Malicious software detection method and apparatus, and electronic device

By adopting a multi-layer collaborative architecture of the cloud edge in the malware detection system, combining multi-engine detection at the cloud center and the cloud edge, the problem of high detection delay in the existing system is solved, and efficient and low-latency malware detection is achieved.

WO2025112735A1PCT designated stage expired Publication Date: 2025-06-05HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/115955
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-30
Filing Date
2024-08-30
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

The existing malware detection system has high latency, resulting in low detection efficiency. Especially in the software startup defense scenario, the detection delay may reach hundreds of milliseconds or even a few seconds.

Method used

Multi-layer collaboration based on cloud edge (cloud center-cloud edge-terminal) is adopted for malware detection and defense, target requests sent by cloud edge nodes are received through cloud center nodes, and preliminary detection is carried out at terminal nodes, and a multi-engine architecture is used to conduct complete detection in cloud centers.

Benefits of technology

It reduces the delay in malware detection, improves detection efficiency, enhances the availability of the overall system, avoids large amounts of data transmission, and realizes the first layer of protection with low latency and low cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024115955_05062025_PF_FP_ABST
    Figure CN2024115955_05062025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a malicious software detection method and apparatus, and an electronic device. The method comprises: by means of a cloud center node, receiving a target request sent by a cloud edge node (S201), wherein the target request at least comprises a target processing policy and a target numerical value, the target processing policy is one of the following: a detection policy and a defense policy, software states corresponding to the detection policy and the defense policy are different, and the target numerical value is used for identifying a software file of software; and according to the target processing policy and the target numerical value, detecting whether the software is malicious software, so as to obtain a target detection result (S202). The technical problem in the prior art of low malicious software detection efficiency due to high latency in detecting malicious software of a terminal by means of a cloud system is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Malware detection method, device and electronic device

[0001] Cross-reference

[0002] This disclosure claims priority to a Chinese patent disclosure filed with the Patent Office of China on November 30, 2023, with publication number 202311632098.8 and titled “Malware Detection Method, Device and Electronic Device,” the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present disclosure relates to the field of cloud security technology, and in particular to a method, device, and electronic device for detecting malware. Background Art

[0004] The Cloud Security Center scans and inspects the contents of massive amounts of software files on user terminals, both in the cloud and outside the cloud. These files, collected from user terminal servers, must be reported across proprietary and regional networks before being uploaded to the cloud center for storage. The entire malware detection process is lengthy and complex, and a single node failure at any location can render the entire service unavailable. In file detection scenarios, large volumes of files are sent to the cloud center for processing. The cloud center handles a significant amount of traffic, including data transmission, software testing, and result storage. This results in a high probability of failure and minimal buffer space in the event of a failure.

[0005] Currently, existing malware detection systems generally fall into two categories: endpoint detection (such as antivirus software detection) and cloud-based detection. Endpoint detection performs detection logic locally, including file collection, detection, alerting, and removal. It is largely unrelated to cloud computing and offers low latency and low cost. However, its detection capabilities are relatively poor, and it cannot effectively leverage the powerful computing power of the cloud to perform high-precision malware removal. Purely centralized cloud-based detection is simple and easy to use, with high accuracy. However, it requires large amounts of data transmission and multiple cross-network interactions across multiple regions, resulting in low timeliness and high latency, leading to low malware detection efficiency. Furthermore, in software-activated defense scenarios, the delay from malware collection by the client to console alerts can be at least several hundred milliseconds. The client will pause the process for several hundred milliseconds or even seconds until it is confirmed to be harmless, allowing it to continue running. This delay can cause problems when user service is time-sensitive.

[0006] To address the above-mentioned problems, no effective solutions have been proposed so far.

[0007] Summary of the Invention

[0008] The embodiments of the present disclosure provide a malware detection method, apparatus, and electronic device to at least address the technical problem in related technologies of detecting malware on a terminal through a cloud system, which results in high latency and low malware detection efficiency.

[0009] According to one aspect of an embodiment of the present disclosure, a method for detecting malware is provided, comprising: receiving, through a cloud center node, a target request sent by a cloud edge node, wherein the target request includes at least a target processing strategy and a target value, the target processing strategy being one of the following: a detection strategy and a defense strategy, the detection strategy and the defense strategy corresponding to different software states, and the target value being used to identify the software file of the software; detecting whether the software is malware based on the target processing strategy and the target value, and obtaining a target detection result.

[0010] Furthermore, the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is the detection strategy, whether the software is malicious software is detected based on the target processing strategy and the target value to obtain a target detection result, including: matching in the malicious file library based on the target value to obtain a first matching result; if the first matching result is that there is a record with the same target value in the malicious file library, then determining the target detection result based on the record detection result contained in the record; if the first matching result is that there is no record with the same target value in the malicious file library, then receiving the software file uploaded by the cloud edge node, and detecting the software file content through multiple detection engines to obtain multiple detection results, and determining the target detection result based on the multiple detection results.

[0011] Furthermore, the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is a defense strategy, the software is detected to see if it is malware based on the target processing strategy and the target value, and a target detection result is obtained, including: matching in the malicious file library based on the target value to obtain a second matching result; if the second matching result is that there is a record with the same target value in the malicious file library, the target detection result is determined based on the record detection result contained in the record; if the second matching result is that there is no record with the same target value in the malicious file library, the cloud edge node is notified to release the pause on the software startup process, and the software file uploaded by the cloud edge node is received, the software file content is asynchronously detected by multiple detection engines to obtain multiple detection results, and the target detection result is determined based on the multiple detection results.

[0012] Furthermore, in the case where the target processing strategy is a detection strategy, after detecting whether the software is malware based on the target processing strategy and the target value and obtaining the target detection result, the method also includes: if the target detection result is that the software is malware, generating an alarm message based on the file information of the software, and sending the alarm message to the console; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, storing the target value and the target detection result in the malicious file library, and sending the target detection result to the cloud edge node.

[0013] Furthermore, in the case where the target processing strategy is a defense strategy, after detecting whether the software is malware based on the target processing strategy and the target value and obtaining the target detection result, the method also includes: if the target detection result is that the software is malware, ending the startup process to prohibit the software from starting; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, storing the target value and target detection result in the malicious file library, and sending the target detection result to the cloud edge node.

[0014] According to one aspect of an embodiment of the present disclosure, a method for detecting malware is also provided, including: receiving a first request sent by a terminal node through a cloud edge node, wherein the first request includes at least a target processing strategy and a target value, the target processing strategy is one of the following: a detection strategy, a defense strategy, the detection strategy and the defense strategy correspond to different software states, and the target value is used to identify the software file of the software; detecting whether the software is malware based on the target processing strategy and the target value to obtain a first detection result; when the first detection result indicates that it is impossible to determine whether the software is malware, sending a target request to the cloud center node to receive the target detection result returned by the cloud center node.

