculation formula includes:

[0008] in, C k Indicates k The number of hits of virus features, W k Indicates k The first weight of the virus feature, S k Indicates k The discreteness of the virus features, ε Represents a preset minimum constant, λ Represents the whitelist attenuation factor, P represents the whitelist probability confidence, n Represents the total number of virus signatures.

[0009] In some embodiments, dynamic feature comparison is performed on the behavior feature information to obtain a dynamic threat value, including: When the file type of the file to be scanned is an executable file type, detecting an abnormal section of the file to be scanned of the executable file type to obtain a first malicious behavior score; Parse the call chain of the file to be scanned of the executable file type, mark high-risk behaviors, and obtain the second malicious behavior score; A third malicious behavior score is obtained by performing a weighted summation according to a preset second weight and the first malicious behavior score and the second malicious behavior score; The third malicious behavior score is compared with a preset first comparison threshold to obtain a dynamic threat value of the file to be scanned of the executable file type.

[0010] In some embodiments, dynamic feature comparison is performed on the behavior feature information to obtain a dynamic threat value, including: When the file type of the to-be-scanned file is a script type, the to-be-scanned file of the script type is imported into a preset sandbox environment for simulation execution to generate a fourth malicious behavior score; The fourth malicious behavior score is compared with a preset second comparison threshold to obtain a dynamic threat value of the script-type file to be scanned.

[0011] In some embodiments, the above method further comprises: Save each threat information to the local database of the mobile terminal; When connected to the cloud, at least one threat information stored in the local database is transmitted to the cloud, and the local database is cleared.

[0012] According to a second aspect of the embodiments of this specification, there is provided a device for processing viruses on a vehicle system based on a mobile terminal, comprising: An acquisition module is used to acquire scanning information of a file to be scanned in a mobile storage device when detecting access to a mobile storage device for the control terminal while maintaining connection with the control terminal of the target vehicle, wherein the scanning information includes basic attribute information, metadata information, content structure information and behavior feature information; A comparison module, used for comparing each scanning information with the current first virus database of the mobile terminal to obtain a target threat value of each file to be scanned; The threat sending module is used to send threat information including a target threat value to a control terminal so that the control terminal performs corresponding processing, wherein the threat information includes the target threat value, and a processing instruction and scanning information corresponding to the target threat value.

[0013] In the case of maintaining connection with the control terminal of the target vehicle, when detecting access to a mobile storage device for the control terminal, obtaining scanning information of the file to be scanned in the mobile storage device, wherein the scanning information includes basic attribute information, metadata information, content structure information and behavior feature information; Compare each scan information with the first virus database currently in the mobile terminal to obtain a target threat value for each file to be scanned; Threat information including the target threat value is sent to the control terminal so that the control terminal performs corresponding processing, wherein the threat information includes the target threat value, and processing instructions and scanning information corresponding to the target threat value.

[0014] In some embodiments, the comparison module 402 is further configured to: Perform static feature comparison on basic attribute information, metadata information, and content structure information in the scanned information to obtain a static threat value; Perform dynamic feature comparison on the behavioral feature information in the scan information to obtain a dynamic threat value; A target threat value is generated according to the static threat value and the dynamic threat value.

[0015] In some embodiments, static feature comparison is performed on basic attribute information, metadata information, and content structure information to obtain a static threat value, including: Determine the whitelist attenuation factor and whitelist probability confidence of each file to be scanned based on the basic attribute information and metadata information; Comparing the content structure information, obtaining the hit count and discreteness for each virus feature in the first virus database; The static threat value of each file to be scanned is calculated based on the whitelist attenuation factor, whitelist probability confidence, hit count and dispersion.

[0016] In some embodiments, the static threat value of each file to be scanned is calculated according to the whitelist attenuation factor, the whitelist probability confidence, the number of hits and the discreteness, including: Get the first weight of each virus feature; According to a preset first calculation formula, a first weight, a whitelist attenuation factor, a whitelist probability confidence, a hit count, and a discreteness, a static threat value of each file to be scanned is calculated, wherein the first calculation formula includes:

[0017] in, C k Indicates k The number of hits of virus features, W k Indicates k The first weight of the virus feature, S k Indicates k The discreteness of the virus features, ε Represents a preset minimum constant, λ Represents the whitelist attenuation factor, P represents the whitelist probability confidence, n Represents the total number of virus signatures.

