Virus detection and removal drilling method and apparatus, device, and storage medium

By conducting virus detection and killing drills in a data sandbox with one-way isolation function, the problem of non-isolation of the anti-virus environment and the production environment is solved, the impact on the production environment is avoided, and the safety of virus detection and killing and the security of production data is achieved.

WO2025092706A1PCT designated stage expired Publication Date: 2025-05-08EISOO SOFTWARE
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/127999
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-31
Filing Date
2024-10-29
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

In the prior art, the antivirus environment is not isolated from the production environment, which may affect the production environment and increase economic losses.

Method used

Virus detection drill is carried out in a pre-built data sandbox with one-way isolation function. By obtaining backup data from the disaster recovery system, data recovery is carried out, and virus detection is carried out on the target recovery data in the data sandbox.

Benefits of technology

It effectively avoids the impact of the virus detection and killing process on the production environment, ensures the security of production data in the production environment, and reduces the economic losses of production.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024127999_08052025_PF_FP_ABST
    Figure CN2024127999_08052025_PF_FP_ABST
Patent Text Reader

Abstract

A virus detection and removal drilling method and apparatus, a device, and a storage medium. The method comprises: when receiving a workflow starting instruction, acquiring backup data from a disaster recovery system (S101); carrying out data recovery on the backup data, and determining target recovery data (S102); and carrying out a virus detection and removal drill on the target recovery data in a preconstructed data sandbox having a unidirectional isolation function (S103).
Need to check novelty before this filing date? Find Prior Art

Description

Virus detection and killing drill method, device, equipment and storage medium

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on October 31, 2023, with application number 202311436379.6, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of data security technology, for example, to a virus detection and killing drill method, device, equipment and storage medium. Background Art

[0003] In recent years, computer viruses, especially ransomware, have had a significant impact on the availability and data security of business systems and have become increasingly rampant.

[0004] The primary data-level response to these threats is to regularly back up necessary data to a disaster recovery system using backup or disaster recovery systems. If production data becomes infected, data in the disaster recovery system can be quickly restored, minimizing losses. However, this approach doesn't address all ransomware protection issues. If production data is already infected before backups are made, or if files are in the latent infection period during backups, backups will be ineffective in preventing the virus from infecting the data.

[0005] A common solution is to regularly restore backup data using a disaster recovery system and then use antivirus software to scan the restored data for viruses to ensure data security. This approach is called a virus scanning drill. However, if the antivirus environment is not isolated from the production environment during the antivirus process, each virus scan could potentially impact the production environment, resulting in even greater and incalculable losses.

[0006] Summary of the Invention

[0007] The present application provides a virus detection and killing drill method, device, equipment and storage medium, which solves the problem of the anti-virus environment and the production environment not being isolated, avoids the impact of the virus detection and killing process on the production environment, and achieves virus detection while ensuring the security of production data in the production environment, thereby reducing economic losses in production.

[0008] In a first aspect, an embodiment of the present application provides a virus detection and removal drill method, comprising:

[0009] After receiving the workflow start instruction, it obtains backup data from the disaster recovery system;

[0010] Performing data recovery on the backup data and determining target recovery data;

[0011] A virus detection and elimination drill is performed on the target recovery data in a pre-built data sandbox with a one-way isolation function.

[0012] In a second aspect, an embodiment of the present application provides a virus detection and killing drill device, comprising:

[0013] The backup data recovery module is configured to obtain backup data from the disaster recovery system after receiving a workflow start instruction;

[0014] A recovery data determination module is configured to perform data recovery on the backup data and determine target recovery data;

[0015] The virus detection and killing drill module is configured to perform a virus detection and killing drill on the target recovery data in a pre-built data sandbox with a one-way isolation function.

[0016] In a third aspect, an embodiment of the present application provides an electronic device, including:

[0017] at least one processor; and

[0018] a memory communicatively connected to at least one processor; wherein,

[0019] The memory stores a computer program that can be executed by at least one processor, and the computer program is executed by at least one processor so that the at least one processor can execute the virus detection and killing drill method provided by the above-mentioned first aspect embodiment.

[0020] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores computer instructions. The computer instructions are used to enable a processor to implement the virus detection and killing drill method provided in the embodiment of the first aspect above when executed. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The following will introduce the drawings required for the description of the embodiments. The drawings described below are some embodiment drawings of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0022] FIG1 is a flow chart of a virus detection and killing drill method provided in Example 1 of the present application;

[0023] FIG2 is a schematic diagram of the structure of a data sandbox involved in a virus detection and killing drill method provided in Example 1 of the present application;

[0024] FIG3 is a flowchart of a data sandbox construction involved in a virus detection and killing drill method provided in Example 1 of the present application;

[0025] FIG4 is a flow chart of a virus detection and killing drill method provided in Example 2 of the present application;

[0026] FIG5 is a schematic diagram of a virus detection and killing drill provided in Example 2 of the present application;

[0027] FIG6 is a schematic diagram of an open integrated antivirus engine involved in a virus detection and killing drill method provided in Example 2 of the present application;

[0028] FIG7 is a schematic structural diagram of a virus detection and killing drill device provided in Example 3 of the present application;

[0029] FIG8 is a schematic structural diagram of an electronic device provided in Example 4 of the present application. DETAILED DESCRIPTION

[0030] In order to help those skilled in the art understand the present invention, the following describes the embodiments of the present invention in conjunction with the accompanying drawings. The embodiments described are some related embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work should fall within the scope of protection of this application.

