Terminal virus processing method and system, medium, equipment and program product

By acquiring terminal network connection behavior, matching and rejecting abnormal requests using intrusion indicator rules, and enabling virus removal and blocking strategies, the problem of remote control external connection and memory Trojan persistence of Silver Fox virus in Internet scenarios was solved, achieving secure and stable operation of the terminal and virus protection.

CN121644223APending Publication Date: 2026-03-10SANGFOR TECH INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202512020634.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-29
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing technologies cannot effectively prevent the Silver Fox virus from remotely controlling external connections and residing in memory in Internet scenarios, leading to repeated virus attacks and system vulnerabilities, and cannot completely remove virus residues.

Method used

By acquiring terminal network connection behavior, using intrusion indicator rules to match and reject abnormal connection requests, enabling virus removal and blocking strategies, monitoring process regeneration behavior, and configuring virus hunting rules for real-time monitoring and updating of intrusion indicator rules.

Benefits of technology

It effectively prevents virus recurrence, completely eliminates virus residue, enhances terminal security and stability, reduces the risk of virus attacks, and avoids system crashes and data leaks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121644223A_ABST
    Figure CN121644223A_ABST
Patent Text Reader

Abstract

The invention provides a terminal virus processing method and system, a medium, equipment and a program product, and relates to the field of network security, and the method comprises the steps: obtaining a network connection behavior of a terminal; matching the network connection behavior of the terminal by using an intrusion index rule, and if a target network connection behavior hitting the intrusion index rule exists, refusing all access requests of the target network connection behavior; and starting a virus clearing strategy and a virus blocking strategy aiming at the target network connection behavior. According to the method and the device, repeated attack and residual of viruses can be effectively prevented, serious problems of system vulnerability, data leakage, system crash and the like possibly caused by the residual viruses are avoided, the resistance of the terminal to the viruses is enhanced, a safer, more reliable and more stable use environment is provided for a terminal user, and the user experience is improved. And the safety protection level of the terminal is obviously improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of network security, in particular to a terminal virus processing method and system, a storage medium and an electronic device. BACKGROUND

[0002] Currently, for silver fox viruses, real-time detection and management of user internet access addresses through firewalls are relied on to timely prevent remote control behaviors of malicious silver fox services. Or, special killing tools are made for typical silver fox attack methods, and the execution of which can effectively identify residual trojans and timely remove them. However, the firewalls are usually deployed at the internet exit, i.e. the terminal, and can only solve the silver fox remote control external connection behavior to a certain extent in the internal network office scene, but cannot avoid the remote control external connection risk in the internet scene (such as business trip, home office, etc.), and cannot curb the memory trojans that have not been effectively removed and the existing resident items of the silver fox viruses that have been run. The residual trojans may try to bypass the network management of the firewall by resisting (such as trying to connect more remote control addresses). The special killing tools rely on active scanning, and the rules themselves have certain limitations, and since the special killing tools are easy to obtain, attackers can use the special killing tools to verify whether they can bypass, and cannot effectively solve all silver fox trojan residual problems.

[0003] Therefore, how to effectively process silver fox viruses is a technical problem that those skilled in the art urgently need to solve. SUMMARY

[0004] The purpose of the present application is to provide a terminal virus processing method, system, medium, device and program product, which can effectively prevent repeated occurrence and residual of viruses, avoid serious problems such as system vulnerability, data leakage and system crash that may be caused by virus residual, and enhance the resistance of the terminal to viruses.

[0005] To solve the above technical problems, the present application provides a terminal virus processing method, and the specific technical solutions are as follows:

[0006] Obtaining the network connection behavior of a terminal;

[0007] Matching the network connection behavior of the terminal with an intrusion index rule, and if there is a target network connection behavior that hits the intrusion index rule, rejecting all access requests of the target network connection behavior;

[0008] Enabling a virus removal strategy and a virus blocking strategy for the target network connection behavior; the virus removal strategy is used to remove a target process and a target process resident item related to the target network connection behavior; the virus blocking strategy is used to monitor the reproduction behavior of the target process and the re-release behavior of the target process resident item; and the virus removal strategy is enabled after the reproduction behavior or the re-release behavior is detected.

[0009] Optionally, before the network connection behavior of the terminal is acquired, the method further comprises:

[0010] acquiring a remote control software blacklist;

[0011] if the target software hits the remote control software blacklist, the running process of the target software is limited, and an uninstall operation of the target software is enabled;

[0012] if the terminal has installed application software that is suspicious remote control software that does not hit the remote control software blacklist, the running process of the suspicious software is monitored; the suspicious remote control software is remote control software that meets at least one of the following exceptions: software installation proportion exception, software version exception, and address carrying exception.

