Multi-engine and white list sample automatic judging and scanning comprehensive virus studying and judging method and device

Through a comprehensive virus analysis method that automatically scans multiple engines and whitelist samples, combined with multi-engine scanning and whitelist scanning, the calling process is optimized, the problem of high false alarm rate in virus detection technology is solved, and efficient virus identification is achieved in the intranet LAN environment.

CN120805129APending Publication Date: 2025-10-17360 ZONGHENG INFORMATION TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510747107.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

Existing virus detection technology relies on multi-engine scanning, resulting in a high false positive rate and is unable to effectively identify whitelist samples in closed environments such as intranets and local area networks.

Method used

A comprehensive virus analysis method using multiple engines and automatic whitelist sample scanning is adopted. By combining multi-engine scanning with whitelist scanning, the calling process is optimized, the false alarm rate is reduced, and the practicality of the system is improved.

Benefits of technology

It reduces the false positive rate of the engine, improves the accuracy of virus analysis and the practicality of the system, and can effectively identify whitelist samples in the intranet LAN environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120805129A_ABST
    Figure CN120805129A_ABST
Patent Text Reader

Abstract

The invention discloses a comprehensive virus research and judgment method and device for multi-engine and white list sample automatic judgment and scanning, and belongs to the technical field of information security. Performing multi-engine scanning judgment on the to-be-searched and killed sample to obtain a first scanning judgment result; judging whether the to-be-searched and killed sample has a signature or not; if yes, performing white list scanning judgment on the to-be-searched and killed sample to obtain a second scanning judgment result, and obtaining a comprehensive virus research and judgment result of the sample based on the first scanning judgment result and the second scanning judgment result; and if not, obtaining a comprehensive virus research and judgment result of the sample based on the first judgment and scanning result. According to the method, the samples containing the signatures are processed by introducing the built-in white list scanning judgment while multi-engine scanning judgment is carried out, selective and sequential optimized calling is realized, the false alarm rate of the engines is reduced, and the practicability of the whole system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of information security, and particularly relates to a comprehensive virus research and judgment method and device for multi-engine and whitelist sample automatic judgment scanning. BACKGROUND

[0002] A computer virus is a program artificially programmed, which can hide or parasitize in storage media (disks, programs) through different channels, and when certain conditions or opportunities are ripe, can self-replicate and spread, causing different degrees of damage to computer resources. The existing virus detection technology usually obtains a comprehensive conclusion through multi-engine judgment scanning, and the comprehensive judgment scanning conclusion is the result of identification and judgment of various engines, and the discrimination intelligence is relatively single.

[0003] The existing virus detection technology usually simply relies on engine identification features, uses multiple different engines to identify different sample features, and the final result is often a comprehensive result of feature identification; therefore, while the identification rate of the single engine and the multi-engine is improved, the false positive rate is also relatively high. The existing virus detection technology can usually judge black through multi-engine judgment scanning, but cannot judge white; the main way of judging white relies on cloud database query, needs to be uploaded to the cloud for black and white comparison, and cannot be realized in a closed environment such as an internal network and a local area network. SUMMARY

[0004] The application aims to provide a comprehensive virus research and judgment method and device based on multi-engine and whitelist sample automatic judgment scanning to solve the problem of high false positive rate of the existing comprehensive virus research and judgment method based on multi-engine and whitelist sample automatic judgment scanning.

[0005] According to a first aspect of an embodiment of the application, a comprehensive virus research and judgment method for multi-engine and whitelist sample automatic judgment scanning is provided, including:

[0006] Obtaining a sample to be detected;

[0007] Performing multi-engine judgment scanning on the sample to be detected to obtain a first judgment scanning result;

[0008] Judging whether the sample to be detected has a signature;

[0009] If yes, performing whitelist judgment scanning on the sample to be detected to obtain a second judgment scanning result, and obtaining a comprehensive virus research and judgment result of the sample based on the first judgment scanning result and the second judgment scanning result;

[0010] If no, obtaining a comprehensive virus research and judgment result of the sample based on the first judgment scanning result.

[0011] In some optional embodiments of the application, before the multi-engine judgment scanning on the sample to be detected to obtain the first judgment scanning result, the method further includes:

[0012] determining a sample level and / or static information of the sample to be scanned;

[0013] allocating one or more engines to the sample to be scanned according to the sample level and / or static information of the sample.