[0031] The terms "first", "second" and "target" in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units listed, but may include other steps or units that are not listed or that are inherent to these processes, methods, products or devices.

[0032] Example 1

[0033] Figure 1 is a flowchart of a virus detection and killing drill method provided in Example 1 of the present application. This embodiment is applicable to the situation where a virus detection and killing drill is performed in a data sandbox with a one-way isolation function. The method can be executed by a virus detection and killing drill device, which can be implemented in the form of hardware and / or software.

[0034] This application proposes a method for performing virus detection and killing drills in a data sandbox. The data sandbox is isolated from the production environment. By performing virus detection and killing in the data sandbox, the security of the virus detection and killing drills is ensured. In addition, the virus detection and killing drill method proposed in this application is open and supports the integration of multiple antivirus engines, which can effectively respond to different virus detection and killing needs.

[0035] As shown in FIG1 , the method includes:

[0036] S101: After receiving a workflow start instruction, obtain backup data from a disaster recovery system.

[0037] In this embodiment, the workflow initiation instruction can be understood as an instruction for initiating the overall workflow. The disaster recovery system can be understood as a backup system used to prevent disasters and is used to back up production data in a production environment. The production environment refers to the customer's business environment. The backup data can be understood as the data generated by backing up the production data in the production environment in the disaster recovery system.

[0038] For example, when a workflow start instruction is received, it can be determined that the current virus detection and killing drill can be started and executed. Therefore, it is necessary to first obtain backup data from the disaster recovery system so that the virus detection and killing drill can be performed based on the backup data later.

[0039] S102: Restore the backup data and determine target recovery data.

[0040] In this embodiment, the target recovery data can be understood as recovery data used for virus detection and killing drills, and the data content of the target recovery data is the same as the production data.

[0041] Exemplarily, the backup data is restored to a resource directory within a pre-built data sandbox according to a preset data recovery algorithm. The preset data recovery algorithm can be determined based on actual needs. The data sandbox includes at least one recovery resource, which contains multiple resource directories. The restored data generated after restoring the backup data is stored in the resource directories within the data sandbox.

[0042] S103: Perform virus detection and elimination drills on target recovery data in a pre-built data sandbox with a one-way isolation function.

[0043] In this embodiment, the data sandbox serves as a line of defense for network security. All programs running in the sandbox are simulated exercises, not real applications. The sandbox operates by running programs in an isolated space, where they are read-only but not writable, preventing them from permanently modifying or damaging other programs and data on the computer. For example, a data sandbox can be understood as a piece of paper. Running and modifying programs is like writing on the paper, while the sandbox is like a piece of glass placed on the paper. Programs can only be run and modified on the glass, while the paper remains clean.

[0044] In some embodiments, the data sandbox in this embodiment can provide a network environment isolated from the production network.

[0045] For example, a data sandbox with a one-way isolation function is pre-built. Except for specified data, the data sandbox cannot interact with the production environment. Therefore, in order to ensure the security of the production environment, in the data sandbox with a one-way isolation function, a virus detection drill is performed on the target recovery data restored to the resource directory in the data sandbox according to a pre-selected virus detection engine.

[0046] The embodiment of the present application provides a virus detection and killing drill method, which obtains backup data from the disaster recovery system after receiving a workflow start instruction; performs data recovery on the backup data and determines the target recovery data; and performs a virus detection and killing drill on the target recovery data in a pre-built data sandbox with a one-way isolation function. The backup data is restored to a network-isolated recovery resource for virus detection, which avoids the impact on the production environment, and realizes virus detection and killing of the data under the specified path of the recovery resource, ensuring the security of the recovery data. It solves the problem of the antivirus environment and the production environment not being isolated, avoids the impact of the virus detection and killing process on the production environment, and realizes virus detection while ensuring the security of production data in the production environment, reducing economic losses in production.

[0047] In some embodiments, based on the above embodiment, the method further includes:

[0048] Generate a virus detection and killing drill report and feed it back to the server.

[0049] In this embodiment, the virus detection and killing drill report can be understood as a report generated based on the results of the virus detection and killing drill. The server can be understood as a server. The server, the client, and the electronic device that is the execution subject of the embodiment of this application are all remotely wirelessly connected, enabling data exchange between any two parties. The client can also interact with the user.

[0050] For example, after performing a virus detection drill on the target recovery data in the data sandbox, a corresponding virus detection drill report is generated based on the results of the virus detection drill, and the virus detection drill report is uploaded to the server. The server can send the virus detection drill report to the client for user query and display according to the client's call requirements.

