Illegal software detection method and device, equipment, medium and product
By collecting and matching software registry information and using large language models to predict the probability value of violations, the problems of accuracy and inefficiency of traditional violation software detection methods are solved, and more efficient and accurate violation software detection is achieved.
Patent Information
- Application Number
- CN202510197057.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-06-10
AI Technical Summary
Traditional illegal software detection methods have low detection accuracy and efficiency, which is difficult to ensure the accuracy of the detection and requires manual review, which affects efficiency.
The software to be detected is determined by collecting the registry information of the candidate software and using the violation registry information and the candidate registry information. Then, the target large language model is used to predict the probability value of the violation of the software to be detected based on the attribute information of the software to be detected, and the violation detection is carried out.
Combining registry information matching and intelligent prediction of large language models improves the accuracy of detection of illegal software, reduces the need for manual review, and improves detection efficiency.
Smart Images

Figure CN120124059A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of artificial intelligence, and in particular, to a method, device, equipment, medium and product for detecting illegal software. Background Art
[0002] With the development of computer technology and Internet technology, different software will be installed on a computer, and these software need to interact with other computers during operation. During the data interaction process, if there is an illegal software attacking other computers, it will inevitably affect the normal operation of the entire networking network.
[0003] It can be seen that it is very necessary to detect illegal software. Traditional detection of illegal software usually adopts the method of code review. On the one hand, it is difficult to ensure the accuracy of detecting illegal software; on the other hand, due to the low detection accuracy, manual review is required, which further affects the efficiency of detecting illegal software. Summary of the Invention
[0004] The present invention provides a method, device, equipment, medium and product for detecting illegal software to solve the problems of low detection accuracy and detection efficiency existing in the traditional method for detecting illegal software.
[0005] According to one aspect of the present invention, there is provided a method for detecting illegal software, the method comprising:
[0006] When the current moment matches any candidate acquisition moment, acquiring candidate registry information respectively corresponding to at least one candidate software in a target terminal, and determining a software to be detected from each of the candidate software according to the illegal registry information and each of the candidate registry information; wherein, the illegal registry information is determined according to the registry information corresponding to the illegal software;
[0007] Obtaining attribute information of the software to be detected corresponding to the software to be detected, and using a target large language model to predict a violation probability value that the software to be detected is an illegal software according to the attribute information of the software to be detected;
[0008] Performing illegal detection on the software to be detected according to the violation probability value.
[0009] According to another aspect of the present invention, there is provided a device for detecting illegal software, the device comprising:
[0010] A software to be detected determination module, configured to collect candidate registry information corresponding to at least one candidate software in a target terminal when the current moment matches any candidate collection moment, and determine the software to be detected from each of the candidate software according to the illegal registry information and each of the candidate registry information; wherein, the illegal registry information is determined according to the registry information corresponding to the illegal software;
[0011] An illegal probability value prediction module, configured to obtain the attribute information of the software to be detected corresponding to the software to be detected, and use a target large language model to predict the illegal probability value of the software to be detected being an illegal software according to the attribute information of the software to be detected;
[0012] An illegal detection module, configured to perform illegal detection on the software to be detected according to the illegal probability value.
[0013] According to another aspect of the present invention, there is provided an electronic device, the electronic device includes:
[0014] At least one processor; and
[0015] A memory communicatively connected to the at least one processor; wherein,
[0016] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the detection method of the illegal software according to any one of the present invention.
[0017] According to another aspect of the present invention, there is provided a computer-readable storage medium, the computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the detection method of the illegal software according to any one of the present invention when executed by a processor.
[0018] According to another aspect of the present invention, there is provided a computer program product, including a computer program, and the computer program implements the detection method of the illegal software according to any one of the present invention when executed by a processor.
[0019] The present invention first collects candidate registry information corresponding to candidate software, and uses the illegal registry information and candidate registry information to determine the software to be detected from the candidate software, and then uses a target large language model to predict the illegal probability value of the software to be detected being an illegal software according to the attribute information of the software to be detected for illegal detection, thereby combining the two methods of "registry information matching" and "intelligent prediction of large language model" to detect illegal software, further ensuring the accuracy of illegal software detection; and, there is no need for manual review, which can improve the efficiency of illegal software detection.
