USB flash disk malicious code detection method and system based on system log
Through the U disk malicious code detection method based on system logs, the U disk file system log is analyzed to identify changing files, and malicious code detection is carried out in combination with key attribute information, which solves the problem of incomplete detection of U disk malicious code in the existing technology, and improves the security and efficiency of USB disk use.
Patent Information
- Application Number
- CN202411927568.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art is difficult to effectively detect malicious code in USB drives, especially when the USB drive is still undetected after being hacked by malicious code, which has led to the security of USB drive usage being compromised.
The system log-based malicious code detection method of USB disk is used to analyze the file system log of each partition of USB disk, and the files that have changed are identified, and the key attribute information of unchanged files is determined, and the information in the tagged file is compared with the information in the tagged file, malicious code detection is performed, and the tagged file is updated.
It improves the security and efficiency of USB drive usage, can quickly identify changing files and perform malicious code detection, and reduces the efficiency loss of invalid HASH calculations during the detection process.
Smart Images

Figure CN120012082A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a method and system for detecting malicious codes in a USB flash drive based on a system log. Background Art
[0002] As the scale of power grids expands and the level of intelligence increases, the management of power grid communication resources becomes increasingly complex. Traditional resource management methods often have difficulty coping with the dynamic changes and uncertainties of communication resources in large-scale power grids, requiring more intelligent and flexible management strategies.
[0003] With the continuous development of information technology, the previous information exchange medium in the form of floppy disks, CDs, etc. is becoming less and less common. The information exchange medium using USB (Universal Serial Bus) mobile storage media, namely U disk, is becoming more and more common. USB has the advantages of fast transmission speed and hot plug support. With the continuous advancement of semiconductor technology, the hardware size of U disk using USB interface is getting smaller and smaller, the storage capacity is getting larger and larger, and the functions are getting more and more complex. While bringing convenience to people, it also brings various security risks. In particular, in recent years, the incidents of spreading malicious code through U disk have occurred frequently, which not only affects the safe production of enterprises, but also brings unnecessary economic losses to people. Before using U disk for data exchange, the files in the U disk are first detected for malicious code to ensure the security of the exchanged data, which has become an important means to ensure the safety of U disk use. However, before each data exchange, the U disk is tested for malicious code, and the unchanged data is also scanned repeatedly, which will greatly reduce the efficiency of data exchange and bring unnecessary time waste. If there is no compulsory means, forget to scan for malicious code first and directly use the files in the U disk, it will bring risks to the operating host and even affect the entire network connected to the host.
[0004] In order to solve the problem of efficiency and security, a current existing technology proposes a method for realizing linkage control of USB flash drives between multiple software systems, which is to create a unique identification ID and a tag file for the USB flash drive, and record the remaining space of each volume of the disk as the basis for security detection of the USB flash drive;
[0005] However, the inventors of the present invention found that although this method solves the problem of controlling the disk after it is infected by malicious code in some cases, there is still a risk that the USB flash drive will still be invaded by malicious code after being marked and controlled, that is, there is a situation where the malicious code cannot be detected. Summary of the invention
[0006] In view of this, the purpose of the present invention is to propose a method and system for detecting malicious code in a USB flash drive based on a system log, which not only improves the security of using a USB flash drive, but also ensures the convenience of using a USB flash drive.
[0007] Based on the above purpose, the present invention provides a method for detecting malicious code in a USB flash drive based on a system log, comprising:
[0008] For a USB flash drive that is not connected for the first time, analyzing the file system log of each partition of the USB flash drive to identify changed files;
[0009] For the unchanged files in the USB flash drive, determining key attribute information of the files;
[0010] Compare the determined key attribute information of the file with the key attribute information of the file pre-stored in the tag file of the partition where the file is located;
[0011] The files with inconsistent comparison results and the files identified as changed are subjected to malicious code detection; and the key attribute information and hash value of the files that have passed the detection are recorded as the tag information of the files and stored in the tag file.
[0012] The key attribute information of the file includes:
[0013] The relative path, file size, creation time, and modification time of the file.
[0014] Preferably, before analyzing the file system log of each partition of the USB flash drive, the method further includes:
[0015] Determine whether the USB flash drive is accessed for the first time;
[0016] After determining that the USB flash drive is accessed for the first time, for each partition of the USB flash drive, a marker file is generated in the root directory of the partition, and all files of the partition are scanned for malicious codes in sequence, and key attribute information and hash values of the scanned files are stored in the marker file as marker information of the files;
[0017] The marking file is stored in encrypted form and signed using a signature algorithm.
