Data processing method and device
By introducing an isolation mechanism between transparent cache area and protected area in the file system, redirecting data operation requests to shadow files, and syncing them to the original file after passing security verification, the problem of file operation performance degradation caused by existing security software when detecting and blocking malware behavior is solved, and efficient file operation performance and malware blocking are achieved.
Patent Information
- Application Number
- CN202410231614.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-24
- Filing Date
- 2024-02-29
- Publication Date
- 2025-05-27
AI Technical Summary
When existing security software detects and blocks malware behavior, it needs to intercept and pause files related operations in real time, resulting in file read and write operations blocking, affecting file operation performance.
By introducing an isolation mechanism between transparent cache area and protected area in the file system, the application's data operation request is redirected to the shadow file in the transparent cache area. The file is only synchronized to the original file in the protected area after the modification has been passed through security verification, thereby blocking the harmful behavior of the malware without affecting the file operation performance.
It realizes the ability to block the harmful behavior of malware to files while improving file operation performance, avoiding blocking of file read and write operations, and ensuring normal operation of the file system.
Smart Images

Figure CN120046177A_ABST
Abstract
Description
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 24, 2023, with application number 202311600657.7 and application name “A method, device and other equipment for data processing”, all contents of which are incorporated by reference in this application. Technical Field
[0002] The embodiments of the present application relate to the field of cloud computing, and in particular to a data processing method and device. Background Art
[0003] After the malware invades the user's system, it will encrypt one or more files. Then the malware user will ask the user for money or other property by providing a decryption key. In order to prevent files from being encrypted by ransomware, users can use security software to scan the system for malicious file features, identify encrypted file features, and detect and block the behavior of malware, thereby reducing or eliminating the harm of malware.
[0004] Existing security software usually needs to intercept the creation and modification of files by the software in real time, and check the file content. If the file content contains malicious file characteristics, the software is prevented from performing subsequent operations on the file. Therefore, the security software needs to intercept and suspend the relevant operations of the file in real time, and allow or block the execution after the inspection is completed, which will block the reading and writing of files and affect the performance of file operations. Summary of the invention
[0005] The present application provides a data processing method and device, thereby improving file operation performance while blocking malicious software from causing harm to files.
[0006] In a first aspect, the present application provides a data processing method, which is applied to a computing device including a file system, wherein the file system includes a transparent cache area and a protected area, wherein the transparent cache area is transparent to the application program, and the transparent cache area and the protected area are isolated from each other, and the protected area is used to store the original file, and the transparent cache area is used to store the shadow file, which is a copy of the original file. In the process of the data processing method, a data operation request of the application program is first obtained, and when the data operation request includes a modification operation on the original file of the protected area, the shadow file corresponding to the original file is modified according to the data operation request to obtain the modified file. Then, it is determined that the modified file passes the security verification, and the modified file is synchronized to the protected area.
[0007] Based on the above data processing method, when the computing device performs security verification and other tests on the shadow file in the transparent cache area, the computing device can still perform operations such as access to the original file in the protected area, which will not block the reading and writing of the file and will not affect the normal operation of the file system. At the same time, the modification operation of the original file by the data operation request is redirected to the shadow file, and only the modified file that has passed the security verification can be synchronized to the original file in the protected area, thereby protecting the files in the protected area from being affected by malware. In this way, while blocking the harmful behavior of malware on the file, the file operation performance is improved.
[0008] As a possible implementation method, when the data operation request includes a modification operation on the original file, the computing device redirects the modification operation to the shadow file, does not perform the modification operation on the original file in the protected area, but performs the modification operation on the shadow file in the transparent cache area to obtain the modified file. In this way, the computing device redirects the modification operation on the original file in the protected area to the shadow file, avoiding the application program from directly modifying the original file in the protected area. Since the protected area and the transparent cache area are isolated from each other, even if the application program's modification operation on the shadow file contains malware behavior, it cannot affect the original file in the protected area, thereby ensuring the security of the original file.
[0009] As a possible implementation method, the computing device redirects the modification operation to the shadow file through the sector link method. In this way, through the file sector link method, the newly added file content occupies the least disk space, and the subsequent file moves from the transparent cache area to the protected area in the least time, thereby improving the file operation performance.
[0010] Optionally, before implementing the file modification redirection of the original file, the computing device also needs to create a shadow file in the transparent cache area. The computing device creates a copy of the original file in the transparent cache area, and the copy serves as the shadow file corresponding to the original file. The sector pointer of the shadow file points to the original sector where the original file is located. In this way, when the data operation request does not involve a modification operation, the access to the original file still points to the original sector. It is only necessary to create a new file in the transparent cache area without copying the file data of the original sector, thereby ensuring the file operation performance.
[0011] Optionally, when the data operation request includes a modification operation, the computing device creates a new sector to store the new data generated by the modification operation, and modifies the sector pointer of the shadow file to point to the new sector. In this way, when the data operation request involves a modification operation, access to the original file is redirected to the shadow file in the transparent cache area through the sector link, thereby ensuring the security of the protected area.
[0012] As a possible implementation, the data operation request may include a new file operation. The computing device redirects the file path of the new file to the file path of the shadow file. In this way, when the computing device needs to access the new file later, it will access the file path of the original file, thereby accessing the shadow file through file path redirection, realizing file path mapping without the application being aware of it, thereby improving the user experience.
[0013] As a possible implementation, the data operation request may include a file opening operation. The computing device obtains the data operation request, which indicates opening the original file. When the original file has a corresponding shadow file, the shadow file is opened. When the original file does not have a corresponding shadow file, the original file is directly opened, and the file handle may also be recorded for tracking.
