Safety protection equipment, safety protection method and safety protection system
By designing a security protection device to isolate the direct contact between USB devices and computing devices, and scan and anti-virus files during transmission, the virus intrusion caused by malicious USB devices is solved, and the security protection of computing devices and USB devices is achieved.
Patent Information
- Application Number
- CN202410060338.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-25
- Filing Date
- 2024-01-15
- Publication Date
- 2025-06-27
AI Technical Summary
The prior art is difficult to effectively prevent virus invasion caused by malicious USB devices through direct contact with computing devices, resulting in security risks to computing devices and USB devices.
Design a security protection device to isolate direct contact between the two by connecting to the USB device and the computing device, and use the first security protection device to scan and kill files in the USB device to ensure that the files transmitted to the computing device are free of viruses.
Effectively prevent viruses from spreading to computing devices through USB devices, reduce the security risks of computing devices and USB devices, and ensure the security during file transfer.
Smart Images

Figure CN120217367A_ABST
Abstract
Description
[0001] This application claims the priority of a Chinese patent application with the application number 202311816432.5 and the invention title "Security Protection Equipment and Security Protection Method" filed with the China National Intellectual Property Administration on December 25, 2023, the entire content of which is incorporated herein by reference. Technical Field
[0002] This application relates to the field of computer technology, and in particular, to a security protection equipment, a security protection method, and a security protection system. Background Art
[0003] With the popularization of computing devices such as computers and servers, and the increasing external intrusion attacks on high-risk vulnerabilities in computing devices, people face more security risks when using computing devices.
[0004] Currently, malicious Universal Serial Bus (USB) devices disguise themselves as human-machine interface devices, connect to the target computing device, and then execute malicious commands or inject malicious payloads, infiltrating and invading by disguising as keyboards, spreading viruses, etc. During the process of infecting a computing device with malicious code by a malicious USB device, the user is completely unaware, and at the same time, it will not cause the slightest alarm from antivirus software or firewalls, which poses a great hidden danger to the security of the computing device.
[0005] Therefore, it is urgent to ensure the security protection of computing devices. Summary of the Invention
[0006] This application provides a security protection equipment, a security protection method, and a security protection system, which can avoid direct contact between the USB device and the computing device, prevent viruses from invading the computing device or the USB device, and ensure the security of the computing device or the USB device.
[0007] In a first aspect, this application provides a security protection equipment. The USB device can be connected to the security protection equipment, and the security protection equipment can be connected to the computing device. In this way, the USB device can transfer files to and from the computing device through the security protection equipment. To avoid direct contact between the USB device and the computing device, which may cause the computing device or the USB device to be invaded by viruses, during the file transfer process, the security protection equipment needs to scan the files. In the case where the transferred files contain virus files, all the files are disinfected, and the virus files are deleted, thereby preventing the spread of viruses to the computing device or the USB device.
[0008] In a possible implementation, the security protection device includes a first security protection device and a second security protection device that communicate with each other. The first security protection device can mount the file system of the USB device to obtain the files in the USB device. After the first security protection device obtains the files in the USB, it scans the files. If the files contain virus files, it disinfects the files and deletes the virus files. The second security protection device can access the computing device and communicate with the first security protection device to obtain the files in the first security protection device. At this time, the files in the first security protection device are the files after disinfection. In this way, the second security protection device transmits the disinfected files to the computing device, thus preventing the virus from invading the computing device when the files in the USB device carry the virus.
[0009] In a possible implementation, the security protection device includes a first security protection device and a second security protection device that communicate with each other. The second security protection device can access the computing device to obtain the files in the computing device. The second security protection device transmits the files to the first security protection device by communicating with the first security protection device. In this way, the first security protection device scans the files. If the files contain virus files, it disinfects the files and deletes the virus files. In this way, it can prevent the computing device from transmitting virus-infected files to the USB device and the virus from invading the USB device. It also prevents other computing devices from being invaded by the virus.
