Virus library updating method and device, electronic equipment and medium

Through the malicious domain name detection model and MQTT protocol based on deep learning convolutional neural network, the problem of untimely update of virus databases is solved, real-time update of virus databases and the improvement of virus detection rate is achieved.

CN120342771APending Publication Date: 2025-07-18BEIJING ANBOTONG TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510739446.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-04
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing virus database update mechanism has the problem of cumbersome collection and sorting of virus domain names, low configuration efficiency, and untimely synchronization of virus database servers and network security devices, resulting in low virus detection rate.

Method used

The malicious domain name detection model based on deep learning convolutional neural network is used to classify the target packets, generate a black and white list of virus domain names, and synchronize it to the virus server through the MQTT protocol to realize real-time update of the virus database.

Benefits of technology

It improves the identification accuracy and stability of the virus database, detects virus domain names in real time, and improves the virus detection rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342771A_ABST
    Figure CN120342771A_ABST
Patent Text Reader

Abstract

The invention relates to a virus library updating method and device, electronic equipment and a medium, and belongs to the technical field of network security, and the method comprises the following steps: receiving a target message sent by a client; and inputting a target domain name in the target message into a preset neural network model to obtain a classification result, and when determining that the target domain name in the target message is not matched with a local domain name virus library based on the classification result, adding the target domain name to a second virus domain name blacklist or a third virus domain name white list, synchronizing the second virus domain name blacklist and the third virus domain name white list to a virus server through a first preset protocol, and receiving a global virus library sent by the virus server; and synchronizing the global virus library to all network security devices through a second preset protocol. According to the method, the virus domain names can be detected in real time by configuring the black list and the white list of the virus domain names and automatically synchronizing the black list and the white list to the virus library server, so that the virus detection rate is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method, device, electronic device and medium for updating a virus database. Background Art

[0002] With the rapid development of the Internet, network security issues have become increasingly severe. As one of the important threats to network security, virus websites are constantly evolving and spreading, bringing great risks to the security of users' devices and data.

[0003] Traditional virus detection methods mainly rely on the update of the virus database. However, there are many deficiencies in the existing virus database update mechanism. On the one hand, the process of collecting and sorting virus domain names is cumbersome and the configuration efficiency is low, resulting in new virus domain names not being able to be included in the virus database for detection in a timely manner; on the other hand, the update synchronization between the virus database server and network security devices is not timely, so that network security devices cannot detect the latest virus domain names for a period of time, thereby reducing the virus detection rate and unable to effectively guarantee network security.

[0004] In summary, the existing technology lacks a method for updating the virus database, thereby improving the virus detection rate. Summary of the Invention

[0005] In view of this, it is necessary to provide a method, device, electronic device and medium for updating a virus database to solve the problem of low virus detection rate in the existing technology.

[0006] To solve the above problems, in a first aspect, the present invention provides a method for updating a virus database, which is applied to a network security device and includes: Receiving a target message sent by a client; When it is determined that the target domain name in the target message does not match both the local first virus domain name blacklist and the local first virus domain name whitelist, inputting the target domain name into a malicious domain name detection model based on a deep learning convolutional neural network that is completely constructed to obtain a classification result; When it is determined that the target message is a virus domain name based on the classification result, adding the target domain name to the first virus domain name blacklist to obtain a second virus domain name blacklist; when it is determined that the target message is a non-virus domain name based on the classification result, adding the target domain name to the first virus domain name whitelist to obtain a second virus domain name whitelist; when it is determined that the target domain name in the target message is misidentified based on the classification result, adding the target domain name to the second virus domain name whitelist to obtain a third virus domain name whitelist; Synchronize the second virus domain name blacklist and the third virus domain name whitelist to the virus server through the first preset protocol, and receive the global virus library sent by the virus server. The global virus library includes the local domain name virus library on the virus server, and the second virus domain name blacklist and the third virus domain name whitelist after being verified and qualified by the virus server; Synchronize the global virus library to all network security devices through the second preset protocol.

[0007] In a possible implementation manner, the first preset protocol includes the MQTT protocol.