[0014] In some optional embodiments of the present application, the sample to be scanned is subjected to multi-engine scanning to obtain a first scanning result, comprising:

[0015] obtaining weights of the multiple engines;

[0016] sequentially scanning the sample to be scanned by each of the engines in descending order of engine weight;

[0017] if the scanning result of an engine is black and the sample virus information is given, the scanning result of the engine is taken as the first scanning result, which includes the virus name, level and type of the sample.

[0018] In some optional embodiments of the present application, the sample to be scanned is subjected to multi-engine scanning to obtain a first scanning result, further comprising:

[0019] if the scanning results of the multiple engines do not exist virus information and the scanning result is black, a default virus name is taken as the first scanning result.

[0020] In some optional embodiments of the present application, the sample to be scanned is subjected to multi-engine scanning to obtain a first scanning result, further comprising:

[0021] determining whether the scanning results of the multiple engines are all non-black; if yes, the first scanning result is non-black;

[0022] if no, the first scanning result is given based on the scanning results of the multiple engines.

[0023] In some optional embodiments of the present application, the sample to be scanned is subjected to whitelist scanning to obtain a second scanning result, comprising:

[0024] determining whether the second scanning result has a value;

[0025] if yes, the second scanning result is taken as the comprehensive virus research and judgment result of the sample;

[0026] if no, the first scanning result is taken as the comprehensive virus research and judgment result of the sample.

[0027] In some optional embodiments of the present application, the sample to be scanned is subjected to whitelist scanning to obtain a second scanning result, comprising:

[0028] extracting a signature certificate of the sample to be scanned;

[0029] comparing the signature certificate with a local signature database;

[0030] obtaining a second scanning result based on the comparison result.

[0031] In some optional embodiments of the present application, a comprehensive virus research and judgment result of the sample is obtained based on the first scanning result and the second scanning result, comprising:

[0032] judging whether the second scanning result is a white sample;

[0033] If not, the second scanning result has no value, and the first scanning result is taken as the comprehensive virus research and judgment result.

[0034] If yes, the second scanning result has value, and the second scanning result is taken as the comprehensive virus research and judgment result.

[0035] In some optional embodiments of the present application, the second scanning result is obtained based on the comparison result, comprising:

[0036] when the signature certificate matches a white list of the local signature database, a white sample level of the signature certificate is taken as the second scanning result;

[0037] when the signature certificate matches a black list of the local signature database, a black sample level of the signature certificate is taken as the second scanning result.

[0038] In some optional embodiments of the present application, before the first scanning result is obtained by multi-engine scanning of the sample to be scanned, the method further comprises:

[0039] judging whether the sample to be scanned is a compressed file;

[0040] If yes, the sample to be scanned is decompressed.

[0041] According to a second aspect of the embodiments of the present application, a comprehensive virus research and judgment device for multi-engine and white list sample automatic scanning is provided, comprising:

[0042] an acquisition module, configured to acquire a sample to be scanned;

[0043] a first scanning module, configured to obtain a first scanning result by multi-engine scanning of the sample to be scanned;

[0044] a second scanning module, configured to judge whether the sample to be scanned has a signature;

[0045] If yes, the whitelist judgment and scanning is performed on the sample to be killed to obtain a second judgment and scanning result, and a comprehensive virus judgment result of the sample is obtained based on the first judgment and scanning result and the second judgment and scanning result.

[0046] If no, a comprehensive virus judgment result of the sample is obtained based on the first judgment and scanning result.

[0047] According to a third aspect of the embodiments of the present application, an electronic device is provided, which can include:

[0048] a processor;

[0049] a memory for storing processor-executable instructions;

[0050] The processor is configured to execute the instructions to implement the comprehensive virus judgment method of the multi-engine and whitelist sample automatic judgment and scanning according to any one of the first aspect.