[0010] In a possible implementation, the first security protection device and the second security protection device communicate wirelessly. In this way, the computing device and the USB device can be isolated to prevent virus-infected files from invading the computing device or the USB device.
[0011] In a possible implementation, the first security protection device and the second security protection device perform file transfer through the Secure Copy Protocol (SCP) or the remote synchronization protocol. In this way, the computing device and the USB device can be isolated to prevent virus-infected files from invading the computing device or the USB device.
[0012] In a possible implementation, when the USB device is connected to the security protection device, the security protection device is also used to obtain the electrical parameters that trigger the USB device and / or the identity identifier of the USB device, and determine whether to mount the file system of the USB device according to the electrical parameters of the USB device and / or the identity identifier of the USB device. In this way, it can directly prohibit malicious USB devices from communicating with the computing device and reduce the risk of the computing device being invaded by the virus.
[0013] In a possible implementation, the identity identifier of the USB device includes the brand information of the USB device and / or the device descriptor of the USB device.
[0014] In a possible implementation, the security protection device is further configured to send a file to the cloud platform for the cloud platform to scan the file; the security protection device receives the file scan result sent by the cloud platform and determines whether the file contains a virus file according to the file scan result. In this way, the recognition accuracy and reliability of virus files can be improved, and the risk of the computing device or the USB device being invaded by viruses can be reduced.
[0015] In a possible implementation, the first security protection device is further configured to synchronize the second file to the USB device. In this way, it is possible to avoid deleting the virus file in the USB device.
[0016] In a possible implementation, when the first file is a virus file, the security protection device is further configured to generate a virus killing event and send the virus killing event to the cloud platform for the cloud platform to store the virus killing event. In this way, the cloud platform can enrich virus cases and improve the accuracy of virus killing.
[0017] In a possible implementation, the security protection device includes a first Universal Serial Bus (USB) interface and a second USB interface; the security protection device is connected to the USB device through the first USB interface and accesses the computing device through the second USB interface.
[0018] In a possible implementation, the security protection device includes a control switch for the user to control the startup of the security protection device through the control switch.
[0019] In a second aspect, the present application provides a security protection method applied to the security protection device described in the first aspect. The method includes:
[0020] The USB device can be connected to the security protection device, and the security protection device can be connected to the computing device. In this way, the USB device can transfer files with the computing device through the security protection device. To avoid the direct contact between the USB device and the computing device, which may cause the computing device or the USB device to be invaded by viruses, during the file transfer process, it is necessary to scan the file through the security protection device. When the transferred file contains a virus file, all files are disinfected and the virus file is deleted, thereby preventing the virus from spreading to the computing device or the USB device.
[0021] In a third aspect, the present application provides a security protection system, including a USB device and the security protection device described in the first aspect.
[0022] Fourth aspect, the present application provides a security protection device, including: at least one memory for storing programs; at least one processor for executing the programs stored in the memory, and when the programs stored in the memory are executed, the processor is used to execute the method provided in the first aspect.
[0023] Fifth aspect, the present application provides a security protection device, characterized in that the security protection device runs computer program instructions to execute the method provided in the first aspect. Exemplarily, the device can be a chip or a processor.
[0024] In one example, the device can include a processor, which can be coupled to a memory, read instructions in the memory and execute the method provided in the first aspect according to the instructions. Among them, the memory can be integrated in the chip or the processor, or can be independent of the chip or the processor.
[0025] Sixth aspect, the present application provides a computer storage medium, in which instructions are stored, and when the instructions run on a computer, the computer is made to execute the method provided in the first aspect.