[0015] Furthermore, the cloud edge node is deployed with a malicious file sub-database and a sub-detection engine. When the target processing strategy is the detection strategy, the software is detected as malware based on the target processing strategy and the target value to obtain a first detection result, including: matching in the malicious file sub-database based on the target value to obtain a third matching result; if the third matching result is that there is a record with the same target value in the malicious file sub-database, the first detection result is determined based on the record detection result contained in the record; if the third matching result is that there is no record with the same target value in the malicious file sub-database, the software file uploaded by the terminal node is received, and the software file content is detected by the sub-detection engine. When the sub-detection engine cannot determine whether the software file content contains malicious behavior, it will not be able to determine whether the software is malware as the first detection result.

[0016] Furthermore, the cloud edge node is deployed with a malicious file sub-database. When the target processing strategy is a defense strategy, the software is detected as malware based on the target processing strategy and the target value to obtain a first detection result, including: matching in the malicious file sub-database based on the target value to obtain a fourth matching result; if the fourth matching result is that there is a record with the same target value in the malicious file sub-database, the first detection result is determined based on the record detection result contained in the record; if the fourth matching result is that there is no record with the same target value in the malicious file sub-database, it will be impossible to determine whether the software is malware as the first detection result.

[0017] According to another aspect of an embodiment of the present disclosure, a malware detection device is also provided, including: a first receiving component, used to receive a target request sent by a cloud edge node through a cloud center node, wherein the target request includes at least a target processing strategy and a target value, and the target processing strategy is one of the following: a detection strategy and a defense strategy, the detection strategy and the defense strategy correspond to different software states, and the target value is used to identify the software file of the software; a first determination component, used to detect whether the software is malware based on the target processing strategy and the target value, and obtain a target detection result.

[0018] Furthermore, the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is a detection strategy, the first determination component includes: a first matching sub-component, which is used to match in the malicious file library according to the target value to obtain a first matching result; a first determination sub-component, which is used to determine the target detection result based on the record detection result contained in the record if the first matching result is that there is a record with the same target value in the malicious file library; a second determination sub-component, which is used to receive the software file uploaded by the cloud edge node if the first matching result is that there is no record with the same target value in the malicious file library, and detect the software file content through multiple detection engines to obtain multiple detection results, and determine the target detection result based on the multiple detection results.

[0019] Furthermore, the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is a defense strategy, the first determination component includes: a second matching sub-component, which is used to match the malicious file library according to the target value to obtain a second matching result; a third determination sub-component, which is used to determine the target detection result based on the record detection result contained in the record if the second matching result is that there is a record with the same target value in the malicious file library; a fourth determination sub-component, which is used to notify the cloud edge node to release the pause of the software startup process if the second matching result is that there is no record with the same target value in the malicious file library, and receive the software files uploaded by the cloud edge node, asynchronously detect the software file content through multiple detection engines, obtain multiple detection results, and determine the target detection result based on the multiple detection results.

[0020] Furthermore, the device also includes: a first processing component, which is used to detect whether the software is malware based on the target processing strategy and the target value when the target processing strategy is a detection strategy, and after obtaining the target detection result, if the target detection result is that the software is malware, generate an alarm message based on the file information of the software, and send the alarm message to the console; a second processing component, which is used to store the target value and target detection result in the malicious file library if the target detection result is that the software is malware or the target detection result is that the software is non-malware, and send the target detection result to the cloud edge node.

[0021] Furthermore, the device also includes: a third processing component for detecting whether the software is malware based on the target processing strategy and the target value when the target processing strategy is a defense strategy, and after obtaining the target detection result, if the target detection result is that the software is malware, then ending the startup process to prohibit the software from starting; a fourth processing component for storing the target value and the target detection result in the malicious file library if the target detection result is that the software is malware or the target detection result is that the software is non-malware, and sending the target detection result to the cloud edge node.

[0022] According to another aspect of an embodiment of the present disclosure, a malware detection device is also provided, including: a second receiving component, used to receive a first request sent by a terminal node through a cloud edge node, wherein the first request includes at least a target processing strategy and a target value, and the target processing strategy is one of the following: a detection strategy, a defense strategy, the detection strategy and the defense strategy correspond to different software states, and the target value is used to identify the software file of the software; a second determination component, used to detect whether the software is malware based on the target processing strategy and the target value, and obtain a first detection result; a first sending component, used to send a target request to the cloud center node when the first detection result indicates that it is impossible to determine whether the software is malware, so as to receive the target detection result returned by the cloud center node.

[0023] Furthermore, the cloud edge node is deployed with a malicious file sub-database and a sub-detection engine. When the target processing strategy is a detection strategy, the second determination component includes: a third matching sub-component, which is used to match in the malicious file sub-database according to the target value to obtain a third matching result; a fifth determination sub-component, which is used to determine the first detection result based on the record detection result contained in the record if the third matching result is that there is a record with the same target value in the malicious file sub-database; a sixth determination sub-component, which is used to receive the software file uploaded by the terminal node if the third matching result is that there is no record with the same target value in the malicious file sub-database, and detect the software file content through the sub-detection engine. When the sub-detection engine cannot determine whether the software file content contains malicious behavior, it will not be able to determine whether the software is malware as the first detection result.

[0024] Furthermore, the cloud edge node is deployed with a malicious file sub-database. When the target processing strategy is a defense strategy, the second determination component includes: a fourth matching sub-component, which is used to match in the malicious file sub-database according to the target value to obtain a fourth matching result; a seventh determination sub-component, which is used to determine the first detection result based on the record detection result contained in the record if the fourth matching result is that there is a record with the same target value in the malicious file sub-database; and an eighth determination sub-component, which is used to determine whether the software is malware as the first detection result if the fourth matching result is that there is no record with the same target value in the malicious file sub-database.

[0025] According to another aspect of an embodiment of the present disclosure, a computer-readable storage medium is further provided, wherein the storage medium stores a program, wherein when the program is running, the device where the storage medium is located is controlled to execute any one of the above-mentioned malware detection methods.

[0026] According to another aspect of an embodiment of the present disclosure, an electronic device is provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes any one of the above-mentioned malware detection methods when running.

[0027] According to another aspect of an embodiment of the present disclosure, a computer program product is provided, which includes a computer program, and when the computer program is executed by a processor, it implements any one of the above-mentioned malware detection methods.

[0028] According to another aspect of an embodiment of the present disclosure, a computer program product is provided, which includes a non-volatile computer-readable storage medium, the non-volatile computer-readable storage medium storing a computer program, and the computer program, when executed by a processor, implements any one of the above-mentioned malware detection methods.

[0029] According to another aspect of an embodiment of the present disclosure, a computer program product is provided. When the computer program product is executed by a processor, the computer program product implements any one of the above-mentioned malware detection methods.