[0008] In a possible implementation manner, the malicious domain name detection model based on the deep learning convolutional neural network includes an input layer, a convolutional layer, a pooling layer, and a fully connected layer. The input layer is the domain name to be tested extracted by packet parsing. The convolutional layer is a nested multi-layer convolutional neural network, and a pooling layer is connected after each convolutional layer. Finally, through the fully connected layer, the sigmoid activation function is used for classification.

[0009] In a possible implementation manner, after synchronizing the global virus library to all network security devices through the second preset protocol, it further includes: Send information indicating that the update of the global virus library is completed to the virus server.

[0010] In a second aspect, the present invention further provides a method for updating a virus library, which is applied to a virus server and includes: Receive and verify the compliance of the second virus domain name blacklist to obtain a third virus domain name blacklist; Receive and verify the compliance of the third virus domain name whitelist to obtain a fourth virus domain name whitelist; Add the third virus domain name blacklist to the local virus library to obtain a first local virus library; When it is determined that the fourth virus domain name whitelist exists in the first local virus library, delete the fourth virus domain name whitelist from the first local virus library to obtain a second local virus library; Synchronize the second local virus library to all network security devices.

[0011] In a possible implementation manner, verifying the compliance of the second virus domain name blacklist includes: When it is determined that the domain names in the second virus domain name blacklist meet the preset rules, confirm that the second virus domain name blacklist is compliant.

[0012] In a possible implementation manner, synchronizing the second local virus library to all network security devices includes: Synchronize the second local virus library to all network security devices in a full amount manner.

[0013] In a third aspect, the present invention further provides a virus database updating device, including: A message receiving module, configured to receive a target message sent by a client; A classification result determining module, configured to input the target domain name into a malicious domain name detection model based on a deep learning convolutional neural network that is completely constructed when it is determined that the target domain name in the target message does not match both the local first virus domain name blacklist and the local first virus domain name whitelist, so as to obtain a classification result; A data comparison module, configured to add the target domain name to the first virus domain name blacklist to obtain a second virus domain name blacklist when it is determined based on the classification result that the target message is a virus domain name, add the target domain name to the first virus domain name whitelist to obtain a second virus domain name whitelist when it is determined based on the classification result that the target message is a non-virus domain name, and add the target domain name to the second virus domain name whitelist to obtain a third virus domain name whitelist when it is determined based on the classification result that the target domain name in the target message is misidentified; An updating module, configured to synchronize the second virus domain name blacklist and the third virus domain name whitelist to a virus server through a first preset protocol, and receive a global virus database sent by the virus server, where the global virus database includes a local domain name virus database on the virus server, and the second virus domain name blacklist and the third virus domain name whitelist that are verified and qualified by the virus server; A synchronization module, configured to synchronize the global virus database to all network security devices through a second preset protocol.

[0014] In a fourth aspect, the present invention further provides an electronic device, including a memory and a processor, where The memory is used for storing a program; The processor is coupled to the memory and is configured to execute the program stored in the memory to implement the steps in a virus database updating method in any one of the above implementation manners.

[0015] In a fifth aspect, the present invention further provides a computer-readable storage medium, used for storing a computer-readable program or instruction, and when the program or instruction is executed by a processor, it can implement the steps in a virus database updating method in any one of the above implementation manners.

[0016] The beneficial effects of the present invention are as follows: A method for updating a virus library provided by the present invention first receives a target message sent by a client, inputs the target domain name in the target message into a preset neural network model to obtain a classification result. When it is determined based on the classification result that the target domain name in the target message does not match the local domain name virus library, when it is determined that the target message is a virus domain name, the target domain name is added to the first virus domain name blacklist to obtain a second virus domain name blacklist. When it is determined based on the classification result that the target message is a non-virus domain name, the target domain name is added to the first virus domain name whitelist to obtain a second virus domain name whitelist. When it is determined based on the classification result that the target domain name in the target message is misidentified, the target domain name is added to the second virus domain name whitelist to obtain a third virus domain name whitelist. Through this step, the detection result of the target message domain name is added to the virus library in a timely manner. The second virus domain name blacklist and the third virus domain name whitelist are synchronized to the virus server through a first preset protocol, and the global virus library sent by the virus server is received. The global virus library includes the local domain name virus library on the virus server, and the second virus domain name blacklist and the third virus domain name whitelist that have passed the verification of the virus server. The global virus library is synchronized to all network security devices through a second preset protocol. By updating to each network security device in a timely manner, the accuracy and stability of virus library recognition are improved. The present invention can detect virus domain names in real time by configuring a virus domain name blacklist and whitelist and automatically synchronizing them to the virus library server, thereby improving the virus detection rate. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is a flowchart of a method according to an embodiment of a method for updating a virus library provided by the present invention; Figure 2 It is a specific flowchart of a method according to an embodiment of a method for updating a virus library provided by the present invention; Figure 3 It is a flowchart of a method according to another embodiment of a method for updating a virus library provided by the present invention; Figure 4 It is an application scenario diagram of a method according to an embodiment of a method for updating a virus library provided by the present invention; Figure 5 It is a schematic flowchart of an embodiment of a virus library update device provided by the present invention; Figure 6 It is a schematic structural diagram of an embodiment of an electronic device provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work fall within the protection scope of the present invention.

