Malicious software detection method and device and electronic equipment

By adopting multi-layer collaborative detection methods in the cloud edge end system, using the collaborative work of cloud center, cloud edge and terminal nodes, the problems of delay and inefficiency of malware detection in the existing technology are solved, and faster and more efficient malware detection is achieved.

CN120074848APending Publication Date: 2025-05-30HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311632098.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing malware detection system uses cloud systems to detect malware at terminals with high latency, resulting in low detection efficiency.

Method used

A multi-layer collaborative detection method based on cloud edge is adopted to receive target requests sent by cloud edge nodes through cloud center nodes, and to detect whether the software is malware based on the target processing strategy and target numerical value. Cloud edge nodes deploy malicious file sub-databases and sub-detection engines, terminal nodes perform preliminary detection and defense actions, and cloud center nodes provide multi-engine architecture for complete detection.

Benefits of technology

It reduces the delay in malware detection, improves detection efficiency, enhances the availability of the overall system, and solves the problem of inefficient detection caused by cloud detection delay.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074848A_ABST
    Figure CN120074848A_ABST
Patent Text Reader

Abstract

The invention discloses a malicious software detection method and device and electronic equipment. The method comprises the steps that a target request sent by a cloud edge node is received through a cloud center node, the target request at least comprises a target processing strategy and a target value, the target processing strategy is one of a detection strategy and a defense strategy, software states corresponding to the detection strategy and the defense strategy are different, and software states corresponding to the defense strategy are different. The target numerical value is used for identifying a software file of software; and detecting whether the software is malicious software or not according to the target processing strategy and the target numerical value to obtain a target detection result. According to the method and the device, the technical problem of relatively low detection efficiency of the malicious software caused by relatively high delay when the malicious software of the terminal is detected through a cloud system in related technologies is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cloud security technology. Specifically, it relates to a method, device, and electronic device for detecting malicious software. Background Art

[0002] The cloud security center scans a large number of software files on the cloud and user terminals outside the cloud and detects their contents. After these files are collected from the user terminal server, they need to be reported across private networks, across regional networks, and uploaded to the cloud center for storage. The entire malicious software detection process is long and complex. A failure at any node may cause the entire service to be unavailable. In the file detection scenario, a large number of files will be sent to the cloud center for processing. The cloud center undertakes a large amount of traffic such as data transmission, software detection, and result storage, and has a relatively high probability of failure. Moreover, the buffer space during a failure is very small.

[0003] Currently, existing malicious software detection systems are generally terminal detection (such as antivirus software detection) and cloud detection. Terminal detection completes the detection logic locally, including file collection, detection, alarm, and killing, etc., which has little to do with cloud computing and has the characteristics of low latency and low cost. However, its detection ability is poor and it cannot effectively utilize the powerful computing power of the cloud to complete high-precision malicious software killing. Pure centralized cloud detection is simple to use and has high accuracy. However, it requires a large amount of data transmission and multiple cross-network interactions between multiple regions, resulting in low timeliness and high latency, which leads to low detection efficiency of malicious software. Moreover, in the scenario of software startup defense, the latency from when the malicious software is collected by the client to when the console alarms is at least several hundred milliseconds. The client will pause the startup of the process for several hundred milliseconds or even several seconds until it is confirmed that the process is harmless before allowing it to continue running. This latency may cause failures when the timeliness of user services is more sensitive.

[0004] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention

[0005] Embodiments of this application provide a method, device, and electronic device for detecting malicious software, so as to at least solve the technical problem in the related art that detecting malicious software on a terminal through a cloud system has a high latency, resulting in low detection efficiency of malicious software.

[0006] According to one aspect of the embodiments of the present application, a method for detecting malware is provided, including: receiving, by a cloud center node, a target request sent by a cloud edge node, where the target request includes at least a target processing policy and a target value, the target processing policy is one of the following: a detection policy, a defense policy, the software states corresponding to the detection policy and the defense policy are different, and the target value is used to identify the software file of the software; detecting whether the software is malware according to the target processing policy and the target value, and obtaining a target detection result.

[0007] Further, a malicious file library and multiple detection engines are deployed in the cloud center node. When the target processing policy is the detection policy, detecting whether the software is malware according to the target processing policy and the target value, and obtaining a target detection result includes: matching according to the target value in the malicious file library to obtain a first matching result; if the first matching result is that there is a record in the malicious file library that is the same as the target value, determining the target detection result according to the record detection result included in the record; if the first matching result is that there is no record in the malicious file library that is the same as the target value, receiving the software file uploaded by the cloud edge node, and detecting the content of the software file through multiple detection engines to obtain multiple detection results, and determining the target detection result according to the multiple detection results.

[0008] Further, a malicious file library and multiple detection engines are deployed in the cloud center node. When the target processing policy is the defense policy, detecting whether the software is malware according to the target processing policy and the target value, and obtaining a target detection result includes: matching according to the target value in the malicious file library to obtain a second matching result; if the second matching result is that there is a record in the malicious file library that is the same as the target value, determining the target detection result according to the record detection result included in the record; if the second matching result is that there is no record in the malicious file library that is the same as the target value, notifying the cloud edge node to release the suspension of the startup process of the software, receiving the software file uploaded by the cloud edge node, asynchronously detecting the content of the software file through multiple detection engines to obtain multiple detection results, and determining the target detection result according to the multiple detection results.

[0009] Further, when the target processing policy is the detection policy, after detecting whether the software is malware according to the target processing policy and the target value and obtaining a target detection result, the method further includes: if the target detection result is that the software is malware, generating an alarm message according to the file information of the software and sending the alarm message to the console; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, storing the target value and the target detection result in the malicious file library, and sending the target detection result to the cloud edge node.

[0010] Further, in the case where the target processing policy is a defense policy, after detecting whether the software is malware based on the target processing policy and the target value to obtain a target detection result, the method further includes: if the target detection result indicates that the software is malware, then end the startup process to prohibit the software from starting; if the target detection result indicates that the software is malware or the target detection result indicates that the software is non-malware, then store the target value and the target detection result in the malicious file library, and send the target detection result to the cloud edge node.

[0011] According to an aspect of an embodiment of the present application, there is also provided a method for detecting malware, including: receiving, by a cloud edge node, a first request sent by a terminal node, where the first request at least includes a target processing policy and a target value, the target processing policy is one of the following: a detection policy, a defense policy, the software states corresponding to the detection policy and the defense policy are different, and the target value is used to identify the software file of the software; detecting whether the software is malware based on the target processing policy and the target value to obtain a first detection result; in the case where the first detection result indicates that it is impossible to determine whether the software is malware, sending a target request to a cloud center node to receive a target detection result returned by the cloud center node.

[0012] Further, the cloud edge node is deployed with a malicious file sub-database and a sub-detection engine. In the case where the target processing policy is a detection policy, detecting whether the software is malware based on the target processing policy and the target value to obtain a first detection result includes: performing a match in the malicious file sub-database based on the target value to obtain a third match result; if the third match result is that there is a record in the malicious file sub-database that is the same as the target value, then determining the first detection result based on the record detection result included in the record; if the third match result is that there is no record in the malicious file sub-database that is the same as the target value, then receiving the software file uploaded by the terminal node, and detecting the content of the software file through the sub-detection engine. In the case where the sub-detection engine is unable to determine whether there is malicious behavior in the content of the software file, taking it as the first detection result that it is impossible to determine whether the software is malware.

[0013] Further, the cloud edge node is deployed with a malicious file sub-database. In the case where the target processing policy is a defense policy, detecting whether the software is malware based on the target processing policy and the target value to obtain a first detection result includes: performing a match in the malicious file sub-database based on the target value to obtain a fourth match result; if the fourth match result is that there is a record in the malicious file sub-database that is the same as the target value, then determining the first detection result based on the record detection result included in the record; if the fourth match result is that there is no record in the malicious file sub-database that is the same as the target value, then taking it as the first detection result that it is impossible to determine whether the software is malware.

[0014] According to another aspect of the embodiments of the present application, there is also provided a malware detection device, including: a first receiving unit, configured to receive a target request sent by a cloud edge node through a cloud center node, where the target request at least includes a target processing policy and a target value, the target processing policy is one of the following: a detection policy, a defense policy, the software states corresponding to the detection policy and the defense policy are different, and the target value is used to identify the software file of the software; a first determination unit, configured to detect whether the software is malware according to the target processing policy and the target value, and obtain a target detection result.

[0015] Further, a malicious file library and a plurality of detection engines are deployed in the cloud center node. When the target processing policy is a detection policy, the first determination unit includes: a first matching subunit, configured to perform a match in the malicious file library according to the target value to obtain a first matching result; a first determination subunit, configured to, if the first matching result is that there is a record in the malicious file library that is the same as the target value, determine the target detection result according to the record detection result included in the record; a second determination subunit, configured to, if the first matching result is that there is no record in the malicious file library that is the same as the target value, receive the software file uploaded by the cloud edge node, and detect the content of the software file through the plurality of detection engines to obtain a plurality of detection results, and determine the target detection result according to the plurality of detection results.