[0030] In the embodiment of the present disclosure, a multi-layer collaborative approach based on cloud-edge-terminal (cloud center-cloud edge-terminal) is adopted to detect and defend against malware. A target request sent by a cloud edge node is received through a cloud center node, wherein the target request includes at least a target processing strategy and a target value. The target processing strategy is one of the following: a detection strategy, a defense strategy. The detection strategy and the defense strategy correspond to different software states. The target value is used to identify the software file of the software. Whether the software is malware is detected based on the target processing strategy and the target value, and a target detection result is obtained. A first request sent by a terminal node is received through a cloud edge node, wherein the first request includes at least a target processing strategy and a target value. Whether the software is malware is detected based on the target processing strategy and the target value, and a first detection result is obtained. When the first detection result indicates that it is impossible to determine whether the software is malware, a target request is sent to the cloud center node to receive the target detection result returned by the cloud center node.

[0031] In summary, malware detection and defense are carried out based on multi-layer collaboration of cloud, edge and terminal (cloud center-cloud edge-terminal), and the proximal advantages of the terminal are used to perform detection and collection work that does not consume performance, completing the low-latency, low-cost first-layer protection. The rules sent to the terminal can identify basic malware behaviors, and directly generate alarms and software start interception actions, thereby avoiding a large amount of data transmission. Then, the software detection results are cached for cloud edge nodes at different levels, and a single engine with only part of the detection rules is deployed to perform file comparison in the cloud edge node. Then, a multi-engine architecture is adopted in the cloud center to provide a more complete detection capability, detect the files reported to the cloud center, and synchronize the results to the cloud edge node, enhancing the filtering capability of the cloud edge node, achieving the purpose of reducing request delays and enhancing overall availability through multi-layer collaboration of cloud, edge and terminal, thereby achieving the technical effect of reducing delays and improving malware detection efficiency, and thus solving the technical problem in the related technology that the malware of the terminal is detected through the cloud system, and the high delay leads to low malware detection efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] The drawings described herein are used to provide a further understanding of the present disclosure and constitute a part of the present disclosure. The exemplary embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation of the present disclosure. In the drawings:

[0033] FIG1 is a schematic diagram of a computer terminal provided according to an embodiment of the present disclosure;

[0034] FIG2 is a flowchart of a method for detecting malware according to an embodiment of the present disclosure;

[0035] FIG3 is a schematic diagram of an optional malware detection and prevention system architecture provided according to an embodiment of the present disclosure;

[0036] FIG4 is a flowchart of a method for detecting malware according to an embodiment of the present disclosure;

[0037] FIG5 is a schematic diagram of a malware detection device according to an embodiment of the present disclosure;

[0038] FIG6 is a schematic diagram of a malware detection device according to an embodiment of the present disclosure;

[0039] FIG7 is a schematic diagram of a computing terminal provided according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0040] In order to enable those skilled in the art to better understand the solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present disclosure.

[0041] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way are interchangeable where appropriate, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or components is not necessarily limited to those steps or components clearly listed, but may include other steps or components that are not clearly listed or inherent to these processes, methods, products or devices.

[0042] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0043] According to an embodiment of the present disclosure, a method for detecting malware is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0044] The method embodiments provided in the embodiments of the present disclosure can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 shows a hardware structure block diagram of a computer terminal (or mobile device) for implementing a malware detection method. As shown in Figure 1, the computer terminal (or mobile device) 10 may include a processor set 102 (the processor set 102 may include but is not limited to a processing device such as a microcontroller unit (MCU) or a programmable logic device (FPGA), and the processor set 102 may include a processor set, as shown in Figure 1 using 102a, 102b, ..., 102n), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that the structure shown in Figure 1 is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may also include more or fewer components than shown in FIG. 1 , or have a configuration different from that shown in FIG. 1 .

[0045] It should be noted that the one or more processors 102 and / or other data processing circuitry described above may generally be referred to herein as "data processing circuitry." The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing component, or may be fully or partially integrated into any of the other components of the computer terminal 10 (or mobile device).

[0046] The memory 104 can be used to store software programs and components of application software, such as the program instructions / data storage device corresponding to the malware detection method in the embodiment of the present disclosure. The processor 102 executes various functional applications and data processing by running the software programs and components stored in the memory 104, that is, implementing the above-mentioned malware detection method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0047] Transmission device 106 is used to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by the communications provider of computer terminal 10. In one embodiment, transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, transmission device 106 may be a radio frequency (RF) component for wireless communication with the Internet.

[0048] The display may be, for example, a touch screen liquid crystal display (LCD), which enables a user to interact with a user interface of the computer terminal 10 (or mobile device).

[0049] The Cloud Security Center scans and inspects the contents of massive amounts of software files on user terminals, both in the cloud and outside the cloud. These files, collected from user terminal servers, must be reported across proprietary and regional networks before being uploaded to the cloud center for storage. The entire malware detection process is lengthy and complex, and a single node failure at any location can render the entire service unavailable. In file detection scenarios, large volumes of files are sent to the cloud center for processing. The cloud center handles a significant amount of traffic, including data transmission, software testing, and result storage. This results in a high probability of failure and minimal buffer space in the event of a failure.

[0050] Currently, existing malware detection systems generally fall into two categories: endpoint detection (such as antivirus software detection) and cloud-based detection. Endpoint detection performs detection logic locally, including file collection, detection, alerting, and removal. It is largely unrelated to cloud computing and offers low latency and low cost. However, its detection capabilities are relatively poor, and it cannot effectively leverage the powerful computing power of the cloud to perform high-precision malware removal. Purely centralized cloud-based detection is simple and easy to use, with high accuracy. However, it requires large amounts of data transmission and multiple cross-network interactions across multiple regions, resulting in low timeliness and high latency, leading to low malware detection efficiency. Furthermore, in software-activated defense scenarios, the delay from malware collection by the client to console alerts can be at least several hundred milliseconds. The client will pause the process for several hundred milliseconds or even seconds until it is confirmed to be harmless, allowing it to continue running. This delay can cause problems when user service is time-sensitive.

[0051] In the above technical context, the present disclosure provides a malware detection method as shown in FIG2. FIG2 is a flow chart of a malware detection method according to an embodiment of the present disclosure. The method includes:

[0052] Step S201: Receive a target request sent by a cloud edge node through a cloud center node, wherein the target request includes at least a target processing strategy and a target value. The target processing strategy is one of the following: a detection strategy and a defense strategy. The detection strategy and the defense strategy correspond to different software states. The target value is used to identify the software file of the software.

[0053] In an optional embodiment, the software state of the software is determined by the terminal engine of the terminal node, and a target processing strategy for the software is determined according to the software state, wherein the software state is one of the following: an unstarted state and a started state.