[0019] In the description of the embodiments of the present invention, unless otherwise specified, the meaning of "a plurality" is two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0020] The descriptions such as "first" and "second" involved in the embodiments of the present invention are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Therefore, the technical features defined with "first" and "second" may explicitly or implicitly include at least one such feature.

[0021] Referring to "embodiments" herein means that the specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present invention. The phrase appears in various positions in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0022] Before presenting the embodiments, the following terms will be explained first.

[0023] ‌Network security devices‌ refer to devices and technologies used to protect computer networks from various network attacks and threats. These devices ensure the security of the network system and the integrity of data through different mechanisms and strategies. Common network security devices include firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), Web application firewalls (WAF), unified threat management (UTM), virtual private networks (VPN), etc.

[0024] ‌The MQTT protocol (Message Queuing Telemetry Transport) is a lightweight messaging protocol based on the publish / subscribe model, mainly used for resource-constrained devices and network environments with low bandwidth, high latency, or instability‌‌. The MQTT protocol works on top of the TCP / IP protocol and is particularly suitable for the Internet of Things (IoT) field, such as machine-to-machine (M2M) communication and smart home scenarios‌.

[0025] The present invention provides a method, apparatus, electronic device, and medium for updating a virus database, which will be described separately below.

[0026] Figure 1 It is a schematic flowchart of an embodiment of the method for updating the virus database provided by the present invention. As Figure 1 shown, the method for updating the virus database is applied to a network security device and includes: S101. Receive a target message sent by a client; The client can access the service server through HTTP, and the network security device obtains the message accessed by the client. It can be understood that the client can also access the service server through other protocols.

[0027] S102. When it is determined that the target domain name in the target message does not match both the local first virus domain name blacklist and the local first virus domain name whitelist, input the target domain name into a malicious domain name detection model based on a deep learning convolutional neural network that is completely constructed to obtain a classification result; S103. When it is determined based on the classification result that the target message is a virus domain name, add the target domain name to the first virus domain name blacklist to obtain a second virus domain name blacklist. When it is determined based on the classification result that the target message is a non-virus domain name, add the target domain name to the first virus domain name whitelist to obtain a second virus domain name whitelist. When it is determined based on the classification result that the target domain name in the target message is mis-identified, add the target domain name to the second virus domain name whitelist to obtain a third virus domain name whitelist; It can be understood that the local domain name virus database on the network security device includes a virus domain name blacklist and a virus domain name whitelist. When the target domain name does not match, it means that the target domain name is a virus domain name or a whitelist. Mis-identification means that through user feedback, it is determined that the target domain name is mis-identified, and the target domain name is added to the whitelist in the system.

[0028] S104. Synchronize the second virus domain name blacklist and the third virus domain name whitelist to the virus server through a first preset protocol, and receive the global virus database sent by the virus server. The global virus database includes the local domain name virus database on the virus server, and the second virus domain name blacklist and the third virus domain name whitelist verified and qualified by the virus server; It can be understood that a real-time communication channel is established between the virus database server and the network security device on the network security device. When the virus domain name black and white lists are updated, the update information is immediately sent to the virus database server through this communication channel to ensure the real-time nature of the virus database.

[0029] S105. Synchronize the global virus database to all network security devices through a second preset protocol.