[0026] Seventh aspect, the present application provides a computer program product containing instructions, and when the instructions run on a computer, the computer is made to execute the method provided in the first aspect. Description of the Drawings
[0027] Figure 1a is a schematic diagram of an application scenario in the prior art provided by the present application;
[0028] Figure 1b is a schematic diagram of another application scenario in the prior art provided by the present application;
[0029] Figure 1c is a schematic diagram of an application scenario provided by the present application;
[0030] Figure 2a is one of the structural schematic diagrams of a security protection device provided by the present application;
[0031] Figure 2b is another structural schematic diagram of a security protection device provided by the present application;
[0032] Figure 3 is yet another structural schematic diagram of a security protection device provided by the present application;
[0033] Figure 4 is still another structural schematic diagram of a security protection device provided by the present application;
[0034] Figure 5It is a schematic diagram of the file flow in an application scenario provided by this application;
[0035] Figure 6 It is a schematic diagram of the file flow in another application scenario provided by this application;
[0036] Figure 7 It is the fifth schematic diagram of the structure of a security protection device provided by this application;
[0037] Figure 8 It is the sixth schematic diagram of the structure of a security protection device provided by this application;
[0038] Figure 9 It is a schematic diagram of the process of a security protection method provided by this application. Detailed implementation manners
[0039] With the popularization of computing devices such as computers and servers, and the increase in external intrusion attacks on high-risk vulnerabilities in computing devices, people face more security risks when using computing devices.
[0040] Currently, as Figure 1a shown, malicious USB devices disguise themselves as human-machine interface devices, connect to the target computing device, and then execute malicious commands or inject malicious payloads, infiltrating and invading by disguising as keyboards, spreading viruses, etc. When malicious USB devices infect computing devices with malicious code, users are completely unaware, and at the same time, it will not cause the slightest alarm from anti-virus software and firewalls, which poses a great hidden danger to the security of computing devices.
[0041] Such as Figure 1b shown, when a virus-infected file in a computing device is transferred to a USB device, the virus will invade the USB device. When the USB is connected to other computing devices, it will cause the virus to spread among a large number of computing devices, posing a great hidden danger to the security of computing devices.
[0042] Based on this, this application proposes a security protection device, a security protection method, and a security protection system. File transfer between the computing device and the USB device is carried out through the security protection device; wherein, when the security protection device is connected to the computing device and the USB device is connected to the security protection device, the security protection device is used to scan the files in the security protection device; the security protection device is used to disinfect the file and delete the first file when the first file is a virus file, and the file includes the first file. By scanning the files transmitted between the USB device and the computing device in advance and disinfecting the files before transmitting them to the computing device or the USB device, the direct contact between the USB device and the computing device is avoided, and the virus-infected files are prevented from invading the computing device or the USB device.
[0043] As Figure 1c shown, in some application scenarios, when the USB device 11 needs to transfer files to the computing device 12, the USB device 11 needs to be connected to the computing device 12. To prevent the possible viruses carried by the USB device 11 from invading the computing device 12. Therefore, file transfer is carried out between the computing device 12 and the USB device 11 through the security protection device 13, so as to prevent the computing device 12 from being invaded by the viruses carried by the USB device.
[0044] In this application, to facilitate the user to carry the security protection device, the form of the security protection device is a patch type. In this way, the security protection device is small and convenient to carry.
[0045] Next, the specific structure and functions of the security protection device provided by this application will be described in detail.
[0046] Figure 2a is a schematic structural diagram of the security protection device provided by this application. As Figure 2a shown, the security protection device provided by this application includes a processor 21, a memory 22, and a communication interface 23.
[0047] Among them, the processor 21 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or this processor can also be any conventional processor, etc.
[0048] The memory 22 may include non-volatile memory, where the non-volatile memory may be read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), or flash memory. The volatile memory may be random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0049] Among them, the memory 22 is used to store an operating system and executable program code. The operating system includes but is not limited to Windows system (an operating system), Linux system (an operating system), HarmonyOS (an operating system), etc., which are not limited here.
[0050] Exemplarily, a computer program may be stored on the memory 22, and the processor 21 implements the solution in this application when executing the computer program.
[0051] The communication interface 23 is used to transfer files. For example, obtaining files from a USB device, receiving files from a computing device, sending files to a USB device, or sending files to a computing device. In this application, the communication interface 23 includes a wired communication interface and a wireless communication interface. For example, the wired communication interface may be a USB interface, etc., and the wireless communication interface may be a Wireless Fidelity (WiFi) port, a fourth-generation mobile communication technology port, a fifth-generation mobile communication technology port, etc.