[0051] Figure 2 is a schematic diagram of the structure of a data sandbox involved in a virus detection and killing drill method provided in Example 1 of the present application. The data sandbox includes at least a proxy device and a virtual switch vSwitch2 without an uplink. The proxy device is provided with a virtual network card vNic1 for external communication and multiple virtual network cards vNic2, vNic3, vNic4, etc. for internal communication. Multiple isolated network port groups are created on the virtual switch vSwitch2. The multiple internally connected virtual network cards and the multiple isolated network port groups are connected one by one to build a network. Based on the above embodiment, in some embodiments, the steps of building a data sandbox are further added, including:

[0052] a1) Create a virtual switch without uplinks on the target virtualization platform, and create a preset number of isolated network ports on the virtual switch.

[0053] In this embodiment, the target virtualization platform is a virtualization platform determined based on the selection of the client user. A virtual switch without an uplink can be understood as a switch with a one-way isolation function. This virtual switch is the basis for the data sandbox to have isolation capabilities. Since it does not have an uplink, the virtual switch is isolated from the external network. At this time, any virtual machine connected to the virtual switch network is isolated from the external network. The isolated network port can be understood as a network port used for networking. The isolated network is a mapping of the production network of the external environment. Each production network can be mapped to an isolated network. Through mapping, multiple isolated networks inside the data sandbox together form a network similar to the production network. The difference is that the network is inside the data sandbox, isolated from the outside world, and will not affect the external environment.

[0054] The virtualization platform selected by the client through interaction with the user is determined as the target virtualization platform, and a data sandbox is constructed on the target virtualization platform based on a program. For example, a virtual switch without an uplink is created on the target virtualization platform, and a preset number of isolated network ports are created on the created virtual switch without an uplink. The preset number of isolated network ports is a mapping of the production network ports in the data sandbox. Therefore, the preset number can be the same as the number of production network ports in the production network, and under certain conditions, can be less than the number of production network ports.

[0055] b1) Creating a virtual machine with a preset operating system and enabled routing and forwarding functions on the target virtualization platform, and determining the virtual machine as a proxy device.

[0056] In this embodiment, the default operating system can be understood as a Linux system. The proxy device can be understood as a device used for data transfer. The proxy device is a Linux virtual machine with routing and forwarding functions enabled. It has multiple virtual network cards, one of which is connected to the external network and the others are connected to the isolated network within the data sandbox. The proxy device is both the only bridge for communication between the outside world and the data sandbox, and also acts as a router connecting multiple isolated networks within the data sandbox.

[0057] Exemplarily, a virtual machine of the Linux operating system is created on the target virtualization platform, and the routing and forwarding function is enabled, and the virtual machine is determined as a proxy device for transferring between virtual machines within the data sandbox and between the data sandbox and the target virtualization platform.

[0058] c1) Establishing a connection between the proxy device and the isolated network port, and a connection between the proxy device and the target virtualization platform.

[0059] In this embodiment, a virtual network card is created on the proxy device, connected to a production network external to the target virtualization platform, and an Internet Protocol (IP) address is configured to establish a connection between the virtual network card and the production network, thereby achieving a connection between the proxy device and the target virtualization platform. In some embodiments, multiple virtual network cards are created on the proxy device, with the number of virtual network cards being equal to the number of isolated network ports. The virtual network cards created on the proxy device, which are equal in number to the number of isolated network ports, are configured with addresses corresponding to the isolated network ports, and connections are established between each of the multiple virtual network cards and the isolated network, thereby achieving a connection between the proxy device and the isolated network ports.

[0060] In some embodiments, establishing a connection between the proxy device and the isolated network port includes:

[0061] c11) Creating a preset number of virtual network cards on the proxy device, and connecting each virtual network card to its corresponding isolated network port.

[0062] In this embodiment, a preset number of virtual network cards are created on the proxy device. The number of virtual network cards is consistent with the number of isolated network ports, and the virtual network cards are connected to the isolated network ports in a one-to-one correspondence.

[0063] c12) Determine the gateway address of the production network mapped to each isolated network as the address of the virtual network card corresponding to the isolated network.

[0064] In this embodiment, the production network mapped to the isolated network is determined, and the gateway address corresponding to the production network is determined, and the gateway address of the production network is determined as the IP address of the virtual network card connected to the isolated network.

[0065] c13) Receive the network configuration information of the client and configure the subnet mask and camouflage network segment of the virtual network card according to the network configuration information.

[0066] In this embodiment, the network configuration information can be understood as the network address information input by the user when the client interacts with the user.

[0067] Exemplarily, network configuration information of a client is received, the network configuration information of the client including configuration information of a subnet mask and a masquerade network segment of a virtual network card, and the subnet mask and masquerade network segment of the virtual network card are configured according to the network configuration information transmitted by the client.

[0068] d1) Receive the firewall configuration information of the client and configure the corresponding firewall rules for the proxy device according to the firewall configuration information.

