Data detection method and system
By receiving scan plug-in configuration information, determining the scan plug-in orchestration results and scanning files, the inefficiency problem caused by engine independence in the virus detection system is solved, and efficient and accurate output of virus detection results is achieved.
Patent Information
- Application Number
- CN202410038086.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-10
- Publication Date
- 2025-07-11
AI Technical Summary
In the existing virus detection system, the engines of the binary multi-engine platform are in independent and discrete states, and cannot meet the needs of multi-scene coverage and commercial output. An engine architecture design solution is needed to achieve productized engine output and coverage of multiple scenarios.
Provide a data detection method, by receiving configuration information of the scanning plug-in, determining the orchestration results of the scanning plug-in, and scanning files based on the plug-in priority and file type, using thread pool and file directory structure information for efficient scanning, and implementing a result summary strategy to improve scanning efficiency and accuracy.
It improves scanning efficiency, can accurately obtain scanning results, provides strong data support for subsequent problem positioning and decision-making, and supports virus detection in multiple scenarios.
Smart Images

Figure CN120296729A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of computer technology, and particularly to a data detection method and system. Background Art
[0002] Virus detection is an ongoing process of confrontation. Currently, virus detection mainly relies on cloud checking. By transmitting the binary files collected from the user's machine to the binary multi-engine platform, the engines of the multi-engine platform detect and combine the results for determination, and then output the detection results to the user side.
[0003] Each engine of the binary multi-engine platform is in an independent and discrete state, unable to meet the requirements of multi-scenario coverage and commercial output. There is a need for an engine architecture design solution to structurally integrate each component to achieve the requirements of engine product output and empower multiple scenarios. Summary of the Invention
[0004] In view of this, the embodiments of this specification provide a data detection method. One or more embodiments of this specification also relate to a data detection system, a computing device, a computer-readable storage medium, and a computer program product to solve the technical defects existing in the prior art.
[0005] According to the first aspect of the embodiments of this specification, a data detection method is provided, including: receiving configuration information of a scanning plugin, where the configuration information at least includes: plugin priority and file types supported by the plugin; determining a current scanned file based on the file directory structure information and scheduling information corresponding to the scanning file task; determining a scanning plugin orchestration result corresponding to the current scanned file according to the configuration information of the scanning plugin; scanning the current scanned file based on the scanning plugin orchestration result, and obtaining a scanning result of the current scanned file based on a result summarization strategy, where the result summarization strategy is determined based on the plugin priority of the scanning plugin corresponding to the current scanned file.
[0006] According to the second aspect of the embodiments of this specification, a data detection system is provided, including: an end-side device for sending a scanning request to a cloud-side device; the cloud-side device for receiving the scanning request, performing scanning by applying the above data detection method, and returning the scanning result to the end-side device.
[0007] According to the third aspect of the embodiments of this specification, a computing device is provided, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, and when the computer-executable instructions are executed by the processor, the steps of the above data detection method are implemented.
[0008] According to a fourth aspect of the embodiments of this specification, a computer-readable storage medium is provided, which stores computer-executable instructions that, when executed by a processor, implement the steps of the above data detection method.
[0009] According to a fifth aspect of the embodiments of this specification, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the above data detection method.
[0010] The embodiments of this specification provide a data detection method, which receives configuration information of a scanning plugin, where the configuration information at least includes: plugin priority and file types supported by the plugin; determines a current scanned file based on file directory structure information and scheduling information corresponding to a scanned file task; determines a scanning plugin orchestration result corresponding to the current scanned file according to the configuration information of the scanning plugin; scans the current scanned file based on the scanning plugin orchestration result, and obtains a scanning result of the current scanned file based on a result summary policy, where the result summary policy is determined based on the plugin priority of the scanning plugin corresponding to the current scanned file.
[0011] The data detection method realizes determining an orchestration result of a scanning plugin according to received configuration information of the scanning plugin and the current scanned file, so as to flexibly scan files in a scanned file task according to the orchestration result of the scanning plugin, improve the scanning efficiency, and be able to accurately obtain the scanning result of the scanned file according to the result summary policy, providing strong data support for subsequent problem location and decision-making. Description of the Drawings
[0012] Figure 1 is an interaction diagram of a data detection system provided by an embodiment of this specification;
[0013] Figure 2 is a flowchart of a data detection method provided by an embodiment of this specification;
[0014] Figure 3a is a schematic diagram of taking out a scanned file task from a scanned file task queue provided by an embodiment of this specification;
[0015] Figure 3b is a schematic diagram of creating a scanned file task and activating a thread provided by an embodiment of this specification;
[0016] Figure 4a is a schematic diagram of a file directory structure provided by an embodiment of this specification;
[0017] Figure 4b is a schematic diagram of the change process of a first-in, first-out queue provided by an embodiment of this specification;
[0018] Figure 5 It is a flowchart of file scanning in a data detection method provided by an embodiment of this specification;
[0019] Figure 6 It is a scanning flowchart of a scanning plug-in provided by an embodiment of this specification;
[0020] Figure 7 It is an implementation architecture diagram of a data detection method provided by an embodiment of this specification;
[0021] Figure 8 It is a schematic structural diagram of a data detection system provided by an embodiment of this specification;
[0022] Figure 9 It is a structural block diagram of a computing device provided by an embodiment of this specification. Detailed implementation manners
[0023] Numerous specific details are set forth in the following description in order to provide a thorough understanding of this specification. However, this specification can be implemented in many other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the connotation of this specification. Therefore, this specification is not limited by the specific implementations disclosed below.
[0024] The terms used in one or more embodiments of this specification are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms "a", "the", and "said" used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0025] It should be understood that although the terms first, second, etc. may be used in one or more embodiments of this specification to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first can also be referred to as the second, and similarly, the second can also be referred to as the first. Depending on the context, the word "if" as used herein can be interpreted as "when" or "while" or "in response to determining".
[0026] In addition, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this specification are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or reject.
[0027] First, the noun terms involved in one or more embodiments of this specification are explained.
[0028] PE: Portable Executable, which means a portable executable file. Common EXE, DLL, OCX, SYS, and COM are all PE files. PE is an executable file format under a certain operating system; a PE file contains the code, data, resources, and metadata of a program and follows a specific file structure.
[0029] ELF: Executable and Linkable Format, which is an executable file and object file format widely used in another operating system; it is a flexible binary file format used to store the code, data, symbol table, dynamic link, and other relevant information of an executable program.
[0030] SHC: Shell Script Compiler, a script compiler, a tool that packages a script into a binary file for execution. Since the way it executes the script does not require the script file to be stored on disk and encrypts the script content in the packaged binary file, leaving no trace of the script in the static file, many malicious files use this tool to complete malicious behaviors, and it is difficult for conventional malware detection to identify them as malicious.