[0013] Optionally, before the remote control software blacklist is acquired, the method further comprises:

[0014] acquiring rule base information of each remote control software in a software whitelist; the rule base information includes at least one of the following: manufacturer, signature, process, and version information of the remote control software;

[0015] collecting installation data of the remote control software, and generating corresponding installation data features based on the installation data; the installation data includes at least one of the following: installation rate, installation version, and console access address;

[0016] updating the remote control software blacklist according to the rule base information and the installation data features.

[0017] Optionally, after the virus removal strategy and the virus blocking strategy for the target network connection behavior are enabled, the method further comprises:

[0018] configuring a virus hunting rule to the terminal; the virus hunting rule is used to monitor system services and / or memory processes;

[0019] if suspected virus software is detected by applying the virus hunting rule, collecting an external connection network address of the suspected virus software;

[0020] identifying the suspected virus software based on the external connection network address and the remote control software blacklist, if the suspected virus software is determined to be malicious software, enabling the virus removal strategy and the virus blocking strategy for the suspected virus program.

[0021] Optionally, if the external connection network address belongs to a malicious address, the method further comprises:

[0022] According to the suspicious virus program and the external connection network address, a cloud invasion index rule library is updated, and the terminal is subjected to invasion index rule updating.

[0023] Optionally, after enabling the virus removal strategy and the virus blocking strategy for the target network connection behavior, the method further comprises:

[0024] extracting parent process information of a process address corresponding to the regeneration behavior of the target process;

[0025] submitting the parent process information to a sandbox for running to obtain a feature rule of the parent process;

[0026] updating the invasion index rule according to the feature rule.

[0027] The application further provides a terminal virus processing system, comprising:

[0028] a behavior monitoring module configured to acquire network connection behaviors of a terminal;

[0029] a rule matching module configured to match the network connection behaviors of the terminal with an invasion index rule, and if there is a target network connection behavior that hits the invasion index rule, reject all access requests of the target network connection behavior;

[0030] a virus processing module configured to enable a virus removal strategy and a virus blocking strategy for the target network connection behavior; the virus removal strategy is configured to remove a target process and a target process resident item related to the target network connection behavior; the virus blocking strategy is configured to monitor a regeneration behavior of the target process and a re-release behavior of the target process resident item, and enable the virus removal strategy after detecting the regeneration behavior or the re-release behavior.

[0031] The application further provides a computer readable storage medium having a computer program stored thereon, the computer program being executed by a processor to implement the steps of the terminal virus processing method.

[0032] The application further provides an electronic device comprising a memory and a processor, the memory having a computer program stored therein, and the processor being configured to invoke the computer program in the memory to implement the steps of the terminal virus processing method.

[0033] The application further provides a computer program product comprising a computer program, the computer program being executed to implement the steps of the terminal virus processing method.

[0034] The application provides a terminal virus processing method, comprising the following steps: obtaining network connection behavior of a terminal; matching the network connection behavior of the terminal by using an intrusion index rule; if there is a target network connection behavior that hits the intrusion index rule, rejecting all access requests of the target network connection behavior; enabling a virus cleaning strategy and a virus blocking strategy for the target network connection behavior; the virus cleaning strategy is used for cleaning a target process and a target process resident item related to the target network connection behavior; the virus blocking strategy is used for monitoring reproduction behavior of the target process and re-release behavior of the target process resident item; and the virus cleaning strategy is enabled after the reproduction behavior or the re-release behavior is detected.

[0035] The application can accurately identify the target network connection behavior with potential virus risk by obtaining the network connection behavior of the terminal and matching by using the intrusion index rule, so that all access requests of the virus are rejected in time before the virus further spreads and causes damage, the virus is effectively prevented from spreading and invading through network connection, the risk of the terminal being attacked by the virus is greatly reduced, and the security and stability of the terminal system are ensured. In addition, the virus cleaning strategy for the target network connection behavior is enabled, so that the target process and the resident item related to the behavior can be completely cleaned, the existence basis of the virus in the terminal system is fundamentally eliminated, the occupation of system resources by the virus and the interference and damage of the virus to normal system functions are avoided, and it is ensured that the terminal can normally and stably operate. The virus blocking strategy further strengthens the security protection capability of the terminal, can monitor the reproduction behavior of the target process and the re-release behavior of the target process resident item in real time, and the virus cleaning strategy is enabled once the behavior that may cause the virus to be active again is detected, so that a dynamic and continuous protection mechanism is formed, the repeated occurrence and residue of the virus are effectively prevented, the system vulnerability, data leakage, system crash and other serious problems caused by the virus residue are avoided, the resistance of the terminal to the virus is greatly enhanced, a safer, more reliable and more stable use environment is provided for the terminal user, and the security protection level of the terminal is significantly improved.