[0051] The above technical solutions of the present application have the following beneficial technical effects:

[0052] The embodiments of the present application provide a comprehensive virus judgment method of multi-engine and whitelist sample automatic judgment and scanning, which introduces the built-in whitelist judgment and scanning processing of the sample containing the signature through the multi-engine judgment and scanning, realizes the selective and sequential optimization call, reduces the false positive rate of the engine, and improves the practicability of the overall system. BRIEF DESCRIPTION OF DRAWINGS

[0053] Figure 1 is a flowchart of a comprehensive virus judgment method of multi-engine and whitelist sample automatic judgment and scanning in an exemplary embodiment of the present application;

[0054] Figure 2 is a flowchart of a comprehensive virus judgment method of multi-engine and whitelist sample automatic judgment and scanning in an exemplary embodiment of the present application;

[0055] Figure 3 is a flowchart of a comprehensive virus judgment method of multi-engine and whitelist sample automatic judgment and scanning in an exemplary embodiment of the present application;

[0056] Figure 4 is a flowchart of a comprehensive virus judgment method of multi-engine and whitelist sample automatic judgment and scanning in another exemplary embodiment of the present application;

[0057] Figure 5 is a flowchart of a comprehensive virus judgment method of multi-engine and whitelist sample automatic judgment and scanning in an exemplary embodiment of the present application;

[0058] Figure 6This is a flow chart of a comprehensive virus analysis method using multiple engines and automatic whitelist sample scanning in another exemplary embodiment of the present application;

[0059] Figure 7 This is a schematic diagram of a comprehensive virus analysis and judgment device with multiple engines and automatic whitelist sample scanning in an exemplary embodiment of the present application;

[0060] Figure 8 is a schematic structural diagram of an electronic device in an exemplary embodiment of the present application; DETAILED DESCRIPTION

[0061] To make the objectives, technical solutions, and advantages of this application more clearly understood, this application is further described below in conjunction with specific embodiments and with reference to the accompanying drawings. It should be understood that these descriptions are merely illustrative and are not intended to limit the scope of this application. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion in the concepts of this application.

[0062] The accompanying drawings illustrate schematic diagrams of layer structures according to embodiments of the present application. These figures are not drawn to scale; for clarity, some details are exaggerated and some details may be omitted. The shapes of the various regions and layers shown in the figures, as well as their relative sizes and positional relationships, are merely exemplary and may deviate in practice due to manufacturing tolerances or technical limitations. Furthermore, those skilled in the art may design regions / layers with different shapes, sizes, and relative positions as needed.

[0063] Obviously, the described embodiments are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0064] In the description of this application, it should be noted that the terms "first", "second" and "third" are used for descriptive purposes only and should not be understood as indicating or implying relative importance.

[0065] In addition, the technical features involved in the different embodiments of the present application described below can be combined with each other as long as they do not conflict with each other.

[0066] Below, in conjunction with the accompanying drawings, a comprehensive virus analysis method and device for automatic scanning of multi-engine and whitelist samples provided in the embodiment of the present application is described in detail through specific embodiments and their application scenarios.

[0067] like Figure 1 As shown, in the first embodiment of the present application, a comprehensive virus analysis method with multiple engines and automatic whitelist sample scanning is provided, including the following steps:

[0068] Step S101: obtaining a sample to be scanned;

[0069] Step S102: performing multi-engine scanning on the sample to be scanned to obtain a first scanning result;

[0070] Step S103: determining whether the sample to be scanned has a signature;

[0071] Step S104: if yes, performing whitelist scanning on the sample to be scanned to obtain a second scanning result, and obtaining a comprehensive virus judgment result of the sample based on the first scanning result and the second scanning result;

[0072] Step S105: if no, obtaining a comprehensive virus judgment result of the sample based on the first scanning result.

[0073] The embodiment provides a comprehensive virus judgment method for multi-engine and whitelist sample automatic scanning, which introduces built-in whitelist scanning processing of samples containing signatures while performing multi-engine scanning, realizes selective and sequential optimization calling, reduces the false positive rate of the engine, and improves the practicability of the overall system.

[0074] Specifically, as shown in Figure 2 Before step S102, the method further includes:

[0075] Step S106: determining the sample level and / or static information of the sample to be scanned;

[0076] Step S107: assigning one or more engines suitable for the sample to be scanned according to the sample level and / or static information of the sample.

[0077] The embodiment optimizes the multi-engine scanning mechanism, and different engines are used to represent different discrimination technologies. The embodiment selects suitable discrimination technologies, i.e., multiple target engines, based on the level and / or static information of the sample to be scanned, comprehensively selects the best one from the scanning results, maximizes the application of the efficiency of multiple engines, and improves the accuracy of sample scanning as much as possible under the premise of ensuring the recognition rate.