[0018] The step of determining whether the USB flash drive is accessed for the first time specifically includes:
[0019] Detecting the marked files in the root directory of each partition volume of the USB flash drive;
[0020] If the marking file does not exist or the signature verification fails, it is determined that the U disk is accessed for the first time; otherwise, the U disk is not accessed for the first time.
[0021] Furthermore, the method further comprises:
[0022] For the file to be copied in the USB flash drive, detecting the tag information of the file in the tag file;
[0023] After the detection is passed, the file is copied to the host.
[0024] The present invention also provides a USB flash drive malicious code detection system based on system log, comprising: a USB flash drive detection device; wherein the USB flash drive detection device comprises:
[0025] The system log analysis module is used to analyze the file system log of each partition of the USB flash drive for non-first access and identify the files that have changed;
[0026] A tag fast detection module is used to determine the key attribute information of the file for the unchanged file in the USB flash drive; compare the determined key attribute information of the file with the key attribute information of the file pre-stored in the tag file of the partition where the file is located;
[0027] The malicious code detection module is used to detect malicious code for files with inconsistent comparison results and files identified as changed; and to store key attribute information and hash values of files that have passed the detection as tag information records of the files in the tag file.
[0028] Preferably, the USB disk detection device further includes:
[0029] The U disk tag detection module is used to determine whether the U disk is accessed for the first time: the tag file under the root directory of each partition volume of the U disk is detected; if the tag file does not exist or the signature verification fails, it is determined that the U disk is accessed for the first time; otherwise, the U disk is not accessed for the first time;
[0030] The U disk tag generation module is used to generate a tag file in the root directory of each partition of the U disk for a U disk that is judged to be connected for the first time, and scan all files of the partition for malicious codes in sequence through the malicious code detection module, and store the key attribute information and hash value of the scanned file as the tag information of the file in the tag file; wherein the tag file is encrypted and saved, and is signed by a signature algorithm.
[0031] Preferably, the system further comprises: a USB disk access control device; wherein the USB disk access control device comprises:
[0032] A file mark detection module, for detecting the mark information of the file to be copied in the USB flash drive in the mark file;
[0033] The U disk file copy module is used to copy the file to the host after the file is detected.
[0034] The present invention also provides a computer device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it is used to implement the steps of the above-mentioned USB flash drive malicious code detection method based on system log.
[0035] The present invention also provides a computer-readable storage medium, in which a computer program is stored. The computer program can be executed by at least one processor to enable the at least one processor to perform the steps of the above-mentioned USB flash drive malicious code detection method based on system log.
[0036] In the technical solution of the present invention, for a USB flash drive that is not accessed for the first time, the file system log of each partition of the USB flash drive is analyzed to identify the files that have changed; for the files that have not changed in the USB flash drive, the key attribute information of the files is determined; the key attribute information of the determined files is compared with the key attribute information of the files pre-stored in the tag file of the partition where the files are located; the files with inconsistent comparison results and the files identified as changed are subjected to malicious code detection; and the key attribute information of the files that have passed the detection is recorded and stored in the tag file as the tag information of the files. In the technical solution of the present invention, by analyzing the file system log of the disk, all the changed files are re-scanned, and the unchanged files are quickly matched according to the key attribute information recorded during the last marking, without having to use the less efficient HASH value matching; it can quickly identify the files that have changed, and avoid the loss of efficiency caused by invalid HASH calculation; further, for the files that failed to match, they are re-scanned, and the tags are updated after the scanning is completed. Since only the changed file part is scanned during the secondary use, the efficiency of the USB flash drive malicious code scanning can be greatly improved, while ensuring the safety of the USB flash drive. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0038] Figure 1 A flow chart of a method for detecting malicious code in a USB flash drive based on a system log provided by an embodiment of the present invention;
[0039] Figure 2 A schematic diagram of the internal structure of a USB flash drive malicious code detection system based on system logs provided by an embodiment of the present invention;
[0040] Figure 3A schematic diagram of the hardware structure of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0041] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with specific embodiments and with reference to the accompanying drawings.