[0016] Further, a malicious file library and a plurality of detection engines are deployed in the cloud center node. When the target processing policy is a defense policy, the first determination unit includes: a second matching subunit, configured to perform a match in the malicious file library according to the target value to obtain a second matching result; a third determination subunit, configured to, if the second matching result is that there is a record in the malicious file library that is the same as the target value, determine the target detection result according to the record detection result included in the record; a fourth determination subunit, configured to, if the second matching result is that there is no record in the malicious file library that is the same as the target value, notify the cloud edge node to release the suspension of the startup process of the software, receive the software file uploaded by the cloud edge node, asynchronously detect the content of the software file through the plurality of detection engines to obtain a plurality of detection results, and determine the target detection result according to the plurality of detection results.

[0017] Further, the device further includes: a first processing unit, configured to, when the target processing policy is a detection policy, after detecting whether the software is malware according to the target processing policy and the target value and obtaining a target detection result, if the target detection result is that the software is malware, generate an alarm message according to the file information of the software, and send the alarm message to the console; a second processing unit, configured to, if the target detection result is that the software is malware or the target detection result is that the software is not malware, store the target value and the target detection result in the malicious file library, and send the target detection result to the cloud edge node.

[0018] Further, the device further includes: a third processing unit, configured to, when the target processing strategy is a defense strategy, after detecting whether the software is malware according to the target processing strategy and the target value to obtain a target detection result, if the target detection result indicates that the software is malware, end the startup process to prohibit the software from starting; a fourth processing unit, configured to, if the target detection result indicates that the software is malware or the target detection result indicates that the software is non-malware, store the target value and the target detection result in the malicious file library, and send the target detection result to the cloud edge node.

[0019] According to another aspect of the embodiments of the present application, there is also provided a malware detection device, including: a second receiving unit, configured to receive a first request sent by a terminal node through a cloud edge node, where the first request at least includes a target processing strategy and a target value, the target processing strategy is one of the following: a detection strategy, a defense strategy, the software states corresponding to the detection strategy and the defense strategy are different, and the target value is used to identify the software file of the software; a second determination unit, configured to detect whether the software is malware according to the target processing strategy and the target value to obtain a first detection result; a first sending unit, configured to, when the first detection result indicates that it is impossible to determine whether the software is malware, send a target request to a cloud center node to receive a target detection result returned by the cloud center node.

[0020] Further, a malicious file sub-database and a sub-detection engine are deployed on the cloud edge node. When the target processing strategy is a detection strategy, the second determination unit includes: a third matching subunit, configured to perform a match in the malicious file sub-database according to the target value to obtain a third matching result; a fifth determination subunit, configured to, if the third matching result indicates that there is a record in the malicious file sub-database that is the same as the target value, determine the first detection result according to the record detection result included in the record; a sixth determination subunit, configured to, if the third matching result indicates that there is no record in the malicious file sub-database that is the same as the target value, receive the software file uploaded by the terminal node, and detect the content of the software file through the sub-detection engine. When the sub-detection engine is unable to determine whether there is a malicious behavior in the content of the software file, use that it is impossible to determine whether the software is malware as the first detection result.

[0021] Furthermore, a malicious file sub-database is deployed on the cloud edge node. When the target processing policy is a defense policy, the second determination unit includes: a fourth matching subunit, configured to perform matching in the malicious file sub-database according to the target value to obtain a fourth matching result; a seventh determination subunit, configured to, if the fourth matching result indicates that there is a record in the malicious file sub-database that is the same as the target value, determine a first detection result according to the record detection result included in the record; an eighth determination subunit, configured to, if the fourth matching result indicates that there is no record in the malicious file sub-database that is the same as the target value, use "unable to determine whether the software is malicious software" as the first detection result.

[0022] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium storing a program, wherein when the program runs, it controls the device where the storage medium is located to execute the malicious software detection method described in any one of the above.

[0023] According to another aspect of the embodiments of the present invention, there is also provided an electronic device, including: a memory storing an executable program; a processor configured to run the program, wherein when the program runs, it executes the malicious software detection method described in any one of the above.

[0024] In the embodiments of the present application, a multi-layer collaboration method based on the cloud-edge-terminal (cloud center-cloud edge-terminal) is adopted for malicious software detection and defense. The cloud center node receives a target request sent by the cloud edge node, where the target request at least includes a target processing policy and a target value. The target processing policy is one of the following: a detection policy and a defense policy. The software states corresponding to the detection policy and the defense policy are different. The target value is used to identify the software file of the software. Whether the software is malicious software is detected according to the target processing policy and the target value to obtain a target detection result. The cloud edge node receives a first request sent by the terminal node, where the first request at least includes a target processing policy and a target value; whether the software is malicious software is detected according to the target processing policy and the target value to obtain a first detection result; when the first detection result indicates that it is unable to determine whether the software is malicious software, a target request is sent to the cloud center node to receive the target detection result returned by the cloud center node.

[0025] In summary, based on the multi-layer collaboration of the cloud-edge-terminal (cloud center-cloud edge-terminal), malware detection and defense are carried out. The proximal advantage of the terminal is utilized to perform detection and acquisition tasks that do not consume performance, completing the first layer of protection with low latency and low cost. The rules sent to the terminal can identify basic malware behaviors and directly generate alarms and software startup interception actions, thus avoiding a large amount of data transmission. Then, the software detection results are cached in cloud edge nodes at different levels, and a single engine with only partial detection rules is deployed. File comparison is performed in the cloud edge nodes, and then a multi-engine architecture is adopted in the cloud center to provide relatively complete detection capabilities. The files reported to the cloud center are detected, and the results are synchronized to the cloud edge nodes to enhance the filtering ability of the cloud edge nodes, achieving the purpose of reducing the latency of requests and enhancing the overall availability through the multi-layer collaboration of the cloud-edge-terminal. Thus, the technical effect of reducing latency and improving the detection efficiency of malware is achieved, and furthermore, the technical problem in the related art that detecting malware on the terminal through the cloud system has a high latency, resulting in a low detection efficiency of malware, is solved. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0027] Figure 1 is a schematic diagram of a computer terminal provided in Embodiment 1 of the present application;

[0028] Figure 2 is a flowchart of a method for detecting malware provided in Embodiment 1 of the present application;

[0029] Figure 3 is a schematic diagram of an optional architecture of a malware detection and defense system provided in Embodiment 1 of the present application;

[0030] Figure 4 is a flowchart of a method for detecting malware provided in Embodiment 2 of the present application;

[0031] Figure 5 is a schematic diagram of a malware detection device provided in Embodiment 3 of the present application;

[0032] Figure 6 is a schematic diagram of a malware detection device provided in Embodiment 4 of the present application;

[0033] Figure 7 is a schematic diagram of a computing terminal provided in Embodiment 5 of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0034] In order to enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0035] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products, or devices.

[0036] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. And the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards in the relevant regions, and corresponding operation entrances are provided for users to choose to authorize or refuse.

[0037] Embodiment 1

[0038] According to the embodiments of this application, a method for detecting malware is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described here can be executed in a different order from here.

[0039] The method embodiment provided in the first embodiment of this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing the method for detecting malware is shown. As Figure 1As shown, the computer terminal (or mobile device) 10 may include a set of processors 102 (the set of processors 102 may include, but is not limited to, processing devices such as a microcontroller unit (MCU) or a field programmable gate array (FPGA), and the set of processors 102 may include a set of processors, Figure 1 which are shown as 102a, 102b, ……, 102n), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown, or have a different configuration from Figure 1 that shown.

[0040] It should be noted that the above one or more processors 102 and / or other data processing circuits may generally be referred to as "data processing circuits" herein. The data processing circuit may be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuit may be a single independent processing module, or be incorporated in whole or in part into any one of other elements in the computer terminal 10 (or mobile device).

[0041] The memory 104 may be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the malware detection method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned malware detection method. The memory 104 may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories may be connected to the computer terminal 10 through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0042] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0043] The display can be, for example, a touch-screen Liquid Crystal Display (LCD), which enables the user to interact with the user interface of the computer terminal 10 (or mobile device).

[0044] The cloud security center scans a large number of software files on the cloud and user terminals outside the cloud and detects their contents. After these files are collected from the user terminal server, they need to be reported and uploaded across private networks, across regional networks, and then saved in the cloud center. The entire malicious software detection process is long and complex, and a failure of any node at any location may cause the entire service to be unavailable. In the file detection scenario, a large number of files will be sent to the cloud center for processing. The cloud center undertakes a large amount of traffic such as data transmission, software detection, and result saving, and the probability of failure is relatively high. Moreover, the buffer space is very small when a failure occurs.

[0045] Currently, existing malicious software detection systems are generally terminal detection (such as antivirus software detection) and cloud detection. Terminal detection completes the detection logic locally, including file collection, detection, alarm, and killing, etc., which has little to do with cloud computing and has the characteristics of low latency and low cost. However, its detection ability is poor and it cannot effectively utilize the powerful computing power of the cloud to complete high-precision malicious software killing. Pure centralized cloud detection is simple to use and has high accuracy. However, it requires a large amount of data transmission and multiple cross-network interactions between multiple regions, resulting in low timeliness and high latency, which leads to low detection efficiency of malicious software. Moreover, in the scenario of software startup defense, the latency from when the malicious software is collected by the client to when the console alarms is at least several hundred milliseconds at the shortest. The client will pause the startup of the process for several hundred milliseconds or even several seconds until it is confirmed that the process is harmless before allowing it to continue running. This latency may cause failures when the timeliness of user services is relatively sensitive.