[0014] As a possible implementation, the data operation request may include an operation of deleting or moving a file. The computing device performs the operation of deleting or moving a file on the shadow file to obtain the modified file, and adds a mark to the original file. When it is determined that the modified file passes the security verification, the operation of deleting or moving the file is performed on the original file carrying the mark. In this way, before the modified file passes the security verification, the original file is still stored in the protected area, which can be regarded as providing a file snapshot point to facilitate the rapid recovery of the file or system.
[0015] As a possible implementation method, when a shadow file is modified, the computing device detects whether the modified file has ciphertext features or malicious program features, and if not, determines that the modified file passes security verification.
[0016] Optionally, when the modified file does not have ciphertext features or malicious program features, and the time after the modification operation reaches a preset threshold, the computing device determines that the modified file has passed the security verification. In this way, when the computing device performs ciphertext feature or malicious program feature detection on the shadow file, it can still access the original file, realizing the concurrent execution of file access and malicious program detection, and improving file operation performance.
[0017] In a second aspect, the present application provides a data processing device, including a transceiver module and a processing module. The transceiver module is used to obtain a data operation request sent by an application, and the data operation request includes a modification operation on an original file in a protected area. The processing module is used to modify a shadow file corresponding to the original file according to the data operation request to obtain a modified file. The processing module is also used to determine that the modified file passes security verification and synchronize the modified file to the protected area.
[0018] As a possible implementation manner, the processing module is specifically used to redirect the modification operation to the shadow file to modify the shadow file to obtain the modified file.
[0019] Optionally, the processing module is specifically used to redirect the modification operation to the shadow file by means of sector linking.
[0020] As a possible implementation method, before redirecting the modification operation to the shadow file through sector linking, the processing module is also used to: create a copy of the original file in the transparent cache area; the copy is the shadow file corresponding to the original file, and the sector pointer of the shadow file points to the original sector where the original file is located.
[0021] As a possible implementation manner, the processing module is further used to: create a new sector to store new data generated by the modification operation; and modify the sector pointer of the shadow file to point to the new sector.
[0022] As a possible implementation manner, the data operation request includes a new file operation, and the processing module is further used to redirect the file path of the new file to the file path of the shadow file.
[0023] As a possible implementation manner, the data operation request includes a file opening operation, and the processing module is further used to: open the shadow file when a corresponding shadow file exists for the original file.
[0024] As a possible implementation method, the data operation request includes a file deletion operation or a file move operation, and the processing module is also used to: perform the file deletion or file move operation on the shadow file; add a mark to the original file; and when it is determined that the modified file passes the security verification, perform the file deletion or file move operation on the original file carrying the mark.
[0025] As a possible implementation method, the processing module is specifically used to: when the shadow file is modified, detect whether the modified file has ciphertext features or malicious program features; when the modified file does not have ciphertext features or malicious program features, determine that the modified file has passed security verification.
[0026] Optionally, the processing module is specifically used to: when the modified file does not have ciphertext features or malicious program features, and the time after the modification operation reaches a preset threshold, determine that the modified file passes the security verification.
[0027] As a possible implementation manner, the data processing device may further include other modules for executing the operation steps of the data processing method described in the first aspect.
[0028] Regarding the technical principles and beneficial effects of the second aspect, reference may be made to the relevant description of the first aspect, which will not be repeated here.
[0029] In a third aspect, a computing device is provided, the computing device comprising a processor and a memory. The processor of the computing device is used to execute instructions stored in the memory of the computing device, so that the computing device executes the data processing method described in any possible implementation of the first aspect.
[0030] In a fourth aspect, a computer program product is provided, which includes a computer program or instructions, and when the computer program or instructions are executed on a computer, the computer executes the data processing method described in any possible implementation of the first aspect.
[0031] In a fifth aspect, a computer-readable storage medium is provided. The computer-readable storage medium includes: a computer program or instructions; when the computer program or instructions are executed on a computer, the computer executes the data processing method described in any possible implementation of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 A schematic diagram of the architecture of a distributed system provided for this application;
[0033] Figure 2 A schematic diagram of the structure of a service node provided for this application;
[0034] Figure 3 A schematic diagram of the structure of a new technology file system provided for this application;
[0035] Figure 4 A flowchart of a data processing method provided in this application;
[0036] Figure 5 A schematic diagram of a process flow of detection and arbitration steps provided for this application;
[0037] Figure 6 A schematic diagram of another process of detection and arbitration steps provided for this application;
[0038] Figure 7 A schematic diagram of a new file creation process provided for this application;
[0039] Figure 8 A schematic diagram of a process for opening a file provided for this application;
[0040] Fig. 9 A schematic diagram of a file modification process provided for this application;
[0041] Fig.10 A flowchart of a file deletion process provided by this application;
[0042] Fig.11A schematic diagram of a file movement process provided for this application;
[0043] Fig.12 A schematic diagram of the structure of a data processing device provided in this application;
[0044] Fig.13 A schematic diagram of the structure of a computing device provided for this application;
[0045] Fig.14 A schematic diagram of the structure of a computing device cluster provided for this application;
[0046] Fig.15 A schematic diagram of a structure in which computing devices are connected via a network provided in the present application. DETAILED DESCRIPTION
[0047] The data processing method provided in the embodiment of the present application can be applied to the file system scenario in the storage field. The following is a brief introduction to the technologies that may be involved in the present application.