[0069] In this embodiment, the firewall configuration information can be understood as the configuration information of the network filter (iptables).

[0070] Exemplarily, the firewall configuration information is information configured by the user during the interaction between the client and the user. Therefore, the firewall configuration information transmitted by the client is received, and the corresponding iptables configuration (firewall rule configuration) is performed on the proxy device according to the firewall configuration information.

[0071] Figure 3 is a flow chart of the data sandbox construction involved in a virus detection and removal drill method provided in Example 1 of the present application. This data sandbox has three functions: one-way external connectivity, internal intercommunication, and support for active requests from within the data sandbox to the outside world based on specified IP addresses and ports. The one-way external connectivity function allows active access to the data sandbox from outside the data sandbox, as well as internal responses, but does not allow active access from within the data sandbox to the outside world. Since the proxy device is the only bridge between the data sandbox and the outside world, one-way isolation is primarily achieved by configuring corresponding iptables rules on the proxy device. Internal intercommunication allows multiple networks within the data sandbox to connect to each other. Internal intercommunication is primarily achieved by marking traffic within the isolated network on the proxy device and setting corresponding routing policies. The support for active requests from within the data sandbox to the outside world based on specified IP addresses and ports is a special case of the one-way external connectivity function. Based on actual needs, requests from within the data sandbox to access specified IP addresses and ports can be passed through. This function is also implemented by configuring corresponding iptables rules on the proxy device.

[0072] As shown in Figure 3, the configuration process of the data sandbox is as follows:

[0073] S10. Select a virtualization platform: Select a virtualization platform (for deploying the data sandbox).

[0074] S11. Create a virtual switch without an uplink: Create a virtual switch without an uplink on the virtualization platform.

[0075] S12. Create a proxy device and enable routing and forwarding: Create a virtual machine with a Linux operating system on the virtualization platform and enable routing and forwarding functions.

[0076] S13. Add a virtual network card to the proxy device, connect it to a production network external to the virtualization platform, and configure an IP address: Add a virtual network card to the proxy device, connect the virtual network card to a production network external to the virtualization platform, and configure an IP address.

[0077] S14. Create N port groups on the previously created virtual switch, where N is the number of production networks that need to be mapped. Create multiple isolated network port groups on the virtual switch based on the number of production networks that need to be mapped. The number of isolated network port groups is the same as the number of production networks that need to be mapped.

[0078] S15. Add N virtual network cards on the proxy device, connect them to the port group created in the previous step, and configure the IP, subnet mask, and camouflage network segment: Create multiple virtual network cards on the proxy device, connect the virtual network cards to the isolated network one by one, and set the IP address, subnet mask, and camouflage network segment of the virtual network cards created on the proxy device. The IP address needs to be set to the gateway address of the production network mapped to the isolated network corresponding to the virtual network card.

[0079] S16. Configure iptables rules and arptables rules on the proxy device: Configure corresponding iptables rules and arptables rules on the proxy device. The basic idea of ​​arptables rules is the same as that of iptables. However, arptables processes packets related to the Address Resolution Protocol (ARP).

[0080] S17. Determine whether the isolated network is interconnected: if so, execute step S18; if not, execute step S19.

[0081] S18. Mark internal traffic on the proxy device and set routing policies: If internal communication within the isolated network is enabled, continue configuration on the proxy device, mark the messages that meet the internal characteristics of the isolated network, and specify the corresponding routing policies.

[0082] S19. Determine whether the specified IP and port are open: If the specified IP and port are open, execute step S20; if the specified IP and port are not open, end the data sandbox construction process and complete the construction of the data sandbox.

[0083] S20. Configure iptables rules on the proxy device: If the traffic of an IP address and port is specified to be released to the outside, continue to configure the corresponding iptables rules on the proxy device. After the configuration is completed, the data sandbox construction process ends and the construction of the data sandbox is completed.

[0084] Example 2

[0085] Figure 4 is a flowchart of a virus detection and killing drill method provided in Example 2 of the present application. This embodiment is an optimization of any of the above embodiments and can be applied to situations where virus detection and killing drills are performed in a data sandbox with a one-way isolation function. The method can be executed by a virus detection and killing drill device, which can be implemented in the form of hardware and / or software.

[0086] As shown in FIG4 , the method includes:

[0087] S201: After receiving a workflow start instruction, obtain backup data from a disaster recovery system.

[0088] S202: Restore the backup data to the recovery resource in the data sandbox to form initial recovery data and verify it.

[0089] In this embodiment, the initial recovery data can be understood as unverified data that is directly restored from the backup data to the recovery resource.