[0052] In this application, as Figure 2bAs shown, the communication interface of the security protection device includes a first USB interface 231 and a second USB 232. Among them, the USB device is connected to the security protection device through the first USB interface, and the security protection device is connected to the computing device through the second USB interface. When the USB device is connected to the security protection device and the security protection device is connected to the computing device, file transfer can be carried out between the computing device and the USB device, that is, the USB device sends files to the computing device, and the computing device sends files to the USB device.
[0053] In this application, during the file transfer process, the security protection device is used to obtain files and perform virus scanning on the files. In the case where the first file is a virus file, all files are disinfected and the first file is deleted. Among them, the first file can be any one of all files. In some embodiments, when the security protection device is connected to the computing device, the computing device can display the security protection device as a USB flash drive, so as to facilitate the user to operate the files in the security protection device through the computing device.
[0054] As a possible implementation method, an antivirus policy is deployed in the security protection device, where the antivirus policy is used to indicate whether to delete virus files. For example, it is determined whether to delete virus files according to the format of the virus files. Exemplarily, when the format of the virus file is a text document (txt, a file format), there is no need to delete the virus file. When the format of the virus file is an executable program (EXE), the virus file is deleted.
[0055] In this application, the security protection device is used to obtain files through the communication interface 23 and store the files in the memory 22. The processor 21 scans the files in the memory and performs antivirus processing and the like.
[0056] The security protection device provided by this application is small and portable, with high flexibility, and can enable the computing device side to avoid virus intrusion at zero cost. At the same time, it enables computing devices without security antivirus software to avoid virus intrusion.
[0057] In some embodiments, the communication interface 23 is also used to communicate with the network. As a possible implementation, the communication interface 23 also includes a wireless network card to achieve communication with the network. Among them, the wireless network card can be built-in and integrated in the security protection device. Or, the security protection device can externally connect a wireless network card to achieve communication with the network.
[0058] For example, as Figure 3As shown, the security protection device communicates with the cloud platform 32 via WiFi 31 to perform cloud scanning on files, and can also perform end-cloud linkage to scan files and update the anti-virus policies in the security protection device, etc.
[0059] The security protection device can scan files through the cloud platform 32 to identify virus files. The cloud platform 32 transmits the scan results to the security protection device, and the security protection device can determine virus files based on the scan results and / or the results of offline scanning. For example, the security protection device can send a file to the cloud platform for scanning to obtain the scan results. The cloud platform sends the scan results to the security protection device, and the security protection device deletes the virus files according to the scan results. Another example is that the security protection device extracts file features and sends the file features to the cloud platform, and the cloud platform determines whether the file is a virus file based on the file features. In this way, end-cloud linkage can be achieved to scan and disinfect files, improving the accuracy and reliability of identifying virus files.
[0060] As a possible implementation, file scanning rules and a virus library can be deployed in the cloud platform 32. The file scanning rules are used to indicate the file features that need to be extracted before scanning a file. The file features are used to indicate the characteristics reflected by the content, format, etc. of the file. For example, the Message Digest Algorithm (MD5) value of the file, the static features of the file, and the dynamic features of the file. Among them, the static features of the file include the file content and the file format. The dynamic features of the file include the operations performed by the file when executed in a sandbox, etc. Here, the extraction method of the file features is determined according to the type of the file features.
[0061] Exemplarily, taking the file feature as the MD5 value as an example, the virus file scanning by the cloud platform is described. The file scanning rules include extracting the MD5 value of the file, and the virus library includes the MD5 values corresponding to different virus files. The security protection device can calculate the MD5 value of the file locally through the Message Digest Algorithm (MD5), and thus send the MD5 value of the file to the cloud platform. The cloud platform compares the MD5 value of the file with the MD5 values corresponding to the virus files in the virus library to determine whether the file is a virus file. If the MD5 value of the file is the same as the MD5 value corresponding to the virus file in the virus library, the file is a virus file.