[0031] Autoit: an automated script language for interface interaction. Due to its high flexibility and low learning curve, it has gradually become a malicious software development tool. The actual malicious software binary file is obfuscated as an Autoit script, and then the Autoit compiler is used to compile the script into an executable file. The malicious program after being packaged by Autoit has a high degree of obfuscation, posing a great challenge to security researchers in analyzing malicious programs.
[0032] MD5: Message-Digest Algorithm 5, a widely used cryptographic hash function that can generate a 128-bit (16-byte) hash value for ensuring the integrity and consistency of information transmission.
[0033] Hash: Hashing is a process that transforms an input of any length into an output of a fixed length through a hashing algorithm. This output is the hash value.
[0034] CRC: Cyclic Redundancy Check. It is a fast algorithm that generates a short fixed-length check code based on data such as network data packets or computer files. It is mainly used to detect or verify possible errors that may occur after data transmission or storage.
[0035] scanner: A scanner is associated with a thread. In the embodiments of this specification, when the engine is initialized, corresponding scanners will be created according to the number of threads.
[0036] In this specification, a data detection method is provided. This specification also relates to a data detection system, a computing device, and a computer-readable storage medium, which will be described in detail one by one in the following embodiments.
[0037] See Figure 1 , Figure 1 shows an interaction diagram of a data detection system provided according to an embodiment of this specification. Among them, the data detection system may include a cloud-side device and an edge-side device.
[0038] In the case where there are multiple edge-side devices, communication connections can be established between the multiple edge-side devices through the cloud-side device. In the prediction model detection scenario, the cloud-side device is used to provide prediction model detection services between the multiple edge-side devices. The multiple edge-side devices can be used as senders or receivers respectively to achieve real-time communication through the cloud-side device.
[0039] Specifically, the edge-side device is used to send a scan request to the cloud-side device; the cloud-side device is used to receive the detection request, receive the configuration information of the scan plugin, and the configuration information at least includes: plugin priority and file types supported by the plugin; determine the current scan file based on the file directory structure information and scheduling information corresponding to the scan file task; determine the scan plugin orchestration result corresponding to the current scan file according to the configuration information of the scan plugin; scan the current scan file based on the scan plugin orchestration result, and obtain the scan result of the current scan file based on the result aggregation strategy, where the result aggregation strategy is determined based on the plugin priority of the scan plugin corresponding to the current scan file; and return the scan result to the edge-side device.
[0040] The edge-side device can also be used to receive the scan result returned by the cloud-side device.
[0041] Among them, a connection can be established between the edge device and the cloud device through a network. The network provides a medium for the communication link between the client and the server. The network can include various connection types, such as wired, wireless communication links, or fiber optic cables, etc. The data transmitted by the edge device may need to be processed such as encoded, transcoded, compressed, etc. before being published to the cloud device.
[0042] The edge device can include a browser, an APP (Application), or a web application such as an H5 (HyperText Markup Language 5) application, or a light application (also known as a mini-program, a lightweight application program), or a cloud application, etc. The edge device can be developed based on the software development kit (SDK) of the corresponding service provided by the server, such as developed based on the Real Time Communication (RTC) SDK. The edge device can be deployed in an electronic device and needs to rely on the device or certain APPs in the device to run, etc. The electronic device can, for example, have a display screen and support information browsing, etc., such as a personal mobile terminal such as a mobile phone, a tablet computer, a personal computer, etc. Various other types of applications can usually be configured in the electronic device, such as human-computer dialogue applications, model training applications, text processing applications, web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.
[0043] The cloud device can include servers that provide various services, such as a server that provides communication services for multiple clients, or a server for background training that supports the models used on the client, or a server that processes the data sent by the client, etc. It should be noted that the cloud device can be implemented as a distributed server cluster composed of multiple servers, or can be implemented as a single server. The server can also be a server of a distributed system, or a server combined with a blockchain. The server can also be a cloud server of basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms, or an intelligent cloud computing server or an intelligent cloud host with artificial intelligence technology.
[0044] It should be noted that the data detection method provided in the embodiments of this specification can be executed by a cloud-side device. In other embodiments of this specification, the end-side device can also have a similar function as the cloud-side device, so as to execute the data detection method provided in the embodiments of this specification; in other embodiments, the data detection method provided in the embodiments of this specification can also be jointly executed by the cloud-side device and the end-side device.
[0045] The data detection system provided in the embodiments of this specification determines the orchestration result of the scanning plug-in according to the received configuration information of the scanning plug-in and the current scanned file, so as to flexibly scan the files in the scanned file task according to the orchestration result of the scanning plug-in, improve the scanning efficiency, and can accurately obtain the scanning result of the scanned file according to the result summary strategy, providing strong data support for subsequent problem positioning and decision-making.
[0046] See Figure 2 , Figure 2 which shows the flowchart of a data detection method provided in an embodiment of this specification, specifically including the following steps.
[0047] Step 202: Receive the configuration information of the scanning plug-in, where the configuration information at least includes: plug-in priority and file types supported by the plug-in.
[0048] Specifically, the configuration information of the scanning plug-in is received through the scanning plug-in configuration interface. Among them, the scanning plug-in configuration interface can be understood as the access interface of the scanning plug-in, which provides a unified access form and interface design for the access of the scanning plug-in, so that there is no need to modify the architecture code when the scanning plug-in is accessed, and the access is flexible and convenient.
[0049] In practical applications, in response to the engine initialization event, the scanning plug-in is loaded; where engine initialization can be understood as starting the scanning engine, and the scanning plug-in can be understood as a plug-in for scanning files.
[0050] Specifically, the configuration information of the scanning plug-in can be received through the scanning plug-in configuration interface, so as to perform plug-in initialization and plug-in rule instance loading according to the configuration information of the scanning plug-in, that is, start the scanning plug-in and configure the scanning rules.
[0051] And in practical applications, in response to the engine de-initialization event, the scanning plug-in is unloaded to release the memory space.
[0052] The configuration information of the scanning plugin includes at least the plugin priority of the scanning plugin and the file types supported by the plugin, so that for a certain file, a scanning plugin that supports its file type is selected for scanning, and according to the plugin priority of the scanning plugin, the execution order of the scanning plugin for a certain file can be determined, and the weight of the scanning result corresponding to the scanning plugin can be set according to the actual situation. For example, for a scanning plugin that is preferentially executed, the weight ratio of its corresponding scanning result is larger, so as to obtain a more accurate scanning result for the file.
[0053] Step 204: Determine the current scanned file based on the file directory structure information and scheduling information corresponding to the scanned file task.
[0054] Among them, the file directory structure information can be understood as the directory structure relationship information between files. For example, after decompressing the compressed package A, files a1 and a2 are obtained. Then, the compressed package A and files a1 and a2 are in a tree structure, that is, the compressed package A is the parent node, and files a1 and a2 are the two child nodes respectively.