[0090] For example, traditional data recovery is abandoned and a mount recovery method is adopted for data recovery. Mount recovery refers to mounting backup data to a recovery resource through protocols such as Network File System (NFS), Internet Small Computer System Interface (iSCSI), Fibre Channel Storage Area Network (FC SAN), Simple Storage Service (S3), Hadoop Distributed File System (HDFS), and Container Storage Interface (CSI), so as to form initial recovery data on the recovery resource and realize rapid business recovery. This method does not require the storage of recovery resources, which not only improves data recovery efficiency but also saves costs. After the backup data is restored to the recovery resource in the data sandbox to form the initial recovery data, the initial recovery data is verified by a preset verification method to determine whether the data content of the initial recovery data is consistent with the production data backed up by the backup data. If so, it is determined that the initial recovery data verification has passed; if not, it is determined that the initial recovery data verification has failed.

[0091] S203: Determine the verified initial recovery data as target recovery data.

[0092] In this embodiment, the target recovery data can be understood as recovery data that is consistent with the production data and can be used for virus detection and removal drills.

[0093] Exemplarily, the initial recovery data passes verification, indicating that the data content is consistent with the production data and can be used for virus detection and killing drills. Therefore, the verified initial recovery data is determined as the target recovery data for virus detection and killing drills.

[0094] S204: Send virus detection engine options to the client, and receive the target virus detection engine feedback from the client.

[0095] In this embodiment, the virus detection engine options can be understood as virus detection engines available for selection by the client user, including software development kits (SDKs), licenses, and anti-virus software with virus databases, etc. The target virus detection engine can be understood as the virus detection engine selected by the client user.

[0096] For example, several virus detection engines are sent as options to a client, and the client user selects one or more desired virus detection engines from the virus detection engine options. The client transmits the selection information back to the electronic device that executes the present application, and the virus detection engine selected by the user is determined as the target virus detection engine.

[0097] S205. In a pre-built data sandbox with a one-way isolation function, perform a virus detection drill on the target recovery data according to the target virus detection engine, wherein the data sandbox includes at least one recovery resource, each recovery resource includes at least one resource directory, and the target recovery data is in the resource directory.

[0098] In this embodiment, a data sandbox with a one-way isolation function includes at least one recovery resource, each recovery resource includes at least one resource directory, and the target recovery data is on the resource directory. Multiple virus detection engine instances (target virus detection engines) are simultaneously launched on the recovery resource to perform parallel detection on the target path on the resource. In order to better control the resource usage of the recovery resource, the configurable concurrency of the recovery resource and the concurrency configured for a single virus detection task are managed as a resource pool. A parallel detection upper limit can be configured based on the actual situation of the recovery resource, and an expected concurrency can be configured for each virus detection task. When the actual task process is executed, the actual number of concurrent detection tasks for each detection task needs to be controlled based on the upper limit of the recovery resource concurrency and the concurrency used by the actual detection task. This method not only makes full use of the recovery resources, but also ensures the efficiency of virus detection. Among them, the resource pool is a configuration mechanism for the recovery resource, which is used to manage the number of virus detection engines that can be used concurrently by the recovery resource and the number of virus detection engines that can be used concurrently by a single virus detection task.

[0099] Figure 5 is a schematic diagram of a virus detection and killing drill provided in Example 2 of the present application. As shown in Figure 5, a virus detection and killing drill is performed on the target recovery data on the recovery resource in the data sandbox. In the figure, the production environment is the client business environment; the distributed storage is the backup medium for storing backup data; the virus detection and killing configuration refers to the configuration of the detection and killing path of the target recovery data for virus detection and killing. This configuration can be connected with other different types of configurations according to a certain topological relationship to form a specific task process. Through this process, a series of functions such as data recovery, virus detection and killing, recovery data verification, recovery resource cleanup and email notification can be realized in sequence; the antivirus engine refers to the antivirus software including the virus detection and killing SDK, license and virus library; the recovery resource refers to the destination end used for data recovery. This resource can be the production environment or other environment that is interconnected with the production environment, and virus detection and killing is also performed on this resource.

[0100] Exemplarily, as shown in Figure 5, virus detection and killing drills are conducted in isolation from the production network, including: S21, creating a data sandbox, and deploying recovery resources and antivirus engine clients in the data sandbox. The data sandbox specifies the registration port of the antivirus engine client open to the outside world to the virus detection and killing drill server; S22, configuring the task process, wherein the virtualization platform on which the data sandbox is deployed is selected as the recovery resource in the recovery resource configuration of the disaster recovery configuration; S23, virus detection and killing configuration, selecting one or more paths on the recovery resource as the path to be virus detected and killed, and selecting the antivirus engine client in the data sandbox as the antivirus client, and then configuring virus detection and killing; S24, configuration of other nodes in the task process; S25, initiating the task process.

[0101] Figure 5 includes a built-in virus detection engine and a third-party virus detection engine, which can support different types of antivirus engines and realize open calls to multiple virus detection engines. Figure 6 is a schematic diagram of an open integrated antivirus engine involved in a virus detection drill method provided in Example 2 of the present application. As shown in Figure 6, the open integrated antivirus engine includes a virus detection scheduling layer, a virus detection adaptation layer, and a virus detection engine. Among them, the virus detection scheduling layer mainly provides a set of public virus detection interface definitions, which are implemented by each virus detection engine adapter. When initiating virus detection, the specified virus detection engine public interface is directly called to implement it, regardless of the function of the virus detection engine. The virus detection adaptation layer mainly stores adapters. The adapter is a unified package for different types of antivirus engines. Different virus detection engines only need to implement a set of interfaces defined by the upper scheduling layer, and the scheduling and use of the virus detection engine are realized in the implementation of these interfaces. The virus detection engine includes the virus detection SDK, license and virus library file. The SDK contains a series of interfaces required for virus detection. The license file is a file that authorizes the call of the interface. The virus library is a file used to record virus characteristics.