[0048] (1) File system
[0049] A file system is a method and data structure used by an operating system to identify files on a storage device (such as a disk, solid-state drive, etc.) or partition, that is, a method of organizing files on a storage device. The software organization in an operating system (OS) that is responsible for managing and storing file information is called a file management system, or file system for short. A file system usually consists of three parts: the file system interface, a collection of software for object manipulation and management, and objects and attributes. From a system perspective, a file system is a system that organizes and allocates space on file storage devices, is responsible for file storage, and protects and retrieves stored files. Specifically, the file system is responsible for creating files for users, storing, reading, modifying, and dumping files, controlling file access, and revoking files when users no longer use them.
[0050] Common file systems include file allocation table (FAT) file system, new technology file system (NTFS), extended file system (EXT), etc. Taking NTFS as an example, NTFS uses a special data structure of Master File Table (MFT) to store metadata information of files and directories. Each file has a record entry in the MFT, which contains the metadata information of the file, such as file name, file size, creation time, modification time, etc. The record entry also contains a pointer to the sector where the file data is located.
[0051] (2) Sector Link
[0052] A sector is the smallest physical storage unit on a disk, usually 512 bytes in size. There are many concentric tracks on a disk, which are equally divided into several arcs, which constitute the sectors of the disk. When the head reads or writes data from the disk, it is done in sectors. The concept of sectors applies not only to traditional mechanical hard disks, but also to modern non-volatile memory (NVM) technology, such as solid state drives (SSDs). A block is the smallest unit of file system access. A block consists of multiple sectors, usually 8 consecutive sectors, forming a 4 kilobyte (KB) block.
[0053] Sector links are a type of file links. Links are used to point to a file's data block. That is, when an application accesses a file in the file system, it accesses the file's data through the file's link. For example, a hard link is a file system that creates multiple file names pointing to the same file's data block. These file names are considered equivalent in the file system because they point to the same data block. When creating a hard link, the new file name and the original file name both point to the same data block. Therefore, if one of the file names is deleted, the file data still exists in the file system because it is still referenced by the other file names. Hard links can only be created in the same file system because they need to point to the same data block. A soft link is a special file that contains a path to another file. For another example, soft links are considered different files in the file system because they point to different data blocks. If the original file is deleted, the soft link will become invalid because the file path it points to no longer exists. Soft links can span different file systems because they are just paths to another file.
[0054] (3) Copy-on-write (COW)
[0055] Copy-on-write is an optimization strategy in the field of computer programming. The core idea is that if multiple callers request the same resource (such as memory or data storage on disk) at the same time, they will jointly obtain the same pointer to the same resource, until a caller tries to modify the content of the resource, the system will actually copy a private copy to the caller, while the original resource seen by other callers remains unchanged.
[0056] The present application provides a data processing method, in particular, a "data processing method for redirecting modification operations on original files to shadow files in a transparent cache area". The data processing method can be applied to a computing device including a file system, wherein the file system includes a transparent cache area and a protected area, wherein the transparent cache area is transparent to the application, and the transparent cache area and the protected area are isolated from each other. In the process of the data processing method, a data operation request of the application is first obtained. When the data operation request includes a modification operation on the original file in the protected area, the shadow file corresponding to the original file is modified according to the operation request to obtain the modified file. Then, it is determined that the modified file passes the security verification, and the modified file is synchronized to the original file.
[0057] Based on the above data processing method, when the computing device performs security verification and other tests on the shadow file in the transparent cache area, the computing device can still perform operations such as access to the original file in the protected area, which will not block the reading and writing of the file and will not affect the normal operation of the file system. At the same time, the modification operation of the original file by the data operation request is redirected to the shadow file, and only the modified file that has passed the security verification can be synchronized to the original file in the protected area, thereby protecting the files in the protected area from being affected by malware. In this way, while blocking the harmful behavior of malware on the file, the file operation performance is improved.
[0058] The implementation of the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0059] Figure 1 This is a schematic diagram of the architecture of a distributed system provided by this application. Figure 1 As shown, the distributed system 100 includes a computing server cluster 110, a storage server cluster 120, a management server cluster 130, a network device cluster 140 and a user terminal 150. The computing server cluster 110, the storage server cluster 120 and the management server cluster 130 communicate with the user terminal 150 through the network device cluster 140 respectively.
[0060] The computing server cluster 110 includes one or more computing servers ( Figure 1 Two computing servers, namely computing server 111 and computing server 112, are shown in FIG. 1 , but are not limited to two computing servers).
[0061] The computing server is a computing resource in the distributed system 100, such as a server, a desktop computer, etc., which is used to generate and allocate computing resources according to user needs based on virtualization technology. At the hardware level, the computing server is equipped with a processor and a memory ( Figure 1The computing function of the computing server is realized by the processor running the program in the memory. The computing server can also read / write data in each storage server in the storage server cluster 120 according to user needs.
[0062] The storage server cluster 120 includes one or more storage servers ( Figure 1 Two storage servers, storage server 121 and storage server 122, are shown in FIG. 1 , but are not limited to two storage servers).
[0063] The storage server is a storage resource in the distributed system 100, such as a server, desktop computer or storage array controller, hard disk frame, etc., which is used to provide logical disk storage, semi-structured data storage, integrated backup and other services for the cloud virtual machines in the distributed system 100. In terms of hardware, the storage server is provided with a network card, a processor and a memory. The processor in the storage server is used to process data from outside the storage server. The network card is used to control the access process of the memory, such as the control of address signals, data signals and various command signals, so that the storage server can provide the memory as a storage resource to the user. The memory is used to store data and may include memory and / or hard disk. Memory refers to an internal memory that directly exchanges data with the processor. The memory can read and write data quickly at any time and serve as a temporary data storage for the operating system or other running programs. Unlike memory, the hard disk reads and writes data slower than memory and is usually used to store data persistently.