[0055] The scheduling information can be understood as the scheduling rules of queue scheduling, such as the first-come, first-served rule.
[0056] Specifically, there can be one file or multiple files in the scanned file task, which is not limited here; but for one or more files corresponding to the scanned file task, it is necessary to determine the file directory structure information between the files and the scheduling rules of the queue where the files are located (such as the first-come, first-served rule), so as to determine the current scanned file based on the file directory structure information and scheduling information between the files.
[0057] In one or more embodiments of this specification, the thread pool can adjust the number of working threads in the thread pool according to the system's bearing capacity. Therefore, using the thread pool, each time a scanned file task is taken out from the scanned file task queue, and an idle thread is activated to execute the scanning task. The specific implementation method is as follows:
[0058] Before determining the current scanned file based on the file directory structure information and scheduling information corresponding to the scanned file task, it further includes:
[0059] Determine the scanned file task from the scanned file task queue, activate the idle thread, and for the determined scanned file task, enter the step of determining the current scanned file based on the file directory structure information and scheduling information corresponding to the scanned file task.
[0060] Specifically, a scanning file task is taken out from the scanning file task queue by using a thread pool. When initializing the thread pool, the number of threads can be controlled to limit the number of threads executing in the system. In the case of taking out a scanning file task, an idle thread is activated to perform the scanning process for the determined scanning file task.
[0061] The scanning file task queue is a first-in-first-out queue. After a scanning file task is completed, the next scanning file task is taken from the scanning file task queue to start execution.
[0062] As Figure 3a shown, Figure 3a FIG. shows a schematic diagram of taking out a scanning file task from the scanning file task queue provided by an embodiment of the present specification.
[0063] When starting to take out a scanning file task from the scanning file task queue, first initialize the thread pool to create a certain number of threads;
[0064] Judge whether to stop creating threads. If so, the thread exits and ends;
[0065] If not, judge whether the scanning file task queue (i.e., the task queue) is empty;
[0066] If it is, wait for the submission of the scanning file task (task). When the scanning file task is submitted, that is, when the scanning file task queue is not empty, activate the thread, and then take out a scanning file task to execute;
[0067] If not, take out a scanning file task from the scanning file task queue to execute; then call back to notify the result and re-enter the step of judging whether to stop creating threads.
[0068] As Figure 3b shown, Figure 3b FIG. shows a schematic diagram of creating a scanning file task and activating a thread provided by an embodiment of the present specification.
[0069] When starting to determine to create a scanning file task, judge whether the scanning file task queue exceeds the quantity limit. If so, end and suspend creating the scanning file task;
[0070] If not, create a scanning file task (task), add the created scanning file task to the scanning file task queue, and activate a thread.
[0071] The data detection method provided in the embodiments of this specification allows multiple threads to exist in the thread pool. When determining a scanning file task from the scanning file task queue and activating idle threads to perform the scanning process, multiple scanning file tasks can be executed concurrently, improving the performance and responsiveness of the program.
[0072] In one or more embodiments of this specification, before determining the current scanning file, the files in the scanning file task are subjected to format recognition, so as to reasonably disassemble the files to obtain one or more scanning files, and then determine the file directory structure among the files in the scanning file task and the one or more scanning files. The specific implementation method is as follows:
[0073] Before determining the current scanning file based on the file directory structure information and scheduling information corresponding to the scanning file task, it further includes:
[0074] Perform file type recognition on the file corresponding to the scanning file task to determine the file type of the file;
[0075] Determine a disassembling strategy according to the file type, and perform corresponding disassembling processing on the file according to the disassembling strategy to obtain one or more scanning files;
[0076] Determine the file directory structure among the file and the one or more scanning files.
[0077] Among them, the file type can be understood as the file format of the file, such as rar (compressed package), exe and other formats.
[0078] The disassembling strategy can be understood as the way to disassemble the file. For example, when the file type is rar or zip format, the compressed package file is decompressed; when the file type is shc or autoit, the file is unpacked.
[0079] The scanning file can be understood as the intermediate file obtained after disassembling the file.
[0080] Specifically, use the file type recognition module to perform file type recognition on the file corresponding to the scanning file task to determine the file type of the file; for example, perform file type recognition on file A corresponding to scanning file task A to determine that the file type of file A is compressed package format.
[0081] Use the preprocessing module to decompress file A according to this file type to obtain files a1 and a2; in practical applications, the preprocessing module is responsible for single-file de-shelling, unpacking or decompression of compressed packages; its input is the file path, and the output is the list of intermediate files generated and file attribute information, such as the shell information or unpacking information of the file.
[0082] Using the file directory structure module, determine the file directory structure between file A and files a1 and a2, which is a tree structure, and the file directory structure module can maintain the directory relationship between each file and the intermediate file.
[0083] The data detection method provided by the embodiments of this specification disassembles by selecting an appropriate disassembly strategy based on the identified file types, and can accurately determine the file directory structure between a file and one or more scanned files, so as to quickly determine the current scanned file according to the file directory structure information and scheduling information in the subsequent process.
[0084] In one or more embodiments of this specification, the scanned files can be placed in a first-in-first-out queue, and the parent-child node relationship between the scanned files can be determined, and then the file directory structure information of the file can be obtained. According to the file directory structure information and the scheduling information of the first-in-first-out queue, the currently scanned file can be quickly determined, improving the execution efficiency of the scanned file task. The specific implementation method is as follows:
[0085] After determining the file directory structure between the file and the one or more scanned files, it further includes:
[0086] Place the one or more scanned files in a first-in-first-out queue, and determine the parent-child node relationship between the file and the one or more scanned files;
[0087] Extract and save the file directory structure information of the file according to the parent-child node relationship between the file and the one or more scanned files.
[0088] Among them, the file directory structure information can be understood as the data information corresponding to the file directory structure; in the above example, when determining the file directory structure between file A and files a1 and a2, file A is the parent node, and files a1 and a2 are the child nodes, and the tree structure between file A and files a1 and a2 is extracted and saved.
[0089] Specifically, refer to Figure 4a , Figure 4a which shows a schematic diagram of a file directory structure provided by an embodiment of this specification.
[0090] A file 1 in zip (compressed package format) contains two files 21 and 22 in zip format; file 21 further contains two files 31 and 32 in exe format; file 22 further contains two files 33 and 34 in exe format.
[0091] After decompressing the zip format files 1, 21, and 22, the file directory structure as shown in Figure 4a can be obtained.
[0092] See Figure 4b , Figure 4b which shows a schematic diagram of the change process of a first-in, first-out queue provided by an embodiment of this specification.