[0042] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present invention should be understood by people with ordinary skills in the field to which the present disclosure belongs. The "first", "second" and similar words used in the present disclosure do not represent any order, quantity or importance, but are only used to distinguish different components. "Including" or "comprising" and similar words mean that the elements or objects appearing in front of the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0043] The inventor of the present invention has found through analysis of the prior art that when malicious code attacks files in a USB flash drive, there is a possibility that the file size may change slightly or remain unchanged. By judging by the remaining space on the disk volume, such file changes may not be detected, and there is a risk that the USB flash drive may still be invaded by malicious code after being marked and controlled. At the same time, during use, once there is an operation to write to the USB flash drive, it means that the security mark is invalid, and it is impossible to achieve the purpose of marking once and using it continuously on multiple devices.
[0044] Therefore, the existing technology cannot solve the problem of safe use of U disk well. A new solution is needed to ensure the stability and efficiency of U disk scanning and the convenience and security of copying U disk, so as to achieve better results. When the U disk is repeatedly marked, the key attributes of the file, such as file size, creation time, and modification time, are used to quickly search for the files that need to be detected, which is efficient. Re-detecting the changed files can find most of the files infected by malicious code, but there is still a certain probability that the above key attribute data remains unchanged after the malicious code invades. By adding file changes detected according to the file system log, the modified files can be further found, which can greatly reduce the possibility of missing detection after the file is modified. In the U disk tag file, not only the key attribute information of all files after malicious code detection is recorded, but also the hash HASH values of these files are recorded. At the U disk user end, the strong file access control based on the HASH value is used to match the file information, which not only ensures the efficiency of U disk tag generation, but also ensures the security of U disk tag use.
[0045] Based on this, the present invention proposes a method for detecting malicious codes in a USB flash drive based on a system log. The USB flash drive used for the first time is scanned for malicious codes in all files on the disk and a mark is recorded. The mark information includes key attribute information of files such as relative path, file size, creation time, modification time, and file HASH value information. When the USB flash drive is used on a host computer equipped with a USB flash drive access control device, only files with check marks can be copied from the USB flash drive through access control software, so as to prevent files infected by malicious codes from being accidentally brought into the host computer during the process of transferring files from the USB flash drive. When the marked USB flash drive is used again, all modified files are re-scanned by analyzing the disk file system log, and the unchanged files are quickly matched according to the key information recorded during the last marking. The files that fail to match are re-scanned, and the marks are updated after the scanning is completed. The access control software is used to complete the copying of the files with check marks in the USB flash drive. Since only the changed file part is scanned during the second use, the efficiency of the USB flash drive malicious code scanning can be greatly improved. If it is directly used on multiple devices without scanning, the USB flash drive access control software strongly matches the copied files according to the marks to ensure the safety of use.
[0046] The technical solutions of the embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0047] The embodiment of the present invention proposes a method for detecting malicious code in a USB flash drive based on a system log. The specific process is as follows: Figure 1 As shown, the following steps are included:
[0048] Step S101: for a connected USB flash drive, determine whether the USB flash drive is connected for the first time; if it is the first time, execute the following step S102; otherwise, execute the following step S111;
[0049] In this step, the marker file under the root directory of each partition volume of the connected U disk is detected; if the marker file does not exist or the signature verification fails, it is determined that the U disk is connected for the first time, and the following step S102 is executed; otherwise, it is determined that the U disk is not connected for the first time, and the following step S111 is executed.
[0050] Step S102: for a USB flash drive connected for the first time, a marking file is generated and all files are marked;
[0051] In this step, for the USB flash drive that is determined to be connected for the first time, a marker file is generated in the root directory of each partition of the USB flash drive; wherein the marker file format is not limited and can be any file format such as database, xml, json, etc.
[0052] Step S103: Mark all files in the USB flash drive and record the marking information in a marking file;
[0053] In this step, for each partition of the USB flash drive, all files in the partition are scanned for malicious code in turn, and the key attribute information of the files that pass the scan and the hash value of the files are stored in the marking file as the marking information of the files; the files that fail the scan are isolated or deleted;
[0054] The key attribute information of the file may include: the relative path, file size, creation time, and modification time of the file.
[0055] Step S104: Encrypt and save the marked file, and sign the marked file using a signature algorithm;
[0056] In this step, the tag file in the root directory of the U disk partition is encrypted and saved, and signed by the signature algorithm. That is to say, the tag information of all files in the partition is encrypted and stored in the tag file in the root directory of the U disk partition; then the signature value is calculated for the data of the generated tag file and stored in the signature file in the root directory of the U disk partition;
[0057] The signature algorithm may be an asymmetric encryption algorithm, and may be any algorithm such as SM2, RSA, etc. The signature information is recorded in a signature file in the root directory of the partition.