[0020] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become readily understood from the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0022] Figure 1 It is a flowchart of a method for detecting illegal software provided in Embodiment 1 of the present invention;
[0023] Figure 2 It is a flowchart of a method for detecting illegal software provided in Embodiment 2 of the present invention;
[0024] Figure 3 It is a flowchart of a method for detecting illegal software provided in Embodiment 3 of the present invention;
[0025] Figure 4 It is a schematic structural diagram of a device for detecting illegal software provided in Embodiment 4 of the present invention;
[0026] Figure 5 It is a schematic structural diagram of an electronic device for implementing the method for detecting illegal software in the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0027] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0028] It should be noted that the terms "candidate", "target", "violation", "first", "second", etc. in the specification, claims and above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0029] Embodiment 1
[0030] Figure 1 The figure is a flowchart of a method for detecting a software with violations provided for Embodiment 1 of the present invention. This embodiment is applicable to the situation of detecting software installed in a terminal for violations. This method can be executed by a detection device for software with violations, and the detection device for software with violations can be implemented in the form of hardware and / or software. As Figure 1 shown, the method includes:
[0031] S101. When the current moment matches any candidate collection moment, collect candidate registry information corresponding to at least one candidate software in the target terminal, and determine the software to be detected from each candidate software according to the violation registry information and each candidate registry information.
[0032] Among them, the current moment refers to the moment corresponding to the current time point. The candidate collection moment refers to the moment corresponding to at least one preset collection time point, and the collection time point refers to the time point corresponding to when the registry information collection operation is triggered. For example, assuming that the candidate collection moments include moment T, moment T + 1, and moment T + 2, it means that the registry information collection operations are triggered at moment T, moment T + 1, and moment T + 2 respectively.
[0033] The target terminal can be any electronic terminal capable of installing software, including but not limited to a computer, a smart phone, a smart tablet, etc. At least one software is installed in the target terminal as candidate software, and the candidate software can be any type of software, including but not limited to system software, support software, and application software, etc.
[0034] The candidate registry information refers to the software registry information corresponding to the candidate software, and the software registry information includes software configuration information, user setting information, software description information, software status information, etc. The illegal registry information is determined based on the registry information corresponding to the illegal software. It can be understood that the illegal registry information refers to the software registry information corresponding to the illegal software, and the illegal registry information can be set based on historical experience, and can also be collected through a public illegal software database, etc.
[0035] In one implementation, the current moment is matched with each candidate collection moment. If the current moment does not match any candidate collection moment, the registry information collection operation is not triggered, and the current moment continues to be matched with each candidate collection moment; if the current moment matches any candidate collection moment, the registry information collection operation is triggered, that is, first determining each candidate software currently installed in the target terminal, and further collecting the candidate registry information corresponding to each candidate software from the area of the target terminal used to store software registry information.
[0036] Further, the violation registry information corresponding to at least one violation software is obtained from the pre-collected violation software list, and each violation registry information is matched with each candidate registry information, and the software to be detected is further determined from each candidate software according to the matching result. It can be understood that the software to be detected refers to the candidate software whose candidate registry information is similar to the violation registry information, that is, the candidate software with violation risk.
[0037] S102: Acquire the software attribute information corresponding to the software to be detected, and use the target large language model to predict the violation probability value of the software to be detected being illegal software according to the software attribute information.
[0038] Among them, the software attribute information to be detected refers to the software attribute information corresponding to the software to be detected, including but not limited to the software name, software version, software manufacturer, software path, executable program name, and number of times collected, etc. A large language model refers to a deep learning model with a large parameter scale, which is mainly used to perform various natural language processing (NLP) tasks, such as generating and classifying text, answering questions in a conversational manner, etc. It usually adopts a Transformer-based architecture, which can efficiently process and understand complex language descriptions and convert them into text information. Under normal circumstances, the parameter scale of a large language model can even reach hundreds of billions. It is understandable that the target large language model can be selected from the public large language models according to actual business needs to ensure the portability and strong robustness of the solution.
[0039] The violation probability value reflects the likelihood that the software to be detected is a violation software. It can be understood that the larger the violation probability value, the greater the likelihood that the software to be detected is a violation software. Correspondingly, the smaller the violation probability value, the smaller the likelihood that the software to be detected is a violation software.