[0093] For the above file directory structure, take out the zip-format file 1 from the first-in, first-out queue in the file directory structure module, after identifying the format of file 1, perform disassembling processing to obtain intermediate files 21 and 22, and put them into the first-in, first-out queue;
[0094] Take out the zip-format file 21 from the head of the first-in, first-out queue, after identifying the format of file 21, perform disassembling processing to obtain intermediate files 31 and 32, and put them into the first-in, first-out queue;
[0095] Take out the exe-format file 31 from the head of the first-in, first-out queue, after identifying the format of file 31, determine that file 31 is the current scanned file, and after file 32 is scanned, take out the exe-format file 32 from the head of the first-in, first-out queue, after identifying the format of file 32, determine that file 32 is the current scanned file;
[0096] And after file 32 is scanned, take out the zip-format file 22 from the head of the first-in, first-out queue, after identifying the format of file 22, perform disassembling processing to obtain intermediate files 33 and 34, and put them into the first-in, first-out queue;
[0097] Take out the exe-format file 33 from the head of the first-in, first-out queue, after identifying the format of file 33, determine that file 33 is the current scanned file, and after file 33 is scanned, take out the exe-format file 34 from the head of the first-in, first-out queue, after identifying the format of file 34, determine that file 34 is the current scanned file, and after file 34 is scanned, continue to take scanned files from the first-in, first-out queue. When it is determined that the first-in, first-out queue is empty, summarize the scanning results corresponding to each scanned file.
[0098] In practical applications, the file directory structure module implements a simplified version of a virtual file system, and this module has a three-layer data structure: AVFileSystem (file system class), AVFileStack (file stack class), and AVStream (file stream class).
[0099] AVFileSystem: Creates a temporary directory during engine initialization. All intermediate files generated by each thread's scanning are in this temporary directory, such as the intermediate files 21, 22, etc. generated above. The temporary directory will be deleted when the engine is de-initialized.
[0100] AVFileStack: Each file has a queue, namely the above-mentioned first-in-first-out queue. Initially, there is only one file in this queue, which is File 1. The scanning context module will sequentially retrieve files from the queue for scanning. When an intermediate file is generated by the file in the preprocessing module, the scanning context module will add the intermediate file to the queue.
[0101] AVStream: Each file is a stream and is added to the AVFileStack in the form of a stream; the stream records the attribute information of the file, such as the file type, file path, etc.
[0102] The data detection method provided by the embodiments of this specification places the scanned files into a first-in-first-out queue, determines the file directory structure information between the scanned files, and quickly determines the currently scanned file from the first-in-first-out queue according to the file directory structure information and scheduling information between the scanned files, improving the execution efficiency of the scanned file task.
[0103] In one or more embodiments of this specification, to reduce resource occupancy, the configuration module provides a scanning configuration for compressed packages. The scanning context management module will read the above scanning configuration and impose resource restrictions on the compressed packages during the execution of the scanned file task. The specific implementation method is as described below:
[0104] Determining the disassembly strategy according to the file type and performing corresponding disassembly processing on the file according to the disassembly strategy to obtain one or more scanned files includes:
[0105] Determining the disassembly strategy according to the file type of the file and determining the resource configuration for the disassembly processing of the file;
[0106] Performing corresponding disassembly processing on the file according to the disassembly strategy and the disassembly processing resource configuration to obtain one or more scanned files.
[0107] Among them, the disassembly processing resource configuration can be understood as the configuration rules when disassembling files, which are used to control resource occupancy, such as the maximum number of decompression layers of the compressed package and the maximum number of decompressed files per layer of the compressed package.
[0108] In practical applications, when disassembling a file, not only how to disassemble the file needs to be considered, that is, the disassembly strategy needs to be determined; but also the number and occupied space of the intermediate files generated after disassembly need to be considered. Therefore, the resource configuration for the disassembly processing of the file needs to be determined to control resource occupancy; for example, according to actual requirements, the maximum number of decompression layers of the compressed package is set to 3 layers, and the maximum number of decompressed files per layer of the compressed package is set to 5, etc.
[0109] The data detection method provided in the embodiments of this specification disassembles a file reasonably by determining the disassembly strategy for the file and the configuration of disassembly processing resources, so that the intermediate files generated after disassembling the file do not overly occupy resources, and avoid the problem of low processing efficiency caused by high resource occupancy.
[0110] Step 206: Determine the scan plug-in orchestration result corresponding to the current scanned file according to the configuration information of the scan plug-in.
[0111] Among them, the scan plug-in orchestration result can be understood as the scan rules for scanning using scan plug-ins. For example, in the case of having scan plug-in a, scan plug-in b, and scan plug-in c, which scan plug-ins are selected to scan the current scanned file, and the execution order when the scan plug-ins perform scanning.
[0112] Specifically, use the configuration information of the scan plug-in to determine which scan plug-ins are used to scan the current scanned file, and the execution order when the scan plug-ins perform scanning.
[0113] In one or more embodiments of this specification, to reasonably use scan plug-ins to scan the current scanned file and improve the scanning efficiency, select the target scan plug-ins corresponding to the current scanned file and the execution order of the target scan plug-ins. The specific implementation method is as follows:
[0114] The determining the scan plug-in orchestration result corresponding to the current scanned file according to the configuration information of the scan plug-in includes:
[0115] Select one or more target scan plug-ins corresponding to the current scanned file according to the file type of the current scanned file and the file types supported by the scan plug-ins;
[0116] Determine the execution order of the target scan plug-ins according to the plug-in priorities of the target scan plug-ins.
[0117] Among them, the target scan plug-in can be understood as the plug-in that scans the current scanned file; the plug-in priority can be understood as the scan sorting between scan plug-ins, and the one with a higher priority scans the current scanned file first.
[0118] Specifically, if the file type of the current scanned file is type A, and among the scan plug-ins there are scan plug-in a, scan plug-in b, and scan plug-in c, the file types supported by scan plug-in a include type A and type B; the file types supported by scan plug-in b include type A and type C; the file types supported by scan plug-in c include type B and type C; therefore, select scan plug-in a and scan plug-in b as the target scan plug-ins corresponding to the current scanned file.
[0119] Between scanning plugin a and scanning plugin b, for file type A, the priority of scanning plugin a is higher than that of scanning plugin b. Therefore, when scanning the current scanned file, scanning plugin a is first used to scan the current scanned file, and then scanning plugin b is used to scan the current scanned file.
[0120] In practical applications, the weight of the scanning result corresponding to the scanning plugin is proportional to the plugin priority, that is, for the scanning result of the current scanned file, the scanning result corresponding to the scanning plugin with a higher plugin priority is preferably referred to.
[0121] The data detection method provided by the embodiments of this specification can reasonably select a target scanning plugin according to the file type of the current scanned file and the file types supported by the scanning plugin; and use the plugin priority of the target scanning plugin to accurately obtain the scanning result of the current scanned file.
[0122] Step 208: Scan the current scanned file based on the scanning plugin scheduling result, and obtain the scanning result of the current scanned file based on the result summarization strategy, where the result summarization strategy is determined based on the plugin priority of the scanning plugin corresponding to the current scanned file.