[0064] The management server cluster 130 includes one or more management servers ( Figure 1 Two management servers, namely, management server 131 and management server 132, are shown in FIG. 1 , but are not limited to two management servers).
[0065] The management server is used to manage all computing services, shared storage, and networks of the entire distributed system 100, and provide users or administrators with an application program interface (API) for managing the entire node. In the present application, the distributed system 100 can provide the program product of the present application to users by providing an accessible application program interface.
[0066] The network device cluster 140 includes one or more switches and routers, such as Figure 1As shown, in this embodiment, the network device cluster 140 includes a router 141, a switch 142, a switch 143, a switch 144, and a switch 145. Among them, the user terminal 150 is connected to the router 141 through the Internet, and the router 141 is connected to the switch 143 through the switch 142, and the switch 143 is connected to each computing server in the computing server cluster 110. The switch 144 is respectively connected to each computing server in the computing server cluster 110 and each storage server in the storage server cluster 120. The switch 145 is respectively connected to each computing server in the computing server cluster 110, each storage server in the storage server cluster 120, and each management server in the management server cluster 130.
[0067] Optionally, the number and type of switches included in the network device cluster 140 can be adjusted according to the needs of the distributed system 100, and the switch 142, the switch 143, the switch 144, and the switch 145 can be switches with different functions, for example, the switch 142 is a core switch, and the switch 143, the switch 144, and the switch 145 are switches for managing a specific network segment. For example, the switch 142 can be a core switch, the switch 143 can be an internal and external switching network segment switch, the switch 144 can be a storage network segment switch, and the switch 145 can be a management network segment switch.
[0068] The user terminal 150 includes one or more user terminals ( Figure 1 Two user terminals, namely user terminal 151 and user terminal 152, are shown in FIG. 1 , but are not limited to two user terminals. The user terminal includes interfaces and applications required for accessing the distributed system 100.
[0069] It is worth noting that Figure 1 This is only a schematic diagram and should not be construed as limiting the present application. Any computing device with a file system can apply the data processing method provided by the present application. The computing device can be any device in the distributed system 100 or an independent computing device in a non-distributed system. On the other hand, the above-mentioned distributed system 100 can also include other devices or other architectures. Figure 1 For example, Figure 1 The computing server cluster 110, storage server cluster 120 and management server cluster 140 are hardware-separated devices. In a possible embodiment, the computing server cluster 110, storage server cluster 120 and management server cluster 140 can also be different servers divided using hardware resources belonging to the same device on hardware.
[0070] The computing servers, storage servers, etc. in the above-mentioned distributed system 100 provided in this application may be nodes in a cloud platform. Figure 1 Based on the equipment of the distributed system 100 shown, the distributed system 100 implements the functions of nodes such as computing nodes and storage nodes based on software as a service (SaaS), platform as a service (PaaS) and infrastructure as a service (IaaS), and provides services (such as computing services, storage services and network services) to the user terminal 150 through the nodes. The node can be a cloud service node (such as a computing node and a storage node, etc.) obtained by virtualizing the resources (such as computing resources and storage resources, etc.) of the distributed system 100.
[0071] For example Figure 2 As shown, the computing server cluster 110, the storage server cluster 120 and / or the management server cluster 140 in the distributed system 100 are virtualized into a service node, and the service node runs an operating system, and the operating system runs an application, a filter driver, a detection and arbitration program, a file system, etc. The file system includes a transparent cache area and a protected area. The transparent cache area is transparent to the application, and the transparent cache area is isolated from the protected area. The protected area includes one or more original files, and the transparent cache area includes one or more shadow files corresponding to the original files.
[0072] The application is used to send data operation requests to the file system. Data operation requests may include operations such as creating a new file, opening a file, modifying a file, deleting a file, or moving a file.
[0073] The file system senses the data operation request for the original file through the filter driver, and redirects the operation to the shadow file in the transparent cache area to obtain the modified file.
[0074] The detection and arbitration program is used to detect the modified files and operations to determine whether the modified files pass the security verification.
[0075] The file system is also used to synchronize modified files in the transparent cache area with original files in the protected area.
[0076] like Figure 3As shown in the figure, taking NTFS as an example, the protected area is used to store the original file, which contains the MFT and data content. The transparent cache area is used to store the shadow file corresponding to the original file in the protected area, that is, a copy of the original file. The MFT contains the metadata information of the file and the pointer to the sector where the file data is located. The shadow file in the transparent cache area is only the MFT of a newly created basic file, and its file data still points to the sector pointer of the original file. When the file data is modified, the file system will create a new sector to save the new data, and the pointer of the original sector of the shadow file will be replaced by the pointer of the new sector.
[0077] The file system redirects the modification operation of the original file to the shadow file by means of sector linking. For example, sector A of the original file is linked to sector C. When the data operation request indicates a modification operation to the file data of the original file stored in sector A, since sector A is linked to sector C, the modification operation is redirected to sector C by means of the sector link. Then, the file system performs the modification operation on the copy of the original file stored in sector C (i.e., the shadow file).
[0078] It is worth noting that the above Figure 2 and Figure 3 This is only a schematic diagram and should not be construed as limiting the present application. The virtual nodes of the distributed system 100 may also include other structures. Figure 2 or Figure 3 Not drawn in.
[0079] Next, the data processing method provided by this embodiment is described in detail with reference to the accompanying drawings.
[0080] The steps of the data processing method provided in this application are executed by a device in a computing server or a storage server in the distributed system 100, or by a node virtualized from the distributed system 100. Both the physical device and the virtualized node can be regarded as a computing device. Figure 4 , taking a computing device as an example, the data processing method provided in an embodiment of the present application is explained.