[0040] In one implementation, information is collected for each software to be detected, and the software attribute information corresponding to each software to be detected collected is respectively used as the software attribute information to be detected corresponding to each software to be detected. Further, the software attribute information to be detected and the first description text are jointly input into the target large language model, and the target large language model outputs the predicted violation probability value that the software to be detected is a violation software according to the software attribute information to be detected and the first description text. Among them, the first description text is used to prompt the target large language model to predict the violation probability value according to the software attribute information to be detected. For example, it can be "Please predict the violation probability value that it is a violation software according to the input software attribute information to be detected", etc. The specific content of the first description text is not limited in this embodiment.
[0041] In another implementation, information is collected for each software to be detected, and the software attribute information corresponding to each software to be detected collected is respectively used as the software attribute information to be detected corresponding to each software to be detected, and the violation software attribute information collected in advance is obtained. Further, the software attribute information to be detected, the violation software attribute information and the second description text are jointly input into the target large language model, and the target large language model outputs the predicted violation probability value that the software to be detected is a violation software according to the software attribute information to be detected, the violation software attribute information and the second description text. Among them, the second description text is used to prompt the target large language model to predict the violation probability value according to the software attribute information to be detected and the violation software attribute information. For example, it can be "Please predict the violation probability value that it is a violation software according to the input software attribute information to be detected and the violation software attribute information", etc. The specific content of the second description text is not limited in this embodiment.
[0042] S103. Perform violation detection on the software to be detected according to the violation probability value.
[0043] In one implementation, the violation probability values corresponding to each software to be detected are respectively compared with the probability value threshold, and it is determined whether each software to be detected is a violation software according to the comparison result. It can be understood that if the violation probability value corresponding to any software to be detected is less than the probability value threshold, it means that the likelihood that the software to be detected is a violation software is small, then it is determined that the software to be detected is not a violation software; if the violation probability value corresponding to any software to be detected is greater than or equal to the probability value threshold, it means that the likelihood that the software to be detected is a violation software is large, then it is determined that the software to be detected is a violation software.
[0044] In another embodiment, the difference operation is performed between the violation probability values corresponding to each software to be detected and the probability value threshold, and whether each software to be detected is a violation software is determined according to the positive or negative nature of the difference operation result. It can be understood that if the difference operation result corresponding to any software to be detected is negative, it is determined that the software to be detected is not a violation software; if the difference operation result corresponding to any software to be detected is non-negative, it is determined that the software to be detected is a violation software.
[0045] In the embodiment of the present invention, by first collecting the candidate registry information corresponding to the candidate software, and using the violation registry information and the candidate registry information to determine the software to be detected from the candidate software, and then using the target large language model to predict the violation probability value of the software to be detected as a violation software according to the attribute information of the software to be detected for violation detection, so as to combine the two methods of "registry information matching" and "intelligent prediction of large language model" to detect violation software, further ensuring the accuracy of violation software detection; moreover, there is no need for manual review, which can improve the efficiency of violation software detection.
[0046] Embodiment 2
[0047] Figure 2 It is a flowchart of a method for detecting a violation software provided by Embodiment 2 of the present invention. This embodiment further optimizes and expands the above embodiment, and can be combined with each of the above optional implementation manners. As Figure 2 shown, the method includes:
[0048] S201. When the current moment matches any candidate collection moment, collect the candidate registry information corresponding to at least one candidate software in the target terminal.
[0049] S202. Match the violation registry information with each candidate registry information to determine the first information similarity between the violation registry information and each candidate registry information.
[0050] In one embodiment, an information similarity matching algorithm is used to match the violation registry information with each candidate registry information, and the information similarity between the violation registry information and each candidate registry information is determined as the first information similarity.
[0051] S203. The candidate registry information with the first information similarity greater than or equal to the first similarity threshold to the violation registry information is used as the target registry information, and the candidate software corresponding to the target registry information is used as the software to be detected.
[0052] Exemplarily, assume that the candidate software includes candidate software A, candidate software B, candidate software C, and candidate software D. Candidate software A corresponds to candidate registry information 1, candidate software B corresponds to candidate registry information 2, candidate software C corresponds to candidate registry information 3, and candidate software D corresponds to candidate registry information 4.