[0123] In practical applications, when the current scanned file can be scanned by multiple scanning plugins, multiple scanning results corresponding to the multiple scanning plugins will be obtained. Therefore, it is necessary to summarize the multiple obtained scanning results.
[0124] The result summarization strategy can be understood as the summarization method for summarizing multiple scanning results; continuing with the above example, scanning plugin a is used to scan the current scanned file to obtain scanning result a; scanning plugin b is used to scan the current scanned file to obtain scanning result b.
[0125] In the case where scanning result a is a virus file and scanning result b is a normal file, because the priority of scanning plugin a is higher than that of scanning plugin b, the scanning result of the current scanned file can be obtained as a virus file.
[0126] In one or more embodiments of this specification, to improve the scanning efficiency of compressed package scanning, the scanning engine is set with a fast mode. If the fast mode is enabled, when a virus file is detected in the intermediate file generated by the compressed package, the scanning is immediately aborted and the step of scanning result summarization is entered. The specific implementation method is as follows:
[0127] The scanning the current scanned file based on the scanning plugin scheduling result and obtaining the scanning result of the current scanned file based on the result summarization strategy includes:
[0128] Determine the current target scanning plugin based on the execution order of the target scanning plugins;
[0129] Scan the current scanned file through the current target scanning plugin to obtain an initial scanning result corresponding to the current target scanning plugin;
[0130] When it is determined that the fast mode is enabled, determine whether the initial scanning result corresponding to the current scanning plugin is a preset scanning result.
[0131] If so, continue to execute the step of determining the current target scanning plugin based on the execution order of the target scanning plugins;
[0132] If not, based on the result summarization strategy, summarize the initial scanning results corresponding to the one or more target scanning plugins to obtain the scanning result of the current scanned file.
[0133] Specifically, the preset scanning result can be understood as the result that the current scanned file is a normal file.
[0134] Continuing with the above example, when the fast mode is enabled, based on the execution order of the target scanning plugins, first determine that the current target scanning plugin is scanning plugin a; use scanning plugin a to scan the current scanned file to obtain the initial scanning result a; determine whether the current scanned file is a virus file according to the initial scanning result a. If so, the scanning can be directly aborted, and based on the result summarization strategy, obtain the scanning result of the current scanned file.
[0135] The data detection method provided by the embodiments of this specification can, when the fast mode is enabled and a virus file is detected in the intermediate file generated by the compressed package, immediately abort the scanning and enter the step of summarizing the scanning results, greatly improving the scanning efficiency of the scanned file task.
[0136] In one or more embodiments of this specification, after obtaining the scanning result of the current scanned file, it further includes:
[0137] Based on the file directory structure information, summarize the scanning results of each scanned file of the scanned file task to obtain the scanning result of the scanned file task.
[0138] Specifically, each scanned file of the scanned file task is obtained by disassembling the file of the scanned file task. Therefore, after obtaining the scanning results of each scanned file of the scanned file task, according to the file directory structure information between the file and the scanned file, summarize to obtain the scanning result of the scanned file task.
[0139] For example, when the file corresponding to the scanned file task is File A, after disassembling File A using the disassembly strategy, Text File 1 and Presentation 2 are obtained. After scanning Text File 1 and Presentation 2 respectively, when the scanning results of both Text File 1 and Presentation 2 are virus-free, based on the relationship with File A as the parent node and Text File 1 and Presentation 2 as the child nodes, it is determined that the scanning result of File A is virus-free, that is, the scanning result of the scanned file task is obtained as virus-free.
[0140] The data detection method provided in the embodiments of this specification can receive the configuration information of the scanning plug-in according to the scanning plug-in configuration interface, and determine the scheduling result of the scanning plug-in based on the currently scanned file, so as to flexibly scan the files in the scanned file task according to the scheduling result of the scanning plug-in, improving the scanning efficiency, and can accurately obtain the scanning result of the scanned file according to the result summary strategy, providing strong data support for subsequent problem location and decision-making.
[0141] See Figure 5 , Figure 5 shows the flowchart of file scanning in a data detection method provided by an embodiment of this specification;
[0142] Step 502: Initialize the scanning queue.
[0143] Specifically, the scanning queue is the first-in-first-out queue in the above embodiment; initializing the scanning queue ensures that there are no historical scanned files in the scanning queue.
[0144] Step 504: Add the scanned file to the scanning queue.
[0145] Add the file in the scanned file task to the scanning queue.
[0146] Step 506: Determine whether to enable the cloud query module; if yes, execute Step 510; if not, execute Step 508.
[0147] Specifically, in the case where the cloud query module is not enabled, determine whether the scanning queue is empty; in the case where the cloud query module is enabled, use the cloud query module to scan the file, obtain and view the cloud query result, and determine whether the file is a virus file.
[0148] Step 508: Determine whether the scanning queue is empty; if yes, execute Step 528; if not, execute Step 512.
[0149] Specifically, in the case where the scanning queue is empty, it is considered that all scanned files have been scanned, and the results are sorted out; in the case where the queue is not empty, take out a file from the scanning queue.
[0150] Step 510: Determine whether the cloud check is black; if so, execute Step 528; if not, execute Step 508.
[0151] Specifically, check whether the cloud check result of the cloud check is black, where black represents a black file, and a black file can be understood as a virus file. In the case of determining that the cloud check result of the file is a virus file, directly organize the result; in the case of determining that the cloud check result of the file is a normal file, determine whether the scan queue is empty.
[0152] Step 512: Take out a file.
[0153] Specifically, take out a file from the scan queue and scan the file.
[0154] Step 514: Determine whether the number of scan layers exceeds the limit; if so, execute Step 508; if not, execute Step 516.
[0155] Specifically, whether the number of scan layers exceeds the limit. In the case where the number of scan layers exceeds the limit, continue to execute the step of determining whether the scan queue is empty; in the case where the number of scan layers does not exceed the limit, identify the file type of the file.
[0156] Step 516: Identify the file type.
[0157] Identify the file type of the file in order to determine the disassembly strategy according to the file type.
[0158] Step 518: Unzip the file and add the intermediate file to the scan queue.
[0159] For files in zip format, perform decompression processing and put the intermediate files generated by decompression into the scan files.
[0160] Step 520: Unshell or unpack, and add the intermediate file to the scan queue.
[0161] For files in shc, autoit and other formats, perform unshelling or unpacking processing and add the intermediate files to the scan queue.
[0162] Step 522: Scan with scan plug-ins.
[0163] In the case of determining the current scan file from the scan file queue, perform the process of scanning with scan plug-ins.
[0164] Step 524: Determine whether it times out; if so, execute Step 508; if not, execute Step 526.