[0036] The application also provides a detection system, a computer readable storage medium and an electronic device, which have the above beneficial effects, and details are not repeated here. BRIEF DESCRIPTION OF DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description only belong to the embodiments of the application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of the provided drawings.

[0038] Figure 1 A flow chart of a terminal virus processing method provided by an embodiment of the present application;

[0039] Figure 2 A structural schematic diagram of a terminal virus processing system provided by an embodiment of the present application;

[0040] Figure 3 A structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0041] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0042] Reference Figure 1 , Figure 1 A flow chart of a terminal virus processing method provided by an embodiment of the present application, the method comprising:

[0043] S101: acquiring a network connection behavior of a terminal;

[0044] S102: matching the network connection behavior of the terminal with an intrusion index rule, and if there is a target network connection behavior that hits the intrusion index rule, rejecting all access requests of the target network connection behavior;

[0045] S103: enabling a virus cleaning strategy and a virus blocking strategy for the target network connection behavior.

[0046] The embodiments can be applied to a cloud server, or an electronic device connected with the cloud and the terminal, to process viruses of the terminal.

[0047] In step S101, in order to obtain the network connection behavior of the terminal, a network traffic monitoring device such as a network intrusion detection system can be deployed to capture and analyze data packets in the network in real time. The network traffic monitoring device can be deployed at a key node of the network, such as a router or a switch, to comprehensively monitor the network traffic. When the data packet is transmitted in the network, the network intrusion detection system can parse the data packet according to a preset rule and protocol, extract key information such as a source IP address, a destination IP address, a port number, a transmission protocol, and the like, and jointly constitute the network layer feature of the network connection behavior of the terminal. For example, a terminal device initiates an HTTP request to an external server, and the NIDS can capture the request data packet and identify the source IP (the IP of the terminal device), the destination IP (the IP of the server), the port number (usually 80), and the transmission protocol (HTTP protocol under the TCP / IP protocol), thereby recording a network connection behavior of the terminal.

[0048] At the system level, the network connection behavior can be obtained by means of a network monitoring tool provided by an operating system on the terminal device or a third-party security software. The operating system usually provides an interface and a log recording function. For example, in the Windows system, the network connection history of the terminal can be obtained by means of the network-related logs in the event viewer, including the network type (wired network, wireless network, and the like) connected, the connection time, the network device connected, and the like. A lightweight proxy program can also be installed on the terminal device to monitor the network connection request and response in real time. When the application program on the terminal device initiates a network connection, the proxy program intercepts the connection request and obtains the detailed information of the request, such as the process ID of the application program, the network resource requested (such as a URL, an IP address, and the like), and the connection state (success, failure, timeout, and the like). The network connection behavior information obtained at the system level can reflect the network activity inside the terminal device.

[0049] By combining the network level and the system level, the network connection behavior of the terminal can be comprehensively and accurately obtained, thereby providing a rich data basis for subsequent intrusion detection and virus protection.

[0050] In step S102, the intrusion index rule is a rule system for identifying potential intrusion behaviors, which usually covers various types of network attack features, such as the typical network connection mode of behaviors such as port scanning, malicious software propagation, and data leakage.

[0051] Again, how to use the intrusion indicator rule to match the network connection behavior of the terminal is not specifically limited, and a feature code matching method can be used in the matching process. The feature code is a unique identifier obtained by digitizing and encoding the network connection characteristics of the intrusion behavior. For example, for a common port scanning attack, the feature code can include specific scanning order, scanning time interval, and specific protocol used in the scanning process, and the like. When the network connection behavior of the terminal is obtained, the network connection behavior is compared with the feature code in the intrusion indicator rule one by one. If it is found that the network connection behavior of the terminal is completely consistent with the feature code of a certain intrusion indicator rule, the network connection behavior is considered to hit the intrusion indicator rule.

[0052] In addition to feature code matching, a behavior pattern matching method can also be used to determine whether there is an intrusion behavior by analyzing the overall pattern of the network connection behavior. For example, for a normal network connection behavior, the frequency of connection, the duration of connection, the data transmission volume and the like will generally remain in a relatively stable range, while the intrusion behavior is easy to cause abnormal fluctuations in these parameters. For example, a terminal device frequently establishes connections with multiple different external IP addresses in a short period of time, and transmits a large amount of data each time, which is obviously inconsistent with the normal network browsing or file transmission behavior, and can be a data leakage attack behavior pattern. That is, if the network connection behavior conforms to the intrusion behavior pattern, the network connection behavior is also considered to hit the intrusion indicator rule.