[0102] In some embodiments, performing a virus detection drill on target recovery data according to a target virus detection engine includes:

[0103] a2) Calling the adapter corresponding to the target virus detection engine through the preset virus detection interface.

[0104] In this embodiment, the preset virus killing interface can be understood as a public virus killing interface definition provided by the virus killing scheduling layer, which can correspond to various types of virus killing adapters.

[0105] Exemplarily, the virus detection scheduling layer calls a preset virus detection interface to connect with the virus detection adaptation layer, and calls the virus detection adapter corresponding to the target virus detection engine in the virus detection adaptation layer through the preset virus detection interface.

[0106] b2) Calling the target virus detection engine according to the adapter corresponding to the target virus detection engine to perform virus detection drill on the target recovery data.

[0107] In this embodiment, after the virus killing scheduling layer calls the adapter of the virus killing adaptation layer, the corresponding target virus killing engine is called according to each adapter, and the target virus killing engine performs parallel virus killing drills on the target recovery data.

[0108] The present embodiment provides a virus detection and killing drill method. After receiving a workflow start instruction, the method obtains backup data from a disaster recovery system; restores the backup data to a recovery resource in a data sandbox to form initial recovery data and verifies it; determines the verified initial recovery data as the target recovery data; sends a virus detection and killing engine option to the client, and receives the target virus detection and killing engine feedback from the client; and performs a virus detection and killing drill on the target recovery data according to the target virus detection and killing engine in a pre-built data sandbox with a one-way isolation function, wherein the data sandbox includes at least one recovery resource, each recovery resource includes at least one resource directory, and the target recovery data is located in the resource directory. Different antivirus engines are openly integrated through the adaptation layer and the virus detection and killing scheduling layer, resolving the differences between multiple types of virus detection and killing engines and providing a technical foundation for the future integration of other virus detection and killing engines. Users can freely configure virus detection and killing, making the virus detection and killing function more complete. By mounting and restoring, detection and killing objects and resource pools are quickly provided to fully utilize recovery resources. The two mechanisms achieve efficient and parallel detection and killing. It solves the problem of the antivirus environment and the production environment not being isolated, avoids the impact of the virus detection process on the production environment, and ensures the security of production data in the production environment while achieving virus detection, thereby reducing economic losses in production.

[0109] Exemplarily, in order to explain the content of the embodiment of the present application, an example is given here. The present application includes building a data sandbox with a one-way isolation function, and performing virus detection and killing drills on the recovered data on the recovery resources of the data sandbox.

[0110] Exemplarily, as shown in FIG2 and FIG5 , the method includes:

[0111] 1. Select a virtualization platform A to deploy a data sandbox;

[0112] 2. Create a virtual switch vSwitch2 without an uplink on A;

[0113] 3. Create a Linux operating system virtual machine appliance proxy on A and enable routing and forwarding functions;

[0114] 4. Add a virtual network card vNic1 to the appliance proxy, connect vNic1 to A's external production network, and configure an IP address;

[0115] 5. Create an isolated network port group, Isolated VM Network1, on vSwitch2. Add a virtual network card, vNic2, to the appliance proxy and connect vNic2 to Isolated VM Network1. Assume that the VM to be recovered is VM1 (with an IP address of 192.168.125.100), which is connected to the production network, VM Network1. The gateway address of VM Network1 is 192.168.125.254. Configure the IP address of vNic2 to 192.168.125.254 and the subnet mask to that of VM Network1. Set the masquerade network of Isolated VM Network1 to 192.168.225.0 / 24.

[0116] 6. Assuming that the IP address of the virus detection and killing drill server is 192.168.10.100 and the port number registered by the antivirus engine client to the server is 9614, configure the data sandbox to open packets with the designated IP address 192.168.10.100 and port number 9614;

[0117] 7. Set the corresponding iptables rules on the appliance proxy;

[0118] 8. Deploy a virtual machine (VM) with an antivirus client installed on Isolated VM Network 1. Let's call it client 1.

[0119] 9. Create a task flow. In the Disaster Recovery Configuration, select Virtualization Platform A for the recovery resource. In the Application Configuration, select VM1 for the virtual machine to be recovered. Select A for the recovery destination. Name the recovered virtual machine VM2. Select Isolated VM Network1 for the network connection.