[0053] Assume that the first information similarity between candidate registry information 1 and any violation registry information is 70%; the first information similarity between candidate registry information 2 and any violation registry information is 75%; the first information similarity between candidate registry information 3 and any violation registry information is 85%; the first information similarity between candidate registry information 4 and any violation registry information is 95%. Assume that the first similarity threshold is 80%. Then, determine candidate software C corresponding to candidate registry information 3 and candidate software D corresponding to candidate registry information 4 as the software to be detected.
[0054] By matching the violation registry information with each candidate registry information, the first information similarity between the violation registry information and each candidate registry information is determined; the candidate registry information with the first information similarity greater than or equal to the first similarity threshold with the violation registry information is used as the target registry information; the candidate software corresponding to the target registry information is used as the software to be detected. The beneficial effects are as follows:
[0055] First, it realizes the effect of preliminarily screening candidate software with violation risks by using the method of "registry information matching", avoiding directly using the target large language model to predict the violation probability values for all candidate software, which leads to a large workload and low prediction efficiency. On the premise of ensuring the detection accuracy of violation software, it further improves the detection efficiency of violation software.
[0056] Second, due to the introduction of the calculation of information similarity and the threshold comparison mechanism, the screening redundancy of candidate software with violation risks is increased, avoiding the problem of missed screening of candidate software with violation risks, and further improving the detection accuracy of violation software.
[0057] S204. Obtain the property information of the software to be detected corresponding to the software to be detected, and obtain the property information of the violation software corresponding to the violation software. Then, use the target large language model to predict the violation probability value that the software to be detected is a violation software based on the property information of the software to be detected and the property information of the violation software.
[0058] Among them, the property information of the violation software refers to the software property information corresponding to the violation software. The property information of the violation software can be set according to historical experience or collected through a publicly available violation software database, etc.
[0059] In one implementation, information is collected for each software to be detected, and the software attribute information corresponding to each software to be detected collected is used as the software attribute information to be detected corresponding to each software to be detected. Further, the attribute information of at least one illegal software corresponding to the illegal software is obtained from the pre-collected list of illegal software. Further, the software attribute information to be detected, the attribute information of the illegal software, and the description text are jointly input into the target large language model. The target large language model outputs the predicted probability value of the software to be detected being an illegal software based on the software attribute information to be detected, the attribute information of the illegal software, and the description text. Among them, the description text is used to prompt the target large language model to predict the probability value of being an illegal software based on the software attribute information to be detected and the attribute information of the illegal software. For example, it can be "Please predict the probability value of being an illegal software based on the input software attribute information to be detected and the attribute information of the illegal software", etc. The specific content of the description text is not limited in this embodiment.
[0060] By obtaining the attribute information of the illegal software corresponding to the illegal software; using the target large language model to predict the probability value of the software to be detected being an illegal software based on the software attribute information to be detected and the attribute information of the illegal software, the target large language model can use the "attribute information of the illegal software" as the reference information and combine the "software attribute information to be detected" to predict the probability value of being an illegal software. Compared with predicting the probability value of being an illegal software only based on the information in a single dimension of the "software attribute information to be detected", it can improve the accuracy and credibility of the prediction of the probability value of being an illegal software.
[0061] Optionally, using the target large language model to predict the probability value of the software to be detected being an illegal software based on the software attribute information to be detected and the attribute information of the illegal software includes:
[0062] A. Performing target information processing operations on the software attribute information to be detected to obtain first processed information, and performing target information processing operations on the attribute information of the illegal software to obtain second processed information.
[0063] Among them, the target information processing operations include at least one of missing value processing, duplicate value processing, and data standardization. Missing value processing includes, but is not limited to, filling missing values with mean, median, mode, etc. Duplicate value processing includes, but is not limited to, deleting duplicate records in the data. Data standardization includes converting the data into standard values, and the data can be normalized.
[0064] In one implementation, missing value processing, duplicate value processing, and data standardization are used to process the software attribute information to be detected to obtain first processed information, and missing value processing, duplicate value processing, and data standardization are used to process the attribute information of the illegal software to obtain second processed information.
[0065] B. Perform word vector conversion on the word segmentation result of the first processed information to generate a first word vector, and perform word vector conversion on the word segmentation result of the second processed information to generate a second word vector.