[0058] In this way, the marking of the USB flash drive is completed, and the following step S120 can be executed to connect the USB flash drive to the host and load it.
[0059] Step S111: for a USB flash drive that is not accessed for the first time, analyzing the file system log of each partition of the USB flash drive;
[0060] In this step, for a USB flash drive that is not connected for the first time, the file system log of each partition of the USB flash drive is analyzed to identify the files that have changed;
[0061] Step S112: for the unchanged files in the USB flash drive, determining the key attribute information of the files;
[0062] In this step, for the unchanged files in the USB flash drive, determining the key attribute information of the files may include: the relative path, file size, creation time, and modification time of the files.
[0063] Step S113: comparing the determined key attribute information of the file with the key attribute information of the file pre-stored in the mark file of the partition where the file is located;
[0064] In this step, the key attribute information of the file stored in advance is obtained from the tag file in the root directory of the partition where the file is located; the key attribute information of the file obtained is compared with the key attribute information of the file determined in step S112; if the comparison results are consistent, it indicates that the file does not need to be further detected for malicious code; if the comparison results are inconsistent, malicious code detection is performed when executing the following step S114.
[0065] Step S114: Perform malicious code detection on files with inconsistent comparison results and files identified as changed;
[0066] In this step, files with inconsistent comparison results and files identified as changed are subjected to malicious code detection.
[0067] Step S115: Mark the files that have passed the inspection, encrypt and save the marked files, and sign the marked files using a signature algorithm;
[0068] In this step, the files that have passed the malicious code detection in the above step S114 are marked: for each file that has passed the malicious code detection in the above step S114, the key attribute information of the file and the hash value of the file are used as the marking information of the file and stored in the marking file in the root directory of the partition where the file is located;
[0069] The marked file is then encrypted and saved, and signed by a signature algorithm.
[0070] In this way, the marking of the USB flash drive is completed, and the following step S120 can be executed to connect the USB flash drive to the host and load it.
[0071] Step S120: prohibiting other programs from accessing the USB flash drive, prohibiting the program on the USB flash drive from automatically running, failing to read the marked file or failing to verify the signature of the marked file, and refusing to use the USB flash drive;
[0072] Step S121: for the file to be copied in the USB flash drive, detect the key attribute information of the file in the tag file; if the detection is passed, execute step S122, otherwise, jump to step S114;
[0073] In this step, for the file to be copied in the USB flash drive, determining the key attribute information of the file may include: the relative path, file size, creation time, and modification time of the file; comparing the determined key attribute information of the file with the key attribute information pre-stored in the tag file of the partition where the file is located;
[0074] If the comparison result is inconsistent, it means that the file has changed, then jump to step S114 to perform malicious code detection without calculating the file HASH to avoid invalid calculation;
[0075] If the comparison results are consistent, execute step S122 to further perform file HASH value detection;
[0076] Step S122: for the file to be copied in the USB flash drive, detect the HASH value of the file in the tag file; if the detection passes, copy the file to the host; otherwise, jump to step S114;
[0077] In this step, for the file to be copied in the USB flash drive, the HASH value of the file is calculated; the calculated HASH value is compared with the HASH value in the tag file to perform a strict file match check; if the comparison result is inconsistent, jump to step S114 to perform malicious code detection; if the comparison result is consistent, the detection passes and the file is copied to the host;
[0078] In this step, the two-step tag verification method of steps S121 and S122 can avoid a large number of invalid file HASH calculations caused by file changes during the use of the USB flash drive.
[0079] For example, in a scenario where files need to be frequently exchanged between hosts, if a file F1 needs to be distributed to hosts A, B, and C via a USB flash drive, host A copies file F2 to the USB flash drive at the same time after copying file F1 from the USB flash drive. Before the USB flash drive is re-scanned for a mark, it will not affect hosts B and C from using the USB flash drive to copy file F1. This allows a USB flash drive with marked files to be used for secure file exchange on multiple controlled host devices in a continuous manner.
[0080] In addition, the convenience of the present invention is also reflected in that, during the exchange of U disk data files, it is not necessary to copy a file to regenerate a marking file in the U disk, and the file that already has a marking file and has not been modified will not be affected in use.