[0046] Against the above technical background, the present application provides a malicious software detection method as Figure 2 shown. Figure 2 is a flowchart of the malicious software detection method provided by Embodiment 1 of the present application. The method includes:

[0047] Step S201, receive a target request sent by a cloud edge node through a cloud center node, where the target request includes at least a target processing policy and a target value. The target processing policy is one of the following: a detection policy and a defense policy. The software states corresponding to the detection policy and the defense policy are different. The target value is used to identify the software file of the software.

[0048] In an alternative embodiment, determine the software state of the software through the terminal engine of the terminal node, and determine the target processing policy for the software based on the software state. The software state is one of the following: an unstarted state and a started state.

[0049] The terminal engine is deployed on the terminal. The response time is relatively fast but the ability is weak. It can perform simple matching behaviors. For example, it can match according to the regular expression content in the detection rule and the file content. If there is a specified content in the file content that is the same as the regular expression content, it can be determined whether the file is malicious or non-malicious.

[0050] Regularly collect file information on the disk through the terminal engine of the terminal node for detection, or perform defense when it is detected that any software has actions such as writing to the disk or starting. Therefore, first determine the current state of the software through the terminal engine of the terminal node, so as to determine whether to detect or defend the software. For example, when the software state is the unstarted state, use the detection policy as the target processing policy and perform corresponding detection processes, including identifying basic malicious software behaviors through rules sent to the terminal, matching according to the cached software detection results at the cloud edge node and detecting through a single engine, matching according to the cached software detection results at the cloud center node and detecting through multiple engines, etc.; when the software state is the started state, use the defense policy as the target processing policy and perform corresponding defense processes, including pausing the software startup, matching layer by layer upwards whether there is a record of malicious software in the malicious file library. If there is and the record is a black software, perform specific operations to prohibit the software from starting and kill the process. If not, release the software startup and asynchronously initiate a comprehensive detection of the software file content, etc.

[0051] In an alternative embodiment, the terminal engine detects whether the software is malicious software according to the target processing policy. For example, it matches the regular expression content in the detection rule with the file content. If the specified content identical to the regular expression content does not exist in the file content, it is impossible to determine whether the software is malicious software, and the inability to determine whether the software is malicious software is taken as the detection result. In this case (the detection result indicates that it is impossible to determine whether the software is malicious software), the cloud edge node can detect whether the software is malicious software according to the target processing policy. The cloud edge node deploys a malicious file sub-database and a simplified single engine (i.e., a sub-detection engine), with a response time and detection ability in the middle, which is used to quickly respond to the on-device requests in this area. For example, the cloud edge node can match according to the software detection result in the malicious file sub-database, or can detect through the single engine to obtain a first detection result. Among them, the single engine detection can be to match using multiple regular expressions, or can be to use a simple malicious software recognition model, which is not limited here.

[0052] In the case where the first detection result indicates that it is impossible to determine whether the software is malicious software, the cloud edge node sends a target request to the cloud center node. Therefore, the cloud center node receives the target request sent by the cloud edge node. Among them, the target request at least includes the target processing policy (i.e., whether to detect or defend the software) and the target value. The target value can be the sha256 hash value of the software file calculated by the secure hash algorithm, or the MD5 value calculated by the message digest algorithm, etc., which is not limited here.

[0053] It should be noted that in the embodiments of the present application, the software file refers to the folder of the software in the terminal. The software file content can be the content in the folder (such as multiple files with suffixes), and the file information can be information such as file size and file path.

[0054] Step S202, detect whether the software is malicious software according to the target processing policy and the target value to obtain a target detection result.

[0055] In the case where the first detection result indicates that it is impossible to determine whether the software is malicious software, that is, when the cloud edge node cannot determine whether the software is malicious software, the cloud center node detects whether the software is malicious software according to the target processing policy and the target value to obtain a target detection result. Among them, the cloud center node deploys a malicious file library and multiple detection engines.

[0056] The cloud center node is responsible for saving the complete malicious file library, deploying the multi-engine platform on the cloud, and deploying multiple detection engines. When the cloud edge node and the terminal node cannot determine the result, the software detection and defense will be executed by the cloud center node to obtain the target detection result, that is, whether the software is malicious software or non-malicious software. The response time of the cloud center node is longer than that of the terminal node and the cloud edge node, but the detection ability is stronger. Among them, the malicious file library records the software file identifier (i.e., the target value) and the detection result corresponding to the file identifier (black or white, that is, malicious software or non-malicious software). The software file identifier can be the sha256 hash value of the software file calculated by the secure hash algorithm, or the MD5 value calculated by the message digest algorithm, etc., which is not limited here.

[0057] In this solution, malicious software detection and defense are carried out based on the multi-layer collaboration of the cloud-edge-terminal (cloud center-cloud edge-terminal). The proximal advantage of the terminal is used to perform detection and acquisition work that does not consume performance, completing the first layer of protection with low latency and low cost. The rules sent to the terminal can identify basic malicious software behaviors and directly generate alarms and software startup interception actions, thus avoiding a large amount of data transmission. Then, the software detection results are cached for different levels of cloud edge nodes, and a single engine with only partial detection rules is deployed to perform file comparison in the cloud edge node. Then, a multi-engine architecture is adopted in the cloud center to provide relatively complete detection capabilities, detect the files reported to the cloud center, and synchronize the results to the cloud edge node to enhance the filtering ability of the cloud edge node.

[0058] In an alternative embodiment, the Figure 3 shown schematic diagram can be adopted to implement the detection and defense of malicious software. As Figure 3As shown in the figure, this solution designs a system that reduces the latency of requests and enhances the overall availability through multi-layer collaboration between the cloud, edge, and terminal in the scenario of malicious software detection and defense on user terminals. Malicious software detection and defense are carried out based on cloud-edge-terminal collaboration. The overall architecture is a multi-level architecture of terminal-cloud edge-cloud center. The cloud center node distributes some detection rules to the cloud edge node, and the cloud edge node distributes a small part of the detection rules (i.e., on-terminal detection rules) to the terminal node. The malicious file library of the cloud center node distributes the detection results to the malicious file library of the cloud edge node (i.e., the malicious file sub-database). Utilize the proximal advantage of the client to perform detection and acquisition work that does not consume performance, achieve the first layer of protection with low latency and low cost through the client, be able to identify basic malicious software behaviors through the rules distributed to the terminal, and directly generate alarms and software startup interception actions, thus avoiding a large amount of data transmission; then cache the software detection results for different levels of cloud edge nodes, and deploy a single engine containing some detection rules to perform file comparison and preliminary screening in the cloud edge node, screening out most duplicate software detection requests, thus avoiding duplicate detection of the same software and improving the detection efficiency; the system adopts a multi-engine architecture in the cloud center (for example, including a sandbox engine, a deep learning engine, etc.), providing complete detection capabilities, being able to detect the files reported to the cloud center, and synchronize the results to the cloud edge node to enhance the filtering ability of the cloud edge node.

[0059] Optionally, the defense action is a synchronization operation within a short period, initiated by the terminal engine when the software starts. The terminal engine will first pause the software startup, and layer by layer match upwards whether there is a record of malicious software in the malicious file library. If there is and the record is for a blacklisted software, prohibit startup and kill the process. If not, allow the software to start and asynchronously initiate a comprehensive detection of the software content. When performing asynchronous detection, it is also layer by layer. When unable to draw a conclusion due to detection capacity limitations at this layer, send a detection request upwards until a result is obtained, and put the result into the malicious file library as the basis for the next detection and defense. For example, the file detection and process defense functions of the cloud security center can use the multi-layer architecture of cloud-edge-terminal in this solution.

[0060] In order to accurately determine whether software is malware, in the malware detection method provided in Embodiment 1 of this application, a malicious file library and multiple detection engines are deployed on the cloud center node. When the target processing policy is the detection policy, it is determined whether the software is malware according to the target processing policy and the target value, and the target detection result is obtained, including: matching according to the target value in the malicious file library to obtain the first matching result; if the first matching result is that there is a record in the malicious file library that is the same as the target value, then determine the target detection result according to the record detection result included in the record; if the first matching result is that there is no record in the malicious file library that is the same as the target value, then receive the software file uploaded by the cloud edge node, and detect the content of the software file through multiple detection engines to obtain multiple detection results, and determine the target detection result according to the multiple detection results.

[0061] Since the cloud center node has complete detection capabilities, including a complete malicious file library and detection engines, when the cloud edge engine cannot determine whether the software is malware, the cloud center node can detect whether the software is malware according to the target processing policy and the target value to obtain the target detection result. Optionally, the cloud center node matches according to the target value in the malicious file library to obtain the first matching result. For example, the cloud center node parses the basic information and sha256 identifier (i.e., the target value) of the file according to the target request and matches it in the malicious file library. If found, the result is directly returned; otherwise, the file content needs to be detected.

[0062] Optionally, if the first matching result is that there is a record in the malicious file library that is the same as the target value, then determine the target detection result according to the record detection result included in the record. For example, after matching according to the sha256 identifier in the malicious file library, if there is a record in the malicious file library that is the same as the sha256 identifier, that is, there is a sha256 identifier that is the same as this sha256 identifier and the corresponding detection result (i.e., the record detection result), then the target detection result can be determined according to the record detection result. For example, if the record detection result is that this sha256 identifier is malware, then determine that the target detection result is that this software is malware; if the record detection result is that this sha256 identifier is non-malware, then determine that the target detection result is that this software is non-malware.