[0030] Compared with the prior art, a method for updating a virus library provided in this embodiment first receives a target message sent by a client, inputs the target domain name in the target message into a preset neural network model to obtain a classification result. When it is determined based on the classification result that the target domain name in the target message does not match the local domain name virus library, when it is determined that the target message is a virus domain name, the target domain name is added to the first virus domain name blacklist to obtain a second virus domain name blacklist. When it is determined based on the classification result that the target message is a non-virus domain name, the target domain name is added to the first virus domain name whitelist to obtain a second virus domain name whitelist. When it is determined based on the classification result that the target domain name in the target message is misidentified, the target domain name is added to the second virus domain name whitelist to obtain a third virus domain name whitelist. Through this step, the detection result of the target message domain name is added to the virus library in a timely manner. The second virus domain name blacklist and the third virus domain name whitelist are synchronized to the virus server through a first preset protocol, and the global virus library sent by the virus server is received. The global virus library includes the local domain name virus library on the virus server, and the second virus domain name blacklist and the third virus domain name whitelist verified and qualified by the virus server. The global virus library is synchronized to all network security devices through a second preset protocol. By updating to each network security device in a timely manner, the accuracy and stability of virus library recognition are improved. In the present invention, by configuring the virus domain name blacklist and whitelist and automatically synchronizing them to the virus library server, virus domain names can be detected in real time, thereby improving the virus detection rate.

[0031] In some embodiments of the present invention, as Figure 2 shown, the specific steps of the method for updating the virus library are as follows: Step 1: The client accesses a web page through HTTP; Step 2: Through the network security device, the domain names of the passing messages are detected; Step 3: If the domain name detected and matched in the virus library is controlled through the virus protection function of the network security device, the client fails to open the virus website; if not detected or misidentified, the virus website is opened or misblocked, and the virus domain name blacklist or whitelist is added through the network security device; Step 4: The virus domain name blacklist or whitelist configured on the network security device is synchronized to the virus library server through the MQTT protocol; Step 5: After the virus library server verifies the legality of the virus domain name blacklist value and whitelist value, the domain names in the blacklist are added to the virus library features, and for the domain names in the whitelist, those existing in the library are compared and deleted, and the virus library version is updated; Step 6: The virus library server actively distributes the feature library to other network security devices through the network security devices monitored by automatic upgrade before; Step 7: Other network security devices actively upgrade the virus database regularly through network protocols, or the virus database server actively distributes the signature database to the devices.

[0032] In some embodiments of the present invention, the first preset protocol includes the MQTT protocol.

[0033] In some embodiments of the present invention, it further includes: The malicious domain name detection model based on the deep learning convolutional neural network includes an input layer, a convolutional layer, a pooling layer, and a fully connected layer. The input layer is the domain name to be tested extracted by message parsing. The convolutional layer is a nested multi-layer convolutional neural network, and a pooling layer is connected after each convolutional layer. Finally, through the fully connected layer, the sigmoid activation function is used for classification.

[0034] In some embodiments of the present invention, after synchronizing the global virus database to all network security devices through the second preset protocol, it further includes: Sending information indicating that the update of the global virus database is completed to the virus server.

[0035] Second aspect, as Figure 3 shown, the present invention also provides a method for updating a virus database, which is applied to a virus server and includes: S301: Receive and verify the compliance of the second virus domain name blacklist to obtain a third virus domain name blacklist; S302: Receive and verify the compliance of the third virus domain name whitelist to obtain a fourth virus domain name whitelist; S303: Add the third virus domain name blacklist to the local virus database to obtain a first local virus database; S304: When it is determined that the fourth virus domain name whitelist exists in the first local virus database, delete the fourth virus domain name whitelist from the first local virus database to obtain a second local virus database; S305: Synchronize the second local virus database to all network security devices.

[0036] In some embodiments of the present invention, verifying the compliance of the second virus domain name blacklist includes: When it is determined that the domain names in the second virus domain name blacklist meet the preset rules, confirm that the second virus domain name blacklist is compliant.

[0037] In a specific embodiment of the present invention, the preset rule is, for example, http.XXXXX.com. When the domain name in the second virus domain name blacklist meets the format of http.XXXXX.com, it means that http.XXXXX.com is compliant. Similarly, determine the compliance of the second virus domain name whitelist.