[0078] In some embodiments, as shown in Figure 3 Step S102 includes:

[0079] Step S1021: obtaining the weights of multiple engines;

[0080] Step S1022: sequentially scanning the sample to be scanned by each engine in descending order of engine weight;

[0081] Step S1023: If the judgment result of a certain engine is black and the sample virus information is given, the judgment result of the engine is taken as the first judgment result, which includes the virus name, level and virus type of the sample;

[0082] Step S1024: If the judgment result of multiple engines is not black and the sample virus information is not given, the default virus name is taken as the first judgment result.

[0083] In some embodiments, as shown in FIG. 1, step S102 includes: Figure 4

[0084] Step S1021: Obtain the weights of multiple engines;

[0085] Step S1022: In descending order of engine weights, use each engine to judge the sample to be killed in sequence;

[0086] Step S1023: If the judgment result of a certain engine is black and the sample virus information is given, the judgment result of the engine is taken as the first judgment result, which includes the virus name, level and virus type of the sample;

[0087] Step S1024: Determine whether the judgment results of multiple engines are all non-black;

[0088] Step S1025: If yes, the first judgment result is non-black;

[0089] Step S1026: If no, the first judgment result is given based on the judgment results of multiple engines.

[0090] The comprehensive virus judgment result is the comprehensive virus judgment result.

[0091] In some embodiments, as shown in FIG. 1, the whitelist judgment of the sample to be killed is performed to obtain a second judgment result, which includes: Figure 5

[0092] Step S1041: Extract the signature certificate of the sample to be killed;

[0093] Step S1042: Compare the signature certificate with the local signature database;

[0094] Step S1043: Obtain the second judgment result based on the comparison result

[0095] Step S1044: Determine whether the second judgment result is a white sample;

[0096] Step S1045: If no, the second judgment result has no value, and the first judgment result is taken as the comprehensive virus judgment result;

[0097] ​​Step S1046: if yes, the second judgment and scanning result has a value, and the second judgment and scanning result is taken as the comprehensive virus judgment result.

[0098] In the embodiment, when the signature certificate matches the white list of the local signature database, the white sample level of the signature certificate is taken as the second judgment and scanning result; and when the signature certificate matches the black list of the local signature database, the black sample level of the signature certificate is taken as the second judgment and scanning result. The embodiment supplements the white list sample judgment and scanning mechanism, judges and scans the white list sample through the mechanism, reduces the false positive rate of the engine, improves the practicability of the overall system, solves the problem of "knowing which cannot be used, but not knowing which can be used", judges and scans the sample through the multi-engine judgment and scanning, and answers the question of which cannot be used; and judges and scans the sample through the white list sample automatic judgment and scanning technology, judges and scans the sample as white, and answers the question of "knowing which can be used".

[0099] As shown in FIG. 6, the second embodiment of the present application provides a comprehensive virus judgment method of multi-engine and white list sample automatic judgment and scanning, which comprises the following steps: Figure 6

[0100] 1) After the sample identification request is sent out, the engine start state in the component is acquired first in step S10, all the started engines in all the six engines are acquired, and the result is recorded;

[0101] 2) In step S20, the sample type can be judged by the engine C, and the type judgment result is transmitted to steps S40 and S50. Here, the sample type judgment includes judging the sample level (priority judgment and scanning level or threat size level), sample static information, whether it is a signature file, whether it is a compressed file, etc. Thus, in steps S40, S50 and S60, different engines or white lists can be allocated according to different sample types for level judgment and scanning.

[0102] Of course, the sample type judgment in step S20 can be omitted, and the engine judgment and scanning or the white list judgment and scanning can be directly performed. For example, for a signature file, the white list judgment and scanning is directly started; for a non-signature file, all the started effective engines are traversed, and a sample is sequentially scanned in descending order according to the engine weight order from high to low, and as long as an effective result is obtained by the engine, the judgment and scanning result of the engine is displayed first.

[0103] 3) In step S20, if the sample is a compressed file, it needs to be decompressed in step S30 first and then transmitted to steps S40, S50 and S60;

[0104] 4) In step S20, if the sample is not a compressed file or has been decompressed, steps S40, S50 and S60 are performed in parallel; ​

[0105] 5) In S40 step, according to the opening of the engine in the configuration, the opened engine in multiple engines is used for judgment scanning. For example, according to the sample level, the adaptive engine is selected for priority judgment scanning.