[0062] Exemplarily, taking the file features as static features as an example, the virus file killing on the cloud platform will be described. The file killing rules include extracting the static features of the file, and the virus library includes the static features of the virus files. For example, the static features include the file content and the file format. The security protection device sends the file to the cloud platform. The cloud platform calculates the information entropy based on the file content and the file format, and based on the information entropy, compares the information entropy of the virus files in the virus library to determine whether the file is a virus file.
[0063] Exemplarily again, taking the file features as dynamic features as an example, the virus file killing on the cloud platform will be described. The file killing rules include extracting the dynamic features of the file, and the virus library includes the dynamic features of the virus files. The dynamic features include the operations performed by the file in the sandbox, and the virus library includes the operations harmful to the operating system performed by the virus files in the sandbox. The cloud platform calls the sandbox interface of the security protection device to determine the operations performed by the file in the sandbox. The cloud platform compares the operations performed by the file in the sandbox with the operations harmful to the operating system performed by the virus files in the virus library to determine whether the file is a virus file.
[0064] Here, in order to improve the accuracy of virus killing, the cloud platform can combine static features and dynamic features to perform virus killing. For example, if any one of the static features and dynamic features conforms to the features of the virus file, it is determined that the file is a virus file.
[0065] This application only gives examples of the file killing rules and the virus library, and may also include various file killing rules, which are not specifically limited in this application.
[0066] As another possible implementation, an antivirus software is deployed in the cloud platform 32. The security protection device sends the file to the cloud platform 32, and the cloud platform 32 calls the antivirus software to perform a virus scan on the file.
[0067] In some embodiments, the file killing rules and the virus library can be deployed in the security protection device. The security protection device can scan and kill viruses on the file according to the file killing rules and the virus library. Among them, for the implementation method of scanning and killing viruses through the file killing rules and the virus library, reference can be made to the detailed description in the above embodiments (the cloud platform scans and kills viruses through the file killing rules and the virus library), which will not be elaborated here. In addition, the security protection device can perform end-cloud linkage with the cloud platform to dynamically update the file killing rules and the virus library in the security protection device to improve the accuracy of the security protection device for file killing.
[0068] In some embodiments, when a USB device is connected to the security protection device, the security protection device is further configured to obtain the electrical parameters of the USB device and / or the identity identifier of the USB device. Among them, sensors are deployed in the security protection device. When the USB device is connected to the security protection device and the security protection device is connected to a computing device, the security protection device can collect the electrical parameters of the USB device through the sensors. When the USB device is connected to the security protection device and the security protection device is connected to a computing device, the security protection device can read the identity identifier of the USB device.
[0069] When the USB device is connected to the security protection device and the security protection device is connected to a computing device, determine whether to mount the file system of the USB device according to the electrical parameters of the USB device and / or the identity identifier of the USB device. For example, taking the electrical parameters of a normal USB device as a standard, when the fluctuation range of the electrical parameters of the USB device is within the preset fluctuation range standard, determine that the USB device is a normal USB device, and thus mount the file system of the USB device. Otherwise, the USB device is a malicious USB device, and the security protection device prohibits mounting the file system of the USB device. Another example is that an identity identifier information table is configured in the security protection device. The identity identifier information table is used to indicate the identity identifiers of the USB devices for which the security protection device can mount the file system. When the identity identifier of the USB device can be matched in the identity identifier information table, the USB device is a normal USB device, and the security protection device can mount the file system of the USB device.
[0070] The electrical parameters can be the startup voltage waveform or the startup current waveform. Exemplarily, the startup voltage waveform or the startup current waveform of a normal USB device is stored in the security protection device. Taking the startup voltage waveform of a normal USB device as a standard, determine whether to mount the file system of the USB device according to the fluctuation of the startup voltage waveform of the USB device. For example, taking the startup voltage waveform of a normal USB device as a standard, when the fluctuation range of the startup voltage waveform of the USB device is greater than the preset fluctuation range, determine that the USB device is a malicious USB device, and the security protection device does not mount the file system of the USB device.