[0081] Step 401: The application sends a data operation request.
[0082] The application responds to the user's operation or sends a data operation request to the file system according to the application's own data needs during operation.
[0083] As a possible implementation manner, the data operation request includes operations such as opening a file, creating a new file, modifying a file, deleting a file, or moving a file.
[0084] Step 402: When the data operation request includes a modification operation on the original file in the protected area, the file system modifies the shadow file corresponding to the original file according to the data operation request to obtain a modified file.
[0085] When the data operation request includes a modification operation on the original file, the file system redirects the modification operation to the transparent cache area, that is, modifies the shadow file corresponding to the original file according to the data operation request, thereby redirecting the modification operation to the shadow file corresponding to the original file in the transparent cache area.
[0086] As a possible implementation manner, the data operation request may also include operations such as opening a file, creating a new file, deleting a file, or moving a file.
[0087] Optionally, when operations such as opening a file, creating a new file, deleting a file, or moving a file make substantial changes to file data, the file system redirects the modification operation to a shadow file in the transparent cache using sector links, so as to modify the shadow file corresponding to the original file according to the data operation request to obtain the modified file.
[0088] Optionally, when operations such as opening a file, creating a new file, deleting a file, or moving a file do not substantially modify the file data, the file system gives priority to accessing the shadow file if a corresponding shadow file exists for the original file, and accesses the original file if a corresponding shadow file does not exist for the original file.
[0089] When the file system accesses the original file, it records the file handle for tracking.
[0090] Whether the data operation request includes substantial modification of the original file can be obtained by analyzing the data operation request by the filter driver. For example, the filter driver obtains the data operation request sent by the application program and determines the file to be created, modified, deleted or moved according to the data identifier (such as address, key-value pair identifier, etc.) contained in the data operation request.
[0091] For detailed steps of the above operations such as opening a file, creating a new file, deleting a file, or moving a file, please refer to Figure 7-Figure 11 And related steps are not repeated here.
[0092] Step 403: The file system determines that the modified file passes security verification.
[0093] When the file system determines that the modified file does not have a ciphertext feature or a malicious program feature, it determines that the modified file passes the security verification.
[0094] As a possible implementation method, whether the modified file has ciphertext features or malicious program features is detected by the detection and arbitration program and then notified to the file system.
[0095] Alternatively, if Figure 5 As shown, the detection and arbitration program can immediately traverse the transparent cache area when the shadow file is modified, or periodically traverse the transparent cache area to perform ciphertext feature detection on the files in the transparent cache area (such as shadow files). When the files in the transparent cache area do not have ciphertext features, it is determined that the modified files have passed the security verification. Among them, the ciphertext feature detection can be based on a variety of methods such as the consistency of the ciphertext random entropy value to detect whether the file meets the ciphertext feature and improve the detection rate.
[0096] For example, when there is no ciphertext feature in the file in the transparent cache area and a preset threshold is reached, it is determined that the modified file passes the security verification and the application continues to run.
[0097] For another example, when the file in the transparent cache area has a ciphertext feature, it is determined that the modified file has not passed the security verification, the shadow file is stopped from being synchronized with the original file, and an alarm is notified. The alarm notification may be a voice, text, or image sent or displayed to the user for alarm. If the user confirms to continue the operation after receiving the alarm, the file system continues to execute the subsequent step 404 according to the user's instruction.
[0098] Alternatively, if Figure 6 As shown, the detection and arbitration program can traverse the transparent cache area to perform malicious program feature detection on files in the transparent cache area (such as shadow files). When the files in the transparent cache area do not have malicious program features, it is determined that the modified file passes the security verification.
[0099] For example, when the file in the transparent cache area does not have malicious program features, it is determined that the modified file passes the security verification and the application continues to run.
[0100] For another example, when a file in the transparent buffer area has malicious program features, it is determined that the modified file has not passed the security verification, and the malicious program is terminated and an alarm is notified. The alarm notification may be sent or displayed to the user as a voice, text or image alarm.
[0101] In some possible implementations, the detection and arbitration program can detect ciphertext features and malicious file features at the same time. The detection method is a combination of the above-mentioned ciphertext features and malicious program features, which will not be repeated here.
[0102] Step 404: The file system synchronizes the modified file to the protected area.
[0103] As a possible implementation manner, after determining that the modified file passes the security verification, the file system synchronizes the modified file to the original file in the protected area through sector links.
[0104] Based on the above data processing method, when the computing device performs security verification and other tests on the shadow file in the transparent cache area, the computing device can still perform operations such as access to the original file in the protected area, which will not block the reading and writing of the file and will not affect the normal operation of the file system. At the same time, the modification operation of the original file by the data operation request is redirected to the shadow file, and only the modified file that has passed the security verification can be synchronized to the original file in the protected area, thereby protecting the files in the protected area from being affected by malware. In this way, while blocking the harmful behavior of malware on the file, the file operation performance is improved.
[0105] Combination of the above Figure 4-Figure 6 The data processing method is described in general. Figure 7-Figure 11 In different file operation scenarios, the file system modifies the shadow file corresponding to the original file according to the data operation request to obtain the specific processing flow of the modified file.
[0106] like Figure 7 As shown, in the scenario of creating a new file, the file system obtains the data operation request sent by the application, and determines through a filter driver (such as a file filter driver) that the data operation request includes a new file operation. After the file system creates the original file at the path specified by the data operation request, it determines whether there is a shadow file corresponding to the original file (such as C:\dir\file). If there is a shadow file corresponding to the original file, the file system returns a message to the application that the file already exists. After the file system first determines whether the shadow file exists, it determines whether the original file exists. If the original file exists, the file system returns a message to the application that the file already exists. If the original file does not exist, the file system redirects the path of the new file to the path of the shadow file (such as C:\cached\dir\file, where cached represents a hidden whitelist folder, i.e., a transparent cache area), and the data of the new file is written to the shadow file.