[0053] Once it is found that there is a target network connection behavior that hits the intrusion indicator rule, a rejection measure is immediately taken. The rejection can be performed by a firewall rule at the network level to block. The firewall can intercept the network connection request that hits the intrusion indicator according to the pre-set rule, and prevent the connection request from continuing to transmit in the network. For example, when it is detected that a terminal device establishes a connection with a known malicious IP address, and the connection behavior hits the intrusion indicator rule, the firewall can immediately close the network port corresponding to the terminal device to cut off the connection with the malicious IP. At the system level, the network connection control function provided by the operating system can also be used to reject the access request. At the same time, warning information can be sent to the user of the terminal device to inform that the network connection behavior is abnormal, and to remind the user to take measures in time, such as checking whether there is malicious software on the terminal device, updating security software, and the like, so as to effectively prevent the potential intrusion behavior from causing further harm to the terminal device.

[0054] In step S103, when it is determined that the target network connection behavior has an intrusion risk, a virus removal strategy and a virus blocking strategy are enabled to remove potential virus threats and prevent them from growing again.

[0055] The virus elimination strategy is mainly used to eliminate the target process and the target process resident item related to the target network connection behavior. The target process refers to a malicious program process running on the terminal device and related to the intrusion behavior. For example, if a malicious software is detected to be downloaded to the terminal device through network connection and run, the running process of the malicious software is the target process. By analyzing the process information obtained through network connection behavior, such as process name and path, the target process is found and forcibly ended. The target process resident item refers to some startup items set in the system by the malicious program in order to automatically run after the system starts, such as the startup item in the registry and the shortcut in the system startup folder. For the startup item in the registry, the registry editor tool can be used to find and delete it. For example, by searching for a specific key value in the registry, the startup item related to the target process is found and deleted, thereby preventing the target process from automatically running at system startup. For the shortcut in the system startup folder, the shortcut file can be directly deleted to cut off the automatic startup path of the target process. By eliminating the target process and its resident item, the running basis of the malicious program on the terminal device can be effectively eliminated, and the possibility of its harm to the system can be reduced.

[0056] The virus blocking strategy is used to monitor the regeneration behavior of the target process and the re-release behavior of the target process resident item. Since some malicious programs have strong regeneration ability, even if they are eliminated once, they can still start again through other ways. For example, some malicious software sets multiple startup points in the system, and when one of the startup points is deleted, the other startup points can still start the malicious program. By monitoring the regeneration behavior of the target process, it can be detected in real time whether the malicious program tries to run again. For example, the process startup event in the system can be monitored in real time by using the event monitoring function or a third-party security monitoring tool. Once the target process appears again, the virus elimination strategy is triggered immediately to eliminate it again. For the re-release behavior of the target process resident item, similar monitoring can also be performed. For example, the modification event of the registry and the file change event of the system startup folder are monitored. If it is found that the target process tries to set the startup item again or create a shortcut in the startup folder, it is timely prevented and the virus elimination strategy is executed again. Through the continuous monitoring and timely response of the virus blocking strategy, the re-growth of the malicious program can be effectively prevented, and the network security and system stability of the terminal device can be ensured.

[0057] In a feasible manner, if the virus blocking strategy is executed, the parent process information of the process address corresponding to the regeneration behavior can be extracted, the parent process information is submitted to the sandbox for running thereafter, the feature rule of the parent process is obtained, and finally the intrusion indicator rule can be updated according to the feature rule.

[0058] When extracting the parent process information, several generations of parent process information can be extracted until the source of the process is traced. A system-level monitoring tool can be used to track the activities of each process in the system in real time, including the creation and end of the process, and the parent-child relationship between processes. By analyzing system log files, log records related to the process address corresponding to the reproduction behavior can be found, which may include the time, environment variables, and other information of the parent process starting the process.

[0059] A sandbox software is used to create an isolated running environment for running the parent process. After the parent process information is configured, it is submitted to the sandbox environment for running. The sandbox can also be constructed by virtualization technology. A virtual machine technology is used to create a virtual operating system instance as a sandbox. The parent process information is imported into the virtual machine to run in the restricted virtual environment. The virtual machine can isolate the parent process and prevent it from causing potential threats to the real system, while observing its behavior.