[0071] Alternatively, taking the startup current waveform of a normal USB device as a standard, determine whether to mount the file system of the USB device according to the startup current waveform of the USB device. For example, taking the startup current waveform of a normal USB device as a standard, when the fluctuation range of the startup current waveform of the USB device is greater than the preset fluctuation range, determine that the USB device is a malicious USB device, and the security protection device does not mount the file system of the USB device.
[0072] The identity identifier includes the descriptor of the USB device, the brand information of the USB device, etc. In this way, it is possible to determine whether the USB device is a normal USB device, so that communication between malicious USB devices and computing devices can be directly prohibited, reducing the risk of the computing device being invaded by viruses. For example, USB devices are divided into storage USB devices and non-storage USB devices. According to the identity identifier of the USB device, the category of the USB device can be identified. The security protection device can access storage USB devices and block non-storage USB devices. Another example is that the security protection device stores different brand names (such as vender identifiers), and the USB devices corresponding to these brand names are the USB devices allowed to be accessed by the security protection device. The security protection device determines whether the brand of the USB device belongs to the brand of the USB device allowed to be accessed by the security protection device according to the brand information of the USB device. If so, the USB device is allowed to be accessed; if not, the USB device is blocked. In this way, malicious USB devices can be prevented from accessing the security protection device, avoiding the computing device being invaded by viruses.
[0073] In some embodiments, as Figure 4 shown, the security protection device includes a first security protection device 41 and a second security protection device 42. Among them, the first security protection device and the second security protection device can communicate wired or wirelessly. For example, file transfer can be performed between the first security protection device 41 and the second security protection device 42 through SCP, remote synchronization protocol, or Transmission Control Protocol (TCP), etc.
[0074] It can be understood that the first security protection device includes a first processor, a first memory, and a first communication interface. For example, the first communication interface can be a first USB interface, so that the first security protection device accesses the USB device through the first USB interface. The second security protection device includes a second processor, a second memory, and a second communication interface. For example, the second communication interface can be a second USB interface, so that the second security protection device accesses the computing device through the second USB interface.
[0075] Next, taking the wireless communication between the first security protection device and the second security protection device as an example, the first security protection device and the second security protection device will be described.
[0076] As a possible implementation, as Figure 5As shown in the figure, the first security protection device 41 is connected to the USB device 11 and is used to obtain files from the USB device. Specifically, the first security protection device 41 can mount the file system of the USB device, where the file system of the USB device is mounted to the first memory of the first security protection device, so that the first security protection device 41 can obtain all the files in the USB device. Then, the first processor in the first security protection device 41 scans all the files, and in the case that the first file is a virus file, disinfects all the files, deletes the first file.
[0077] The first security protection device 41 is also used to send the second file to the second security protection device 42. Among them, the remaining files except the first file among all the files are the second files.
[0078] The second security protection device 42 is used to be connected to the computing device, and is used to receive the second file sent by the first security protection device 41. Among them, the second file can be cached in the second memory of the second security protection device 42. The second security protection device 42 is used to transfer the second file to the computing device. In this way, after disinfecting all the files through the first security protection device, and then transferring them to the computing device through the second security protection device, it avoids the direct contact between the files in the computing device and the USB device, thereby preventing viruses from invading the computing device and ensuring the security of the computing device.
[0079] As another possible implementation, as Figure 6 shown in the figure, the second security protection device 42 is connected to the computing device 12, and is used to receive the files sent by the computing device and send the files to the first security protection device 41. The first security protection device 41 scans all the files. In the case that the first file is a virus file, disinfects all the files, and deletes the first file. For the specific processing process of the virus file, reference can be made to the detailed description of the disinfection strategy in the above embodiments, which will not be elaborated here.
[0080] As Figure 6 shown in the figure, the first security protection device 41 is connected to the USB device 11 and is used to send the second file to the USB device. In this way, by pre-disinfecting the files through the first security protection device, it can prevent viruses from invading the USB device and ensure the security of the USB device.