[0107] The file system redirects the newly created file path to the path of the shadow file by mapping the file path of the original file to the file path of the shadow file. For example, the file system maps C:\dir\file to C:\cached\dir\file.
[0108] like Figure 8 As shown, in the file opening scenario, the file system obtains the data operation request sent by the application, and determines through a filter driver (such as a file filter driver) that the data operation request includes a file opening operation. When the shadow file corresponding to the original file exists, the file system opens the shadow file for access. When the shadow file corresponding to the original file does not exist, the file system opens the original file for access.
[0109] For example, the file system determines whether the shadow file corresponding to the original file exists based on the mapping method between the original file and the shadow file. For example, when the file path of the original file is C:\dir\file, it is determined whether the shadow file corresponding to the original file exists in the transparent cache area based on C:\cached\dir\file. If the shadow file corresponding to the original file exists in the transparent cache area, the file system opens the shadow file based on C:\cached\dir\file. If the shadow file corresponding to the original file does not exist in the transparent cache area, the file system opens the original file based on C:\dir\file and records the file handle for tracking.
[0110] like Fig. 9 As shown, in the file modification scenario, the file system obtains the data operation request sent by the application, and determines through the filter driver (such as the file filter driver) that the data operation request contains a modification operation. The file system redirects the modification operation to the shadow file by means of sector linking, that is, the sector corresponding to the existing data of the original file points to the shadow file, and sets the sector to read-only. In this way, when the file system performs a modification operation according to the data operation request, it will perform the modification operation on the shadow file. Among them, the sector pointed to by the original file can be a sector written by the filter driver (such as the disk filter driver) when the file system hook perceives the file modification.
[0111] For example, the file system performs a modification operation on an original file such as C:\dir\file according to a data operation request, and the file system determines whether a shadow file corresponding to the original file exists according to the mapping method between the original file and the shadow file. If the shadow file C:\cached\dir\file corresponding to the original file does not exist in the transparent cache area, the file system creates a shadow file corresponding to the original file and sets the sector corresponding to the original file to read-only. If the shadow file C:\cached\dir\file corresponding to the original file exists in the transparent cache area, the sector corresponding to the original file is set to read-only, and a new sector is created to save the new data generated by the modification operation, and the sector pointer of the shadow file is modified to point to the new sector.
[0112] In some possible embodiments, the modified file is a small file (eg, less than 1 byte) and does not have independent data sectors, so the file system directly copies the entire original file to the transparent cache as a new shadow file.
[0113] In some possible embodiments, the modified file is newly added data, and the file system stores the newly added data in a new sector corresponding to the shadow file.
[0114] In some possible embodiments, the modified file is a modification of the original file, and the file system performs copy-on-write (COW) to copy the original file to a new sector corresponding to the shadow file and then modify the data in the new sector.
[0115] like Fig.10 As shown, in the file deletion scenario, the file system obtains the data operation request sent by the application, and determines through a filter driver (such as a file filter driver) that the data operation request includes a file deletion operation. The file system performs a file deletion operation on the shadow file corresponding to the original file to obtain the modified file, and adds a mark to the original file and hides it. The mark is used to indicate that the original file has been deleted. When it is determined that the deleted file passes the security verification, for example, when the time threshold is reached after the operation, the file system performs a file deletion operation on the original file carrying the mark and clears the mark.
[0116] For example, the file system deletes the original file such as C:\dir\file according to the data operation request. The file system determines whether the shadow file corresponding to the original file exists according to the mapping method between the original file and the shadow file. If the shadow file C:\cached\dir\file corresponding to the original file exists in the transparent cache area, the file system deletes the shadow file corresponding to the original file. If the original file still exists after deleting the shadow file, the file system adds a mark to the original file and hides it. If the shadow file C:\cached\dir\file corresponding to the original file does not exist in the transparent cache area, determine whether the original file exists. If the original file exists, the file system adds a mark to the original file and hides it. If the original file does not exist, the file system fails to delete the original file.
[0117] like Fig.11 As shown, in the file moving scenario, the file system obtains the data operation request sent by the application, and determines through a filter driver (such as a file filter driver) that the data operation request includes a file moving operation. The file system performs a file moving operation on the shadow file corresponding to the original file, obtains the modified (moved) file, and adds a mark to the original file and hides it. The mark is used to indicate that the original file has been moved. When it is determined that the file has passed the security verification after the move, for example, when the time threshold is reached after the operation, the file system performs a deletion operation on the original file carrying the mark and clears the mark.
[0118] For example, the file system moves the original file such as C:\dir\file according to the data operation request, and the file system determines whether the shadow file corresponding to the original file exists according to the mapping method between the original file and the shadow file. If the shadow file C:\cached\dir\file corresponding to the original file exists in the transparent cache area, the file system moves the shadow file corresponding to the original file. If the original file still exists after the shadow file is moved, the file system adds a mark to the original file and hides it. If the shadow file C:\cached\dir\file corresponding to the original file does not exist in the transparent cache area, determine whether the original file exists. If the original file exists, the file system creates a shadow file after the move, adds a mark to the original file and hides it. If the original file does not exist, the file system fails to move the original file.
[0119] In order to cooperate with the above Figure 4 The present application also provides a data processing device 1200, which can be used to implement the above data processing method. Figure 4 The function of the service node in the data processing method shown in FIG. Fig.12 As shown, the data processing device 1200 includes a transceiver module 1210 and a processing module 1220 .