[0060] In the sandbox environment, the running behavior of the parent process is comprehensively monitored. The monitoring content includes the resource usage of the process (such as CPU usage, memory occupation, etc.), file operation behavior (such as creating, deleting, modifying files, etc.), network communication behavior (such as connected ports, communication server addresses, etc.), and various characteristic data of the parent process during running are collected. The collected behavior data can be analyzed using data mining technology. Through data mining algorithms such as association rule mining and clustering analysis, regularity characteristic rules can be found from a large amount of behavior data, and then the intrusion indicator rules are updated based on the characteristic rules to improve the matching ability of the network connection behavior based on the intrusion indicator rule matching, and further improve the detection accuracy of the virus.

[0061] As can be seen from the above, the embodiment of the application forms a complete network security protection mechanism by acquiring the terminal network connection behavior, matching the intrusion index rule and rejecting the abnormal connection request, and enabling the virus removal and blocking strategy. By acquiring the network connection behavior of the terminal and matching the intrusion index rule, the target network connection behavior with potential virus risk can be accurately identified, so that all access requests of the virus are rejected in time before the virus further spreads and causes damage, the way of virus spreading and intrusion through network connection is effectively prevented, the risk of the terminal being attacked by the virus is greatly reduced, and the security and stability of the terminal system are ensured. Secondly, by enabling the virus removal strategy for the target network connection behavior, the target process and its resident items related to the behavior can be completely removed, the existence basis of the virus in the terminal system is fundamentally eliminated, the occupation of system resources by the virus and the interference and damage to normal system functions are avoided, and it is ensured that the terminal can normally and stably run. The use of the virus blocking strategy further strengthens the security protection capability of the terminal, can monitor the regeneration behavior of the target process and the re-release behavior of the target process resident item in real time, and enables the virus removal strategy once the behavior that may cause the virus to be active again is detected, forming a dynamic and continuous protection mechanism, effectively preventing the repeated occurrence and residue of the virus, avoiding serious problems such as system vulnerability, data leakage and system crash caused by virus residue, greatly enhancing the resistance of the terminal to the virus, providing a safer, more reliable and stable use environment for the terminal user, and significantly improving the security protection level of the terminal.

[0062] On the basis of the above embodiment, in order to better perform terminal virus prevention, on the basis of the pre-blocking and post-deep cleaning realized in the above embodiment, intelligent analysis can be performed in advance to cover the whole life cycle of virus attack. Specifically, a remote control software blacklist can be acquired, and the installed application software of the terminal can be matched.

[0063] If the target software of the installed application software of the terminal hits the remote control software blacklist, the running process of the target software is limited, and the uninstallation operation of the target software is enabled;

[0064] If the installed application software of the terminal exists suspicious remote control software that does not hit the remote control software blacklist, the running process of the suspicious software is monitored; the suspicious remote control software is remote control software that meets at least one of the following exceptions: abnormal software installation proportion, abnormal software version and abnormal address carrying.

[0065] The acquisition of the remote control software blacklist is not limited herein. It should be noted that the remote control software blacklist can be different for different terminal clusters or terminals. For example, the remote control software blacklist corresponding to an enterprise can be acquired. Generally, an enterprise will purchase control software of a specified manufacturer. If most of the terminals of the enterprise are installed with software of a certain brand, the version is the latest version, and the console access address carried is an intranet address, it indicates that the enterprise has a legal use demand for the white remote control software (remote control software located in the whitelist, referred to as "white remote software") of the manufacturer, and then the remote control software blacklist of other brand white remote control software is issued to the administrator to prevent hackers from using other brand white remote control software to attack the enterprise.

[0066] In the specific application process, the installation and use of the white remote control software on the terminal side can be collected, and the software installation rate, software version, and console access address carried are combined for comprehensive judgment to evaluate whether the white remote control software installed on the terminal of the enterprise is normally used. The judgment result is combined to generate a recommended strategy for the remote control software blacklist, and after manual confirmation, the remote control software blacklist is directly issued, which can prevent white remote control tool attacks in advance and prevent white remote control tool attacks that have taken effect from running.

[0067] In addition, even if it is not hit, the running process of the software can be monitored. All running software processes are monitored in real time, and when suspicious remote control software is found, various behaviors in the running process are recorded, such as network connection requests, file access operations, system configuration modifications, etc. At the same time, the behavior data of the suspicious software can be analyzed to determine whether it has signs of malicious activity. Or the running behavior information of the suspicious software is uploaded to the cloud security platform for more in-depth analysis and comparison. The remote control software can satisfy at least one of the software installation proportion anomaly, software version anomaly, and address carrying anomaly. The software installation proportion anomaly is that the software installation proportion is lower than the installation proportion threshold, for example, only a few terminals of hundreds of terminals of an enterprise are installed with a remote control software. The installation proportion threshold is not specifically limited herein and can be set by those skilled in the art. The software version anomaly is that the version of the remote control software is low. Since the remote control software of the historical version usually has vulnerabilities that have been exploited by malicious attackers, if an old version of the remote control software is used, it can also be considered as having a software version anomaly. The address carrying anomaly refers to the remote control software carrying a malicious address, which can be identified based on the intrusion index rule. For example, if it is found that the proportion of terminals of an enterprise installed with white remote control software is very small, and the version is old and the address carried is a malicious address, it indicates that the enterprise does not have a demand for white remote control software at the moment, and may have been attacked by network attacks, and the white remote control software needs to be immediately restricted.