[0106] a) If the sample file research and judgment result is black, according to the weight descending order of engine A to engine F, the level, virus name, virus type and other information of the sample are given. That is, if engine A gives the virus name, level and virus type, the judgment scanning result of engine A is displayed preferentially, if engine A does not give the judgment scanning result, the judgment scanning result of engine B is used, and so on; if the six engines fail to output the virus name and virus type and still judge as black, the default virus name is given;

[0107] b) If the sample file research and judgment is non-black, the sample level is identified as non-black, and the result of the next step of white list sample automatic judgment scanning is waited;

[0108] 6) In S50 step, multiple engines are used to extract the static information of the sample file, the selection of the engine is to select the corresponding engine type according to the sample file type, and the multiple engine program is automatically distributed according to the type judgment of S20 step; for example, one or more engines suitable for a certain virus sample can be selected based on the preset mapping relationship in the virus judgment scanning engine library.

[0109] 7) In S60 step, all PE files with signature are identified, and sign_info is identified as 1;

[0110] 8) In S70 step, the weight in table 1-1 is used to integrate the multiple engine judgment scanning level and static information, and the result is recorded as a1;

[0111] 9) In S80 step, the sample with sign_info as 1 in S60 is scanned by signature,

[0112] The result is recorded as a2;

[0113] In S10, in the comprehensive research and judgment sub-process, a1 and a2 are compared, if a2 has a value, a2 is directly taken as the comprehensive research and judgment result; if a2 has no value, a1 is taken as the comprehensive research and judgment result.

[0114] In the main process of the embodiment, the object to be identified / researched and judged is the sample, and the subject of the research and judgment action is different engine / engine combination or white list automatic judgment scanning component;

[0115] All the engines involved are six in total, and the weights of multiple engines and white list automatic judgment scanning are shown in the following table (table 1-1);

[0116]

[0117] Table 1-1

[0118] In the above table, the meaning of PE file is Portable Executable (English: Portable Executable, abbreviated as PE), which is a file format for executable files, object files and dynamic link libraries, mainly used on 32-bit and 64-bit Windows operating systems. "Portable" refers to the versatility of the file format, which can be used in many different operating systems and architectures.

[0119] The meaning of ELF file is Executable and Linkable Format (English: Executable and Linkable Format, abbreviated as ELF), which is a standard file format for executable files, object code, shared libraries and core dumps in computing. ELF file is a common binary file format on Linux platform.

[0120] The comprehensive virus research and judgment method of multi-engine and whitelist sample automatic judgment provided by the embodiment can be used for different scenes or needs by combining different sample files in different combination calling modes according to different sample files, and can be combined with the built-in and newly added whitelist sample judgment scanning mechanism for automatic comparison and judgment scanning, and finally the comprehensive judgment scanning result of the sample is obtained. Case 1: only through the combination of multiple engines can the correct judgment be realized, which is suitable for samples without signature; case 2: when the multi-engine combination judgment is insufficient, the whitelist judgment scanning mechanism needs to be called in the case of sample with signature, and the built-in whitelist signature data is compared to realize selective and sequential optimization calling.

[0121] Specifically, the introduction of the whitelist sample automatic judgment scanning technology is one of the important designs of the embodiment.

[0122] The traditional technology mainly relies on engine judgment scanning, which is mainly aimed at various characteristics of samples and cannot judge white samples; the whitelist sample automatic judgment scanning technology compares the signature certificate in the file with the localized signature database, gives the corresponding white sample level for the sample with white signature, gives the corresponding black sample level for the sample with black signature, and gives the corresponding gray sample level for the sample with unknown signature.

[0123] The automatic judgment scanning result weight of the white list sample is the highest, and the sample passing through the white list sample automatic judgment scanning process directly adopts the result. The reason is that, first, the signature data in the signature database used for white list automatic judgment scanning in the embodiment is mainly provided by a trusted company, directly extracted from the sample, and verified by hundreds of millions of users, and has high credibility on the Internet side; second, the signature can be used by others, and the signature company and certificate used by others will be revoked, and the sample using the revoked signature will be marked as untrusted or black signature sample, and the database will be synchronized to the isolation environment through offline import in a regular manner, so that the signature data in the environment is the latest, and the data used for judgment scanning is prevented from being polluted to affect the judgment scanning result.

[0124] Compared with the conventional multi-engine judgment scanning which cannot judge white or has single or non-updatable basis for judgment, the white list sample automatic judgment scanning technology in the embodiment has more advantages. Moreover, the multi-engine has higher weight.