[0063] Optionally, if there is no record in the malicious file library that matches the target value for the first matching result, the software file uploaded by the cloud edge node is received, and the content of the software file is detected by multiple detection engines to obtain multiple detection results, and the target detection result is determined based on the multiple detection results. For example, after matching in the malicious file library according to the sha256 identifier, if there is no record in the malicious file library that matches the sha256 identifier, the software file uploaded by the cloud edge node is received. The cloud center node uses a multi-engine architecture to improve the detection ability. By detecting whether the content of the software file is malicious through multiple detection engines, multiple detection results can be obtained. By setting priorities and score ratios for the detection engines (such as sandbox engines, machine learning engines, taint engines, etc.), the results of multiple engines can be combined to determine whether this software is malicious and the probability of it being malicious software, and the target detection result is obtained.

[0064] It should be noted that in the cloud center, a multi-engine architecture (such as a sandbox engine, a deep learning engine, etc.) is adopted to provide complete detection capabilities, which can detect the files reported to the cloud center and synchronize the results to the cloud edge node, enhancing the filtering ability of the cloud edge node and improving the detection accuracy.

[0065] In order to accurately determine whether the software is malicious software, in the malicious software detection method provided in Embodiment 1 of this application, the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is a defense strategy, it is detected whether the software is malicious software according to the target processing strategy and the target value to obtain the target detection result, including: matching according to the target value in the malicious file library to obtain a second matching result; if the second matching result is that there is a record in the malicious file library that matches the target value, the target detection result is determined according to the record detection result included in the record; if the second matching result is that there is no record in the malicious file library that matches the target value, the cloud edge node is notified to release the suspension of the startup process of the software, and the software file uploaded by the cloud edge node is received, and the content of the software file is asynchronously detected by multiple detection engines to obtain multiple detection results, and the target detection result is determined based on the multiple detection results.

[0066] Optionally, since the cloud center node includes a complete malicious file library, in the case where the cloud edge engine cannot determine whether the software is malicious software, the cloud center node can detect whether the software is malicious software according to the target processing strategy and the target value to obtain the target detection result. Optionally, the cloud center node matches according to the target value in the malicious file library to obtain a second matching result. For example, the cloud center node parses the basic information and sha256 identifier (i.e., the target value) of the file according to the target request and matches in the malicious file library.

[0067] Optionally, if there is a record in the malicious file library that is the same as the target value in the second matching result, determine the target detection result based on the record detection result included in the record. For example, after matching based on the sha256 identifier in the malicious file library, if there is a record in the malicious file library that is the same as the sha256 identifier, that is, there is a sha256 identifier that is the same as the sha256 identifier and the corresponding detection result (i.e., the record detection result), then the target detection result can be determined based on the record detection result. For example, if the record detection result is that the sha256 identifier is malware, determine that the target detection result is that the software is malware; if the record detection result is that the sha256 identifier is non-malware, determine that the target detection result is that the software is non-malware. Optionally, if found, directly return the result.

[0068] Optionally, if there is no record in the malicious file library that is the same as the target value in the second matching result, notify the cloud edge node to release the suspension of the software startup process, and receive the software file uploaded by the cloud edge node. Asynchronously detect the content of the software file through multiple detection engines to obtain multiple detection results, and determine the target detection result based on the multiple detection results. For example, after matching based on the sha256 identifier in the malicious file library, if there is no record in the malicious file library that is the same as the sha256 identifier, release the suspension of the file on the device to avoid affecting the user's real process, and then asynchronously initiate a comprehensive detection of the software content, transfer the file from the device to the cloud. For example, detect whether the software content is malicious in the local single engine of the cloud edge node. If the edge detection engine can obtain a clear result, the detection ends; otherwise, continue to report the detection request to the cloud center node. The cloud center node detects whether the software file content is malicious through multiple detection engines, and multiple detection results can be obtained. By setting priorities and score ratios for the detection engines (such as sandbox engines, machine learning engines, taint engines, etc.), the results of multiple engines can be combined to determine whether this software is malicious and the probability that it is malware, and obtain the target detection result.

[0069] It should be noted that when the software starts, the terminal engine first suspends the software startup, and matches layer by layer upwards whether there are records of malware in the malicious file library. If there are and the record is a black software, prohibit the startup and kill the process. If not, release the software startup and asynchronously initiate a comprehensive detection of the software content. When performing asynchronous detection, it is also layer by layer upwards. When it is impossible to draw a conclusion due to detection ability limitations at this layer, initiate a detection request upwards until a result is obtained, and put the result into the malicious file library as the basis for the next detection and defense, effectively improving the detection and defense efficiency.

[0070] To improve the detection efficiency of malware, in the malware detection method provided in Embodiment 1 of this application, when the target processing policy is the detection policy, after detecting whether the software is malware based on the target processing policy and the target value to obtain the target detection result, the method further includes: if the target detection result is that the software is malware, generating an alarm message based on the file information of the software and sending the alarm message to the console; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, storing the target value and the target detection result in the malicious file library and sending the target detection result to the cloud edge node.

[0071] Optionally, when the target processing policy is the detection policy, after detecting whether the software is malware based on the target processing policy and the target value to obtain the target detection result, the software can be processed according to the target detection result. For example, if the target detection result is that the software is malware, an alarm message can be generated based on the file information of the software and sent to the console; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, storing the target value and the target detection result in the malicious file library, that is, storing the sha256 hash value of the software file and the detected detection result, and sending the target detection result to the cloud edge node for the next malware detection and defense.

[0072] To improve the defense efficiency of malware, in the malware detection method provided in Embodiment 1 of this application, when the target processing policy is the defense policy, after detecting whether the software is malware based on the target processing policy and the target value to obtain the target detection result, the method further includes: if the target detection result is that the software is malware, ending the startup process to prohibit the software from starting; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, storing the target value and the target detection result in the malicious file library and sending the target detection result to the cloud edge node.

[0073] Optionally, when the target processing policy is the defense policy, after detecting whether the software is malware based on the target processing policy and the target value to obtain the target detection result, the software can be processed according to the target detection result. For example, if the target detection result is that the software is malware, ending the startup process to prohibit the software from starting; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, storing the target value and the target detection result in the malicious file library, that is, storing the sha256 hash value of the software file and the detected detection result, and sending the target detection result to the cloud edge node for the next malware detection and defense.

[0074] In the embodiments of the present application, a method for malware detection and defense based on multi-layer collaboration of cloud-edge-terminal (cloud center-cloud edge-terminal) is adopted. The cloud center node receives a target request sent by the cloud edge node. The target request includes at least a target processing policy and a target value. The target processing policy is one of the following: a detection policy and a defense policy. The software states corresponding to the detection policy and the defense policy are different. The target value is used to identify the software file of the software. Whether the software is malware is detected according to the target processing policy and the target value to obtain a target detection result. The cloud edge node receives a first request sent by the terminal node. The first request includes at least a target processing policy and a target value. Whether the software is malware is detected according to the target processing policy and the target value to obtain a first detection result. When the first detection result indicates that it is impossible to determine whether the software is malware, a target request is sent to the cloud center node to receive the target detection result returned by the cloud center node.

[0075] In summary, for malware detection and defense based on multi-layer collaboration of cloud-edge-terminal (cloud center-cloud edge-terminal), the proximal advantage of the terminal is utilized to perform detection and acquisition work that does not consume performance, completing the first layer of protection with low latency and low cost. The rules sent to the terminal can identify basic malware behaviors and directly generate alarms and software startup interception actions, thus avoiding a large amount of data transmission. Then, the software detection results are cached in cloud edge nodes at different levels, and a single engine with only some detection rules is deployed. File comparison is performed in the cloud edge nodes. Then, a multi-engine architecture is adopted in the cloud center to provide a relatively complete detection ability. The files reported to the cloud center are detected, and the results are synchronized to the cloud edge nodes to enhance the filtering ability of the cloud edge nodes. The purpose of reducing the latency of requests and enhancing the overall availability through multi-layer collaboration of cloud-edge-terminal is achieved, thus realizing the technical effect of reducing latency and improving the detection efficiency of malware, and further solving the technical problem in the related art that when detecting malware on the terminal through the cloud system, the high latency leads to low detection efficiency of malware.

[0076] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.

[0077] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation manner. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which may be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in various embodiments of the present application.

[0078] Embodiment 2

[0079] According to an embodiment of the present application, there is also provided a Figure 4 detection method for malicious software as shown. Figure 4 It is a flowchart of the detection method for malicious software provided in the second embodiment of the present application. The method includes:

[0080] Step S401, receiving a first request sent by a terminal node through a cloud edge node, where the first request at least includes a target processing policy and a target value. The target processing policy is one of the following: a detection policy and a defense policy. The software states corresponding to the detection policy and the defense policy are different, and the target value is used to identify the software file of the software.

[0081] In an alternative embodiment, the software state of the software is determined by a terminal engine of the terminal node, and the target processing policy for the software is determined according to the software state, where the software state is one of the following: an unstarted state and a started state.

[0082] The terminal engine is deployed on the terminal, and the response time is relatively fast but the ability is weak. It can perform simple matching behaviors. For example, it can match the content of the regular expression in the detection rule with the file content. If there is a specified content in the file content that is the same as the content of the regular expression, it can be determined whether the file is malicious or non-malicious.