[0120] 10. In the verification configuration, select the virtual machine verification method as ping and the target IP address as 192.168.225.100 (the masquerade IP of vm1);

[0121] 11. In the virus scanning configuration, select client1 as the antivirus engine client (since port 9614 of 192.168.10.100 is open, the virus scanning drill server can discover client1). Select the / home path of the restored virtual machine vm2 for the antivirus path, and select Scan and Disinfect.

[0122] 12. Select script cleanup in the cleanup configuration and specify the virtual machine to be cleaned as vm2;

[0123] 13. After configuration, execute the task flow.

[0124] In this embodiment, according to the previously configured task flow, during the task execution process, vm1 will be restored to the virtualization platform A where the data sandbox is located. The restored virtual machine is named vm2, and the network is connected to Isolated VM Network1. In the verification phase, ping 192.168.225.100 is used from outside the data sandbox to verify whether the recovery of vm2 is normal. After verification, the / home path of vm2 is checked for viruses. Since the antivirus engine client and vm2 are both connected to Isolated VM Network1, and Isolated VM Network1 is in the data sandbox and isolated from the outside world, the security of the virus detection process can be ensured, and finally a report on this virus detection drill is generated.

[0125] Example 3

[0126] FIG7 is a schematic diagram of the structure of a virus detection and killing drill device provided in Example 3 of the present application. As shown in FIG7 , the device includes:

[0127] The backup data recovery module 31 is configured to obtain backup data from the disaster recovery system after receiving a workflow start instruction;

[0128] A recovery data determination module 32 is configured to perform data recovery on the backup data and determine target recovery data;

[0129] The virus detection and killing drill module 33 is configured to perform a virus detection and killing drill on the target recovery data in a pre-built data sandbox with a one-way isolation function.

[0130] The virus detection and killing drill device used in this application solves the problem of the anti-virus environment and the production environment not being isolated, avoids the impact of the virus detection and killing process on the production environment, and ensures the security of production data in the production environment while achieving virus detection and killing, thereby reducing economic losses in production.

[0131] Optionally, the restored data determination module 32 is configured to:

[0132] Restoring the backup data to the recovery resource in the data sandbox to form initial recovery data and verifying it;

[0133] The initial restored data that passes the verification is determined as the target restored data.

[0134] Optionally, the virus detection and killing drill module 33 includes:

[0135] a target engine determination unit configured to send a virus detection and killing engine option to a client and receive a target virus detection and killing engine feedback from the client;

[0136] The virus detection and killing drill unit is configured to perform virus detection and killing drills on the target recovery data according to the target virus detection and killing engine in a pre-built data sandbox with a one-way isolation function, wherein the data sandbox includes at least one recovery resource, each recovery resource includes at least one resource directory, and the target recovery data is on the resource directory.

[0137] Optional, virus detection drill unit is set to:

[0138] Calling the adapter corresponding to the target virus detection engine through a preset virus detection interface;

[0139] The target virus detection and killing engine is called according to the adapter corresponding to the target virus detection and killing engine to perform virus detection and killing drill on the target recovery data.

[0140] Optionally, the device further includes:

[0141] The drill report generating module is configured to generate a virus detection and killing drill report and feed the virus detection and killing drill report back to the server.

[0142] Optionally, the device further includes a data sandbox creation module, including:

[0143] an isolated network creation unit, configured to create a virtual switch without an uplink on a target virtualization platform, and create a preset number of isolated network ports on the virtual switch;

[0144] An agent device determining unit is configured to create a virtual machine with a preset operating system and a routing and forwarding function enabled on the target virtualization platform, and determine the virtual machine as a agent device;

[0145] an agent connection establishing unit, configured to establish a connection between the agent device and the preset number of isolated network ports, and a connection between the agent device and the target virtualization platform;

[0146] The rule configuration unit is configured to receive firewall configuration information from the client and perform corresponding firewall rule configuration on the proxy device according to the firewall configuration information.

[0147] Optionally, the proxy connection establishment unit is set to:

[0148] Creating a preset number of virtual network cards on the proxy device, and connecting the preset number of virtual network cards to the preset number of isolated network ports in a one-to-one correspondence;

[0149] Determine the gateway address of the production network mapped to each isolated network as the address of the virtual network card corresponding to the isolated network;

[0150] Receive network configuration information from the client and configure the subnet mask and camouflage network segment of the virtual network card according to the network configuration information.

[0151] The virus detection and killing drill device provided in the embodiment of the present application can execute the virus detection and killing drill method provided in any embodiment of the present application, and has the corresponding functional modules and beneficial effects of the execution method.

[0152] Example 4

[0153] FIG8 shows a block diagram of an electronic device 40 that can be used to implement an embodiment of the present application. The electronic device can represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are for example only.

[0154] As shown in Figure 8, the electronic device 40 includes at least one processor 41 and a memory connected to the at least one processor 41, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc., wherein the memory stores a computer program that can be executed by the at least one processor, and the processor 41 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or the computer program loaded from the storage unit 48 to the random access memory (RAM) 43. Various programs and data required for the operation of the electronic device 40 can also be stored in the RAM 43. The processor 41, ROM 42 and RAM 43 are connected to each other via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.