[0054] The end-to-end engine is deployed on the end, which has a faster response time but weaker capabilities. It can perform simple matching behaviors. For example, it can match the file content with the regular expression content in the detection rule. If the file content contains the same specified content as the regular expression content, it can be determined whether the file is malicious or not.

[0055] The terminal engine of the terminal node regularly collects file information on the disk for detection, or performs defense when it detects any software writing to the disk, starting up, etc. Therefore, the current status of the software is first determined by the terminal engine of the terminal node, so as to determine whether to detect or defend the software. For example, when the software status is not started, the detection strategy is used as the target processing strategy, and the corresponding detection process is carried out, including identifying basic malware behavior through the rules sent to the terminal, matching the cached software detection results at the cloud edge node and detecting through a single engine, matching the cached software detection results at the cloud center node and detecting through multiple engines, etc.; when the software status is started, the defense strategy is used as the target processing strategy, and the corresponding defense process is carried out, including pausing the software startup, matching the malicious file library layer by layer to see if there is a record of malware, and if there is and the record is black software, executing specific operations of prohibiting the software startup and killing the process; if not, the software startup is released, and a comprehensive detection of the software file content is asynchronously initiated.

[0056] In an optional embodiment, the terminal engine detects whether the software is malware based on the target processing strategy. For example, the regular expression content in the detection rule is matched with the file content. If the file content does not contain the same specified content as the regular expression content, it is impossible to determine whether the software is malware, that is, the inability to determine whether the software is malware is used as the detection result. In this case (the detection result indicates that it is impossible to determine whether the software is malware), the cloud edge node can detect whether the software is malware based on the target processing strategy. The cloud edge node deploys a malicious file sub-database and a simplified single engine (i.e., a sub-detection engine). The response time and detection capability are intermediate, and are used to quickly respond to terminal requests in this area. For example, the cloud edge node can match based on the software detection results in the malicious file sub-database, or it can detect through a single engine to obtain a first detection result, wherein the single-engine detection can be matched using multiple regular expressions or a simple malware identification model, which is not limited here.

[0057] When the first detection result indicates that it is impossible to determine whether the software is malware, the cloud edge node sends a target request to the cloud center node. Therefore, the target request sent by the cloud edge node is received by the cloud center node, wherein the target request includes at least a target processing strategy (i.e., whether to detect or defend the software) and a target value. The target value can be the sha256 hash value of the software file calculated by the secure hash algorithm, or the MD5 value calculated by the information digest algorithm, etc., which is not limited here.

[0058] It should be noted that in the embodiment of the present disclosure, the software file refers to the folder of the software in the terminal, the software file content can be the content in the folder (such as multiple files with suffixes), and the file information can be information such as file size, file path, etc.

[0059] Step S202 : detecting whether the software is malware based on the target processing strategy and the target value, and obtaining a target detection result.

[0060] When the first detection result indicates that it is impossible to determine whether the software is malware, that is, when the cloud edge node cannot determine whether the software is malware, the cloud center node detects whether the software is malware based on the target processing strategy and target value to obtain the target detection result, wherein the cloud center node is deployed with a malicious file library and multiple detection engines.

[0061] The cloud center node is responsible for the storage of the complete malicious file library, the deployment of the multi-engine platform on the cloud, and the deployment of multiple detection engines. When the cloud edge node and the terminal node are unable to determine the result, the software detection and defense will be performed by the cloud center node to obtain the target detection result, that is, whether the software is malware or non-malware. The response time of the cloud center node is longer than that of the terminal node and the cloud edge node, but the detection capability is stronger. Among them, the malicious file library records the software file identifier (that is, the target value) and the detection result corresponding to the file identifier (black or white, that is, malware or non-malware). The software file identifier can be the sha256 hash value of the software file calculated by the secure hash algorithm, or the MD5 value calculated by the information digest algorithm, etc., which is not limited here.

[0062] In this solution, malware detection and defense are carried out based on multi-layer collaboration of cloud, edge and terminal (cloud center-cloud edge-terminal), and the proximal advantage of the terminal is used to perform non-performance-consuming detection and collection work to complete the low-latency, low-cost first-layer protection. The rules sent to the terminal can identify basic malware behaviors, and directly generate alarms and software-initiated interception actions, thereby avoiding large amounts of data transmission. Then, the software detection results are cached for cloud edge nodes at different levels, and a single engine with only partial detection rules is deployed to perform file comparison in the cloud edge nodes. Then, a multi-engine architecture is adopted in the cloud center to provide a more complete detection capability, detect files reported to the cloud center, and synchronize the results to the cloud edge nodes to enhance the filtering capabilities of the cloud edge nodes.

[0063] In an optional embodiment, the schematic diagram shown in Figure 3 can be used to implement malware detection and defense. As shown in Figure 3, this solution designs a system that reduces request latency and enhances overall availability through multi-layer collaboration of cloud, edge, and end in the scenario of malware detection and defense on user terminals. Malware detection and defense are performed based on cloud, edge, and end collaboration. The overall architecture is a multi-level architecture of terminal-cloud edge-cloud center. The cloud center node sends some detection rules to the cloud edge node, and the cloud edge node sends a small part of the detection rules (i.e., end-to-end detection rules) to the terminal node. The malicious file library of the cloud center node sends the detection results to the malicious file library of the cloud edge node (i.e., the malicious file sub-database). It utilizes the proximal advantages of the client to perform non-performance-consuming detection and collection work, and realizes low-latency, low-cost first-layer protection through the client. It can identify basic malware behaviors through the rules sent to the terminal, and directly generate alarms and software startup interception actions, thereby avoiding large amounts of data transmission; then cache software detection results for cloud edge nodes at different levels, and deploy a single engine containing some detection rules, perform file comparison and preliminary screening in the cloud edge nodes, filter out most of the repeated software detection requests, thereby avoiding repeated detection of the same software and improving detection efficiency; the system adopts a multi-engine architecture in the cloud center (for example, including sandbox engines, deep learning engines, etc.), providing complete detection capabilities, able to detect files reported to the cloud center, and synchronize the results to the cloud edge nodes, enhancing the filtering capabilities of the cloud edge nodes.

[0064] Optionally, the defense action is a short-term synchronous operation, initiated by the terminal engine when the software starts. The terminal engine will first pause the software startup and match the malicious file library layer by layer to see if there is a record of malware. If there is and the record is black software, the startup is prohibited and the process is killed. If not, the software startup is allowed and a comprehensive detection of the software content is initiated asynchronously. Asynchronous detection is also performed layer by layer. When the current layer cannot reach a conclusion due to detection capability limitations, a detection request is sent upward until a result is obtained. The result is placed in the malicious file library as the basis for the next detection and defense. For example, the file detection and process defense functions of the cloud security center can use the cloud-edge multi-layer architecture in this solution.