[0066] In one implementation, a word segmentation algorithm is used to perform word segmentation on the first processed information to obtain the word segmentation result of the first processed information, and further a word vector conversion algorithm is used to perform word vector conversion on the word segmentation result of the first processed information to generate a first word vector; and a word segmentation algorithm is used to perform word segmentation on the second processed information to obtain the word segmentation result of the second processed information, and further a word vector conversion algorithm is used to perform word vector conversion on the word segmentation result of the second processed information to generate a second word vector.
[0067] C. Use the target large language model to predict the violation probability value that the software to be detected is a violation software according to the first word vector and the second word vector.
[0068] In one implementation, the first word vector and the second word vector are jointly input into the target large language model, so that the target large language model predicts the violation probability value that the software to be detected is a violation software according to the first word vector and the second word vector.
[0069] By performing target information processing operations on the software attribute information to be detected to obtain the first processed information, and performing target information processing operations on the violation software attribute information to obtain the second processed information; performing word vector conversion on the word segmentation result of the first processed information to generate a first word vector, and performing word vector conversion on the word segmentation result of the second processed information to generate a second word vector; using the target large language model to predict the violation probability value that the software to be detected is a violation software according to the first word vector and the second word vector, making the information input into the target large language model more standard, complete and accurate, and further improving the accuracy of the prediction of the violation probability value.
[0070] S205. When the violation probability value is greater than the probability value threshold, determine that the software to be detected is a violation software.
[0071] In one implementation, compare the violation probability value with the probability value threshold. When the violation probability value is less than or equal to the probability value threshold, it means that the possibility that the software to be detected is a violation software is small, so determine that the software to be detected is not a violation software; when the violation probability value is greater than the probability value threshold, it means that the possibility that the software to be detected is a violation software is large, so determine that the software to be detected is a violation software.
[0072] S206. When it is detected that the software to be detected is in the open state, terminate the software process corresponding to the software to be detected and generate a violation software prompt message.
[0073] In one embodiment, the working state of each software to be detected that has been confirmed as a violation software is detected in real time. When it is detected that any software to be detected is in an open state, the software process corresponding to the software to be detected is further determined, and the software process corresponding to the software to be detected is terminated. At the same time, a violation software prompt message is generated and visually displayed on the display interface of the target terminal. For example, the violation software prompt message can be "This software is a violation software, please uninstall it immediately", etc.
[0074] By determining that the software to be detected is a violation software when the violation probability value is greater than the probability value threshold, terminating the software process corresponding to the software to be detected when it is detected that the software to be detected is in an open state, and generating a violation software prompt message, on the one hand, the effect of automatically terminating the software process of the violation software is achieved, so that the user cannot use the violation software, improving the security of the target terminal operation; on the other hand, because the violation software prompt message is generated, it can prompt the user the specific reason why the software cannot be opened, alleviating the sense of abruptness.
[0075] Embodiment III
[0076] Figure 3 The flowchart of a method for detecting a violation software provided in Embodiment III of the present invention further optimizes and expands the above embodiments and can be combined with the above various optional embodiments. As Figure 3 shown, the method includes:
[0077] S301. When it is detected that the candidate software process corresponding to any candidate software is opened, collect the candidate process information corresponding to the candidate software process, and determine whether the candidate software is the software to be detected according to the violation process information and the candidate process information.
[0078] Among them, the candidate process information refers to the process information of the candidate software process corresponding to the candidate software, and the process information includes process identifier, process status information, process priority, process resource allocation information, I / O device allocation information, etc. The violation process information is determined according to the process information of the violation software. It can be understood that the violation process information refers to the process information of the software process corresponding to the violation software, and the violation process information can be set according to historical experience, and can also be collected through a publicly available violation software database, etc.
[0079] In one implementation, it is detected in real time whether the candidate software processes of each candidate software are enabled on the target terminal. When it is detected that the candidate software process corresponding to any candidate software is enabled, information collection is performed on the candidate software process corresponding to the candidate software to obtain candidate process information. Further, the illegal process information corresponding to at least one illegal software is obtained from the pre-collected list of illegal software, and the illegal process information and the candidate process information are matched, and further, it is determined whether the candidate software is the software to be detected according to the matching result.
[0080] Optionally, determining whether the candidate software is the software to be detected according to the illegal process information and the candidate process information includes:
[0081] Match the illegal process information and the candidate process information to determine the second information similarity between the illegal process information and the candidate process information; in the case where the second information similarity is greater than or equal to the second similarity threshold, determine that the candidate software is the software to be detected.