[0038] In some embodiments of the present invention, synchronizing the second local virus library to all network security devices includes: Synchronizing the second local virus library to all network security devices in a full-volume manner.

[0039] For ease of understanding the above solution content, as Figure 4 shown is a schematic diagram of a scenario of an application example of this embodiment. Specifically, Virus protection functions are enabled on network security devices A, B, and C. PC1 accesses the external network through the HTTP protocol, but accidentally clicks on a domain name website that is a virus website. It is not detected by network device A, resulting in PC1 being poisoned. The administrator discovers through layers of investigation that PC1 accessed a virus website, and this domain name is not in the virus library. At this time, the administrator adds this website to the virus domain blacklist. When PC1 and PC2 access this website through the HTTP protocol again, the web page cannot be opened and the website is blocked by device A; PC1 cannot access an external network website through the HTTP protocol. After investigation, it is found that it is accidentally blocked by the virus protection function. The domain name of this website is added to the virus domain whitelist. PC1 can access this website normally again and the website will not be accidentally blocked; Network security devices A, B, and C configure regular virus library upgrade tasks. The virus library server monitors these devices when the network security devices A, B, and C regularly request the virus library from the server. After adding virus domain black and white lists on network security device A, they are automatically synchronized to the virus library server through a synchronization task. After the virus library server verifies the legality of these virus domain black and white lists, it updates them to the virus library. The virus library server then actively synchronizes and distributes the latest signature library to other network security devices B and C to improve the virus detection rate.

[0040] Finally, it should be noted that this embodiment can solve the problem of false positives or missed detections of virus detection at the user site without upgrading the virus library. At the same time, the virus domain blacklist and whitelist configured at the network points are automatically synchronized to the virus library server, the blacklist is added to the virus library, and the whitelist domain names are deleted from the virus library to dynamically update the virus signature library. After the virus signature library is updated, it is automatically distributed to other network security devices in the network or other network security devices regularly upgrade the signature library from the virus library server to improve the accuracy and stability of virus signature library recognition.

[0041] In summary, through the configuration of virus domain blacklist and whitelist, this embodiment can detect virus domain names in real time, thereby improving the virus detection rate. Further, the virus black and white list domain names configured in the live network are synchronized to the virus library server, thereby further improving the virus detection rate of the virus library.

[0042] To better implement a method for updating a virus database in an embodiment of the present invention, correspondingly, based on a method for updating a virus database, as Figure 5 shown, an embodiment of the present invention further provides a virus database update device. The virus database update device 500 includes: A message receiving module 501, configured to receive a target message sent by a client; A classification result determination module 502, configured to input the target domain name into a malicious domain name detection model based on a complete deep learning convolutional neural network when it is determined that the target domain name in the target message does not match both the local first virus domain name blacklist and the local first virus domain name whitelist, to obtain a classification result; A data comparison module 503, configured to add the target domain name to the first virus domain name blacklist to obtain a second virus domain name blacklist when it is determined based on the classification result that the target message is a virus domain name, add the target domain name to the first virus domain name whitelist to obtain a second virus domain name whitelist when it is determined based on the classification result that the target message is a non-virus domain name, and add the target domain name to the second virus domain name whitelist to obtain a third virus domain name whitelist when it is determined based on the classification result that the target domain name in the target message is misidentified; An update module 504, configured to synchronize the second virus domain name blacklist and the third virus domain name whitelist to a virus server through a first preset protocol, and receive a global virus database sent by the virus server. The global virus database includes a local domain name virus database on the virus server, and the second virus domain name blacklist and the third virus domain name whitelist verified and qualified by the virus server; A synchronization module 505, configured to synchronize the global virus database to all network security devices through a second preset protocol.

[0043] The virus database update device 500 provided in the above embodiment can implement the technical solution described in the above embodiment of the method for updating a virus database. The specific implementation principles of the above modules or units can be referred to the corresponding content in the above embodiment of the method for updating a virus database, and will not be elaborated here.

[0044] As Figure 6 shown, the present invention further correspondingly provides an electronic device 600. The electronic device 600 includes a processor 601, a memory 602, and a display 603. Figure 6 Only some components of the electronic device 600 are shown, but it should be understood that it is not required to implement all the shown components, and more or fewer components can be alternatively implemented.