[0165] Specifically, whether the scan time times out. In the case of timeout, continue to execute the step of determining whether the scan queue is empty; in the case of not timing out, determine whether the zip file enables the fast mode and is detected.
[0166] Step 526: Determine whether the compressed package enables the fast mode and is checked out; if so, execute Step 528; if not, execute Step 508.
[0167] Specifically, in the case where the fast mode is enabled for the compressed package, when a virus file is detected, the results are summarized; otherwise, the step of determining whether the scan queue is empty is continued to be executed.
[0168] Step 528: Result collation.
[0169] Collate and summarize the scan results obtained from the scan.
[0170] For the specific step implementation, reference can be made to the above embodiments, which will not be elaborated here.
[0171] The data detection method provided by the embodiments of this specification can receive the configuration information of the scan plug-in according to the scan plug-in configuration interface, and determine the arrangement result of the scan plug-in according to the currently scanned file, so as to flexibly scan the files in the scan file task according to the arrangement result of the scan plug-in, improve the scan efficiency, and can accurately obtain the scan results of the scanned files according to the result summarization strategy, providing strong data support for subsequent problem positioning and decision-making.
[0172] See Figure 6 , Figure 6 which shows the scan flow chart of a scan plug-in provided by an embodiment of this specification.
[0173] Step 602: Obtain the plug-in list.
[0174] Specifically, according to the scan plug-in arrangement result, obtain an ordered scan plug-in list, and scan the scanned file according to the scan plug-in list.
[0175] Step 604: Determine whether the plug-in list has been traversed; if so, execute Step 620; if not, execute Step 606.
[0176] Specifically, in the case where all the scan plug-ins in the scan plug-in list have been traversed, end the scan process and obtain the scan results; in the case where the scan plug-ins in the scan plug-in list have not been traversed, determine whether the scan process times out.
[0177] Step 606: Determine whether it times out; if so, execute Step 620; if not, execute Step 608.
[0178] In the case where the scan process times out, end the scan process and obtain the scan results; in the case where the scan process does not time out, determine whether the sample signature verification passes.
[0179] Step 608: Determine whether the sample signature verification passes; if so, execute Step 612; if not, execute Step 610.
[0180] Specifically, determine whether the signature verification of the scanned file passes. If it passes, the crc module can be directly skipped. If it does not pass, obtain the scanner according to the thread ID.
[0181] Step 610: Obtain the scanner according to the thread ID (Identity document).
[0182] Specifically, corresponding scanners are created according to the number of threads during engine initialization; therefore, the corresponding scanner can be obtained according to the thread identifier.
[0183] Step 612: Skip the crc module.
[0184] If the signature verification of the scanned file passes, the crc module can be directly skipped.
[0185] Step 614: Call the scanning function.
[0186] Specifically, scan the scanned file by calling the scanning functions of each scanning plugin.
[0187] Step 616: Release the memory.
[0188] After the scanning is completed, release the memory space of the scanning plugin.
[0189] Step 618: Determine whether the file is a virus file; if so, execute Step 620; if not, execute Step 604.
[0190] Specifically, determine whether the scanned file is a virus file. If so, end the scanning process and obtain the scanning result. If not, continue to execute Step 604.
[0191] Step 620: End.
[0192] Specifically, end the scanning process and obtain the scanning result.
[0193] By applying the scanning process provided in the embodiments of this specification, the files in the scanning file task can be scanned flexibly according to the arrangement result of the scanning plugin, and the scanning of the scanning plugin can be aborted when a virus file is detected, greatly improving the scanning efficiency.
[0194] To make the data detection method provided in the embodiments of this specification easier to understand, below, an exemplary description is given of the implementation architecture combining the above-mentioned multiple embodiments. Figure 7The figure shows an implementation architecture diagram of a data detection method provided by an embodiment of this specification. The implementation architecture may include: a thread pool, a file format recognition module, a preprocessing module, a file directory structure module, a scanning engine, and a configuration module; the scanning engine includes a plugin management module and a scanning context module.
[0195] Specifically, the data detection method applying this implementation architecture will be described in detail.
[0196] First, initialize the scanning engine. The scanning engine reads configuration parameter information related to scanning plugins such as log configuration, resource configuration, scanning configuration, and compressed packages from the configuration module through the scanning plugin configuration interface, and initializes the thread pool according to the configuration parameter information. The purpose of the initialization is to create a certain number of threads and save the created threads in the thread pool. The resource limit in the thread pool can control the number of threads. Then, the plugin management module in the scanning engine performs plugin initialization, plugin rule instance loading, and creation of a scanner to implement the access of the scanning plugin.
[0197] The thread pool takes out a scanning file task from the file task queue and activates an idle thread, that is, creates a task and wakes up the thread. For this scanning file task, it enters the file scanning process of the scanning context management module: takes out a file from the scanning file task from the first-in, first-out queue in the file directory structure module. First, the file type recognition module performs format recognition on this file. The recognizable file formats include but are not limited to file formats such as PE, ELF, zip, rar, msi (an installation package file format), shc, autoit, etc.
[0198] According to different file formats, the scanning context management module has different processing: that is, if the file format is PE, ELF, etc., the preprocessing module will perform shell recognition on this file. If it is recognized that this file is a shelled sample, the file will be unpacked; if the file format is shc, autoit, etc., the file will be unpacked; the unpacked or decompressed file is added to the first-in, first-out queue in the file directory structure module; if it is recognized that this file is a compressed package (that is, the file format is zip, rar), the preprocessing module will decompress this file under the parameter limit of the compressed package configuration in the configuration module. The intermediate file after decompression can be stored in the created temporary directory and then enter the first-in, first-out queue in the file directory structure module; specifically, the file directory structure module can also record the attribute information of the file (attribute information recording) and maintain the tree structure between the file and the intermediate file (tree structure maintenance).
[0199] After the preprocessing module is completed, the current scanned file is determined from the first-in, first-out queue in the file directory structure module, and the plug-in scanning link in the scanning context management module is entered: First, according to the configuration parameter information of the scanning plug-ins (including plug-in priority and file types supported by the plug-ins), the scanning plug-ins to scan the current scanned file are determined, as well as the execution order of these scanning plug-ins. With the help of the plug-in management module, the scanning functions and rule instances of each scanning plug-in are called in sequence according to the execution order of the scanning plug-ins to scan the current scanned file.
[0200] Among them, the scanning plug-ins provided in the embodiments of this specification are the cloud check module, the dynamic rule detection module, the high generalization logic rule detection module, and the micro generalization hash module; the cloud check module performs md5 calculation and result query output, the dynamic rule detection module performs scripted rules and family-specific killing, the high generalization logic rule detection module performs state machine matching, precise matching, condition parsing, and result output, and the micro generalization hash module performs crc extraction and crc calculation and matching; of course, other scanning plug-ins can also be connected, which are not limited here; when using the current scanning plug-ins for evaluation, the accuracy rate of the scanning results is as high as 99.13%, and the false alarm rate is less than 0.01%.