[0120] The transceiver module 1210 is used to obtain a data operation request from an application. For example, the transceiver module 1210 is used to perform the following steps: Figure 4 Step 401 is shown.
[0121] The processing module 1220 is used to modify the shadow file corresponding to the original file according to the data operation request to obtain the modified file when the data operation request includes the modification operation of the original file in the protected area. Figure 4 Step 402 is shown.
[0122] The processing module 1220 is also used to determine that the modified file passes the security verification and synchronize the modified file to the protected area. Figure 4 Step 403 is shown.
[0123] As a possible implementation manner, the processing module 1220 is specifically used for: when the data operation request includes a modification operation on the original file, redirecting the modification operation to the shadow file to modify the shadow file to obtain the modified file.
[0124] As a possible implementation manner, the processing module 1220 is specifically used to redirect the file path of the newly created file to the file path of the shadow file.
[0125] As a possible implementation manner, the modification operation includes file modification, and the processing module 1220 is specifically used to redirect the modification operation to the shadow file by means of sector linking.
[0126] As a possible implementation, the processing module 1220 is further used to: create a copy of the original file in the transparent cache area; the copy serves as a shadow file corresponding to the original file, and the sector pointer of the shadow file points to the original sector where the original file is located.
[0127] As a possible implementation manner, the processing module 1220 is specifically used to: create a new sector to store new data generated by the modification operation; and modify the sector pointer of the shadow file to point to the new sector.
[0128] As a possible implementation method, the modification operation includes deleting a file or moving a file, and the processing module 1220 is specifically used to: perform the operation of deleting a file or moving a file on the shadow file to obtain a modified file; add a mark to the original file; and when it is determined that the modified file passes the security verification, perform the operation of deleting a file or moving a file on the original file carrying the mark.
[0129] As a possible implementation method, the processing module 1220 is specifically used to: when the shadow file is modified, detect whether the modified file has ciphertext features or malicious program features; when the modified file does not have ciphertext features or malicious program features, determine that the modified file passes the security verification.
[0130] As a possible implementation, the processing module 1220 is specifically used to: when the modified file does not have ciphertext features or malicious program features and the time after the modification operation reaches a preset threshold, determine that the modified file passes the security verification.
[0131] Among them, the transceiver module 1210 and the processing module 1220 can be implemented by software or by hardware. Exemplarily, the implementation of the transceiver module 1210 is introduced below by taking the transceiver module 1210 as an example. Similarly, the implementation of the processing module 1220 can refer to the implementation of the transceiver module 1210.
[0132] As an example of a software functional unit, the transceiver module 1210 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above-mentioned computing instance may be one or more. For example, the transceiver module 1210 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region (region) or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including a data center or multiple data centers with similar geographical locations. Among them, usually a region may include multiple AZs.
[0133] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, a VPC is set up in a region. For cross-region communication between two VPCs in the same region and between VPCs in different regions, a communication gateway needs to be set up in each VPC to achieve interconnection between VPCs through the communication gateway.
[0134] As an example of a hardware functional unit, the transceiver module 1210 may include at least one computing device, such as a server, etc. Alternatively, the transceiver module 1210 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.
[0135] The multiple computing devices included in the transceiver module 1210 can be distributed in the same region or in different regions. The multiple computing devices included in the transceiver module 1210 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the transceiver module 1210 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0136] It should be noted that, in other embodiments, any module in the transceiver module 1210 or the processing module 1220 can be used to execute any step in the data processing method, and the steps that the transceiver module 1210 and the processing module 1220 are responsible for implementing can be specified as needed. The full functions of the data processing device 1200 can be realized by respectively implementing different steps in the data processing method through the transceiver module 1210 and the processing module 1220.
[0137] The present application also provides a computing device 1300. Fig.13 As shown, the computing device 1300 includes: a bus 1302, a processor 1304, a memory 1306, and a communication interface 1308. The processor 1304, the memory 1306, and the communication interface 1308 communicate through the bus 1302. The computing device 1300 can be a server or a terminal device. It should be understood that the present application does not limit the number of processors and memories in the computing device 1300.
[0138] The bus 1302 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.13 The bus 1302 may include a path for transmitting information between various components of the computing device 1300 (eg, the memory 1306, the processor 1304, and the communication interface 1308).
[0139] The processor 1304 may include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0140] The memory 1306 may include a volatile memory, such as a random access memory (RAM). The processor 1304 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0141] The memory 1306 stores executable program codes, and the processor 1304 executes the executable program codes to respectively implement the functions of the various modules included in the aforementioned data processing device 1200, thereby implementing the data processing method. That is, the memory 1306 stores instructions for executing the data processing method.
[0142] Alternatively, the memory 1306 stores executable codes, and the processor 1304 executes the executable codes to respectively implement the functions of the aforementioned service nodes, thereby implementing the data processing method. That is, the memory 1306 stores instructions for executing the data processing method.
[0143] The communication interface 1308 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1300 and other devices or communication networks.
[0144] Considering that the data processing method provided in the present application is applied to the distributed system 100, the respective infrastructures of the computing server cluster 110 and the storage server cluster 120 of the distributed system 100 usually include multiple computing devices. Therefore, the present application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop, a laptop, or a smart phone.
[0145] like Fig.14As shown, the computing device cluster includes at least one computing device 1300. The memory 1306 in one or more computing devices 1300 in the computing device cluster may store the same instructions for executing the data processing method.