[0018] In some embodiments, dynamic feature comparison is performed on the behavior feature information to obtain a dynamic threat value, including: When the file type of the file to be scanned is an executable file type, detecting an abnormal section of the file to be scanned of the executable file type to obtain a first malicious behavior score; Parse the call chain of the file to be scanned of the executable file type, mark high-risk behaviors, and obtain the second malicious behavior score; A third malicious behavior score is obtained by performing a weighted summation according to a preset second weight and the first malicious behavior score and the second malicious behavior score; The third malicious behavior score is compared with a preset first comparison threshold to obtain a dynamic threat value of the file to be scanned of the executable file type.

[0019] In some embodiments, dynamic feature comparison is performed on the behavior feature information to obtain a dynamic threat value, including: When the file type of the to-be-scanned file is a script type, the to-be-scanned file of the script type is imported into a preset sandbox environment for simulation execution to generate a fourth malicious behavior score; The fourth malicious behavior score is compared with a preset second comparison threshold to obtain a dynamic threat value of the script-type file to be scanned.

[0020] In some embodiments, a cloud update module is also included, including: saving each threat information to a local database of the mobile terminal; when connected to the cloud, transmitting at least one threat information stored in the local database to the cloud, and clearing the local database.

[0021] According to a third aspect of an embodiment of this specification, a computing device is provided, including: Memory and processor; The memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions. When the computer executable instructions are executed by the processor, the steps of the above-mentioned method for processing viruses on a vehicle system based on a mobile terminal are implemented.

[0022] According to a fourth aspect of the embodiments of this specification, a computer-readable storage medium is provided, which stores computer-executable instructions, and when the instructions are executed by a processor, the steps of the above-mentioned method for virus processing on a vehicle system based on a mobile terminal are implemented.

[0023] According to a fifth aspect of the embodiments of this specification, a computer program is provided, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the above-mentioned method for virus processing on a vehicle system based on a mobile terminal.

[0024] At least one embodiment of the embodiments of this specification obtains scanning information of the files to be scanned in the mobile storage device when the mobile storage device access to the control terminal is detected while maintaining connection with the control terminal of the target vehicle; compares each scanning information with the current first virus library of the mobile terminal to obtain the target threat value of each file to be scanned; and sends the threat information including the target threat value to the control terminal so that the control terminal performs corresponding processing. The mobile terminal can be used for scanning without using the computing power of the vehicle system, so as not to affect the operation of other applications in the vehicle, greatly reducing the potential safety hazards caused by this. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 It is a scenario diagram of a method for processing viruses on a vehicle system based on a mobile terminal provided in some embodiments of this specification; Figure 2 is a flowchart of some embodiments of a method for processing viruses on a vehicle system based on a mobile terminal provided by some embodiments of this specification; Figure 3 is a flowchart of another embodiment of a method for processing a virus on a vehicle system based on a mobile terminal provided by some embodiments of this specification; Figure 4 It is a simplified structural diagram of a device for processing viruses on a vehicle system based on a mobile terminal provided in some embodiments of this specification; Figure 5 It is a structural block diagram of a computing device provided in some embodiments of this specification. DETAILED DESCRIPTION

[0026] Many specific details are described in the following description to facilitate a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar generalizations without violating the connotation of this specification, so this specification is not limited to the specific implementation disclosed below.

[0027] The terms used in one or more embodiments of this specification are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms of "one" and "the" used in one or more embodiments of this specification and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items. The modifications of "one" and "multiple" mentioned in this disclosure are illustrative and non-restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0028] It should be understood that although the terms first, second, etc. may be used to describe various information in one or more embodiments of this specification, this information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0029] In this specification, a method for processing viruses on a vehicle system based on a mobile terminal is provided. This specification also relates to an apparatus for processing viruses on a vehicle system based on a mobile terminal, a computing device, a computer-readable storage medium, and a computer program, which are described in detail one by one in the following embodiments.

[0030] See also Figure 1 , Figure 1 A schematic diagram of a scenario of a method for processing viruses on a vehicle system based on a mobile terminal according to some embodiments of this specification is shown.