[0068] On the basis of the embodiment, rule base information of each remote control software in the software white list can also be acquired, and installation data of the remote control software is collected, and corresponding installation data features are generated based on the installation data, so that the remote control software black list is updated according to the rule base information and the installation data features. The rule base information can include at least one of manufacturer, signature, process and version information of the remote control software, and the installation data can include at least one of installation rate, installation version and console access address.

[0069] In the specific application process, the rule base information of the remote control software can be acquired by interface connection with the software white list database, using a query statement or calling a corresponding API interface.

[0070] For the collection of the installation rate, the number of successfully installed devices can be recorded by the installation program during the installation process of the software, and the installation rate is calculated in combination with the total number of devices; for the collection of the installation version, the version number of the installed software can be acquired through the version management module of the software; for the collection of the console access address, the related address information can be extracted from the configuration file or the log of the software. The collected installation data is analyzed and processed, and representative features are extracted, such as the distribution of the installation rate, the installation proportion of different versions, the access frequency of the console access address, etc., to form corresponding installation data features.

[0071] Finally, the rule base information and the installation data features are comprehensively analyzed, and according to the preset rules and algorithms, it is judged which remote control software has security risks or does not meet the management requirements, so as to add it to the black list. For example, if the signature of a remote control software is inconsistent with the signature in the rule base, or its installation rate is abnormally high and the console access address frequently changes, it can be regarded as suspicious software and updated to the black list.

[0072] The embodiment can realize the three-layer cooperative defense mechanism of intelligent analysis in advance, real-time plugging in the middle and deep cleaning after the event, and systematically cover the whole life cycle of virus remote control attack. In the pre-event stage, based on the dynamic indicators such as the installation rate, version and console address attribute of the terminal side white remote control software, the legal operation and maintenance demand and malicious attack behavior are intelligently distinguished, and the differential remote control software blacklist is automatically generated. In the middle stage, the intrusion index rule is applied for rule matching and real-time monitoring of external connection behavior, the connection of the malicious address matched is quickly blocked, and the heuristic memory scanning is triggered to clear the residual process. In the post-event stage, in view of the process regeneration problem caused by incomplete resident item cleaning, the virus blocking strategy is enabled, and the closed-loop protection system of “strategy prediction-plugging interception-resident cleaning” is formed. Through the deep coupling mechanism of multiple means, the embodiment effectively solves the defense blind spot caused by the dependence of the traditional scheme on a single technology (such as static feature detection), significantly improves the suppression success rate of virus remote control attacks such as silver fox virus, and is especially suitable for coping with the high countermeasures of silver fox organization such as using legal software signature and multi-stage loading.

[0073] In addition, on the basis of the above-mentioned embodiment, in order to further improve the virus detection accuracy and effectively suppress the virus attack through the remote control connection, a virus hunting rule can also be configured to the terminal. The virus hunting rule is used to monitor system services and / or memory processes. Specifically, it can be used to monitor suspicious silver fox resident and memory attack behavior, for example, if the virus hunting rule detects that there is a self-starting service named UserDataSvc_[random alphanumeric], its possible intention is to disguise as a system background process to achieve automatic loading at startup, or the memory scanning finds that the memory of a system process (such as explorer.exe) is malicious code, and the possible intention is to improve the process injection.

[0074] If the suspected virus software is detected by applying the virus hunting rule, the external connection network address of the suspected virus software is collected. Thereafter, the suspected virus software is identified based on the external connection network address and the remote control software blacklist, if it is determined that the suspected virus software is malicious software, the virus cleaning strategy and the virus blocking strategy are enabled for the suspected virus program. Specifically, the active external connection analysis function of the cloud firewall can be used to analyze the data by viewing the external connection network address, or query the IP reputation database, or call a large model to analyze the related behavior characteristics of the external connection IP, and reverse DNS query and WHOIS query can also be performed to determine whether the external connection network address is a malicious address, and whether the software is malicious software in combination with the remote control software blacklist.

[0075] The embodiment can discover suspicious compromised terminals as early as possible by configuring a virus hunting rule. For example, if a file exists a scheduled task, a process without a signature is periodically pulled up, and suspicious behavior exists. At this time, all memory codes and resident items related to the process without a signature can be collected, whether there is a resident item residue is judged, and then the suspected virus software creating the file is determined as malicious software.