[0081] Based on the above-mentioned USB flash drive malicious code detection method based on system log, the embodiment of the present invention provides a USB flash drive malicious code detection system based on system log, and its internal structure is as follows: Figure 2 As shown, it includes: a USB disk detection device 201;
[0082] The USB disk detection device 201 specifically includes the following modules: a system log analysis module 211, a tag rapid detection module 212, and a malicious code detection module 213;
[0083] The system log analysis module 211 is used to analyze the file system log of each partition of the USB flash drive for a non-first access, and identify the files that have changed and the files that have not changed;
[0084] The tag fast detection module 212 is used to determine the key attribute information of the file for the unchanged file in the USB flash drive according to the recognition result of the system log analysis module 211; compare the determined key attribute information of the file with the key attribute information of the file pre-stored in the tag file of the partition where the file is located to obtain a comparison result; wherein the key attribute information of the file may include: the relative path, file size, creation time, and modification time of the file;
[0085] The malicious code detection module 213 is used to perform malicious code detection on files with inconsistent comparison results and files identified as changed based on the comparison results of the mark fast detection module 212; and store the key attribute information of the file that has passed the detection and the hash value of the file as the mark information record of the file in the said mark file.
[0086] Furthermore, the USB disk detection device 201 may also include the following modules: a USB disk tag detection module 214, a USB disk tag generation module 215;
[0087] The USB flash drive tag detection module 214 is used to determine whether the USB flash drive is accessed for the first time: the tag file under the root directory of each partition volume of the USB flash drive is detected; if the tag file does not exist or the signature verification fails, it is determined that the USB flash drive is accessed for the first time; otherwise, the USB flash drive is not accessed for the first time;
[0088] The USB flash drive tag generation module 215 is used to generate a tag file in the root directory of each partition of the USB flash drive for the USB flash drive that is judged to be connected for the first time according to the judgment result of the USB flash drive tag detection module 214, and perform malicious code scans on all files of the partition in turn through the malicious code detection module 213, and stores the key attribute information of the scanned file and the hash value of the file as the tag information of the file in the tag file; wherein the tag file is encrypted and saved, and is signed by a signature algorithm.
[0089] Accordingly, the system log analysis module 211 is specifically used to analyze the file system log of each partition of the USB flash drive for a non-first access USB flash drive according to the judgment result of the USB flash drive tag detection module 214, and identify the changed files and the unchanged files.
[0090] Furthermore, the USB flash drive malicious code detection system based on system log provided by the embodiment of the present invention may also include: a USB flash drive access control device 202;
[0091] The U disk access control device 202 specifically includes the following modules: a file mark detection module 221, a U disk file copy module 222;
[0092] The file tag detection module 221 is used to detect the tag information of the file to be copied in the U disk in the tag file; specifically, the file tag detection module 221 determines the key attribute information of the file to be copied in the U disk, which may include: the relative path, file size, creation time, and modification time of the file; compares the determined key attribute information and hash value of the file with the key attribute information of the file pre-stored in the tag file of the partition where the file is located; if the comparison result is inconsistent, it means that the file has changed, then the U disk detection device 201 is notified to perform malicious code detection on the file, without calculating the file HASH, to avoid invalid calculation; if the comparison result is consistent, further perform file HASH value detection: for the file to be copied in the U disk, calculate the HASH value of the file; compare the calculated HASH value with the HASH value in the tag file; if the comparison result is inconsistent, it means that the file has changed, then the U disk detection device 201 is notified to perform malicious code detection on the file; if the comparison result is consistent, the detection passes.
[0093] The U disk file copy module 222 is used to copy the file to the host after the file mark detection module 221 determines that the file has passed the detection.
[0094] Further, the USB disk access control device 202 may also include the following modules: a USB disk access control module 223, a USB disk tag detection module 224;
[0095] The USB disk access control module 223 is used to prohibit other programs from accessing the USB disk and prohibit the programs on the USB disk from automatically running. Then, the USB disk tag detection module 224 is used to detect the tag file of the USB disk and verify the signature of the tag file.
[0096] Correspondingly, when the USB flash drive tag detection module 224 detects the tag file and verifies the signature, the file tag detection module 221 detects the tag information of the file to be copied in the USB flash drive in the tag file.