[0031] exist Figure 1 In the application scenario, the mobile device 101 can be connected to the built-in system of the vehicle (i.e., the vehicle system) by wire or wirelessly, and when the mobile storage device access to the control terminal is detected while maintaining connection with the control terminal of the target vehicle, the scanning information of the file to be scanned in the mobile storage device is obtained, wherein the scanning information includes basic attribute information, metadata information, content structure information, and behavior characteristic information; a target threat value of each file to be scanned is obtained by comparing the scanning information with the current first virus library of the mobile device 101; and the threat information including the target threat value is sent to the control terminal so that the control terminal performs corresponding processing, wherein the threat information includes the target threat value, and the processing instructions and scanning information corresponding to the target threat value.

[0032] It should be noted that the mobile device 101 may refer to a mobile phone, a tablet computer, a laptop computer, etc. In general, the computing power of the mobile device 101 is much greater than that of the vehicle's control terminal. Therefore, a mobile phone is needed to replace the vehicle's control terminal to perform virus scanning and processing. In addition, the mobile device 101 can be wirelessly connected to the cloud to update the virus library of the mobile device 101.

[0033] See also Figure 2 , Figure 2 A flowchart of a method for processing viruses in a vehicle system based on a mobile terminal according to some embodiments of this specification is shown, which specifically includes the following steps.

[0034] Step 201: While maintaining connection with a control terminal of a target vehicle, when detecting access of a mobile storage device to the control terminal, obtaining scanning information of a file to be scanned in the mobile storage device.

[0035] In some embodiments, the execution subject (such as Figure 1 The mobile device 101 shown can be connected to the target device via a wired connection or a wireless connection, and then, while maintaining a connection with the control terminal of the target vehicle, when access to a mobile storage device for the control terminal is detected, scanning information of the file to be scanned in the mobile storage device is obtained, wherein the scanning information includes basic attribute information, metadata information, content structure information and behavioral characteristic information.

[0036] Obviously, when the vehicle system is virus-processed based on a mobile terminal, the mobile terminal needs to always maintain a connection (wired or wireless) with the vehicle's control terminal (in which the vehicle system is set). The problem with vehicle system virus scanning is that during the operation of the vehicle, the connection of the external mobile storage device makes it impossible to scan the external mobile storage device in time, resulting in virus infection. Therefore, when the access of the mobile storage device to the control terminal is detected, the above-mentioned execution subject can obtain the scanning information of the file to be scanned in the mobile storage device. The scanning information may include basic attribute information, metadata information, content structure information and behavior feature information.

[0037] Basic attribute information may refer to the commonly used basic information of a file. For example, the basic information may include information such as the file name, file type, and file size. Metadata information may refer to information such as the signature information and modification information of a file. For example, the metadata information may include the file creation time, modification time, file owner, permission information, etc. Content structure information may refer to information related to the composition architecture of a file. For example, content structure information may include header information, digital signatures, hash values ​​used to uniquely identify file content, etc. Behavioral feature information may refer to related information such as file import tables and script file key function call sequences.

[0038] It should be noted that the above-mentioned wireless connection methods may include but are not limited to 3G / 4G / 5G / 6G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (ultra wideband) connection, and other wireless connection methods currently known or developed in the future.

[0039] Step 202: Compare each scanning information with the first virus database currently in the mobile terminal to obtain a target threat value for each file to be scanned.

[0040] In some embodiments, the execution entity may compare the basic attribute information, metadata information, content structure information and behavior characteristic information of each file to be scanned with the first virus database set in the execution entity to obtain the threat value of each file to be scanned.

[0041] In some optional implementations, a target threat value is obtained by comparing each scanning information with the current first virus database of the mobile terminal, including: performing a static feature comparison on the basic attribute information, metadata information, and content structure information in the scanning information to obtain a static threat value; performing a dynamic feature comparison on the behavioral feature information in the scanning information to obtain a dynamic threat value; and generating a target threat value based on the static threat value and the dynamic threat value.

[0042] When scanning files, files can be simply divided into two categories: static files and dynamic files. Static files can refer to files that do not interact with other files, such as plain text files or image files. Static files often only need to scan their basic attribute information, metadata information, and content structure information to determine whether they contain viruses. Dynamic files can refer to files that interact with other files, such as executable files, script files, etc. In addition to scanning basic attribute information, metadata information, and content structure information, such files also need to be further determined for their actions. This increases the accuracy of security judgments on various types of files. Similarly, a static threat value can refer to a threat value obtained by static feature comparison based on basic attribute information, metadata information, and content structure information, and a dynamic threat value can refer to a threat value obtained by dynamic feature comparison of behavioral feature information in the scan information. The target threat value can refer to a threat value obtained by combining a static threat value and a dynamic threat value. Static threat values ​​and dynamic threat values ​​can be combined by various combination methods, such as direct addition, multiplication, weighted combination, etc., and can be set as needed, without specific restrictions here.