[0045] In some embodiments, the processor 601 may be a central processing unit (CPU), a microprocessor, or other data processing chips, which are used to run the program code stored in the memory 602 or process data, such as a method for updating a virus library in the present invention.

[0046] In some embodiments, the processor 601 may be a single server or a server group. The server group may be centralized or distributed. In some embodiments, the processor 601 may be local or remote. In some embodiments, the processor 601 may be implemented on a cloud platform. In some embodiments, the cloud platform may include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an internal cloud, a multi-cloud, etc., or any combination of the above.

[0047] In some embodiments, the memory 602 may be an internal storage unit of the electronic device 600, such as a hard disk or memory of the electronic device 600. In some other embodiments, the memory 602 may also be an external storage device of the electronic device 600, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc., equipped on the electronic device 600.

[0048] Furthermore, the memory 602 may include both the internal storage unit of the electronic device 600 and the external storage device. The memory 602 is used to store the application software installed in the electronic device 600 and various types of data.

[0049] In some embodiments, the display 603 may be an LED display, a liquid crystal display, a touch liquid crystal display, and an OLED (Organic Light-Emitting Diode) toucher, etc. The display 603 is used to display the information in the electronic device 600 and to display a visual user interface. The components 601 - 603 of the electronic device 600 communicate with each other through a system bus.

[0050] In one embodiment, when the processor 601 executes a virus library update program in the memory 602, the following steps may be implemented: Receive a target message sent by a client; When it is determined that the target domain name in the target message does not match both the local first virus domain name blacklist and the local first virus domain name whitelist, input the target domain name into a malicious domain name detection model based on a deep learning convolutional neural network that has been built completely, and obtain a classification result; When it is determined based on the classification result that the target message is a virus domain name, add the target domain name to the first virus domain blacklist to obtain the second virus domain blacklist. When it is determined based on the classification result that the target message is a non-virus domain name, add the target domain name to the first virus domain whitelist to obtain the second virus domain whitelist. When it is determined based on the classification result that the target domain name in the target message is misidentified, add the target domain name to the second virus domain whitelist to obtain the third virus domain whitelist; Synchronize the second virus domain blacklist and the third virus domain whitelist to the virus server through the first preset protocol, and receive the global virus library sent by the virus server. The global virus library includes the local domain name virus library on the virus server, and the second virus domain blacklist and the third virus domain whitelist after being verified and qualified by the virus server; Synchronize the global virus library to all network security devices through the second preset protocol.

[0051] It should be understood that when the processor 601 executes a virus library update program in the memory 602, in addition to the above functions, other functions can also be realized. For specific details, reference can be made to the description of the corresponding method embodiments above.

[0052] Furthermore, the type of the electronic device 600 mentioned in the embodiments of the present invention is not specifically limited. The electronic device 600 can be a mobile phone, a tablet computer, a personal digital assistant (PDA), a wearable device, a laptop computer and other portable electronic devices. Exemplary embodiments of the portable electronic device include, but are not limited to, portable electronic devices running IOS, android, microsoft or other operating systems. The above portable electronic devices can also be other portable electronic devices, such as a laptop computer with a touch-sensitive surface (such as a touch panel). It should also be understood that in some other embodiments of the present invention, the electronic device 600 may not be a portable electronic device, but a desktop computer with a touch-sensitive surface (such as a touch panel).

[0053] Those skilled in the art can understand that all or part of the processes of implementing the above method embodiments can be completed by instructing relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. Among them, the computer-readable storage medium is a disk, an optical disk, a read-only memory or a random access memory, etc.

[0054] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention.