[0155] Multiple components in electronic device 40 are connected to I / O interface 45, including an input unit 46, such as a keyboard, mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a magnetic disk, optical disk, etc.; and a communication unit 49, such as a network card, modem, wireless communication transceiver, etc. The communication unit 49 allows electronic device 40 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0156] The processor 41 may be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 41 may include a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors for running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 41 executes the various methods and processes described above, such as the virus detection and removal drill method.

[0157] In some embodiments, the virus detection and killing drill method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 48. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 40 via the ROM 42 and / or the communication unit 49. When the computer program is loaded into the RAM 43 and executed by the processor 41, one or more steps of the virus detection and killing drill method described above can be performed. Alternatively, in other embodiments, the processor 41 can be configured to perform the virus detection and killing drill method in any other appropriate manner (for example, by means of firmware).

[0158] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard parts (ASSPs), system-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0159] Computer programs for implementing the methods of the present application may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0160] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. A computer-readable storage medium can include an electronic, magnetic, optical, electromagnetic, infrared or semiconductor system, device or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. The example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (Electronic Programmable Read Only Memory, EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (Compact Disc-Read Only Memory, CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0161] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a cathode ray tube (CRT), a liquid crystal display (LCD), or a monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0162] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0163] A computing system may include a client and a server. The client and server are generally remote from each other and typically interact via a communication network. The client-server relationship arises through computer programs running on the respective computers and establishing a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, a host product within a cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosts and virtual private server (VPS) services.

Claims

1. A virus detection and killing drill method, comprising: After receiving the workflow start instruction, the backup data is obtained from the disaster recovery system; Performing data recovery on the backup data and determining target recovery data; A virus detection and killing drill is performed on the target recovery data in a pre-built data sandbox with a one-way isolation function.

2. The method according to claim 1, wherein: The performing data recovery on the backup data and determining target recovery data includes: Restoring the backup data to the recovery resources in the data sandbox to form initial recovery data and verifying it; The initial restored data that has passed the verification is determined as the target restored data.

3. The method according to claim 1, wherein: The virus detection and killing drill on the target recovery data in a pre-built data sandbox with a one-way isolation function includes: Sending virus detection engine options to the client, and receiving target virus detection engine feedback from the client; In a pre-built data sandbox with a one-way isolation function, a virus detection drill is performed on the target recovery data according to the target virus detection engine, wherein the data sandbox includes at least one recovery resource, each recovery resource includes at least one resource directory, and the target recovery data is on the resource directory.

4. The method according to claim 3, wherein: The performing virus detection and killing drill on the target recovery data according to the target virus detection and killing engine includes: Calling the adapter corresponding to the target virus detection engine through a preset virus detection interface; The target virus detection engine is called according to the adapter corresponding to the target virus detection engine to perform virus detection drill on the target recovery data.

5. The method according to claim 1, further comprising: Generate a virus detection and killing drill report, and feed the virus detection and killing drill report back to the server.

6. The method according to claim 1, wherein: The construction of the data sandbox includes: Creating a virtual switch without an uplink on the target virtualization platform, and creating a preset number of isolated network ports on the virtual switch; Creating a virtual machine with a preset operating system and enabled routing and forwarding functions on the target virtualization platform, and determining the virtual machine as a proxy device; Establishing a connection between the proxy device and the preset number of isolated network ports, and the proxy The connection between the device and the target virtualization platform; Receive the firewall configuration information of the client and perform corresponding firewall rule configuration on the proxy device according to the firewall configuration information.

7. The method according to claim 6, wherein: The establishing of the connection between the proxy device and the preset number of isolated network ports includes: Creating a preset number of virtual network cards on the proxy device, and connecting the preset number of virtual network cards to the preset number of isolated network ports in a one-to-one correspondence; Determine the gateway address of the production network mapped by each isolated network as the address of the virtual network card corresponding to the isolated network; Receive network configuration information from the client and configure the subnet mask and camouflage network segment of the virtual network card according to the network configuration information.

8. A virus detection and killing drill device, comprising: A backup data recovery module is configured to obtain backup data from a disaster recovery system after receiving a workflow start instruction; A recovery data determination module, configured to perform data recovery on the backup data and determine target recovery data; The virus detection and killing drill module is configured to perform a virus detection and killing drill on the target recovery data in a pre-built data sandbox with a one-way isolation function.

9. An electronic device, comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute a virus detection and killing drill method according to any one of claims 1 to 7.

10. A computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable a processor to implement a virus detection and killing drill method according to any one of claims 1 to 7 when executed.

Citation Information

Patent Citations

  • Test method, equipment and computer readable storage media of virtual machine backup

    CN107506295A

  • Data detection method and device

    CN110674502A

  • Drilling method and system based on virtual machine backup data

    CN110727501A

  • Virus searching and killing drill method, device and equipment and storage medium

    CN117251845A

  • System for securely recovering backup and data protection infrastructure

    US11341234B1