[0043] In some optional implementations, a static feature comparison is performed on basic attribute information, metadata information, and content structure information to obtain a static threat value, including: determining a whitelist attenuation factor and a whitelist probability confidence level for each file to be scanned based on the basic attribute information and metadata information; comparing the content structure information to obtain the number of hits and the discreteness for each virus feature in the first virus library; and calculating the static threat value for each file to be scanned based on the whitelist attenuation factor, the whitelist probability confidence level, the number of hits, and the discreteness.

[0044] When analyzing each file, it can be first determined whether the file is a whitelist file. A whitelist file may refer to a file that is scanned out of order, such as a firmware package signed by a car company. For non-whitelist files, the corresponding approximation coefficient (0 to 1) is set according to the degree of similarity between the file and the whitelist file, and 1 minus the approximation coefficient is the whitelist attenuation factor. As an example, the whitelist attenuation factor of the firmware package signed by the car company is 0, indicating that the file is a whitelist file. If the file to be scanned is similar to the virus file scanned last time, its whitelist attenuation factor is 1. Correspondingly, the whitelist probability confidence may refer to the probability of matching with the whitelist (assuming the probability is P, 0≤P≤1, P=1 indicates a complete match with a trusted file). When calculating the whitelist attenuation factor and the whitelist probability confidence, the calculation can be based on the prior art, and no specific restrictions are made here. For example, the whitelist probability confidence can be calculated by a Bloom Filter. The number of hits may refer to the number of successful matches with virus features. The discreteness may refer to the degree of discreteness of the distribution of features that successfully match the virus in the file. The static threat value can refer to the threat value identified based on the information of the file itself. By combining the whitelist attenuation factor, whitelist probability confidence, hit count and discreteness, the static threat value of each file to be scanned is calculated to improve the recognition accuracy of the basic information of the file.

[0045] In some optional implementations, the static threat value of each file to be scanned is calculated according to the whitelist attenuation factor, the whitelist probability confidence, the number of hits and the discreteness, including: obtaining a first weight of each virus feature; calculating the static threat value of each file to be scanned according to a preset first calculation formula, as well as the first weight, the whitelist attenuation factor, the whitelist probability confidence, the number of hits and the discreteness, wherein the first calculation formula includes:

[0046] in, C k Indicates k The number of hits of virus features, W k Indicates k The first weight of the virus feature, S k Indicates k The discreteness of the virus features, ε Represents a preset minimum constant, λ Represents the whitelist attenuation factor, P represents the whitelist probability confidence, n Represents the total number of virus signatures.

[0047] Since there is a large amount of information that has been determined to be a virus in the virus database for comparison, the information in each file to be scanned needs to be compared with the virus features in the virus database. In order to increase the comparison speed, different files have different possibilities of corresponding viruses, so their corresponding scanning weights are also different. Therefore, when scanning each file to be scanned, the first weight corresponding to each virus feature must be determined first, and then combined with the first calculation formula for calculation, so that a more accurate threat value can be obtained for subsequent judgment.

[0048] In some optional implementations, dynamic feature comparison is performed on the behavior feature information to obtain a dynamic threat value, including: when the file type of the file to be scanned is an executable file type, detecting an abnormal section of the file to be scanned of the executable file type to obtain a first malicious behavior score; parsing the call chain of the file to be scanned of the executable file type, marking high-risk behaviors, and obtaining a second malicious behavior score; performing weighted summation according to a preset second weight, and the first malicious behavior score and the second malicious behavior score to obtain a third malicious behavior score; comparing the third malicious behavior score with a preset first comparison threshold to obtain a dynamic threat value of the file to be scanned of the executable file type. Detecting an abnormal section of the file to be scanned of the executable file type to obtain a first malicious behavior score and parsing the call chain of the file to be scanned of the executable file type to obtain a second malicious behavior score are common technologies in the art and will not be described in detail here. The second weight may refer to one of the weights of the first malicious behavior score and the second malicious behavior score or the weight ratio of the two. The first comparison threshold may refer to a preset threshold for determining whether an executable file type file constitutes malicious behavior, which is determined by experience.