[0082] In one implementation, an information similarity matching algorithm is used to match the illegal process information and the candidate process information to determine the information similarity between the illegal process information and the candidate process information as the second information similarity. Compare the second information similarity with the second similarity threshold. In the case where the second information similarity is less than the second similarity threshold, it means that the risk that the candidate software is an illegal software is not high, so it is determined that the candidate software is not the software to be detected; in the case where the second information similarity is greater than or equal to the second similarity threshold, it means that the risk that the candidate software is an illegal software is relatively high, so it is determined that the candidate software is the software to be detected.
[0083] By matching the illegal process information and the candidate process information to determine the second information similarity between the illegal process information and the candidate process information; in the case where the second information similarity is greater than or equal to the second similarity threshold, determining that the candidate software is the software to be detected, the beneficial effects are as follows:
[0084] Firstly, it realizes the effect of preliminarily screening candidate software with illegal risks by using the method of "process information matching", avoiding directly using the target large language model to predict the illegal probability values of all candidate software, resulting in a large workload and low prediction efficiency. On the premise of ensuring the detection accuracy of illegal software, the detection efficiency of illegal software is further improved.
[0085] Secondly, due to the introduction of the calculation of information similarity and the threshold comparison mechanism, the screening redundancy of candidate software with illegal risks is increased, avoiding the problem of missed screening of candidate software with illegal risks, and further improving the detection accuracy of illegal software.
[0086] S302. When the candidate software is the software to be detected, obtain the attribute information of the software to be detected corresponding to the software to be detected, and use the target large language model to predict the violation probability value of the software to be detected as a violation software according to the attribute information of the software to be detected.
[0087] In one implementation, when it is determined that the candidate software is the software to be detected, information collection is performed on each software to be detected, and the software attribute information corresponding to each software to be detected collected is respectively used as the attribute information of the software to be detected corresponding to each software to be detected. Further, the attribute information of the software to be detected and the description text are jointly input into the target large language model, and the target large language model outputs the predicted violation probability value of the software to be detected as a violation software according to the attribute information of the software to be detected and the description text.
[0088] S303. Perform violation detection on the software to be detected according to the violation probability value.
[0089] In the embodiment of the present invention, when it is detected that the candidate software process corresponding to any candidate software is started, the candidate process information corresponding to the candidate software process is collected, and it is determined whether the candidate software is the software to be detected according to the violation process information and the candidate process information; when the candidate software is the software to be detected, obtain the attribute information of the software to be detected corresponding to the software to be detected, and use the target large language model to predict the violation probability value of the software to be detected as a violation software according to the attribute information of the software to be detected; perform violation detection on the software to be detected according to the violation probability value, and the beneficial effects are as follows:
[0090] First, combine the two methods of "process information matching" and "intelligent prediction of large language model" to detect violation software, which further ensures the accuracy of violation software detection; moreover, there is no need for manual review, which can improve the efficiency of violation software detection.
[0091] Second, it realizes the effect of identifying violation software in real time according to the detected candidate process information, improves the timeliness of violation software identification, and further improves the security of the target terminal operation.
[0092] Third, it can be combined with the method of "registry information matching" to further expand the usage scenarios of violation software detection and enrich the detection means.
[0093] Embodiment 4
[0094] Figure 4 It is a schematic structural diagram of a detection device for violation software provided in Embodiment 4 of the present invention, which is applicable to the situation of detecting violation software installed in a terminal, such as Figure 4 As shown, the device includes:
[0095] The software to be detected determination module 41 is used to collect the candidate registry information corresponding to at least one candidate software in the target terminal when the current moment matches any candidate collection moment, and determine the software to be detected from each candidate software according to the illegal registry information and each candidate registry information; wherein, the illegal registry information is determined according to the registry information corresponding to the illegal software;
[0096] The illegal probability value prediction module 42 is used to obtain the attribute information of the software to be detected corresponding to the software to be detected, and use the target large language model to predict the illegal probability value of the software to be detected being an illegal software according to the attribute information of the software to be detected;
[0097] The illegal detection module 43 is used to perform illegal detection on the software to be detected according to the illegal probability value.