[0065] In order to accurately determine whether the software is malware, in the malware detection method provided in the embodiment of the present disclosure, the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is the detection strategy, the software is detected as malware based on the target processing strategy and the target value to obtain a target detection result, including: matching in the malicious file library based on the target value to obtain a first matching result; if the first matching result is that there is a record with the same target value in the malicious file library, then determining the target detection result based on the record detection result contained in the record; if the first matching result is that there is no record with the same target value in the malicious file library, then receiving the software file uploaded by the cloud edge node, and detecting the software file content through multiple detection engines to obtain multiple detection results, and determining the target detection result based on the multiple detection results.

[0066] Since the cloud center node has complete detection capabilities, including a complete malicious file library and detection engine, when the cloud edge engine cannot determine whether the software is malware, the cloud center node can detect whether the software is malware based on the target processing strategy and target value to obtain the target detection result. Optionally, the cloud center node matches the malicious file library based on the target value to obtain a first matching result. For example, the cloud center node parses the basic information and sha256 identifier (i.e., the target value) of the file according to the target request, and matches it in the malicious file library. If found, the result is directly returned, otherwise the file content needs to be detected.

[0067] Optionally, if the first matching result is that there is a record with the same target value in the malicious file library, the target detection result is determined based on the record detection result contained in the record. For example, after matching in the malicious file library based on the sha256 identifier, if there is a record with the same sha256 identifier in the malicious file library, that is, there is a sha256 identifier with the same sha256 identifier and the corresponding detection result (that is, the record detection result), then the target detection result can be determined based on the record detection result. For example, if the record detection result is that the sha256 identifier is malware, then the target detection result is determined to be that the software is malware; if the record detection result is that the sha256 identifier is non-malware, then the target detection result is determined to be that the software is non-malware.

[0068] Optionally, if the first matching result is that there is no record with the same target value in the malicious file library, then the software file uploaded by the cloud edge node is received, and the content of the software file is detected by multiple detection engines to obtain multiple detection results, and the target detection result is determined based on the multiple detection results. For example, after matching in the malicious file library based on the sha256 identifier, if there is no record with the same sha256 identifier in the malicious file library, then the software file uploaded by the cloud edge node is received, and the cloud center node uses a multi-engine architecture to improve the detection capability. By detecting whether the content of the software file is malicious through multiple detection engines, multiple detection results can be obtained. By setting priorities and score ratios for detection engines (for example, sandbox engines, machine learning engines, stain engines, etc.), the results of multiple engines can be combined to determine whether the software is malicious and the probability of it being malware, and obtain the target detection result.

[0069] It should be noted that the cloud center adopts a multi-engine architecture (for example, sandbox engine, deep learning engine, etc.) to provide complete detection capabilities, which can detect files reported to the cloud center and synchronize the results to the cloud edge nodes, thereby enhancing the filtering capabilities of the cloud edge nodes and improving the detection accuracy.

[0070] In order to accurately determine whether the software is malware, in the malware detection method provided in the embodiment of the present disclosure, the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is a defense strategy, the software is detected as malware based on the target processing strategy and the target value to obtain a target detection result, including: matching in the malicious file library based on the target value to obtain a second matching result; if the second matching result is that there is a record with the same target value in the malicious file library, then determining the target detection result based on the record detection result contained in the record; if the second matching result is that there is no record with the same target value in the malicious file library, then notifying the cloud edge node to release the pause of the software startup process, and receiving the software file uploaded by the cloud edge node, asynchronously detecting the software file content through multiple detection engines to obtain multiple detection results, and determining the target detection result based on the multiple detection results.

[0071] Optionally, since the cloud center node includes a complete malicious file library, when the cloud edge engine cannot determine whether the software is malware, the cloud center node can detect whether the software is malware based on the target processing strategy and the target value to obtain a target detection result. Optionally, the cloud center node matches the malicious file library based on the target value to obtain a second matching result. For example, the cloud center node parses the basic information and sha256 identifier (i.e., the target value) of the file according to the target request and matches it in the malicious file library.

[0072] Optionally, if the second matching result is that there is a record with the same target value in the malicious file library, the target detection result is determined based on the record detection result contained in the record. For example, after matching in the malicious file library based on the sha256 identifier, if there is a record with the same sha256 identifier in the malicious file library, that is, there is a sha256 identifier with the same sha256 identifier and a corresponding detection result (that is, a record detection result), then the target detection result can be determined based on the record detection result. For example, if the record detection result is that the sha256 identifier is malware, then the target detection result is determined to be that the software is malware; if the record detection result is that the sha256 identifier is non-malware, then the target detection result is determined to be that the software is non-malware. Optionally, if found, the result is returned directly.

[0073] Optionally, if the second matching result is that there is no record with the same target value in the malicious file library, the cloud edge node is notified to release the suspension of the software startup process, and the software file uploaded by the cloud edge node is received. The software file content is asynchronously detected by multiple detection engines to obtain multiple detection results, and the target detection result is determined based on the multiple detection results. For example, after matching in the malicious file library according to the sha256 identifier, if there is no record with the same sha256 identifier in the malicious file library, the suspension of the file is released on the end to avoid affecting the user's real process, and then a comprehensive detection of the software content is asynchronously initiated, and the file is transferred from the end to the cloud. For example, the software content is detected in the local single engine of the cloud edge node to determine whether it is malicious. If the edge detection engine can obtain a clear result, the detection ends, otherwise the detection request continues to be reported to the cloud center node. The cloud center node detects whether the software file content is malicious through multiple detection engines, and multiple detection results can be obtained. By setting priorities and score ratios for detection engines (for example, sandbox engines, machine learning engines, stain engines, etc.), the results of multiple engines can be combined to determine whether the software is malicious and the probability of it being malware, and obtain the target detection result.

[0074] It should be noted that when the software is started, the terminal engine first pauses the software startup, and then matches the malicious file library layer by layer to see if there is any record of malware. If there is and the record is black software, the startup is prohibited and the process is killed. If not, the software startup is allowed, and a comprehensive detection of the software content is initiated asynchronously. The asynchronous detection is also done layer by layer. When the current layer cannot reach a conclusion due to detection capability limitations, a detection request is initiated upward until a result is obtained, and the result is placed in the malicious file library as the basis for the next detection and defense, effectively improving the detection and defense efficiency.

[0075] In order to improve the efficiency of malware detection, in the malware detection method provided in the embodiment of the present disclosure, when the target processing strategy is the detection strategy, after detecting whether the software is malware based on the target processing strategy and the target value and obtaining the target detection result, the method also includes: if the target detection result is that the software is malware, generating an alarm information based on the file information of the software, and sending the alarm information to the console; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, storing the target value and the target detection result in the malicious file library, and sending the target detection result to the cloud edge node.