[0049] In some optional implementations, a dynamic feature comparison is performed on the behavior feature information to obtain a dynamic threat value, including: when the file type of the file to be scanned is a script type, the script type file to be scanned is imported into a preset sandbox environment for simulated execution to generate a fourth malicious behavior score; the fourth malicious behavior score is compared with a preset second comparison threshold to obtain a dynamic threat value for the script type file to be scanned. Similar to the above, importing the script type file to be scanned into a preset sandbox environment for simulated execution to generate a fourth malicious behavior score is a common technique in the art and will not be elaborated on here. The sandbox environment may refer to a simulation environment for simulating script execution. The second comparison threshold may refer to a preset threshold for determining whether a script type file constitutes malicious behavior, which is determined by experience.

[0050] By setting the dynamic feature comparison of executable file type files and script type files, combined with the determination of the aforementioned static threat value, the overall judgment accuracy can be further increased.

[0051] Step 203: Send the threat information including the target threat value to the control terminal so that the control terminal performs corresponding processing.

[0052] In some embodiments, the above-mentioned execution subject may send threat information including the target threat value to the control terminal so that the control terminal performs corresponding processing. The threat information may refer to comprehensive information including the target threat value, corresponding scanning information (such as basic attribute information, metadata information, content structure information and behavior feature information), and processing instructions. The processing instructions may refer to instructions corresponding to the processing method corresponding to the target threat value. Different threat values ​​may correspond to different processing methods, and different processing methods may correspond to different processing instructions. As an example, the processing methods may include the following: The first processing method: deleting files, may refer to performing secure erasure on high-risk files (for example, overwriting physical storage blocks three times).

[0053] The second processing method: isolating files, which can mean transferring medium-risk files to a preset read-only encrypted partition, which requires the user's secondary authorization before they can be restored.

[0054] The third processing method: permission restriction: This can mean disabling execution permissions for low-risk files and only allowing read operations. It is a common operation in this field to classify different files and generate different instructions, so I will not go into details here.

[0055] The beneficial effects of one of the embodiments of the present specification include at least: by maintaining a connection with the control terminal of the target vehicle, when a mobile storage device for the control terminal is detected to be connected, the scanning information of the files to be scanned in the mobile storage device is obtained; the target threat value of each file to be scanned is obtained by comparing the scanning information with the current first virus library of the mobile terminal; the threat information including the target threat value is sent to the control terminal so that the control terminal performs corresponding processing. The mobile terminal can be used for scanning without using the computing power of the vehicle system, so as not to affect the operation of other applications of the vehicle, and greatly reduce the potential safety hazards caused by this.

[0056] In some embodiments, the method further includes: saving each threat information to a local database of the mobile terminal; when connected to the cloud, transmitting at least one threat information stored in the local database to the cloud, and clearing the local database. By connecting the mobile terminal to the cloud, the virus database of the mobile terminal can be continuously updated, thereby ensuring timely identification of new viruses, further increasing the accuracy of virus identification, and reducing security risks.

[0057] The following combination Figure 3, shows a process flow chart of a method for processing viruses in a vehicle system based on a mobile terminal provided in some embodiments of this specification, which specifically includes the following steps.

[0058] Step 301: While maintaining connection with the control terminal of the target vehicle, when access to a mobile storage device for the control terminal is detected, scanning information of the file to be scanned in the mobile storage device is obtained, wherein the scanning information includes basic attribute information, metadata information, content structure information and behavioral feature information.

[0059] Step 302: Perform static feature comparison on basic attribute information, metadata information, and content structure information in the scanned information to obtain a static threat value.

[0060] Step 303: Perform dynamic feature comparison on the behavior feature information in the scan information to obtain a dynamic threat value.

[0061] Step 304: Generate a target threat value according to the static threat value and the dynamic threat value.

[0062] Step 305: Send threat information including the target threat value to the control terminal so that the control terminal performs corresponding processing, wherein the threat information includes the target threat value, and processing instructions and scanning information corresponding to the target threat value.

[0063] In some embodiments, steps 301-305 are Figure 2 The specific implementation of the corresponding steps in the corresponding embodiments and the technical effects brought about can be referred to Figure 2 The steps in will not be repeated here.