[0125] The embodiment provides a comprehensive virus judgment method of multi-engine and white list sample automatic judgment scanning. The comprehensive judgment of the sample is based on the two technical methods of multi-engine and white list sample automatic judgment scanning, which can supplement the results of the multi-engine and improve the judgment accuracy of the whole system:

[0126] The comprehensive judgment of multiple engines is usually based on comparison of samples and their characteristics, and the technical method is usually an intelligent engine of a machine learning algorithm or a built-in local white list. When multiple engines conflict, human judgment is needed again. The embodiment introduces the white list sample automatic judgment scanning technology, and opens the interface and method of signature iteration, so that the white signature verified by hundreds of millions of users is used as the comparison database, the data has higher confidence, and the self-knowledge evolution ability is also provided.

[0127] The embodiment still uses multi-engine judgment scanning first, mainly based on two reasons: first, the performance of multi-engine judgment scanning is superior, and the comprehensive judgment and processing size of the multiple engines used in the embodiment is 400 samples per second for samples of 10-100k, and the original design is to automatically process most samples through efficient multi-engine judgment scanning. The number of samples with signatures is highly related to the local area network environment and daily business, and generally does not exceed 10%, so using multi-engine to judge first and marking the samples with signatures to the white list sample automatic judgment scanning process is in line with the optimal process design.

[0128] As shown in Figure 7 based on the same inventive concept, the third embodiment of the present application provides a comprehensive virus judgment device of multi-engine and white list sample automatic judgment scanning, comprising:

[0129] The acquisition module 11 is configured to acquire a to-be-killed sample.

[0130] The first scanning module 12 is used to perform a multi-engine scanning on the sample to be detected and eliminated to obtain a first scanning result;

[0131] The second judging module 13 is used to judge whether the sample to be detected and killed has a signature;

[0132] If yes, perform a whitelist scan on the sample to be checked and obtain a second scan result, and obtain a comprehensive virus analysis result of the sample based on the first and second scan results;

[0133] If not, a comprehensive virus analysis result of the sample is obtained based on the first scan result.

[0134] Alternatively, as Figure 8 As shown, an embodiment of the present application also provides an electronic device 1100, including a processor 1101, a memory 1102, and a program or instruction stored in the memory 1102 and executable on the processor 1101. When the program or instruction is executed by the processor 1101, each process of the embodiment of the comprehensive virus analysis method for automatic scanning of multi-engine and whitelist samples is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0135] It should be noted that the electronic devices in the embodiments of the present application include the mobile electronic devices and non-mobile electronic devices mentioned above.

[0136] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, each process of the embodiment of the comprehensive virus analysis method for automatic scanning of multiple engines and whitelist samples is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0137] The processor is the processor in the electronic device described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), random access memory (RAM), a magnetic disk, or an optical disk.

[0138] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned comprehensive virus analysis method embodiment with multiple engines and automatic scanning of whitelist samples, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0139] It should be understood that the chip mentioned in the embodiments of the present application can also be referred to as a system-level chip, a system chip, a chip system, or a system-on-chip chip, etc.

[0140] It should be noted that in the embodiments, the terms "comprising", "containing" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of other identical elements in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, but can also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved, for example, the described method can be performed in an order different from that described, and various steps can also be added, omitted or combined. In addition, the features described with reference to certain examples can be combined in other examples.

[0141] From the above description of the embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment method can be realized by means of software and the necessary general hardware platform, of course, it can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM / RAM, magnetic disc, optical disc), including a plurality of instructions for making a terminal (which can be a mobile phone, computer, server, or network equipment, etc.) execute the method described in each embodiment of the present application.

[0142] The embodiments of the present application are described above in combination with the drawings, but the present application is not limited to the above specific embodiments, and the above specific embodiments are only illustrative, not restrictive, and those skilled in the art can make many forms under the inspiration of the present application without departing from the scope of the present application and the scope protected by the claims.

Claims

1. A comprehensive virus analysis method with multi-engine and whitelist sample automatic scanning, characterized by: include: Obtain samples to be detected and killed; Performing a multi-engine scan on the sample to be detected and killed to obtain a first scan result; Determine whether the sample to be detected and killed has a signature; If yes, perform a whitelist scan on the sample to be detected and killed to obtain a second scan result, and obtain a comprehensive virus analysis result of the sample based on the first scan result and the second scan result; If not, a comprehensive virus analysis result of the sample is obtained based on the first scanning result.