[0076] Optionally, when the target processing strategy is a detection strategy, after detecting whether the software is malware based on the target processing strategy and the target value and obtaining the target detection result, the software can be processed based on the target detection result. For example, if the target detection result is that the software is malware, an alarm message can be generated based on the file information of the software, and the alarm message can be sent to the console; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, the target value and the target detection result are stored in the malicious file library, that is, the sha256 hash value of the software file and the detection result obtained by the detection are stored, and the target detection result is sent to the cloud edge node for the next malware detection and defense.

[0077] In order to improve the defense efficiency of malware, in the malware detection method provided in the embodiment of the present disclosure, when the target processing strategy is a defense strategy, after detecting whether the software is malware based on the target processing strategy and the target value and obtaining the target detection result, the method also includes: if the target detection result is that the software is malware, ending the startup process to prohibit the software from starting; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, storing the target value and target detection result in the malicious file library, and sending the target detection result to the cloud edge node.

[0078] Optionally, when the target processing strategy is a defense strategy, after detecting whether the software is malware based on the target processing strategy and the target value and obtaining the target detection result, the software can be processed based on the target detection result. For example, if the target detection result is that the software is malware, the startup process is ended to prohibit the software from starting; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, the target value and the target detection result are stored in the malicious file library, that is, the sha256 hash value of the software file and the detection result obtained by the detection are stored, and the target detection result is sent to the cloud edge node for the next malware detection and defense.

[0079] In the embodiment of the present disclosure, a multi-layer collaborative approach based on cloud-edge-terminal (cloud center-cloud edge-terminal) is adopted to detect and defend against malware. A target request sent by a cloud edge node is received through a cloud center node, wherein the target request includes at least a target processing strategy and a target value. The target processing strategy is one of the following: a detection strategy, a defense strategy. The detection strategy and the defense strategy correspond to different software states. The target value is used to identify the software file of the software. Whether the software is malware is detected based on the target processing strategy and the target value, and a target detection result is obtained. A first request sent by a terminal node is received through a cloud edge node, wherein the first request includes at least a target processing strategy and a target value. Whether the software is malware is detected based on the target processing strategy and the target value, and a first detection result is obtained. When the first detection result indicates that it is impossible to determine whether the software is malware, a target request is sent to the cloud center node to receive the target detection result returned by the cloud center node.

[0080] In summary, malware detection and defense are carried out based on multi-layer collaboration of cloud, edge and terminal (cloud center-cloud edge-terminal), and the proximal advantages of the terminal are used to perform detection and collection work that does not consume performance, completing the low-latency, low-cost first-layer protection. The rules sent to the terminal can identify basic malware behaviors, and directly generate alarms and software start interception actions, thereby avoiding a large amount of data transmission. Then, the software detection results are cached for cloud edge nodes at different levels, and a single engine with only part of the detection rules is deployed to perform file comparison in the cloud edge node. Then, a multi-engine architecture is adopted in the cloud center to provide a more complete detection capability, detect the files reported to the cloud center, and synchronize the results to the cloud edge node, enhancing the filtering capability of the cloud edge node, achieving the purpose of reducing request delays and enhancing overall availability through multi-layer collaboration of cloud, edge and terminal, thereby achieving the technical effect of reducing delays and improving malware detection efficiency, and thus solving the technical problem in the related technology that the malware of the terminal is detected through the cloud system, and the high delay leads to low malware detection efficiency.

[0081] It should be noted that for the aforementioned method embodiments, for simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present disclosure is not limited by the order of the actions described, because according to the present disclosure, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and components involved are not necessarily required by the present disclosure.

[0082] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present disclosure is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), including a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present disclosure.

[0083] According to an embodiment of the present disclosure, a method for detecting malware is also provided as shown in FIG4 . FIG4 is a flow chart of a method for detecting malware according to an embodiment of the present disclosure. The method includes:

[0084] Step S401: Receive a first request sent by a terminal node through a cloud edge node, wherein the first request includes at least a target processing strategy and a target value. The target processing strategy is one of the following: a detection strategy and a defense strategy. The detection strategy and the defense strategy correspond to different software states. The target value is used to identify the software file of the software.

[0085] In an optional embodiment, the software state of the software is determined by the terminal engine of the terminal node, and a target processing strategy for the software is determined according to the software state, wherein the software state is one of the following: an unstarted state and a started state.

[0086] The end-to-end engine is deployed on the end, which has a faster response time but weaker capabilities. It can perform simple matching behaviors. For example, it can match the file content with the regular expression content in the detection rule. If the file content contains the same specified content as the regular expression content, it can be determined whether the file is malicious or not.

[0087] The terminal engine of the terminal node regularly collects file information on the disk for detection, or performs defense when it detects any software writing to the disk, starting up, etc. Therefore, the current status of the software is first determined by the terminal engine of the terminal node, so as to determine whether to detect or defend the software. For example, when the software status is not started, the detection strategy is used as the target processing strategy, and the corresponding detection process is carried out, including identifying basic malware behavior through the rules sent to the terminal, matching the cached software detection results at the cloud edge node and detecting through a single engine, matching the cached software detection results at the cloud center node and detecting through multiple engines, etc.; when the software status is started, the defense strategy is used as the target processing strategy, and the corresponding defense process is carried out, including pausing the software startup, matching the malicious file library layer by layer to see if there is a record of malware, and if there is and the record is black software, executing specific operations of prohibiting the software startup and killing the process; if not, the software startup is released, and a comprehensive detection of the software file content is asynchronously initiated.

[0088] In an optional embodiment, the terminal engine detects whether the software is malware based on the target processing strategy, for example, by matching the regular expression content in the detection rule with the file content. If the file content does not contain the same specified content as the regular expression content, it is impossible to determine whether the software is malware, and the detection result is that it is impossible to determine whether the software is malware. In this case (the detection result indicates that it is impossible to determine whether the software is malware), the terminal node sends a first request to the cloud edge node.

[0089] In an optional embodiment, when the terminal engine is unable to determine whether the software is malware, it calculates a target value based on the software file content, obtains the file information of the software, and generates a detection request (i.e., a first request) based on the target value and the file information and reports it to the cloud edge node. For example, when the terminal engine is unable to determine whether the software is malware, the terminal engine calculates a sha256 hash value based on the software file content as a file identifier, collects file information, such as file size, path, etc., and encapsulates the sha256 hash value and the collected information into a detection request and reports it to the cloud edge node.

[0090] Therefore, the first request sent by the terminal node is received by the cloud edge node, wherein the first request includes at least a target processing strategy (i.e., whether to detect or defend the software) and a target value. The target value can be the sha256 hash value of the software file calculated by the secure hash algorithm, or the MD5 value calculated by the information digest algorithm, etc., which is not limited here.

[0091] Step S402 : detecting whether the software is malware based on the target processing strategy and the target value, and obtaining a first detection result.