[0064] Corresponding to the above method embodiment, this specification also provides an embodiment of a device for processing viruses on a vehicle system based on a mobile terminal. Figure 4 FIG. 1 shows a schematic diagram of a structure of a device for processing viruses in a vehicle system based on a mobile terminal provided in some embodiments of this specification. Figure 4 As shown, the device comprises: The acquisition module 401 is used to acquire scanning information of the file to be scanned in the mobile storage device when the mobile storage device access to the control terminal is detected while maintaining connection with the control terminal of the target vehicle, wherein the scanning information includes basic attribute information, metadata information, content structure information and behavior feature information; A comparison module 402 is used to compare the scanning information with the first virus database currently in the mobile terminal to obtain a target threat value of each file to be scanned; The threat sending module 403 is used to send threat information including a target threat value to the control terminal so that the control terminal performs corresponding processing, wherein the threat information includes the target threat value, and processing instructions and scanning information corresponding to the target threat value.

[0065] In the case of maintaining connection with the control terminal of the target vehicle, when detecting access to a mobile storage device for the control terminal, obtaining scanning information of the file to be scanned in the mobile storage device, wherein the scanning information includes basic attribute information, metadata information, content structure information and behavior feature information; Compare each scan information with the first virus database currently in the mobile terminal to obtain a target threat value for each file to be scanned; Threat information including the target threat value is sent to the control terminal so that the control terminal performs corresponding processing, wherein the threat information includes the target threat value, and processing instructions and scanning information corresponding to the target threat value.

[0066] In some embodiments, the comparison module 402 is further configured to: Perform static feature comparison on basic attribute information, metadata information, and content structure information in the scanned information to obtain a static threat value; Perform dynamic feature comparison on the behavioral feature information in the scan information to obtain a dynamic threat value; A target threat value is generated according to the static threat value and the dynamic threat value.

[0067] In some embodiments, static feature comparison is performed on basic attribute information, metadata information, and content structure information to obtain a static threat value, including: Determine the whitelist attenuation factor and whitelist probability confidence of each file to be scanned based on the basic attribute information and metadata information; Comparing the content structure information, obtaining the hit count and discreteness for each virus feature in the first virus database; The static threat value of each file to be scanned is calculated based on the whitelist attenuation factor, whitelist probability confidence, hit count and dispersion.

[0068] In some embodiments, the static threat value of each file to be scanned is calculated according to the whitelist attenuation factor, the whitelist probability confidence, the number of hits and the discreteness, including: Get the first weight of each virus feature; According to a preset first calculation formula, a first weight, a whitelist attenuation factor, a whitelist probability confidence, a hit count, and a discreteness, a static threat value of each file to be scanned is calculated, wherein the first calculation formula includes:

[0069] in, C k Indicates k The number of hits of virus features, W k Indicates k The first weight of the virus feature, S k Indicates k The discreteness of the virus features, ε Represents a preset minimum constant, λ Represents the whitelist attenuation factor, P represents the whitelist probability confidence, n Represents the total number of virus signatures.

[0070] In some embodiments, dynamic feature comparison is performed on the behavior feature information to obtain a dynamic threat value, including: When the file type of the file to be scanned is an executable file type, detecting an abnormal section of the file to be scanned of the executable file type to obtain a first malicious behavior score; Parse the call chain of the file to be scanned of the executable file type, mark high-risk behaviors, and obtain the second malicious behavior score; A third malicious behavior score is obtained by performing a weighted summation according to a preset second weight and the first malicious behavior score and the second malicious behavior score; The third malicious behavior score is compared with a preset first comparison threshold to obtain a dynamic threat value of the file to be scanned of the executable file type.

[0071] In some embodiments, dynamic feature comparison is performed on the behavior feature information to obtain a dynamic threat value, including: When the file type of the to-be-scanned file is a script type, the to-be-scanned file of the script type is imported into a preset sandbox environment for simulation execution to generate a fourth malicious behavior score; The fourth malicious behavior score is compared with a preset second comparison threshold to obtain a dynamic threat value of the script-type file to be scanned.

[0072] In some embodiments, a cloud update module is also included, including: saving each threat information to a local database of the mobile terminal; when connected to the cloud, transmitting at least one threat information stored in the local database to the cloud, and clearing the local database.