[0076] On this basis, the cloud intrusion indicator rule library can also be updated according to the suspected virus program and the external connection network address, and the terminal can be updated with the intrusion indicator rule. By collecting the corresponding external IP, whether the external IP belongs to a malicious IP can be verified, and the intrusion indicator rule library can be continuously updated.

[0077] Referring to Figure 2 , Figure 2 A structure diagram of a terminal virus processing system provided by the embodiment of the application is shown in FIG. 1. The system includes:

[0078] a behavior monitoring module configured to acquire network connection behavior of the terminal;

[0079] a rule matching module configured to match the network connection behavior of the terminal with an intrusion indicator rule, and if there is a target network connection behavior that hits the intrusion indicator rule, reject all access requests of the target network connection behavior;

[0080] a virus processing module configured to enable a virus cleaning strategy and a virus blocking strategy for the target network connection behavior; the virus cleaning strategy is configured to clean a target process and a target process resident item related to the target network connection behavior; the virus blocking strategy is configured to monitor reproduction behavior of the target process and re-release behavior of the target process resident item; and the virus cleaning strategy is enabled after the reproduction behavior or the re-release behavior is detected.

[0081] The application further provides a computer readable storage medium and a computer program product, both of which can store a computer program. When the computer program is executed, the steps of the method provided by the above embodiment can be implemented. The storage medium can include a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0082] The application further provides an electronic device, which can include a memory and a processor. The memory stores a computer program, and when the processor invokes the computer program in the memory, the steps of the method provided by the above embodiment can be implemented. Of course, the electronic device can also include various network interfaces, power supplies and other components. Please refer to Figure 3, Figure 3 A structural schematic diagram of an electronic device provided in an embodiment of the present application, the electronic device of the embodiment can include a processor 2101 and a memory 2102.

[0083] Optionally, the electronic device can further include a communication interface 2103, an input unit 2104, and a display 2105, and a communication bus 2106.

[0084] The processor 2101, the memory 2102, the communication interface 2103, the input unit 2104, and the display 2105 can communicate with each other through the communication bus 2106.

[0085] In the embodiment of the present application, the processor 2101 can be a central processing unit (CPU), an application specific integrated circuit, a digital signal processor, a programmable logic device, or other programmable logic devices.

[0086] The processor can call a program stored in the memory 2102. Specifically, the processor can perform the operations of the electronic device in the above embodiments.

[0087] The memory 2102 is used to store one or more programs, and the program can include program code including computer operation instructions. In the embodiment of the present application, the memory at least stores a program for implementing the following functions:

[0088] Obtaining a network connection behavior of a terminal;

[0089] Matching the network connection behavior of the terminal with an intrusion index rule, and if there is a target network connection behavior that hits the intrusion index rule, rejecting all access requests of the target network connection behavior;

[0090] Enabling a virus removal strategy and a virus blocking strategy for the target network connection behavior; the virus removal strategy is used to remove a target process and a target process resident item related to the target network connection behavior; the virus blocking strategy is used to monitor a regeneration behavior of the target process and a re-release behavior of the target process resident item; and the virus removal strategy is enabled after the regeneration behavior or the re-release behavior is detected.

[0091] In a possible implementation, the memory 2102 can include a program storage area and a data storage area, wherein the program storage area can store an operating system and at least one application required by a function; and the data storage area can store data created during use of the computer.

[0092] In addition, the memory 2102 can include a high-speed random access memory, and can also include a nonvolatile memory, such as at least one disk memory device or other volatile solid memory device.

[0093] The communication interface 2103 can be an interface of a communication module, such as an interface of a GSM module.

[0094] The present application can also include a display 2105 and an input unit 2104, and the like.

[0095] Figure 3 The structure of the electronic device shown does not constitute a limitation on the electronic device in the embodiments of the present application, and the electronic device can include more or fewer components than those shown, or combine certain components in actual applications. Figure 3 The structure of the electronic device shown does not constitute a limitation on the electronic device in the embodiments of the present application, and the electronic device can include more or fewer components than those shown, or combine certain components in actual applications.

[0096] The embodiments in the specification are described in a progressive manner, and each embodiment focuses on the difference from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the system provided by the embodiments, since it corresponds to the method provided by the embodiments, the description is relatively simple, and the related parts can be referred to the method part.

[0097] The principles and implementation manners of the present application are described by using specific examples in the present application. The above description of the embodiments is only used to help understand the method of the present application and its core idea. It should be pointed out that, for those skilled in the art, without departing from the principles of the present application, some improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the present application.