[0092] The cloud edge node detects whether the software is malware based on the target processing strategy and target value. The cloud edge node deploys a malicious file sub-database and a simplified single engine (i.e., a sub-detection engine). The response time and detection capability are intermediate, and are used to quickly respond to terminal requests in this area. For example, the cloud edge node can match based on the software detection results in the malicious file sub-database, or it can perform detection through a single engine to obtain the first detection result. Among them, the single-engine detection can be matched using multiple regular expressions, or it can be a simple malware identification model, which is not limited here.

[0093] Step S403: When the first detection result indicates that it is impossible to determine whether the software is malware, a target request is sent to the cloud center node to receive the target detection result returned by the cloud center node.

[0094] When the first detection result indicates that it is impossible to determine whether the software is malware, the cloud edge node sends a target request to the cloud center node, so that the cloud center node detects whether the software is malware based on the target processing strategy and target value, obtains the target detection result, and sends the target detection result to the cloud edge node for the next malware detection and defense.

[0095] In an optional embodiment, when the target processing strategy is a detection strategy, the software file content and detection rules of the software are obtained through the terminal engine; the software file content is compared with the target content corresponding to the detection rule to obtain a first comparison result; if the first comparison result is that the software file content and the target content are the same, the detection result is determined based on the target type corresponding to the target content; if the first comparison result is that the software file content and the target content are different, it will be impossible to determine whether the software is malware as a detection result.

[0096] When the target processing strategy is a detection strategy, the terminal engine actively initiates malicious behavior detection of the software file content through the on-terminal detection rules. The terminal engine obtains the software file content and detection rules (for example, regular expression matching rules) of the software, compares the software file content with the target content corresponding to the detection rule, and obtains a first comparison result, wherein the target content includes two types, one for determining that the software is malware and the other for determining that the software is non-malware. For example, the regular expression content (i.e., target content) in the detection rule can be matched with the file content.

[0097] If the first comparison result is that the software file content is identical to the target content, the detection result can be determined based on the target type corresponding to the target content. Among them, there are two target types, one is a malware determination type, and the other is a non-malware determination type. For example, after matching the regular expression content in the detection rule with the file content, if there is specified content in the file content that is identical to the regular expression content, that is, if the first comparison result is that the software file content is identical to the target content, the detection result can be determined based on the target type corresponding to the target content. For example, if the target type is a malware determination type, the detection result is determined to be that the software is malware; if the target type is a non-malware determination type, the detection result is determined to be that the software is non-malware.

[0098] Alternatively, if the first comparison result indicates that the software file content is not identical to the target content, then it is not possible to determine whether the software is malware as a detection result. For example, after matching the file content with the regular expression content in the detection rule, if the file content does not contain the same specified content as the regular expression content, then it is not possible to determine whether the software is malware.

[0099] It should be noted that in the above process, the client's proximal advantage is used to perform non-performance-consuming detection and collection work. The client implements a low-latency, low-cost first-layer protection in the terminal node. Basic malware behaviors are identified through rules sent to the terminal, avoiding large amounts of data transmission. This can cover scenarios of commonly used software, achieve low-latency detection, and effectively improve detection efficiency.

[0100] In order to accurately determine whether the software is malware, in the malware detection method provided in the embodiment of the present disclosure, the cloud edge node is deployed with a malicious file sub-database and a sub-detection engine. When the target processing strategy is the detection strategy, the software is detected as malware based on the target processing strategy and the target value to obtain a first detection result, including: matching in the malicious file sub-database based on the target value to obtain a third matching result; if the third matching result is that there is a record with the same target value in the malicious file sub-database, the first detection result is determined based on the record detection result contained in the record; if the third matching result is that there is no record with the same target value in the malicious file sub-database, the software file uploaded by the terminal node is received, and the software file content is detected by the sub-detection engine. If the sub-detection engine cannot determine whether the software file content contains malicious behavior, it will not be able to determine whether the software is malware as the first detection result.

[0101] Optionally, the cloud edge node matches the malicious file sub-database based on the target value to obtain a third matching result. For example, an edge node closer to the terminal (which can be a regional edge node or a proprietary network edge node) responds to the first request, parses the basic information and SHA256 identifier of the file, and matches it in the local malicious file sub-database.

[0102] Optionally, if the third matching result is that there is a record with the same target value in the malicious file sub-database, the first detection result is determined based on the record detection result contained in the record. For example, after matching in the malicious file sub-database based on the sha256 identifier, if there is a record with the same sha256 identifier in the malicious file sub-database, that is, there is a sha256 identifier with the same sha256 identifier and the corresponding detection result (that is, the record detection result), then the first detection result can be determined based on the record detection result. For example, if the record detection result is that the sha256 identifier is malware, then the first detection result is determined to be that the software is malware; if the record detection result is that the sha256 identifier is non-malware, then the first detection result is determined to be that the software is non-malware.

[0103] Optionally, if the third matching result is that there is no record with the same target value in the malicious file sub-database, the software file uploaded by the terminal node is received, and the content of the software file is detected by the sub-detection engine. If the sub-detection engine cannot determine whether the content of the software file contains malicious behavior, it will not be able to determine whether the software is malware as the first detection result. For example, after matching in the malicious file sub-database based on the sha256 identifier, if there is no record with the same sha256 identifier in the malicious file sub-database, the software file uploaded by the terminal node can be received, and the software content can be detected in the local single engine (i.e., the sub-detection engine) to see if it is malicious. For example, multiple regular expressions are used for matching or a simple malware identification model is used. If the edge detection engine can obtain a clear result, the detection ends, otherwise the request will continue to be reported to the cloud center node.

[0104] It should be noted that the software detection results are cached for cloud edge nodes at different levels, and a single engine containing some detection rules is deployed to perform file comparison and preliminary screening in the cloud edge nodes to filter out most of the repeated software detection requests, thereby avoiding repeated detection of the same software and effectively improving detection efficiency.

[0105] In an optional embodiment, when the target processing strategy is a defense strategy, the startup process of the software is suspended through the terminal engine, and the software file content and detection rules of the software are obtained through the terminal engine; the software file content is compared with the target content corresponding to the detection rule to obtain a second comparison result; if the second comparison result is that the software file content and the target content are the same, the detection result is determined based on the target type corresponding to the target content; if the second comparison result is that the software file content and the target content are different, it will be impossible to determine whether the software is malware as a detection result.

[0106] When the target processing strategy is a defense strategy, the terminal engine initiates a defense action when the software is started. That is, the terminal engine first pauses the software startup process and then matches the malicious file library layer by layer to see if there is any record of malware. Optionally, the terminal engine obtains the software file content and detection rules (for example, regular expression matching rules) of the software, and compares the software file content with the target content corresponding to the detection rule to obtain a second comparison result, wherein the target content includes two types, one for determining whether the software is malware and the other for determining whether the software is non-malware. For example, the regular expression content in the detection rule (that is, the target content) can be matched with the file content.