[0201] After the scanning plug-ins scan the current scanned file, they will return the scanning results, that is, whether the current scanned file is a virus file or a normal file; after the current scanned file is scanned, the scanning context management module will continue to take out the next current scanned file from the first-in, first-out queue in the file directory structure module and repeat the above process until the queue is empty. Finally, the scanning context management module will organize the scanning results (result summary), and at the same time perform time statistics and error code recording for each module, and output the scanning results of the scanned file task.
[0202] In the case of obtaining the scanning results of the scanned file task, the scanning context management module can also count the scanning time occupied by each model during the entire scanning process; and record the error information generated by each module, such as failure to decompress the compressed package and failure to unpack the shell.
[0203] It should be noted that the scanning context management module can control the scanning mode (mode control). For example, in the case of enabling the fast mode, after a certain scanning plug-in scans the current scanned file and the obtained scanning result is that the current scanned file is a virus file, the scanning process is directly ended and the scanning results are summarized; and the scanning configuration in the configuration module can include the maximum number of decompression layers of the compressed package, the maximum number of decompressions per layer of the compressed package, etc. The scanning context management module will read the above configuration and perform resource restrictions on the compressed package during the scanning process (configuration restrictions) to improve the scanning efficiency.
[0204] After the processing is completed, the scanning engine is de-initialized. First, the plugin management module releases the scanners of each scanning plugin, uninstalls the plugin rule instances, and uninstalls each scanning plugin (plugin de-initialization). Then, the thread pool module waits for each thread to exit (thread pool de-initialization). Next, the file format recognition module and the preprocessing module are de-initialized. Finally, the scanning engine exits.
[0205] The data detection system provided by the embodiments of this specification can receive the configuration information of the scanning plugin according to the scanning plugin configuration interface, and determine the scheduling result of the scanning plugin based on the current scanned file, so as to flexibly scan the files in the scanned file task according to the scheduling result of the scanning plugin, improve the scanning efficiency, and can accurately obtain the scanning result of the scanned file according to the result summarization strategy, providing strong data support for subsequent problem location and decision-making.
[0206] Corresponding to the above method embodiments, this specification also provides embodiments of a data detection system. Figure 8 FIG. shows a schematic structural diagram of a data detection system provided by an embodiment of this specification. As Figure 8 shown, the system includes:
[0207] The edge device 802 is used to send a scanning request to the cloud device;
[0208] The cloud device 804 is used to receive the scanning request, receive the configuration information of the scanning plugin, and the configuration information at least includes: plugin priority and file types supported by the plugin; determine the current scanned file based on the file directory structure information and scheduling information corresponding to the scanned file task; determine the scheduling result of the scanning plugin corresponding to the current scanned file according to the configuration information of the scanning plugin; scan the current scanned file based on the scheduling result of the scanning plugin, and obtain the scanning result of the current scanned file based on the result summarization strategy, where the result summarization strategy is determined based on the plugin priority of the scanning plugin corresponding to the current scanned file; and return the scanning result to the edge device 802.
[0209] Optionally, the cloud device 804 is further used for:
[0210] Identify the file type of the file corresponding to the scanned file task, and determine the file type of the file;
[0211] Determine the disassembly strategy according to the file type, and perform corresponding disassembly processing on the file according to the disassembly strategy to obtain one or more scanned files;
[0212] Determine the file directory structure between the file and the one or more scanned files.
[0213] Optionally, the cloud - side device 804 is further configured to:
[0214] Put the one or more scanned files into a first - in - first - out queue, and determine the parent - child node relationship of the file and the one or more scanned files;
[0215] Extract and save the file directory structure information of the file according to the parent - child node relationship of the file and the one or more scanned files.
[0216] Optionally, the cloud - side device 804 is further configured to:
[0217] Select one or more target scanning plugins corresponding to the current scanned file according to the file type of the current scanned file and the file types supported by the scanning plugins;
[0218] Determine the execution order of the target scanning plugins according to the plugin priorities of the target scanning plugins.
[0219] Optionally, the cloud - side device 804 is further configured to:
[0220] Load the scanning plugins in response to an engine initialization event;
[0221] And / or,
[0222] Unload the scanning plugins in response to an engine de - initialization event to release memory space.
[0223] Optionally, the cloud - side device 804 is further configured to:
[0224] Determine a scanned file task from the scanned file task queue, activate an idle thread, and enter the step of determining the current scanned file based on the file directory structure information and scheduling information corresponding to the scanned file task.
[0225] Optionally, the cloud - side device 804 is further configured to:
[0226] Determine the current target scanning plugin based on the execution order of the target scanning plugins;
[0227] Scan the current scanned file through the current target scanning plugin to obtain an initial scanning result corresponding to the current target scanning plugin;
[0228] When it is determined that the fast mode is enabled, determine whether the initial scanning result corresponding to the current scanning plugin is a preset scanning result,
[0229] If so, continue to execute the step of determining the current target scanning plugin based on the execution order of the target scanning plugins;
[0230] Otherwise, based on the result summarization strategy, summarize the initial scan results corresponding to the one or more target scan plugins to obtain the scan result of the current scanned file.
[0231] Optionally, the cloud-side device 804 is further configured to:
[0232] Determine a disassembly strategy according to the file type of the file, and determine the disassembly processing resource configuration for the file;
[0233] Perform corresponding disassembly processing on the file according to the disassembly strategy and the disassembly processing resource configuration to obtain one or more scanned files.
[0234] Optionally, the cloud-side device 804 is further configured to:
[0235] Based on the file directory structure information, summarize the scan results of each scanned file of the scanned file task to obtain the scan result of the scanned file task.
[0236] The embodiments of the present specification provide a data detection system, which can receive the configuration information of the scan plugin according to the scan plugin configuration interface, and determine the orchestration result of the scan plugin according to the current scanned file, so as to flexibly scan the current scanned file according to the orchestration result of the scan plugin, and can accurately obtain the scan result of the scanned file according to the result summarization strategy, providing strong data support for subsequent problem positioning and decision-making.
[0237] The above is a schematic solution of a data detection system according to this embodiment. It should be noted that the technical solution of this data detection system and the technical solution of the above data detection method belong to the same concept. For the details not described in detail in the technical solution of the data detection system, reference can be made to the description of the technical solution of the above data detection method.
[0238] Figure 9 FIG. shows a structural block diagram of a computing device 900 according to an embodiment of the present specification. The components of the computing device 900 include, but are not limited to, a memory 910 and a processor 920. The processor 920 is connected to the memory 910 through a bus 930, and the database 950 is used to store data.