[0146] In some possible implementations, the memory 1306 of one or more computing devices 1300 in the computing device cluster may also store partial instructions for executing the data processing method. In other words, the combination of one or more computing devices 1300 may jointly execute instructions for executing the data processing method.
[0147] It should be noted that the memory 1306 in different computing devices 1300 in the computing device cluster may store different instructions, which are respectively used to execute part of the functions of the data processing apparatus 1200. That is, the instructions stored in the memory 1306 in different computing devices 1300 may implement the functions of one or more modules included in the data processing apparatus 1200.
[0148] In some possible implementations, one or more computing devices in the computing device cluster may be connected via a network, which may be a wide area network or a local area network. Fig.15 A possible implementation is shown. Fig.15 As shown, two computing devices 1300A and 1300B are connected via a network. Specifically, the network is connected via a communication interface in each computing device. In this type of possible implementation, the memory 1306 in the computing device 1300A stores instructions for executing the functions of one or more modules in the transceiver module 1210 and the processing module 1220. Fig.15 In the example, the memory 1306 in the computing device 1300A stores instructions for executing the functions of the transceiver module 1210. Meanwhile, the memory 1306 in the computing device 1300B stores instructions for executing the functions of one or more modules in the transceiver module 1210 and the processing module 1220. Fig.15 In the example, the memory 1306 in the computing device 1300B stores instructions for executing the functions of the processing module 1220.
[0149] It should be understood that Fig.15 The functions of the computing device 1300A shown in FIG. 1300A may also be completed by multiple computing devices 1300. Similarly, the functions of the computing device 1300B may also be completed by multiple computing devices 1300.
[0150] The present application also provides a computer program product including instructions. The computer program product may be software or a program product including instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device executes the following steps: Figure 4 The data processing method shown, or Figure 4 The steps performed by the service node in the data processing method shown.
[0151] The present application also provides a computer-readable storage medium. The computer-readable storage medium may be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk). The computer-readable storage medium includes instructions that instruct the computing device to store data such as Figure 4 The data processing method shown.
[0152] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state hard disk.
[0153] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0154] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0155] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0156] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0157] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0158] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory, a random access memory, a magnetic disk, or an optical disk.
[0159] In the present application, "at least one" means one or more, and "plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b and c can be single or multiple.
[0160] It should be noted that, in this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in this application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.
[0161] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.
Claims
1. A data processing method, characterized in that: The file system of the host includes a protected area and a transparent cache area, the protected area is used to store original files, the transparent cache area is used to store shadow files, and the shadow files are copies of the original files. The method includes: Acquire a data operation request sent by an application, wherein the data operation request includes a modification operation on an original file in the protected area; Modify the shadow file corresponding to the original file according to the data operation request to obtain a modified file; Determine that the modified file passes the security verification, and synchronize the modified file to the protected area.
2. The method according to claim 1, characterized in that: The step of modifying the shadow file corresponding to the original file according to the data operation request to obtain a modified file includes: The modification operation is redirected to the shadow file to modify the shadow file and obtain the modified file.
3. The method according to claim 2, characterized in that The redirecting the modification operation to the shadow file comprises: The modification operation is redirected to the shadow file by means of sector linking.
4. The method according to claim 3, characterized in that Before redirecting the modification operation to the shadow file by means of sector linking, the method further includes: A copy of the original file is created in the transparent cache area; the copy is a shadow file corresponding to the original file, and a sector pointer of the shadow file points to an original sector where the original file is located.
5. The method according to claim 4, characterized in that The step of redirecting the modification operation to the shadow file by means of sector linking includes: Creating a new sector to store new data generated by the modification operation; The sector pointer of the shadow file is modified to point to the new sector.
6. The method according to any one of claims 1 to 5, characterized in that The data operation request includes a new file operation, and the method further includes: Redirect the file path of the newly created file to the file path of the shadow file.
7. The method according to any one of claims 1 to 6, characterized in that The data operation request includes an open file operation, and the method further includes: When a corresponding shadow file exists for the original file, open the shadow file.
8. The method according to any one of claims 1 to 7, characterized in that The data operation request includes a file deletion operation or a file move operation, and the method further includes: Performing an operation of deleting or moving a file on the shadow file; Adding a mark to the original file; When it is determined that the modified file passes the security verification, an operation of deleting or moving the file is performed on the original file carrying the mark.
9. The method according to any one of claims 1 to 8, characterized in that Determining that the modified file passes the security verification includes: When the shadow file is modified, detecting whether the modified file has ciphertext features or malicious program features; When the modified file does not have a ciphertext feature or a malicious program feature, it is determined that the modified file passes the security verification.
10. The method according to claim 9, characterized in that When the modified file does not have a ciphertext feature or a malicious program feature, determining that the modified file passes the security verification includes: When the modified file does not have a ciphertext feature or a malicious program feature, and the time after the modification operation is performed reaches a preset threshold, it is determined that the modified file passes the security verification.
11. A data processing device, characterized in that: include: The transceiver module is used to obtain a data operation request sent by an application program, wherein the data operation request includes a modification operation on an original file in the protected area; A processing module, used for modifying the shadow file corresponding to the original file according to the data operation request to obtain a modified file; The processing module is further used to determine that the modified file passes the security verification and synchronize the modified file to the protected area.
12. A computing device, characterized in that: including a processor and a memory; The processor is configured to execute instructions stored in the memory, so that the computing device performs the method according to any one of claims 1 to 10.
13. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device, the computing device is caused to perform the method according to any one of claims 1 to 10.
14. A computer-readable storage medium, characterized in that: The method comprises computer program instructions, and when the computer program instructions are executed by a computing device, the computing device performs the method according to any one of claims 1 to 10.