[0097] In the technical solution of the present invention, for a USB flash drive that is not accessed for the first time, the file system log of each partition of the USB flash drive is analyzed to identify the files that have changed; for the files that have not changed in the USB flash drive, the key attribute information of the files is determined; the key attribute information of the determined files is compared with the key attribute information of the files pre-stored in the tag file of the partition where the files are located; the files with inconsistent comparison results and the files identified as changed are subjected to malicious code detection; and the key attribute information of the files that have passed the detection is recorded and stored in the tag file as the tag information of the files. In the technical solution of the present invention, by analyzing the file system log of the disk, all the changed files are re-scanned, and the unchanged files are quickly matched according to the key attribute information recorded during the last marking, without having to use the less efficient HASH value matching; it can quickly identify the files that have changed, and avoid the loss of efficiency caused by invalid HASH calculation; further, the files that failed to match are re-scanned, and the tags are updated after the scanning is completed. Since only the changed file part is scanned during the secondary use, the efficiency of the USB flash drive malicious code scanning can be greatly improved, while ensuring the safety of the USB flash drive.
[0098] That is to say, the technical solution of the present invention performs a full disk malicious code scan and creates a marking file for the first access to the USB flash drive; if it is not the first access and there is an existing marked file, the file change information is automatically extracted based on the operation log information of the file system, and only the changed files are re-detected for malicious codes and the HASH value of the files is calculated; for those without change records, the key attribute information of the file is checked to see if it is consistent with the record. If it is inconsistent, malicious code detection and file HASH calculation will be re-performed to update the file mark. Through this mechanism, the number of file HASH calculations performed during the detection process is effectively reduced.
[0099] Through the USB flash drive malicious code detection method based on system log provided by the present invention, changes in some files can only affect the access to the changed files without affecting the normal operation of other files. A USB flash drive with marked files can be used to continuously and securely exchange files on multiple controlled host devices.
[0100] In addition, the convenience of the present invention is also reflected in that, during the exchange of U disk data files, it is not necessary to copy a file to regenerate a marking file in the U disk, and the file that already has a marking file and has not been modified will not be affected in use.
[0101] Figure 3The hardware architecture diagram of the computer device 1300 according to the USB flash drive malicious code detection method based on system logs according to the embodiment of the present application is schematically shown. In this embodiment, the computer device 1300 is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions. For example, it can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a rack server, a blade server, a tower server or a cabinet server (including an independent server, or a server cluster composed of multiple servers), etc. Figure 3 As shown, the computer device 1300 includes at least but is not limited to: a memory 1310, a processor 1320, and a network interface 1330 which can communicate with each other via a system bus. Among them:
[0102] The memory 1310 includes at least one type of computer-readable storage medium, and the readable storage medium includes a flash memory, a hard disk, a multimedia card, a card-type memory (e.g., an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the memory 1310 may be an internal storage module of the computer device 1300, such as a hard disk or a memory of the computer device 1300. In other embodiments, the memory 1310 may also be an external storage device of the computer device 1300, such as a plug-in hard disk equipped on the computer device 1300, a smart memory card (Smart Media Card, referred to as SMC), a secure digital (Secure Digital, referred to as SD) card, a flash card, etc. Of course, the memory 1310 may also include both the internal storage module of the computer device 1300 and its external storage device. In this embodiment, the memory 1310 is generally used to store the operating system and various application software installed on the computer device 1300, such as the program code of the USB flash drive malicious code detection method based on the system log, etc. In addition, the memory 1310 can also be used to temporarily store various data that have been output or will be output.
[0103] In some embodiments, the processor 1320 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 1320 is generally used to control the overall operation of the computer device 1300, such as performing control and processing related to data interaction or communication with the computer device 1300. In this embodiment, the processor 1320 is used to run the program code stored in the memory 1310 or process data.
[0104] The network interface 1330 may include a wireless network interface or a wired network interface, and the network interface 1330 is generally used to establish a communication link between the computer device 1300 and other computer devices. For example, the network interface 1330 is used to connect the computer device 1300 to an external terminal through a network, and to establish a data transmission channel and a communication link between the computer device 1300 and the external terminal. The network may be a wireless or wired network such as an intranet, the Internet, the Global System of Mobile communication (GSM), Wideband Code Division Multiple Access (WCDMA), 4G network, 5G network, Bluetooth, Wi-Fi, etc.
[0105] It should be pointed out that Figure 3 Only a computer device having components 1310 - 1330 is shown, but it should be understood that implementing all of the components shown is not a requirement, and more or fewer components may alternatively be implemented.
[0106] In this embodiment, the USB flash drive malicious code detection method based on system log stored in the memory 1310 can also be divided into one or more program modules and executed by one or more processors (processor 1320 in this embodiment) to complete the embodiment of the present application.