[0083] The terminal engine of the terminal node regularly collects file information on the disk for detection, or performs defense when it detects that any software is writing to the disk or starting up. Therefore, the current state of the software is first determined through the terminal engine of the terminal node, so as to determine whether to detect or defend the software. For example, when the software state is the unstarted state, the detection policy is used as the target processing policy, and the corresponding detection process is carried out, including identifying basic malware behaviors through rules sent to the terminal, matching according to the cached software detection results at the cloud edge node and detecting through a single engine, matching according to the cached software detection results at the cloud center node and detecting through multiple engines, etc.; when the software state is the started state, the defense policy is used as the target processing policy, and the corresponding defense process is carried out, including pausing the software startup, matching layer by layer upwards whether there is a record of malware in the malicious file library. If there is and the record is a blacklisted software, specific operations such as prohibiting the software from starting up and killing the process are executed. If not, the software startup is allowed, and a comprehensive detection of the software file content is initiated asynchronously, etc.

[0084] In an alternative embodiment, the terminal engine determines whether the software is malware according to the target processing policy. For example, it matches the content of the regular expression in the detection rule with the file content. If there is no specified content in the file content that is the same as the content of the regular expression, it cannot be determined whether the software is malware, and the result that it cannot be determined whether the software is malware is used as the detection result. In this case (the detection result indicates that it cannot be determined whether the software is malware), the terminal node sends a first request to the cloud edge node.

[0085] In an alternative embodiment, when the terminal engine cannot determine whether the software is malware, a target value is calculated based on the software file content, and the file information of the software is obtained. A detection request (i.e., the first request) is generated based on the target value and the file information and reported to the cloud edge node. For example, when the terminal engine cannot determine whether the software is malware, the terminal engine calculates the sha256 hash value as the file identifier based on the software file content, collects file information, such as file size, path, etc., and encapsulates the sha256 hash value and the collected information into a detection request and reports it to the cloud edge node.

[0086] Therefore, the cloud edge node receives the first request sent by the terminal node. Among them, the first request at least includes the target processing policy (i.e., whether to detect or defend the software) and the target value. The target value can be the sha256 hash value of the software file calculated through the secure hash algorithm, or the MD5 value calculated through the message digest algorithm, etc., which is not limited here.

[0087] Step S402: Detect whether the software is malicious software based on the target processing policy and the target value, and obtain a first detection result.

[0088] The cloud edge node detects whether the software is malicious software based on the target processing policy and the target value. The cloud edge node deploys a malicious file sub-database and a simplified single engine (i.e., a sub-detection engine). The response time and detection ability are at a medium level, which is used to quickly respond to the on-device requests in this area. For example, the cloud edge node can match according to the software detection results in the malicious file sub-database, or can detect through the single engine to obtain a first detection result. Among them, the single engine detection can be to match using multiple regular expressions, or can be to use a simple malicious software recognition model, which is not limited here.

[0089] Step S403: In the case where the first detection result indicates that it is impossible to determine whether the software is malicious software, send a target request to the cloud center node to receive the target detection result returned by the cloud center node.

[0090] In the case where the first detection result indicates that it is impossible to determine whether the software is malicious software, the cloud edge node sends a target request to the cloud center node, so that the cloud center node detects whether the software is malicious software based on the target processing policy and the target value, obtains a target detection result, and sends the target detection result to the cloud edge node for the next detection and defense of malicious software.

[0091] In an alternative embodiment, when the target processing policy is a detection policy, the software file content and the detection rules of the software are obtained through the terminal engine; the software file content is compared with the target content corresponding to the detection rules to obtain a first comparison result; if the first comparison result is that the software file content is the same as the target content, the detection result is determined according to the target type corresponding to the target content; if the first comparison result is that the software file content is different from the target content, it is determined that it is impossible to determine whether the software is malicious software as the detection result.

[0092] When the target processing policy is a detection policy, the terminal engine actively initiates a malicious behavior detection of the software file content through the on-device detection rules. The software file content and the detection rules (such as regular expression matching rules) of the software are obtained through the terminal engine, and the software file content is compared with the target content corresponding to the detection rules to obtain a first comparison result. Among them, there are two types of target content, one is used to determine that the software is malicious software, and the other is used to determine that the software is non-malicious software. For example, the regular expression content (i.e., the target content) in the detection rules can be matched with the file content.

[0093] If the first comparison result is that the content of the software file is the same as the target content, the detection result can be determined according to the target type corresponding to the target content. Among them, the target type includes two types, one is the malicious software determination type and the other is the non-malicious software determination type. For example, after matching the regular expression content in the detection rule with the file content, if there is a specified content in the file content that is the same as the regular expression content, that is, if the first comparison result is that the content of the software file is the same as the target content, the detection result can be determined according to the target type corresponding to the target content. For example, if the target type is the malicious software determination type, it is determined that the detection result is that the software is malicious software; if the target type is the non-malicious software determination type, it is determined that the detection result is that the software is non-malicious software.

[0094] Optionally, if the first comparison result is that the content of the software file is different from the target content, then taking the inability to determine whether the software is malicious software as the detection result. For example, after matching the regular expression content in the detection rule with the file content, if there is no specified content in the file content that is the same as the regular expression content, then it is impossible to determine whether the software is malicious software.

[0095] It should be noted that in the above process, the proximal advantage of the client is used to perform detection and acquisition work that does not consume performance. In the terminal node, the first layer of protection with low latency and low cost is achieved through the client. The basic malicious software behavior is identified through the rules issued to the terminal, avoiding a large amount of data transmission, being able to cover the scenarios of common software, achieving low-latency detection, and effectively improving the detection efficiency.

[0096] In order to accurately determine whether the software is malicious software, in the malicious software detection method provided in Embodiment 1 of the present application, a malicious file sub-database and a sub-detection engine are deployed in the cloud edge node. In the case where the target processing strategy is the detection strategy, it is detected whether the software is malicious software according to the target processing strategy and the target value, and the first detection result is obtained, including: matching according to the target value in the malicious file sub-database to obtain a third matching result; if the third matching result is that there is a record in the malicious file sub-database that is the same as the target value, then determining the first detection result according to the record detection result included in the record; if the third matching result is that there is no record in the malicious file sub-database that is the same as the target value, then receiving the software file uploaded by the terminal node, and detecting the content of the software file through the sub-detection engine. In the case where the sub-detection engine cannot determine whether there is malicious behavior in the content of the software file, taking the inability to determine whether the software is malicious software as the first detection result.

[0097] Optionally, the cloud edge node matches in the malicious file sub-database according to the target value to obtain a third matching result. For example, an edge node closer to the terminal (which can be a regional edge node or a dedicated network edge node) responds to the first request, parses the basic information and sha256 identifier of the file, and matches them in the local malicious file sub-database.

[0098] Optionally, if the third matching result indicates that there is a record in the malicious file sub-database that is the same as the target value, then determine the first detection result according to the record detection result included in the record. For example, after matching according to the sha256 identifier in the malicious file sub-database, if there is a record in the malicious file sub-database that is the same as the sha256 identifier, that is, there is a sha256 identifier that is the same as the sha256 identifier and the corresponding detection result (i.e., the record detection result), then the first detection result can be determined according to the record detection result. For example, if the record detection result is that the sha256 identifier is malware, then determine that the first detection result is that the software is malware; if the record detection result is that the sha256 identifier is non-malware, then determine that the first detection result is that the software is non-malware.

[0099] Optionally, if the third matching result indicates that there is no record in the malicious file sub-database that is the same as the target value, then receive the software file uploaded by the terminal node, and detect the content of the software file through the sub-detection engine. In the case where the sub-detection engine cannot determine whether there is malicious behavior in the software file content, take the inability to determine whether the software is malicious as the first detection result. For example, after matching according to the sha256 identifier in the malicious file sub-database, if there is no record in the malicious file sub-database that is the same as the sha256 identifier, then the software file uploaded by the terminal node can be received, and whether the software content is malicious can be detected in the local single engine (i.e., the sub-detection engine). For example, multiple regular expressions can be used for matching or a simple malware recognition model can be used, etc. If the edge detection engine can obtain a clear result, the detection ends; otherwise, the request is reported to the cloud center node continuously.

[0100] It should be noted that cache the software detection results for cloud edge nodes at different levels, and deploy a single engine containing some detection rules to perform file comparison and preliminary screening in the cloud edge nodes to screen out most duplicate software detection requests, thereby avoiding duplicate detection of the same software and effectively improving the detection efficiency.

[0101] In an alternative embodiment, when the target processing policy is a defense policy, the terminal engine suspends the startup process of the software and obtains the software file content and detection rules of the software through the terminal engine; compares the software file content with the target content corresponding to the detection rules to obtain a second comparison result; if the second comparison result is that the software file content is the same as the target content, determines the detection result according to the target type corresponding to the target content; if the second comparison result is that the software file content is different from the target content, takes the inability to determine whether the software is malicious software as the detection result.

[0102] When the target processing policy is a defense policy, when the software starts, the terminal engine initiates a defense action, that is, the terminal engine first suspends the startup process of the software and matches layer by layer upward whether there is a record of malicious software in the malicious file library. Optionally, the terminal engine obtains the software file content and detection rules (for example, regular expression matching rules) of the software, and compares the software file content with the target content corresponding to the detection rules to obtain a second comparison result. Among them, the target content includes two types, one is for determining that the software is malicious software, and the other is for determining that the software is non-malicious software. For example, the regular expression content (i.e., the target content) in the detection rules can be matched with the file content.