[0073] The above is a schematic scheme of a virus processing device for a vehicle system based on a mobile terminal of this embodiment. It should be noted that the technical scheme of the virus processing device for a vehicle system based on a mobile terminal and the technical scheme of the virus processing method for a vehicle system based on a mobile terminal belong to the same concept. For details not described in detail in the technical scheme of the virus processing device for a vehicle system based on a mobile terminal, please refer to the description of the technical scheme of the virus processing method for a vehicle system based on a mobile terminal.

[0074] Figure 5 The structure block diagram of a computing device 500 provided according to some embodiments of the present specification is shown. The components of the computing device 500 include but are not limited to a memory 501 and a processor 502. The processor 502 is connected to the memory 501 via a bus 503, and a database 505 is used to store data.

[0075] The computing device 500 also includes an access device 504 that enables the computing device 500 to communicate via one or more networks 506. Examples of these networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. The access device 504 may include one or more of any type of network interface (e.g., a network interface card (NIC)) of wired or wireless, such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a world-wide interoperability for microwave access (Wi-MAX) interface, an Ethernet interface, a universal serial bus (USB) interface, a cellular network interface, a Bluetooth interface, and a near field communication (NFC).

[0076] In one embodiment of the present specification, the above components of the computing device 500 and Figure 4 Other components not shown in the figure may also be connected to each other, for example, via a bus. It should be understood that Figure 4 The computing device structure block diagram shown is only for the purpose of illustration, and is not intended to limit the scope of this specification. Those skilled in the art can add or replace other components as needed.

[0077] The computing device 500 may be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (e.g., a smart phone), a wearable computing device (e.g., a smart watch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or a personal computer (PC). The computing device 500 may also be a mobile or stationary server.

[0078] Among them, the processor 502 is used to execute the following computer executable instructions, which, when executed by the processor, implement the steps of the above-mentioned method for processing viruses on a vehicle system based on a mobile terminal. The above is a schematic scheme of a computing device of this embodiment. It should be noted that the technical scheme of the computing device and the technical scheme of the above-mentioned method for processing viruses on a vehicle system based on a mobile terminal belong to the same concept. For details not described in detail in the technical scheme of the computing device, please refer to the description of the technical scheme of the above-mentioned method for processing viruses on a vehicle system based on a mobile terminal.

[0079] An embodiment of the present specification also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the above-mentioned method for processing viruses on a vehicle system based on a mobile terminal.

[0080] The above is a schematic scheme of a computer-readable storage medium of this embodiment. It should be noted that the technical scheme of the storage medium and the technical scheme of the above-mentioned method for processing viruses for a vehicle system based on a mobile terminal belong to the same concept, and the details not described in detail in the technical scheme of the storage medium can be referred to the description of the above-mentioned technical scheme for processing viruses for a vehicle system based on a mobile terminal.

[0081] An embodiment of the present specification also provides a computer program, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the above-mentioned method for processing viruses on a vehicle system based on a mobile terminal.

[0082] The above is a schematic scheme of a computer program of this embodiment. It should be noted that the technical scheme of the computer program and the technical scheme of the above-mentioned method for processing viruses on a vehicle system based on a mobile terminal belong to the same concept, and the details not described in detail in the technical scheme of the computer program can be referred to the description of the above-mentioned technical scheme for processing viruses on a vehicle system based on a mobile terminal.

[0083] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0084] The computer instructions include computer program codes, which may be in source code form, object code form, executable files or some intermediate forms, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the content contained in the computer-readable medium may be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.

[0085] It should be noted that, for the above-mentioned method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the embodiments of this specification are not limited by the order of the actions described, because according to the embodiments of this specification, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the embodiments of this specification.

[0086] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0087] The preferred embodiments of this specification disclosed above are only used to help explain this specification. The optional embodiments do not describe all the details in detail, nor do they limit the invention to only the specific implementation methods described. Obviously, many modifications and changes can be made according to the content of the embodiments of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the embodiments of this specification, so that technicians in the relevant technical field can well understand and use this specification. This specification is only limited by the claims and their full scope and equivalents.

Claims

1. A method for processing viruses in a vehicle system based on a mobile terminal, characterized in that: The method is applied to a mobile terminal, and the method comprises: In the case of maintaining connection with the control terminal of the target vehicle, when detecting access to a mobile storage device for the control terminal, obtaining scanning information of the file to be scanned in the mobile storage device, wherein the scanning information includes basic attribute information, metadata information, content structure information and behavior feature information; Comparing the scanning information with the first virus database currently in the mobile terminal to obtain a target threat value for each file to be scanned; Threat information including the target threat value is sent to the control terminal so that the control terminal performs corresponding processing, wherein the threat information includes the target threat value, a processing instruction corresponding to the target threat value, and the scanning information.