[0098] It should also be noted that, in the present specification, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of another identical element in the process, method, article or device including the element.

Claims

1. A terminal virus processing method, characterized by, The method comprises the following steps: acquiring network connection behavior of a terminal; matching the network connection behavior of the terminal with an intrusion indicator rule, and if there is a target network connection behavior that hits the intrusion indicator rule, rejecting all access requests of the target network connection behavior; enabling a virus cleaning strategy and a virus blocking strategy for the target network connection behavior; the virus cleaning strategy is used to clean a target process and a target process resident item related to the target network connection behavior; the virus blocking strategy is used to monitor the reproduction behavior of the target process and the re-release behavior of the target process resident item; and enabling the virus cleaning strategy after detecting the reproduction behavior or the re-release behavior.

2. The terminal virus processing method according to claim 1, wherein Before acquiring the network connection behavior of the terminal, the method further comprises the following steps: acquiring a remote control software blacklist; if there is a target software installed on the terminal that hits the remote control software blacklist, limiting the running process of the target software and enabling the uninstallation operation of the target software; if there is a suspicious remote control software that does not hit the remote control software blacklist among the application software installed on the terminal, monitoring the running process of the suspicious software; the suspicious remote control software is a remote control software that meets at least one of the following exceptions: software installation proportion exception, software version exception and address carrying exception.

3. The terminal virus processing method according to claim 2, wherein Before acquiring the remote control software blacklist, the method further comprises the following steps: acquiring rule library information of each remote control software in a software whitelist; the rule library information includes at least one of the following: manufacturer, signature, process and version information of the remote control software; collecting installation data of the remote control software, and generating corresponding installation data features based on the installation data; the installation data includes at least one of the following: installation rate, installation version and console access address; updating the remote control software blacklist according to the rule library information and the installation data features.

4. The terminal virus processing method according to claim 2, wherein After enabling the virus cleaning strategy and the virus blocking strategy for the target network connection behavior, the method further comprises the following steps: configuring a virus hunting rule to the terminal; the virus hunting rule is used to monitor system services and / or memory processes; if suspected virus software is detected by applying the virus hunting rule, collecting external connection network addresses of the suspected virus software; identifying the suspected virus software based on the external connection network addresses and the remote control software blacklist, if it is determined that the suspected virus software is malicious software, enabling the virus cleaning strategy and the virus blocking strategy for the suspected virus program.

5. The terminal virus processing method according to claim 4, wherein If the external connection network address belongs to a malicious address, the method further comprises the following steps: updating a cloud intrusion indicator rule library according to the suspected virus program and the external connection network address, and updating the intrusion indicator rule of the terminal.

6. The terminal virus treatment method according to any one of claims 1 to 5, characterized by, After enabling the virus cleaning strategy and the virus blocking strategy for the target network connection behavior, the method further comprises the following steps: extracting parent process information of a process address corresponding to the reproduction behavior; submitting the parent process information to a sandbox for running to obtain a feature rule of the parent process; updating the intrusion indicator rule according to the feature rule.

7. A terminal virus handling system, characterized in that, The method comprises the following steps: an behavior monitoring module, configured to acquire network connection behavior of a terminal; The rule matching module is configured to match the network connection behavior of the terminal with an intrusion indicator rule, and if there is a target network connection behavior that hits the intrusion indicator rule, reject all access requests of the target network connection behavior. The virus processing module is configured to enable a virus removal strategy and a virus blocking strategy for the target network connection behavior; the virus removal strategy is configured to remove a target process and a target process resident item associated with the target network connection behavior; The virus blocking strategy is configured to monitor a regeneration behavior of the target process and a re-release behavior of the target process resident item; and enable the virus removal strategy after detecting the regeneration behavior or the re-release behavior.

8. An electronic device, comprising: The computer readable storage medium has a computer program stored thereon, and the computer program is executed to implement the steps of the terminal virus processing method according to any one of claims 1 to 6. The computer readable storage medium has a computer program stored thereon, and the computer program is executed to implement the steps of the terminal virus processing method according to any one of claims 1 to 6. The computer program is executed to implement the steps of the terminal virus processing method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, ​ 10. A computer program product, characterised in that, ​

Citation Information

Patent Citations

  • Method and system for preventing computer virus from frequently infecting systems

    CN102867146A

  • Virus searching and killing method, device, equipment and storage medium

    CN110717183A

  • Threat processing method, device and equipment and readable storage medium

    CN111277585A

  • Malicious file processing method, device and equipment and storage medium

    CN111368300A

  • Systems and methods for real-time detection and mitigation of malicious electronic communications

    US12452296B1