[0081] In this application, as Figure 5 and Figure 6As shown, the first security protection device 41 can also communicate with the network, so as to communicate with the cloud platform 32 and transmit the file to the cloud platform 32. The cloud platform 32 scans the file to determine the virus file, and the cloud platform 32 transmits the scanning result to the security protection device. The first security protection device 41 can determine the virus file according to the scanning result and the result of the offline scanning. In this way, it is possible to realize the end-cloud linkage, scan and disinfect the file, and improve the accuracy and reliability of identifying the virus file. For the specific virus disinfection process of the cloud platform, reference can be made to the detailed description of the above embodiments, which will not be elaborated here.
[0082] In this application, the first security protection device and the second security protection device communicate through a wireless network, such as the Transmission Control Protocol (TCP), etc.
[0083] In some embodiments, such as Figure 7 As shown, the security protection device further includes a control switch 70, and the user can turn on the security protection device through the control switch to perform the operation of scanning and disinfecting the file.
[0084] Exemplarily, as Figure 8 As shown, the first security protection device 41 includes a first control switch 81, and the second security protection device 42 includes a second control switch 82. Among them, when the user operates the first control switch 81, the first security protection device can receive the start instruction, thereby obtaining the file and performing operations such as scanning and disinfecting the file. When the user operates the second control switch 82, the second security protection device can receive the start instruction and thereby perform the transmission of the file.
[0085] In some embodiments, the security protection device can isolate its own files from the files transmitted externally, so as to prevent the files of the security protection device itself from becoming virus files and ensure the security of the computing device.
[0086] Based on the same concept as the embodiments of the security protection device of this application, this application also provides a security protection method. The security protection method can be applied to the security protection device shown in the above embodiments. For the specific execution process of the above method, reference can be made to the corresponding process in the foregoing embodiments of the security protection equipment, which will not be elaborated here.
[0087] Figure 9 is a schematic flowchart of the security protection method provided by this application. As Figure 9 As shown, the security protection method provided by this application includes S901 to S902.
[0088] S901, when the security protection device is connected to the computing device and the USB device is connected to the security protection device, scan the files in the security protection device.
[0089] S902. When the first file is a virus file, disinfect the file and delete the first file. The file includes the first file.
[0090] In a possible implementation, the method further includes:
[0091] Obtain the electrical parameters that trigger the USB device and / or the identity identifier of the USB device;
[0092] Determine whether to mount the file system of the USB device according to the electrical parameters of the USB device and / or the identity identifier of the USB device.
[0093] In this way, it is possible to directly prohibit communication between malicious USB devices and computing devices, reducing the risk of the computing device being invaded by viruses.
[0094] In a possible implementation, the method further includes:
[0095] Send the file to the cloud platform so that the cloud platform scans the file;
[0096] Receive the file scan result sent by the cloud platform, and determine whether the file contains a virus file according to the file scan result.
[0097] In this way, it is possible to improve the accuracy and reliability of virus file identification and reduce the risk of the computing device or USB device being invaded by viruses.
[0098] In a possible implementation, the method further includes:
[0099] When the first file is a virus file, the security protection device is further configured to generate a virus disinfection event and send the virus disinfection event to the cloud platform so that the cloud platform stores the virus disinfection event.
[0100] In this way, the cloud platform can enrich virus cases and improve the accuracy of virus disinfection.
[0101] In addition, the present application may also provide a computer program product, which includes computer program instructions. When the computer program instructions are run by a processor, the processor is caused to execute the steps in the methods of various embodiments of the present application described in the above "Methods" section of this specification. Among them, the computer program product may be written in any combination of one or more programming languages for the computer program code to perform the operations of the present application. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. Among them, the computer program code may be in the form of source code, object code, executable file, or some intermediate form, etc. The computer program code may be executed entirely on the user's computing device, partially on the user's device, executed as an independent software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0102] In addition, the present application may also provide a computer-readable storage medium, on which computer program instructions are stored. When the computer program instructions are run by a processor, the processor is caused to execute the steps in the display control method according to various embodiments of the present application described in the above "Methods" section of this specification. The computer-readable storage medium may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may, for example, include but not be limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: electrical connections with one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. It should be noted that the content included in the computer-readable medium may be appropriately increased or decreased according to the requirements of legislation and patent practice within the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.