2. The method according to claim 1, characterized in that Comparing the scanning information with the first virus database currently used by the mobile terminal to obtain a target threat value includes: Performing static feature comparison on basic attribute information, metadata information, and content structure information in the scan information to obtain a static threat value; Performing dynamic feature comparison on the behavior feature information in the scanning information to obtain a dynamic threat value; The target threat value is generated according to the static threat value and the dynamic threat value.

3. The method according to claim 2, characterized in that Perform static feature comparison on the basic attribute information, metadata information, and content structure information to obtain a static threat value, including: Determine a whitelist attenuation factor and a whitelist probability confidence level for each file to be scanned according to the basic attribute information and metadata information; Comparing the content structure information to obtain the hit count and discreteness for each virus feature in the first virus database; The static threat value of each file to be scanned is calculated according to the whitelist attenuation factor, the whitelist probability confidence, the number of hits and the discreteness.

4. The method according to claim 3, characterized in that According to the whitelist attenuation factor, the whitelist probability confidence, the number of hits and the discreteness, the static threat value of each file to be scanned is calculated, including: Get the first weight of each virus feature; The static threat value of each file to be scanned is calculated according to a preset first calculation formula, the first weight, the whitelist attenuation factor, the whitelist probability confidence, the number of hits and the discreteness, wherein the first calculation formula includes: in, C k Indicates k The number of hits of virus features, W k Indicates k The first weight of the virus feature, S k Indicates k The discreteness of the virus features, ε Represents a preset minimum constant, λ Represents the whitelist attenuation factor, P represents the whitelist probability confidence, n Represents the total number of virus signatures.

5. The method according to claim 2, characterized in that: Performing dynamic feature comparison on the behavior feature information to obtain a dynamic threat value includes: When the file type of the file to be scanned is an executable file type, detecting an abnormal section of the file to be scanned of the executable file type to obtain a first malicious behavior score; Parse the call chain of the file to be scanned of the executable file type, mark high-risk behaviors, and obtain the second malicious behavior score; Obtain a third malicious behavior score by performing a weighted summation according to a preset second weight and the first malicious behavior score and the second malicious behavior score; The third malicious behavior score is compared with a preset first comparison threshold to obtain a dynamic threat value of the file to be scanned of the executable file type.

6. The method according to claim 2, characterized in that Performing dynamic feature comparison on the behavior feature information to obtain a dynamic threat value includes: When the file type of the to-be-scanned file is a script type, the to-be-scanned file of the script type is imported into a preset sandbox environment for simulation execution to generate a fourth malicious behavior score; The fourth malicious behavior score is compared with a preset second comparison threshold to obtain a dynamic threat value of the script type file to be scanned.

7. The method according to any one of claims 1 to 6, characterized in that: Also includes: Save each threat information to the local database of the mobile terminal; When connected to the cloud, at least one threat information stored in the local database is transmitted to the cloud, and the local database is cleared.

8. A device for processing viruses in a vehicle system based on a mobile terminal, characterized in that: The device is applied to a mobile terminal, and comprises: An acquisition module, used for acquiring scanning information of a file to be scanned in the mobile storage device when detecting access to the mobile storage device for the control terminal while maintaining connection with the control terminal of the target vehicle, wherein the scanning information includes basic attribute information, metadata information, content structure information and behavior feature information; A comparison module, used for comparing the scanning information and the first virus database currently used by the mobile terminal to obtain a target threat value of each file to be scanned; A threat sending module is used to send threat information including the target threat value to the control terminal so that the control terminal performs corresponding processing, wherein the threat information includes the target threat value, and a processing instruction corresponding to the target threat value and the scanning information.

9. A computing device, characterized in that include: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the method for virus processing on a vehicle system based on a mobile terminal are implemented as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing computer-executable instructions, characterized in that: When the computer executable instructions are executed by the processor, the steps of the method for virus processing on a vehicle system based on a mobile terminal as described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Vehicle security defense method and device, electronic equipment and readable storage medium

    CN115866603A

  • Method and device for managing and controlling mobile storage device

    CN115879106A

  • Detecting malicious software

    US8863288B1