[0103] Optionally, if the second comparison result is that the software file content is the same as the target content, the detection result can be determined according to the target type corresponding to the target content. Among them, the target type includes two types, one is a malicious software determination type, and the other is a non-malicious software determination type. For example, after matching the regular expression content in the detection rules with the file content, if there is a specified content in the file content that is the same as the regular expression content, that is, if the second comparison result is that the software file content is the same as the target content, the detection result can be determined according to the target type corresponding to the target content. For example, if the target type is a malicious software determination type, it is determined that the detection result is that the software is malicious software; if the target type is a non-malicious software determination type, it is determined that the detection result is that the software is non-malicious software.

[0104] Optionally, if the second comparison result is that the software file content is different from the target content, the inability to determine whether the software is malicious software is taken as the detection result. For example, after matching the regular expression content in the detection rules with the file content, if there is no specified content in the file content that is the same as the regular expression content, it is impossible to determine whether the software is malicious software.

[0105] It should be noted that in the above process, the detection and acquisition work that does not consume performance is performed by taking advantage of the proximal advantage of the client. In the terminal node, the first layer of protection with low latency and low cost is achieved through the client. By identifying basic malware behaviors through the rules distributed to the terminal, a large amount of data transmission is avoided, and the scenarios of common software can be covered, enabling low-latency detection and effectively improving the detection efficiency.

[0106] In order to accurately determine whether a software is malware, in the malware detection method provided in Embodiment 1 of this application, a malicious file sub-database is deployed on the cloud edge node. When the target processing policy is a defense policy, it is detected whether the software is malware according to the target processing policy and the target value, and a first detection result is obtained, including: matching according to the target value in the malicious file sub-database to obtain a fourth matching result; if the fourth matching result is that there is a record in the malicious file sub-database that is the same as the target value, then determine the first detection result according to the record detection result included in the record; if the fourth matching result is that there is no record in the malicious file sub-database that is the same as the target value, then take that it cannot be determined whether the software is malware as the first detection result.

[0107] Optionally, the cloud edge node matches according to the target value in the malicious file sub-database to obtain a fourth matching result. For example, an edge node closer to the terminal (which can be a regional edge node or a private network edge node) responds to the first request, parses out the basic information and sha256 identifier of the file, and matches them in the local malicious file sub-database.

[0108] Optionally, if the fourth matching result is that there is a record in the malicious file sub-database that is the same as the target value, then determine the first detection result according to the record detection result included in the record. For example, after matching according to the sha256 identifier in the malicious file sub-database, if there is a record in the malicious file sub-database that is the same as the sha256 identifier, that is, there is a sha256 identifier that is the same as this sha256 identifier and the corresponding detection result (i.e., the record detection result), then the first detection result can be determined according to the record detection result. For example, if the record detection result is that this sha256 identifier is malware, then determine that the first detection result is that this software is malware; if the record detection result is that this sha256 identifier is non-malware, then determine that the first detection result is that this software is non-malware. Then, the result is sent to the terminal (i.e., the terminal node), and the terminal engine can judge whether to cancel the defense of the file according to this result.

[0109] Optionally, if there is no record in the malicious file sub-database that is the same as the target value in the fourth matching result, then taking the inability to determine whether the software is malicious as the first detection result. For example, after matching according to the sha256 identifier in the malicious file sub-database, if there is no record in the malicious file sub-database that is the same as the sha256 identifier, the request needs to be reported to the cloud center node continuously.

[0110] It should be noted that caching the software detection results at different levels of cloud edge nodes can perform file comparison and preliminary screening in the cloud edge nodes, screening out most duplicate software judgment requests, thereby avoiding duplicate judgments on the same software and effectively improving the detection and defense efficiency.

[0111] In summary, for malicious software detection and defense based on multi-layer collaboration of the cloud-edge-terminal (cloud center - cloud edge - terminal), the proximal advantage of the terminal is utilized to perform detection and acquisition work that does not consume performance, completing the first layer of protection with low latency and low cost. Through the rules issued to the terminal, basic malicious software behaviors can be identified, and alarms and software startup interception actions can be directly generated, thereby avoiding a large amount of data transmission. Then, the software detection results are cached at different levels of cloud edge nodes, and a single engine with only some detection rules is deployed. File comparison is performed in the cloud edge nodes, and then a multi-engine architecture is adopted in the cloud center to provide a relatively complete detection ability. The files reported to the cloud center are detected, and the results are synchronized to the cloud edge nodes to enhance the filtering ability of the cloud edge nodes, achieving the purpose of reducing the latency of requests and enhancing the overall availability through multi-layer collaboration of the cloud-edge-terminal, thereby realizing the technical effect of reducing latency and improving the detection efficiency of malicious software, and further solving the technical problem in the related art that detecting malicious software on the terminal through the cloud system has a relatively high latency, resulting in a relatively low detection efficiency of malicious software.

[0112] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0113] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to enable a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0114] Embodiment 3

[0115] According to an embodiment of the present application, there is also provided a malware detection device for implementing the above-mentioned malware detection method, as Figure 5 shown. The device includes: a first receiving unit 501 and a first determining unit 502.

[0116] The first receiving unit 501 is configured to receive a target request sent by a cloud edge node through a cloud center node. The target request at least includes a target processing policy and a target value. The target processing policy is one of the following: a detection policy and a defense policy. The software states corresponding to the detection policy and the defense policy are different. The target value is used to identify the software file of the software.

[0117] The first determining unit 502 is configured to detect whether the software is malware according to the target processing policy and the target value, and obtain a target detection result.

[0118] In the malware detection device provided in Embodiment 3 of the present application, the first receiving unit 501 receives a target request sent by a cloud edge node through a cloud center node. The target request includes at least a target processing policy and a target value. The target processing policy is one of the following: a detection policy and a defense policy. The software states corresponding to the detection policy and the defense policy are different. The target value is used to identify the software file of the software. The first determination unit 502 detects whether the software is malware based on the target processing policy and the target value, and obtains a target detection result. In this solution, malware detection and defense are performed based on multi-layer collaboration among the cloud, edge, and terminal (cloud center - cloud edge - terminal). The proximal advantage of the terminal is used to perform detection and acquisition tasks that do not consume performance, completing the first layer of protection with low latency and low cost. The rules sent to the terminal can identify basic malware behaviors and directly generate alarms and software startup interception actions, thus avoiding a large amount of data transmission. Then, the software detection results are cached in cloud edge nodes at different levels, and a single engine with only partial detection rules is deployed. File comparison is performed in the cloud edge nodes, and then a multi-engine architecture is adopted in the cloud center to provide a relatively complete detection ability. The files reported to the cloud center are detected, and the results are synchronized to the cloud edge nodes to enhance the filtering ability of the cloud edge nodes, achieving the purpose of reducing the latency of requests and enhancing the overall availability through multi-layer collaboration among the cloud, edge, and terminal. Thus, the technical effect of reducing latency and improving the detection efficiency of malware is achieved, and the technical problem in the related art that detecting malware on a terminal through a cloud system has a high latency and low detection efficiency is solved.

[0119] Optionally, in the malware detection device provided in Embodiment 3 of the present application, a malicious file library and multiple detection engines are deployed in the cloud center node. When the target processing policy is a detection policy, the first determination unit includes: a first matching subunit, configured to perform a match in the malicious file library according to the target value to obtain a first matching result; a first determination subunit, configured to, if the first matching result is that there is a record in the malicious file library that is the same as the target value, determine the target detection result according to the detection result included in the record; a second determination subunit, configured to, if the first matching result is that there is no record in the malicious file library that is the same as the target value, receive the software file uploaded by the cloud edge node, detect the content of the software file through multiple detection engines to obtain multiple detection results, and determine the target detection result according to the multiple detection results.

[0120] Optionally, in the malware detection device provided in Embodiment 3 of the present application, a malicious file library and multiple detection engines are deployed on the cloud center node. When the target processing policy is a defense policy, the first determination unit includes: a second matching subunit, configured to perform matching in the malicious file library according to the target value to obtain a second matching result; a third determination subunit, configured to, if the second matching result indicates that there is a record in the malicious file library that is the same as the target value, determine the target detection result according to the record detection result included in the record; a fourth determination subunit, configured to, if the second matching result indicates that there is no record in the malicious file library that is the same as the target value, notify the cloud edge node to release the suspension of the software startup process, receive the software file uploaded by the cloud edge node, asynchronously detect the content of the software file through multiple detection engines to obtain multiple detection results, and determine the target detection result according to the multiple detection results.

[0121] Optionally, in the malware detection device provided in Embodiment 3 of the present application, the device further includes: a first processing unit, configured to, when the target processing policy is a detection policy, after detecting whether the software is malware according to the target processing policy and the target value to obtain a target detection result, if the target detection result indicates that the software is malware, generate an alarm message according to the file information of the software and send the alarm message to the console; a second processing unit, configured to, if the target detection result indicates that the software is malware or the target detection result indicates that the software is non-malware, store the target value and the target detection result in the malicious file library and send the target detection result to the cloud edge node.