[0107] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.
[0108] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present disclosure (including the claims) is limited to these examples. Within the scope of the present invention, the above embodiments or technical features in different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the present invention as described above, which are not provided in detail for the sake of simplicity.
[0109] In addition, to simplify the description and discussion, and in order not to obscure the present invention, known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided figures. In addition, the devices may be shown in the form of block diagrams to avoid obscuring the present invention, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the present invention will be implemented (i.e., these details should be fully within the scope of understanding of those skilled in the art). Where specific details (e.g., circuits) are set forth to describe exemplary embodiments of the present invention, it will be apparent to those skilled in the art that the present invention may be implemented without these specific details or with variations in these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0110] Although the invention has been described in conjunction with specific embodiments of the invention, many replacements, modifications and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the embodiments discussed.
[0111] The embodiments of the present invention are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for detecting malicious code in a USB flash drive based on system logs, characterized in that: include: For a USB flash drive that is not connected for the first time, analyzing the file system log of each partition of the USB flash drive to identify changed files; For the unchanged files in the USB flash drive, determining key attribute information of the files; Compare the determined key attribute information of the file with the key attribute information of the file pre-stored in the tag file of the partition where the file is located; Perform malicious code detection on files with inconsistent comparison results and files identified as changed; The key attribute information and hash value of the file that has passed the detection are recorded as the tag information of the file and stored in the tag file.
2. The method according to claim 1, characterized in that The key attribute information of the file includes: The relative path, file size, creation time, and modification time of the file.
3. The method according to claim 1, characterized in that Before analyzing the file system log of each partition of the USB flash drive, the method further includes: Determine whether the USB flash drive is accessed for the first time; After determining that the USB flash drive is accessed for the first time, for each partition of the USB flash drive, a marker file is generated in the root directory of the partition, and all files of the partition are scanned for malicious codes in sequence, and key attribute information and hash values of the scanned files are stored in the marker file as marker information of the files; The marking file is stored in encrypted form and signed using a signature algorithm.
4. The method according to claim 3, characterized in that The determining whether the USB flash drive is accessed for the first time specifically includes: Detecting the marked files in the root directory of each partition volume of the USB flash drive; If the marking file does not exist or the signature verification fails, it is determined that the U disk is accessed for the first time; otherwise, the U disk is not accessed for the first time.
5. The method according to claim 3, characterized in that: Also includes: For the file to be copied in the USB flash drive, detecting the tag information of the file in the tag file; After the detection is passed, the file is copied to the host.
6. A USB flash drive malicious code detection system based on system log, characterized in that: include: U disk detection device; wherein, the U disk detection device comprises: The system log analysis module is used to analyze the file system log of each partition of the USB flash drive for non-first access and identify the files that have changed; A tag fast detection module is used to determine the key attribute information of the file for the unchanged file in the USB flash drive; compare the determined key attribute information of the file with the key attribute information of the file pre-stored in the tag file of the partition where the file is located; The malicious code detection module is used to detect malicious code for files with inconsistent comparison results and files identified as changed; and to store key attribute information and hash values of files that have passed the detection as tag information records of the files in the tag file.
7. The system according to claim 6, characterized in that The USB disk detection device also includes: The U disk tag detection module is used to determine whether the U disk is accessed for the first time: the tag file under the root directory of each partition volume of the U disk is detected; if the tag file does not exist or the signature verification fails, it is determined that the U disk is accessed for the first time; otherwise, the U disk is not accessed for the first time; The U disk tag generation module is used to generate a tag file in the root directory of each partition of the U disk for a U disk that is judged to be connected for the first time, and scan all files of the partition for malicious codes in sequence through the malicious code detection module, and store the key attribute information and hash value of the scanned file as the tag information of the file in the tag file; wherein the tag file is encrypted and saved, and is signed by a signature algorithm.
8. The system according to claim 7, characterized in that Also includes: U disk access control device; wherein, the U disk access control device comprises: A file mark detection module, for detecting the mark information of the file to be copied in the USB flash drive in the mark file; The U disk file copy module is used to copy the file to the host after the file is detected.
9. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, it is used to implement the steps of the USB flash drive malicious code detection method based on system log as described in any one of claims 1 to 4.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and the computer program can be executed by at least one processor so that the at least one processor executes the steps of the USB flash drive malicious code detection method based on system logs as described in any one of claims 1 to 4.