2. The comprehensive virus analysis method of claim 1, characterized by: Before performing a multi-engine scan on the sample to be detected and killed to obtain a first scan result, the method further includes: Determining the sample level and / or static information of the sample to be detected and eliminated; According to the sample level and / or static information of the sample to be detected and killed, one or more engines are allocated to the sample.

3. A comprehensive virus analysis method based on multi-engine and whitelist sample automatic scanning according to claim 1 or 2, characterized in that: Performing a multi-engine scan on the sample to be detected and killed to obtain a first scan result, including: Get the weights of multiple engines; In descending order of engine weight, use each engine to scan the sample to be detected and killed in turn; If a certain engine's scanning result is black and provides sample virus information, the engine's scanning result is used as the first scanning result, which includes the sample's virus name, level, and virus type.

4. The comprehensive virus analysis method of claim 3, characterized in that: Performing a multi-engine scan on the sample to be detected and killed to obtain a first scan result further includes: If the virus information does not exist in the scan results of the multiple engines and the scan result is black, the default virus name is used as the first scan result.

5. A comprehensive virus analysis method based on multi-engine and whitelist sample automatic scanning according to claim 3 or 4, characterized in that: Performing a multi-engine scan on the sample to be detected and killed to obtain a first scan result further includes: Determine whether the plurality of engine scan results are all non-black; if so, the first scan result is non-black; If not, the first scan result is given based on the multiple engine scan results.

6. A comprehensive virus analysis method based on multiple engines and automatic whitelist sample scanning according to any one of claims 1 to 5, characterized in that: A second scanning result is obtained by performing a whitelist scan on the sample to be detected and killed, including: Determine whether the second scan result has a value; If there is a value, the second scan result is used as the comprehensive virus identification result of the sample; If there is no value, the first scan result is used as the comprehensive virus analysis result of the sample.

7. A comprehensive virus analysis method using multiple engines and automatic whitelist sample scanning according to any one of claims 1-6, characterized in that: A second scanning result is obtained by performing a whitelist scan on the sample to be detected and killed, including: Extract the signature certificate of the sample to be detected and killed; Comparing the signature certificate with the local signature database; The second scanning result is obtained based on the comparison result.

8. The comprehensive virus analysis method of claim 7, characterized in that: Obtaining a comprehensive virus analysis result of the sample based on the first scan result and the second scan result includes: Determining whether the second scanning result is a white sample; If not, the second scan result has no value, and the first scan result is used as the comprehensive virus analysis result; If so, the second scanning result is valuable, and the second scanning result is used as the comprehensive virus analysis result.

9. The comprehensive virus analysis method of claim 8, characterized by: Obtaining the second scanning result based on the comparison result includes: When the signature certificate matches the whitelist of the local signature database, the white sample level of the signature certificate is used as the second scanning result; When the signature certificate matches the blacklist of the local signature database, the black sample level of the signature certificate is used as the second scanning result.

10. A comprehensive virus analysis method using multiple engines and automatic whitelist sample scanning according to any one of claims 1 to 9, characterized in that: Before performing a multi-engine scan on the sample to be detected and killed to obtain a first scan result, the method further includes: Determine whether the sample to be detected and killed is a compressed file; If so, the sample to be detected and killed is decompressed.

11. A comprehensive virus analysis and judgment device with multiple engines and automatic whitelist sample scanning, characterized by: include: The acquisition module is used to obtain samples to be detected and killed; A first scanning module is used to perform a multi-engine scanning on the sample to be detected and killed to obtain a first scanning result; The second judgment and scanning module is used to determine whether the sample to be detected and killed has a signature; If yes, perform a whitelist scan on the sample to be detected and killed to obtain a second scan result, and obtain a comprehensive virus analysis result of the sample based on the first scan result and the second scan result; If not, a comprehensive virus analysis result of the sample is obtained based on the first scanning result.

12. An electronic device, characterized in that: include: A processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements a comprehensive virus analysis method for automatic scanning of multi-engine and whitelist samples as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Parallel antivirus methods and systems using multiple antivirus engines

    CN102279917A

  • Virus detection method and virus detection engine

    CN104200163A

  • File security detection method and device, electronic equipment and storage medium

    CN114003914A

  • Suspicious file deep analysis and identification method, system and device and medium

    CN116471071A

  • Method and Device for Multiple Engine Virus Killing

    US20140304818A1