[0122] Optionally, in the malware detection device provided in Embodiment 3 of the present application, the device further includes: a third processing unit, configured to, when the target processing policy is a defense policy, after detecting whether the software is malware according to the target processing policy and the target value to obtain a target detection result, if the target detection result indicates that the software is malware, end the startup process to prohibit the software from starting; a fourth processing unit, configured to, if the target detection result indicates that the software is malware or the target detection result indicates that the software is non-malware, store the target value and the target detection result in the malicious file library and send the target detection result to the cloud edge node.

[0123] It should be noted here that the above-mentioned first receiving unit 501 and first determination unit 502 correspond to steps S201 to S202 in Embodiment 1. The above-mentioned units have the same implementation examples and application scenarios as the corresponding steps, but are not limited to the content disclosed in the above-mentioned Embodiment 1. It should be noted that the above-mentioned module can run in the computer terminal 10 provided in Embodiment 1 as a part of the device.

[0124] It should be noted that the preferred implementation solutions involved in the above embodiments of the present application are the same as the solutions, application scenarios, and implementation processes provided in Embodiment 1, but are not limited to the solutions provided in Embodiment 1.

[0125] Embodiment 4

[0126] According to an embodiment of the present application, there is also provided a malware detection device for implementing the above malware detection method, as Figure 6 shown. The device includes: a second receiving unit 601, a second determining unit 602, and a first sending unit 603.

[0127] The second receiving unit 601 is configured to receive a first request sent by a terminal node through a cloud edge node. The first request at least includes a target processing policy and a target value. The target processing policy is one of the following: a detection policy and a defense policy. The software states corresponding to the detection policy and the defense policy are different. The target value is used to identify the software file of the software.

[0128] The second determining unit 602 is configured to detect whether the software is malware according to the target processing policy and the target value, and obtain a first detection result.

[0129] The first sending unit 603 is configured to send a target request to a cloud center node to receive a target detection result returned by the cloud center node when the first detection result indicates that it is impossible to determine whether the software is malware.

[0130] In the malware detection device provided in the fourth embodiment of the present application, the second receiving unit 601 receives a first request sent by a terminal node through a cloud edge node. The first request includes at least a target processing policy and a target value. The target processing policy is one of the following: a detection policy and a defense policy. The software states corresponding to the detection policy and the defense policy are different. The target value is used to identify the software file of the software. The second determination unit 602 detects whether the software is malware based on the target processing policy and the target value, and obtains a first detection result. The first sending unit 603 sends a target request to the cloud center node to receive the target detection result returned by the cloud center node when the first detection result indicates that it is impossible to determine whether the software is malware. In this solution, malware detection and defense are performed through multi-layer collaboration of the cloud-edge-terminal (cloud center-cloud edge-terminal). The proximal advantage of the terminal is used to perform detection and acquisition work that does not consume performance, completing the first layer of protection with low latency and low cost. The rules issued to the terminal can identify basic malware behaviors and directly generate alarms and software startup interception actions, thus avoiding a large amount of data transmission. Then, the software detection results are cached in cloud edge nodes at different levels, and a single engine with only partial detection rules is deployed. File comparison is performed in the cloud edge nodes, and then a multi-engine architecture is adopted in the cloud center to provide a relatively complete detection ability. The files reported to the cloud center are detected, and the results are synchronized to the cloud edge nodes to enhance the filtering ability of the cloud edge nodes, achieving the purpose of reducing the latency of requests and enhancing the overall availability through multi-layer collaboration of the cloud-edge-terminal, thereby realizing the technical effect of reducing latency and improving the detection efficiency of malware, and further solving the technical problem that in the related art, detecting malware on a terminal through a cloud system has a high latency, resulting in a low detection efficiency of malware.

[0131] Optionally, in the malware detection device provided in the fourth embodiment of the present application, a malicious file sub-database and a sub-detection engine are deployed in the cloud edge node. When the target processing policy is a detection policy, the second determination unit includes: a third matching sub-unit, configured to perform matching in the malicious file sub-database according to the target value to obtain a third matching result; a fifth determination sub-unit, configured to, if the third matching result is that there is a record in the malicious file sub-database that is the same as the target value, determine the first detection result according to the record detection result included in the record; a sixth determination sub-unit, configured to, if the third matching result is that there is no record in the malicious file sub-database that is the same as the target value, receive the software file uploaded by the terminal node, and detect the content of the software file through the sub-detection engine. When the sub-detection engine cannot determine whether there is a malicious behavior in the content of the software file, it is used as the first detection result that it is impossible to determine whether the software is malware.

[0132] Optionally, in the malware detection device provided in the fourth embodiment of this application, a malicious file sub-database is deployed on the cloud edge node. When the target processing policy is a defense policy, the second determination unit includes: a fourth matching subunit, configured to perform a match in the malicious file sub-database according to the target value to obtain a fourth matching result; a seventh determination subunit, configured to, if the fourth matching result indicates that there is a record in the malicious file sub-database that is the same as the target value, determine a first detection result according to the record detection result included in the record; an eighth determination subunit, configured to, if the fourth matching result indicates that there is no record in the malicious file sub-database that is the same as the target value, use that it is impossible to determine whether the software is malware as the first detection result.

[0133] It should be noted here that the above-mentioned second receiving unit 601, second determination unit 602, and first sending unit 603 correspond to steps S401 to S403 in Embodiment 2. The above units have the same implementation examples and application scenarios as the corresponding steps, but are not limited to the content disclosed in the above-mentioned Embodiment 2. It should be noted that the above modules, as part of the device, can run in the computer terminal 10 provided in Embodiment 2.

[0134] It should be noted that the preferred implementation schemes involved in the above embodiments of this application are the same as the schemes, application scenarios, and implementation processes provided in Embodiment 2, but are not limited to the schemes provided in Embodiment 2.

[0135] Embodiment 5

[0136] The embodiments of this application can provide a computer terminal, which can be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the above computer terminal can also be replaced with a terminal device such as a mobile terminal.

[0137] Optionally, in this embodiment, the above computer terminal can be located in at least one of multiple network devices in a computer network.

[0138] In this embodiment, the above computer terminal can execute the program code of the following steps in the malware detection method: receiving, by a cloud center node, a target request sent by a cloud edge node, where the target request at least includes a target processing policy and a target value, the target processing policy is one of the following: a detection policy, a defense policy, the software states corresponding to the detection policy and the defense policy are different, and the target value is used to identify the software file of the software; detecting whether the software is malware according to the target processing policy and the target value to obtain a target detection result.

[0139] The above computer terminal can also execute the program code of the following steps in the malware detection method: A malicious file library and multiple detection engines are deployed on the cloud center node. When the target processing policy is a detection policy, it detects whether the software is malware according to the target processing policy and the target value, and obtains the target detection result, including: matching according to the target value in the malicious file library to obtain the first matching result; if the first matching result is that there is a record in the malicious file library that is the same as the target value, determining the target detection result according to the record detection result included in the record; if the first matching result is that there is no record in the malicious file library that is the same as the target value, receiving the software file uploaded by the cloud edge node, and detecting the content of the software file through multiple detection engines to obtain multiple detection results, and determining the target detection result according to the multiple detection results.

[0140] The above computer terminal can also execute the program code of the following steps in the malware detection method: A malicious file library and multiple detection engines are deployed on the cloud center node. When the target processing policy is a defense policy, it detects whether the software is malware according to the target processing policy and the target value, and obtains the target detection result, including: matching according to the target value in the malicious file library to obtain the second matching result; if the second matching result is that there is a record in the malicious file library that is the same as the target value, determining the target detection result according to the record detection result included in the record; if the second matching result is that there is no record in the malicious file library that is the same as the target value, notifying the cloud edge node to release the suspension of the startup process of the software, receiving the software file uploaded by the cloud edge node, asynchronously detecting the content of the software file through multiple detection engines to obtain multiple detection results, and determining the target detection result according to the multiple detection results.

[0141] The above computer terminal can also execute the program code of the following steps in the malware detection method: When the target processing policy is a detection policy, after detecting whether the software is malware according to the target processing policy and the target value and obtaining the target detection result, if the target detection result is that the software is malware, generating an alarm message according to the file information of the software and sending the alarm message to the console; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, storing the target value and the target detection result in the malicious file library, and sending the target detection result to the cloud edge node.

[0142] The above computer terminal can also execute the program code of the following steps in the method for detecting malware: When the target processing policy is a defense policy, after detecting whether the software is malware based on the target processing policy and the target value to obtain a target detection result, if the target detection result is that the software is malware, then end the startup process to prohibit the software from starting; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, then store the target value and the target detection result in the malware library, and send the target detection result to the cloud edge node.

[0143] Optionally, Figure 7 is a structural block diagram of a computer terminal according to an embodiment of the present application. As Figure 7 shown, the computer terminal 10 may include: one or more ( Figure 7 only one is shown in the figure) processors 102, a memory 104. The computer terminal 10 may further include a storage controller for controlling and managing the memory 104 through the storage controller; the computer terminal 10 may further include a peripheral interface for connecting a radio frequency module, an audio module, a display screen, etc. through the peripheral interface.

[0144] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the method and device for detecting malware in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above-mentioned method for detecting malware. The memory may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely disposed relative to the processor, and these remote memories may be connected to the terminal 10 through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0145] The processor can call the information and application programs stored in the memory through the transmission device to execute the following steps: receiving a target request sent by the cloud edge node through the cloud center node, where the target request at least includes a target processing policy and a target value, the target processing policy is one of the following: a detection policy, a defense policy, the software states corresponding to the detection policy and the defense policy are different, and the target value is used to identify the software file of the software; detecting whether the software is malware based on the target processing policy and the target value to obtain a target detection result.