[0239] The computing device 900 also includes an access device 940 that enables the computing device 900 to communicate via one or more networks 960. Examples of such networks include the Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or a combination of communication networks such as the Internet. The access device 940 may include one or more of any type of wired or wireless network interface (e.g., a network interface card (NIC)), such as an IEEE 902.11 Wireless Local Area Network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC) interface, and so on.
[0240] In one embodiment of the present specification, the above components of the computing device 900 and Figure 9 other components not shown therein may also be connected to each other, for example, via a bus. It should be understood that Figure 9 the block diagram of the computing device shown is for illustrative purposes only and is not a limitation on the scope of the present specification. Those skilled in the art can add or replace other components as needed.
[0241] The computing device 900 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.) or other types of mobile devices, or a stationary computing device such as a desktop computer or a Personal Computer (PC). The computing device 900 can also be a mobile or stationary server.
[0242] Among them, the processor 920 is used to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the above data detection method.
[0243] The above is a schematic solution of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the above data detection method belong to the same concept. For the details not described in detail in the technical solution of the computing device, reference can be made to the description of the technical solution of the above data detection method.
[0244] An embodiment of this specification also provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, the steps of the above data detection method are implemented.
[0245] The above is a schematic solution of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the above data detection method belong to the same concept. For the details not described in detail in the technical solution of the storage medium, reference can be made to the description of the technical solution of the above data detection method.
[0246] An embodiment of this specification also provides a computer program. When the computer program is executed on a computer, the computer is made to execute the steps of the above data detection method.
[0247] The above is a schematic solution of a computer program according to this embodiment. It should be noted that the technical solution of this computer program and the technical solution of the above data detection method belong to the same concept. For the details not described in detail in the technical solution of the computer program, reference can be made to the description of the technical solution of the above data detection method.
[0248] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain implementations, multitasking and parallel processing are also possible or may be advantageous.
[0249] The computer instructions include computer program code, which may be in the form of source code, object code, executable files, or some intermediate forms, etc. The computer-readable medium may include: any entity or system capable of carrying the computer program code, recording media, USB flash drives, mobile hard disks, magnetic disks, optical disks, computer memories, read-only memories (ROMs), random access memories (RAMs), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of patent practice. For example, in some regions, according to patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.
[0250] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of this specification are not limited by the described action sequence, because according to the embodiments of this specification, some steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential for the embodiments of this specification.
[0251] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0252] The preferred embodiments of this specification disclosed above are only used to help explain this specification. The optional embodiments do not elaborate on all details and do not limit the invention to the specific embodiments described. Obviously, many modifications and changes can be made according to the content of the embodiments of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the embodiments of this specification, so that those skilled in the art can well understand and utilize this specification. This specification is only limited by the claims and their full scope and equivalents.
Claims
1. A data detection method, comprising: Receiving configuration information of a scanning plugin, where the configuration information at least includes: plugin priority and file types supported by the plugin; Determining a current scanned file based on file directory structure information and scheduling information corresponding to a scanning file task; Determining a scanning plugin orchestration result corresponding to the current scanned file according to the configuration information of the scanning plugin; Scanning the current scanned file based on the scanning plugin orchestration result, and obtaining a scanning result of the current scanned file based on a result summarization policy, where the result summarization policy is determined based on the plugin priority of the scanning plugin corresponding to the current scanned file.
2. The data detection method according to claim 1, before determining the current scanned file based on the file directory structure information and scheduling information corresponding to the scanning file task, further comprising: Identifying a file type of a file corresponding to the scanning file task to determine the file type of the file; Determining a disassembling strategy according to the file type, and performing corresponding disassembling processing on the file according to the disassembling strategy to obtain one or more scanned files; Determining a file directory structure between the file and the one or more scanned files.
3. The data detection method according to claim 2, after determining the file directory structure between the file and the one or more scanned files, further comprising: Putting the one or more scanned files into a first-in-first-out queue, and determining a parent-child node relationship between the file and the one or more scanned files; Extracting and saving the file directory structure information of the file according to the parent-child node relationship between the file and the one or more scanned files.
4. The data detection method according to claim 1, where determining the scanning plugin orchestration result corresponding to the current scanned file according to the configuration information of the scanning plugin includes: Selecting one or more target scanning plugins corresponding to the current scanned file according to the file type of the current scanned file and the file types supported by the scanning plugin; Determining an execution order of the target scanning plugins according to the plugin priorities of the target scanning plugins.
5. The data detection method according to claim 1, further comprising: Loading the scanning plugin in response to an engine initialization event; and / or, Unloading the scanning plugin in response to an engine de-initialization event to release memory space.
6. The data detection method according to claim 1, before determining the current scanned file based on the file directory structure information and scheduling information corresponding to the scanning file task, further comprising: Determining a scanning file task from a scanning file task queue, activating an idle thread, and entering the step of determining the current scanned file based on the file directory structure information corresponding to the determined scanning file task.
7. The data detection method according to claim 4, where scanning the current scanned file based on the scanning plugin orchestration result, and obtaining a scanning result of the current scanned file based on a result summarization policy, includes: Determine the current target scanning plugin based on the execution order of the target scanning plugins; Scan the current scanned file through the current target scanning plugin to obtain the initial scanning result corresponding to the current target scanning plugin; When it is determined that the fast mode is enabled, determine whether the initial scanning result corresponding to the current scanning plugin is the expected scanning result; If so, continue to execute the step of determining the current target scanning plugin based on the execution order of the target scanning plugins; If not, based on the result summarization strategy, summarize the initial scanning results corresponding to the one or more target scanning plugins to obtain the scanning result of the current scanned file.
8. The data detection method according to claim 2, wherein determining the disassembly strategy according to the file type and performing corresponding disassembly processing on the file according to the disassembly strategy to obtain one or more scanned files includes: Determine the disassembly strategy according to the file type of the file and determine the disassembly processing resource configuration for the file; Perform corresponding disassembly processing on the file according to the disassembly strategy and the disassembly processing resource configuration to obtain one or more scanned files.
9. The data detection method according to claim 1, after obtaining the scanning result of the current scanned file, further includes: Based on the file directory structure information, summarize the scanning results of each scanned file of the scanned file task to obtain the scanning result of the scanned file task.
10. A data detection system, comprising: An edge device for sending a scanning request to the cloud device; A cloud device for receiving the scanning request, performing scanning by applying the data detection method according to any one of claims 1-9, and returning the scanning result to the edge device.
11. A computing device, comprising: A memory and a processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, and when the computer-executable instructions are executed by the processor, the steps of the data detection method according to any one of claims 1 to 9 are implemented.
12. A computer-readable storage medium storing computer-executable instructions, and when the computer-executable instructions are executed by a processor, the steps of the data detection method according to any one of claims 1 to 9 are implemented.
13. A computer program product comprising a computer program, and when the computer program is executed by a processor, the steps of the data detection method according to any one of claims 1 to 9 are implemented.