[0098] Optionally, the software to be detected determination module 41 is specifically used for:
[0099] Match the illegal registry information and each candidate registry information to determine the first information similarity between the illegal registry information and each candidate registry information;
[0100] Take the candidate registry information whose first information similarity with the illegal registry information is greater than or equal to the first similarity threshold as the target registry information;
[0101] Take the candidate software corresponding to the target registry information as the software to be detected.
[0102] Optionally, the illegal probability value prediction module 42 is specifically used for:
[0103] Obtain the attribute information of the illegal software corresponding to the illegal software;
[0104] Use the target large language model to predict the illegal probability value of the software to be detected being an illegal software according to the attribute information of the software to be detected and the attribute information of the illegal software.
[0105] Optionally, the illegal probability value prediction module 42 is specifically further used for:
[0106] Perform target information processing operations on the attribute information of the software to be detected to obtain first processed information, and perform the target information processing operations on the attribute information of the illegal software to obtain second processed information; wherein, the target information processing operations include at least one of missing value processing, duplicate value processing, and data standardization;
[0107] Perform word vector conversion on the word segmentation result of the first processed information to generate a first word vector, and perform word vector conversion on the word segmentation result of the second processed information to generate a second word vector;
[0108] Use the target large language model to predict the violation probability value that the software to be detected is a violation software according to the first word vector and the second word vector.
[0109] Optionally, the violation detection module 43 is specifically used for:
[0110] In the case where the violation probability value is greater than the probability value threshold, determine that the software to be detected is a violation software;
[0111] Optionally, the device further includes a process termination module, which is specifically used for:
[0112] When it is detected that the software to be detected is in an open state, terminate the software process corresponding to the software to be detected, and generate a violation software prompt message.
[0113] Optionally, the device further includes an auxiliary violation detection module, which is specifically used for:
[0114] When it is detected that any candidate software corresponding candidate software process is opened, collect the candidate process information corresponding to the candidate software process, and determine whether the candidate software is the software to be detected according to the violation process information and the candidate process information; wherein, the violation process information is determined according to the process information corresponding to the violation software;
[0115] In the case where the candidate software is the software to be detected, obtain the attribute information of the software to be detected corresponding to the software to be detected, and use the target large language model to predict the violation probability value that the software to be detected is a violation software according to the attribute information of the software to be detected;
[0116] Perform violation detection on the software to be detected according to the violation probability value.
[0117] Optionally, the auxiliary violation detection module is specifically further used for:
[0118] Match the violation process information and the candidate process information to determine the second information similarity between the violation process information and the candidate process information;
[0119] In the case where the second information similarity is greater than or equal to the second similarity threshold, determine that the candidate software is the software to be detected.
[0120] The detection device for violation software provided by the embodiments of the present invention can execute the detection method for violation software provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0121] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0122] Embodiment 5
[0123] Figure 5 FIG. shows a schematic structural diagram of an electronic device 50 that can be used to implement an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as, for example, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, a personal digital processor, a cellular phone, a smart phone, a wearable device (such as a helmet, glasses, a watch, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described herein and / or claimed.
[0124] As Figure 5 shown, the electronic device 50 includes at least one processor 51, and a memory communicatively connected to the at least one processor 51, such as a read-only memory (ROM) 52, a random access memory (RAM) 53, etc. The memory stores a computer program executable by the at least one processor. The processor 51 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 52 or the computer program loaded from the storage unit 58 into the random access memory (RAM) 53. In the RAM 53, various programs and data required for the operation of the electronic device 50 can also be stored. The processor 51, the ROM 52, and the RAM 53 are connected to each other through a bus 54. The input / output (I / O) interface 55 is also connected to the bus 54.
[0125] A plurality of components in the electronic device 50 are connected to the I / O interface 55, including: an input unit 56, such as a keyboard, a mouse, etc.; an output unit 57, such as various types of displays, speakers, etc.; a storage unit 58, such as a magnetic disk, an optical disk, etc.; and a communication unit 59, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 59 allows the electronic device 50 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0126] The processor 51 may be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 51 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 51 executes the various methods and processes described above, such as the method for detecting malicious software.
[0127] In some embodiments, the method for detecting malicious software can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 58. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 50 via the ROM 52 and / or the communication unit 59. When the computer program is loaded into the RAM 53 and executed by the processor 51, one or more steps of the method for detecting malicious software described above can be performed. Alternatively, in other embodiments, the processor 51 can be configured to execute the method for detecting malicious software by any other suitable means (e.g., by means of firmware).