[0146] Optionally, the above-mentioned processor may also execute the program code of the following steps: A malicious file library and multiple detection engines are deployed on the cloud center node. When the target processing policy is a detection policy, it detects whether the software is malicious software according to the target processing policy and the target value, and obtains the target detection result, including: matching according to the target value in the malicious file library to obtain a first matching result; if the first matching result is that there is a record in the malicious file library that is the same as the target value, then determine the target detection result according to the record detection result included in the record; if the first matching result is that there is no record in the malicious file library that is the same as the target value, then receive the software file uploaded by the cloud edge node, and detect the content of the software file through multiple detection engines to obtain multiple detection results, and determine the target detection result according to the multiple detection results.

[0147] Optionally, the above-mentioned processor may also execute the program code of the following steps: A malicious file library and multiple detection engines are deployed on the cloud center node. When the target processing policy is a defense policy, it detects whether the software is malicious software according to the target processing policy and the target value, and obtains the target detection result, including: matching according to the target value in the malicious file library to obtain a second matching result; if the second matching result is that there is a record in the malicious file library that is the same as the target value, then determine the target detection result according to the record detection result included in the record; if the second matching result is that there is no record in the malicious file library that is the same as the target value, then notify the cloud edge node to release the suspension of the startup process of the software, receive the software file uploaded by the cloud edge node, asynchronously detect the content of the software file through multiple detection engines to obtain multiple detection results, and determine the target detection result according to the multiple detection results.

[0148] Optionally, the above-mentioned processor may also execute the program code of the following steps: When the target processing policy is a detection policy, after detecting whether the software is malicious software according to the target processing policy and the target value and obtaining the target detection result, if the target detection result is that the software is malicious software, then generate an alarm message according to the file information of the software and send the alarm message to the console; if the target detection result is that the software is malicious software or the target detection result is that the software is non-malicious software, then store the target value and the target detection result in the malicious file library, and send the target detection result to the cloud edge node.

[0149] Optionally, the above-mentioned processor may also execute the program code of the following steps: when the target processing policy is a defense policy, after detecting whether the software is malicious software according to the target processing policy and the target value to obtain a target detection result, if the target detection result is that the software is malicious software, then end the startup process to prohibit the software from starting; if the target detection result is that the software is malicious software or the target detection result is that the software is non-malicious software, then store the target value and the target detection result in the malicious file library, and send the target detection result to the cloud edge node.

[0150] Those of ordinary skill in the art can understand that Figure 7 the structure shown is only schematic, and the computer terminal may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a palm computer, and a mobile Internet device (Mobile Internet Devices, MID), a PAD and other terminal devices. Figure 7 It does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components (such as a network interface, a display device, etc.) than those shown in Figure 7 or have a different configuration from that shown in Figure 7 shown.

[0151] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium. The storage medium may include: a flash drive, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disc, etc.

[0152] Embodiment 6

[0153] The embodiment of the present application also provides a computer-readable storage medium. Optionally, in this embodiment, the above storage medium may be used to store the program code executed by the method for detecting malicious software provided in the first embodiment above.

[0154] Optionally, in this embodiment, the above storage medium may be located in any one of the computer terminals in the computer terminal group in the computer network, or located in any one of the mobile terminals in the mobile terminal group.

[0155] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.

[0156] In the above embodiments of the present application, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0157] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings, direct couplings, or communication connections shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of the units or modules can be in electrical or other forms.

[0158] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0159] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0160] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs and other various media that can store program codes.

[0161] The above is only the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A method for detecting malware, characterized in that, it includes: Receiving a target request sent by a cloud edge node through a cloud center node, where the target request includes at least a target processing policy and a target value. The target processing policy is one of the following: a detection policy and a defense policy. The software states corresponding to the detection policy and the defense policy are different, and the target value is used to identify the software file of the software; Detecting whether the software is malware according to the target processing policy and the target value to obtain a target detection result.

2. The method according to claim 1, characterized in that, The cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing policy is the detection policy, detecting whether the software is malware according to the target processing policy and the target value to obtain a target detection result includes: Matching according to the target value in the malicious file library to obtain a first matching result; If the first matching result is that there is a record in the malicious file library that is the same as the target value, determining the target detection result according to the record detection result included in the record; If the first matching result is that there is no record in the malicious file library that is the same as the target value, receiving the software file uploaded by the cloud edge node, detecting the content of the software file through the multiple detection engines to obtain multiple detection results, and determining the target detection result according to the multiple detection results.

3. The method according to claim 1, characterized in that, The cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing policy is the defense policy, detecting whether the software is malware according to the target processing policy and the target value to obtain a target detection result includes: Matching according to the target value in the malicious file library to obtain a second matching result; If the second matching result is that there is a record in the malicious file library that is the same as the target value, determining the target detection result according to the record detection result included in the record; If the second matching result is that there is no record in the malicious file library that is the same as the target value, notifying the cloud edge node to release the suspension of the startup process of the software, receiving the software file uploaded by the cloud edge node, asynchronously detecting the content of the software file through the multiple detection engines to obtain multiple detection results, and determining the target detection result according to the multiple detection results.

4. The method according to claim 2, characterized in that, When the target processing policy is the detection policy, after detecting whether the software is malware according to the target processing policy and the target value to obtain a target detection result, the method further includes: If the target detection result is that the software is malware, generating an alarm message according to the file information of the software and sending the alarm message to the console; If the target detection result is that the software is malicious software or the target detection result is that the software is non-malicious software, then store the target value and the target detection result in the malicious file library, and send the target detection result to the cloud edge node.

5. The method according to claim 3, wherein, when the target processing strategy is the defense strategy, after detecting whether the software is malicious software according to the target processing strategy and the target value to obtain a target detection result, the method further includes: if the target detection result is that the software is malicious software, then end the startup process to prohibit the software from starting; If the target detection result is that the software is malicious software or the target detection result is that the software is non-malicious software, then store the target value and the target detection result in the malicious file library, and send the target detection result to the cloud edge node.

6. A method for detecting malicious software, wherein, it includes: Receiving a first request sent by a terminal node through a cloud edge node, where at least the target processing strategy and the target value are included in the first request, the target processing strategy is one of the following: a detection strategy, a defense strategy, the software states corresponding to the detection strategy and the defense strategy are different, and the target value is used to identify the software file of the software; Detecting whether the software is malicious software according to the target processing strategy and the target value to obtain a first detection result; When the first detection result indicates that it is impossible to determine whether the software is malicious software, send a target request to the cloud center node to receive the target detection result returned by the cloud center node.

7. The method according to claim 6, wherein, The cloud edge node is deployed with a malicious file sub-database and a sub-detection engine. When the target processing strategy is the detection strategy, detecting whether the software is malicious software according to the target processing strategy and the target value to obtain a first detection result includes: Performing a match in the malicious file sub-database according to the target value to obtain a third match result; If the third match result is that there is a record in the malicious file sub-database that is the same as the target value, then determine the first detection result according to the record detection result included in the record; If the third match result is that there is no record in the malicious file sub-database that is the same as the target value, then receive the software file uploaded by the terminal node, and detect the content of the software file through the sub-detection engine. When the sub-detection engine cannot determine whether there is malicious behavior in the content of the software file, take that it is impossible to determine whether the software is malicious software as the first detection result.

8. The method according to claim 6, wherein, The cloud edge node is deployed with a malicious file sub-database. When the target processing strategy is the defense strategy, detecting whether the software is malicious software according to the target processing strategy and the target value to obtain a first detection result includes: Match in the malicious file sub-database according to the target value to obtain a fourth matching result; If the fourth matching result indicates that there is a record in the malicious file sub-database that is the same as the target value, determine the first detection result according to the record detection result included in the record; If the fourth matching result indicates that there is no record in the malicious file sub-database that is the same as the target value, then use the inability to determine whether the software is malicious software as the first detection result.

9. A detection device for malicious software, characterized in that, it includes: A first receiving unit, configured to receive a target request sent by a cloud edge node through a cloud center node, where the target request at least includes a target processing policy and a target value, the target processing policy is one of the following: a detection policy, a defense policy, the software states corresponding to the detection policy and the defense policy are different, and the target value is used to identify the software file of the software; A first determination unit, configured to detect whether the software is malicious software according to the target processing policy and the target value to obtain a target detection result.

10. A detection device for malicious software, characterized in that, it includes: A second receiving unit, configured to receive a first request sent by a terminal node through a cloud edge node, where the first request at least includes a target processing policy and a target value, the target processing policy is one of the following: a detection policy, a defense policy, the software states corresponding to the detection policy and the defense policy are different, and the target value is used to identify the software file of the software; A second determination unit, configured to detect whether the software is malicious software according to the target processing policy and the target value to obtain a first detection result; A first sending unit, configured to send a target request to the cloud center node to receive the target detection result returned by the cloud center node when the first detection result indicates that it is impossible to determine whether the software is malicious software.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, where when the program runs, it controls the device where the storage medium is located to execute the malicious software detection method according to any one of claims 1 to 8.

12. An electronic device, characterized in that, it includes: A memory, storing an executable program; A processor, configured to run the program, where when the program runs, it executes the malicious software detection method according to any one of claims 1 to 8.