[0103] The method steps in the embodiments of the present application can be implemented in a hardware manner or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory (RAM), flash memory, read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), register, hard disk, removable hard disk, CD-ROM, or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.
[0104] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. that includes one or more integrated available media. The available medium can be a magnetic medium (for example, floppy disk, hard disk, magnetic tape), an optical medium (for example, DVD), or a semiconductor medium (for example, solid state disk (SSD)), etc. It can be understood that the various numerical numbers involved in the embodiments of the present application are only for convenience of description and are not used to limit the scope of the embodiments of the present application.
Claims
1. A safety protection device, characterized in that: File transfer is performed between a computing device and a universal serial bus (USB) device via the security protection device; Wherein, when the security protection device is connected to the computing device and the USB device is connected to the security protection device, the security protection device is used to obtain a file and scan the file; The security protection device is also used to disinfect the file and delete the first file when the first file is a virus file, and the file includes the first file.
2. The safety protection device according to claim 1, characterized in that: The safety protection equipment includes: A first security protection device, used for obtaining the file from the USB device, scanning the file, and if the first file is a virus file, disinfecting the file and deleting the first file; A second security protection device, used to access the computing device and communicate with the first security protection device to receive a second file sent by the first security protection device, wherein the file also includes the second file; The second security protection device is also used to transmit the second file to the computing device.
3. The safety protection device according to claim 1, characterized in that: The safety protection equipment includes: First safety protection device; A second security protection device, used to access the computing device and receive the file sent by the computing device; the second security protection device is also used to communicate with the first security protection device to send the file to the first security protection device; The first security protection device is used to scan the file, and if the first file is a virus file, disinfect the file and delete the first file; The first security protection device is also used to mount the file system of the USB device to transfer a second file to the file system, and the file also includes the second file.
4. The safety protection device according to claim 2 or 3, characterized in that: The first safety protection device and the second safety protection device communicate wirelessly.
5. The safety protection device according to any one of claims 1 to 4, characterized in that: When the USB device is connected to the security protection device, the security protection device is also used to obtain the electrical parameters that trigger the USB device and / or the identity of the USB device, and determine whether to mount the file system of the USB device based on the electrical parameters of the USB device and / or the identity of the USB device.
6. The safety protection device according to any one of claims 1 to 5, characterized in that: The security protection device is also used to send the file to the cloud platform so that the cloud platform scans the file; The security protection device is also used to receive the file scanning result sent by the cloud platform, and determine whether the file contains a virus file based on the file scanning result.
7. The safety protection device according to claim 2, characterized in that: The first security protection device is also used to synchronize the second file to the USB device.
8. The safety protection device according to any one of claims 1 to 7, characterized in that: In the case that the first file is a virus file, the security protection device is further used to generate a virus detection and killing event, and send the virus detection and killing event to the cloud platform, so that the cloud platform stores the virus detection and killing event.
9. The safety protection device according to any one of claims 1 to 5, characterized in that: The safety protection device comprises a first universal serial bus USB interface and a second USB interface; The security protection device is connected to the USB device via the first USB interface and is connected to the computing device via the second USB interface.
10. The safety protection device according to any one of claims 1 to 5, characterized in that: The safety protection device comprises a control switch, so that a user can control the start-up of the safety protection device through the control switch.
11. A safety protection method, characterized in that: Applied to the safety protection device according to any one of claims 1 to 10, the safety protection device, the method comprising: When the security protection device is connected to the computing device and the USB device is connected to the security protection device, scanning files in the security protection device; In the case that the first file is a virus file, the file is disinfected and the first file is deleted, and the file includes the first file.
12. A safety protection system, characterized in that: It comprises a USB device and the safety protection device as described in any one of claims 1 to 10.