Claims

1. A method for updating a virus database, applied to a network security device, characterized in that Including: Receiving a target message sent by a client; When it is determined that the target domain name in the target message does not match both the local first virus domain name blacklist and the local first virus domain name whitelist, inputting the target domain name into a malicious domain name detection model based on a fully constructed deep learning convolutional neural network to obtain a classification result; When it is determined based on the classification result that the target message is a virus domain name, adding the target domain name to the first virus domain name blacklist to obtain a second virus domain name blacklist. When it is determined based on the classification result that the target message is a non-virus domain name, adding the target domain name to the first virus domain name whitelist to obtain a second virus domain name whitelist. When it is determined based on the classification result that the target domain name in the target message is misidentified, adding the target domain name to the second virus domain name whitelist to obtain a third virus domain name whitelist; Synchronizing the second virus domain name blacklist and the third virus domain name whitelist to a virus server through a first preset protocol, and receiving a global virus library sent by the virus server. The global virus library includes a local domain name virus library on the virus server, and the second virus domain name blacklist and the third virus domain name whitelist that have passed the verification of the virus server; Synchronizing the global virus library to all network security devices through a second preset protocol.

2. The method for updating the virus database according to claim 1, wherein The first preset protocol includes the MQTT protocol.

3. The malicious domain name detection and protection method based on deep learning according to claim 1, characterized in that: The malicious domain name detection model based on a deep learning convolutional neural network includes an input layer, a convolutional layer, a pooling layer, and a fully connected layer. The input layer is the domain name to be tested extracted by message parsing. The convolutional layer is a nested multi-layer convolutional neural network, and a pooling layer is connected after each convolutional layer. Finally, through the fully connected layer, the sigmoid activation function is used for classification.

4. The method for updating the virus database according to claim 1, wherein After synchronizing the global virus library to all network security devices through the second preset protocol, it further includes: Sending information indicating that the update of the global virus library is completed to the virus server.

5. A method for updating a virus database, applied to a virus server, characterized in that, Including: Receiving and verifying the compliance of the second virus domain name blacklist to obtain a third virus domain name blacklist; Receiving and verifying the compliance of the third virus domain name whitelist to obtain a fourth virus domain name whitelist; Adding the third virus domain name blacklist to the local virus library to obtain a first local virus library; When it is determined that the fourth virus domain name whitelist exists in the first local virus library, deleting the fourth virus domain name whitelist from the first local virus library to obtain a second local virus library; Synchronizing the second local virus library to all network security devices.

6. The method for updating the virus database according to claim 5, wherein Verifying the compliance of the second virus domain name blacklist includes: When it is determined that the domain names in the second virus domain name blacklist meet the preset rules, confirming that the second virus domain name blacklist is compliant.

7. The method for updating a virus database according to claim 5, characterized in that, The synchronizing the second local virus library to all network security devices includes: Synchronizing the second local virus library to all network security devices in a full volume manner.

8. An update device for a virus database, characterized in that Including: A message receiving module for receiving a target message sent by a client; A classification result determination module for, when it is determined that the target domain name in the target message does not match both the local first virus domain name blacklist and the local first virus domain name whitelist, inputting the target domain name into a malicious domain name detection model based on a fully constructed deep learning convolutional neural network to obtain a classification result; A data comparison module, which is used to add the target domain name to the first virus domain name blacklist to obtain a second virus domain name blacklist when it is determined based on the classification result that the target message is a virus domain name, add the target domain name to the first virus domain name whitelist to obtain a second virus domain name whitelist when it is determined based on the classification result that the target message is a non-virus domain name, and add the target domain name to the second virus domain name whitelist to obtain a third virus domain name whitelist when it is determined based on the classification result that the target domain name in the target message is misidentified; An update module, which is used to synchronize the second virus domain name blacklist and the third virus domain name whitelist to the virus server through a first preset protocol, and receive the global virus library sent by the virus server. The global virus library includes the local domain name virus library on the virus server, and the second virus domain name blacklist and the third virus domain name whitelist that are verified and qualified by the virus server; A synchronization module, which is used to synchronize the global virus library to all network security devices through a second preset protocol.

9. An electronic device, characterized in that, It includes a memory and a processor, wherein, The memory is used to store programs; The processor is coupled to the memory and is used to execute the program stored in the memory to implement the steps in a method for updating a virus library according to any one of claims 1 to 4 above, or to implement the steps in a method for updating a virus library according to any one of claims 5 to 7 above.

10. A computer-readable storage medium, characterized in that, It is used to store computer-readable programs or instructions to implement the steps in a method for updating a virus library according to any one of claims 1 to 4 above, or the programs or instructions can implement the steps in a method for updating a virus library according to any one of claims 5 to 7 above when executed by the processor.