[0128] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), systems-on-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs executable and / or interpretable on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0129] The computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer program can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0130] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0131] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0132] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0133] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs that run on respective computers and have a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0134] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0135] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for detecting illegal software, characterized in that: The method comprises: In the case where the current moment matches any candidate collection moment, candidate registry information corresponding to at least one candidate software in the target terminal is collected, and the software to be detected is determined from each candidate software according to the violation registry information and each candidate registry information; wherein the violation registry information is determined according to the registry information corresponding to the violation software; Acquire the software attribute information corresponding to the software to be detected, and use the target large language model to predict the violation probability value of the software to be detected being illegal software according to the software attribute information; The software to be detected is subjected to violation detection according to the violation probability value.
2. The method according to claim 1, characterized in that: The step of determining the software to be detected from each of the candidate software according to the violation registry information and each of the candidate registry information includes: Matching the illegal registration information with each of the candidate registration information to determine a first information similarity between the illegal registration information and each of the candidate registration information; The candidate registry information having a first information similarity with the illegal registry information greater than or equal to a first similarity threshold is used as the target registry information; The candidate software corresponding to the target registry information is used as the software to be detected.
3. The method according to claim 1, characterized in that: The using the target large language model to predict the violation probability value of the software to be detected as illegal software according to the attribute information of the software to be detected includes: Obtaining illegal software attribute information corresponding to illegal software; The target large language model is used to predict the violation probability value of the software to be detected being the illegal software according to the attribute information of the software to be detected and the attribute information of the illegal software.
4. The method according to claim 3, characterized in that The using the target large language model to predict the violation probability value of the software to be detected being the violating software according to the attribute information of the software to be detected and the attribute information of the violating software includes: The target information processing operation is used to process the attribute information of the software to be detected to obtain first processed information, and the target information processing operation is used to process the attribute information of the illegal software to obtain second processed information; wherein the target information processing operation includes at least one of missing value processing, duplicate value processing and data normalization; Performing word vector conversion on the word segmentation result of the first processing information to generate a first word vector, and performing word vector conversion on the word segmentation result of the second processing information to generate a second word vector; The target large language model is used to predict the violation probability value of the software to be detected as illegal software according to the first word vector and the second word vector.
5. The method according to claim 1, characterized in that The performing violation detection on the software to be detected according to the violation probability value includes: When the violation probability value is greater than the probability value threshold, determining that the software to be detected is a violation software; After determining that the software to be detected is illegal software, the method further includes: When it is detected that the software to be detected is in an on state, the software process corresponding to the software to be detected is terminated, and illegal software prompt information is generated.
6. The method according to claim 1, further comprising: When it is detected that the candidate software process corresponding to any of the candidate software is started, the candidate process information corresponding to the candidate software process is collected, and whether the candidate software is the software to be detected is determined based on the illegal process information and the candidate process information; wherein the illegal process information is determined based on the process information corresponding to the illegal software; In the case where the candidate software is the software to be detected, obtaining the software to be detected attribute information corresponding to the software to be detected, and using the target large language model to predict the violation probability value of the software to be detected being the violation software according to the software to be detected attribute information; The software to be detected is subjected to violation detection according to the violation probability value.
7. The method according to claim 6, characterized in that The step of determining whether the candidate software is the software to be detected based on the illegal process information and the candidate process information includes: Matching the illegal process information with the candidate process information to determine a second information similarity between the illegal process information and the candidate process information; When the second information similarity is greater than or equal to a second similarity threshold, the candidate software is determined to be the software to be detected.
8. A device for detecting illegal software, characterized in that: The device comprises: The software to be detected determining module is used to collect candidate registry information corresponding to at least one candidate software in the target terminal when the current moment matches any candidate collection moment, and determine the software to be detected from each candidate software according to the violation registry information and each candidate registry information; wherein the violation registry information is determined according to the registry information corresponding to the violation software; A violation probability value prediction module is used to obtain the property information of the software to be detected corresponding to the software to be detected, and use the target large language model to predict the violation probability value of the software to be detected as illegal software according to the property information of the software to be detected; The violation detection module is used to perform violation detection on the software to be detected according to the violation probability value.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the method for detecting illegal software according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to execute the method for detecting illegal software according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the method for detecting illegal software according to any one of claims 1 to 7.