[0107] Optionally, if the second comparison result is that the software file content is identical to the target content, the detection result can be determined based on the target type corresponding to the target content. There are two types of target types: one is a malware determination type, and the other is a non-malware determination type. For example, after matching the regular expression content in the detection rule with the file content, if there is specified content in the file content that is identical to the regular expression content, that is, if the second comparison result is that the software file content is identical to the target content, the detection result can be determined based on the target type corresponding to the target content. For example, if the target type is a malware determination type, the detection result is determined to be that the software is malware; if the target type is a non-malware determination type, the detection result is determined to be that the software is non-malware.

[0108] Alternatively, if the second comparison result indicates that the software file content is not identical to the target content, then it is not possible to determine whether the software is malware as a detection result. For example, after matching the file content with the regular expression content in the detection rule, if the file content does not contain the same specified content as the regular expression content, then it is not possible to determine whether the software is malware.

[0109] It should be noted that in the above process, the client's proximal advantage is used to perform non-performance-consuming detection and collection work. The client implements a low-latency, low-cost first-layer protection in the terminal node. Basic malware behaviors are identified through rules sent to the terminal, avoiding large amounts of data transmission. This can cover scenarios of commonly used software, achieve low-latency detection, and effectively improve detection efficiency.

[0110] In order to accurately determine whether the software is malware, in the malware detection method provided in the embodiment of the present disclosure, the cloud edge node is deployed with a malicious file sub-database. When the target processing strategy is a defense strategy, the software is detected as malware based on the target processing strategy and the target value to obtain a first detection result, including: matching in the malicious file sub-database based on the target value to obtain a fourth matching result; if the fourth matching result is that there is a record with the same target value in the malicious file sub-database, then the first detection result is determined based on the record detection result contained in the record; if the fourth matching result is that there is no record with the same target value in the malicious file sub-database, it will be impossible to determine whether the software is malware as the first detection result.

[0111] Optionally, the cloud edge node matches the malicious file sub-database based on the target value to obtain a fourth matching result. For example, an edge node closer to the terminal (which can be a regional edge node or a proprietary network edge node) responds to the first request, parses the basic information and sha256 identifier of the file, and matches it in the local malicious file sub-database.

[0112] Optionally, if the fourth matching result is that there is a record with the same target value in the malicious file sub-database, the first detection result is determined based on the record detection result contained in the record. For example, after matching in the malicious file sub-database based on the sha256 identifier, if there is a record with the same sha256 identifier in the malicious file sub-database, that is, there is a sha256 identifier with the same sha256 identifier and a corresponding detection result (that is, a record detection result), then the first detection result can be determined based on the record detection result. For example, if the record detection result is that the sha256 identifier is malware, then the first detection result is determined to be that the software is malware; if the record detection result is that the sha256 identifier is non-malware, then the first detection result is determined to be that the software is non-malware. Afterwards, the result is sent down to the end (that is, the terminal node), and the terminal engine can determine whether to cancel the defense for the file based on this result.

[0113] Alternatively, if the fourth matching result is that there is no record with the same target value in the malicious file sub-database, it will be impossible to determine whether the software is malware as the first detection result. For example, after matching the malicious file sub-database based on the sha256 identifier, if there is no record with the same sha256 identifier in the malicious file sub-database, the request needs to be reported to the cloud center node.

[0114] It should be noted that by caching software detection results at cloud edge nodes at different levels, file comparison and preliminary screening can be performed in the cloud edge nodes to filter out most repeated software judgment requests, thereby avoiding repeated judgments on the same software and effectively improving detection and defense efficiency.

[0115] In summary, malware detection and defense are carried out based on multi-layer collaboration of cloud, edge and terminal (cloud center-cloud edge-terminal), and the proximal advantages of the terminal are used to perform detection and collection work that does not consume performance, completing the low-latency, low-cost first-layer protection. The rules sent to the terminal can identify basic malware behaviors, and directly generate alarms and software start interception actions, thereby avoiding a large amount of data transmission. Then, the software detection results are cached for cloud edge nodes at different levels, and a single engine with only part of the detection rules is deployed to perform file comparison in the cloud edge node. Then, a multi-engine architecture is adopted in the cloud center to provide a more complete detection capability, detect the files reported to the cloud center, and synchronize the results to the cloud edge node, enhancing the filtering capability of the cloud edge node, achieving the purpose of reducing request delays and enhancing overall availability through multi-layer collaboration of cloud, edge and terminal, thereby achieving the technical effect of reducing delays and improving malware detection efficiency, and thus solving the technical problem in the related technology that the malware of the terminal is detected through the cloud system, and the high delay leads to low malware detection efficiency.

[0116] It should be noted that for the aforementioned method embodiments, for simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present disclosure is not limited by the order of the actions described, because according to the present disclosure, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and components involved are not necessarily required by the present disclosure.

[0117] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present disclosure is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), including a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present disclosure.

[0118] According to an embodiment of the present disclosure, a malware detection device for implementing the above malware detection method is also provided. As shown in FIG5 , the device includes: a first receiving component 501 and a first determining component 502 .

[0119] A first receiving component 501 is configured to receive a target request sent by a cloud edge node through a cloud center node, wherein the target request includes at least a target processing strategy and a target value, wherein the target processing strategy is one of the following: a detection strategy and a defense strategy, wherein the detection strategy and the defense strategy correspond to different software states, and the target value is used to identify a software file of the software;

[0120] The first determination component 502 is configured to detect whether the software is malware according to the target processing strategy and the target value, and obtain a target detection result.

[0121] In the malware detection device provided in the embodiment of the present disclosure, a target request sent by a cloud edge node is received by a first receiving component 501 through a cloud center node, wherein the target request includes at least a target processing strategy and a target value, and the target processing strategy is one of the following: a detection strategy and a defense strategy. The detection strategy and the defense strategy correspond to different software states, and the target value is used to identify the software file of the software; the first determination component 502 detects whether the software is malware based on the target processing strategy and the target value, and obtains a target detection result. In this solution, malware detection and defense are performed based on multi-layer collaboration of cloud, edge and terminal (cloud center-cloud edge-terminal), and the proximal advantages of the terminal are used to perform non-performance-consuming detection and collection work to complete the low-latency, low-cost first-layer protection. The rules sent to the terminal can identify basic malware behaviors, and directly generate alarms and software-initiated interception actions, thereby avoiding large amounts of data transmission. Then, the software detection results are cached for cloud edge nodes at different levels, and a single engine with only partial detection rules is deployed to perform file comparison in the cloud edge node. Then, a multi-engine architecture is adopted in the cloud center to provide more complete detection capabilities, detect files reported to the cloud center, and synchronize the results to the cloud edge node to enhance the filtering capability of the cloud edge node. The purpose of reducing request delays and enhancing overall availability through multi-layer collaboration of cloud, edge and terminal is achieved, thereby achieving the technical effect of reducing delays and improving malware detection efficiency, and thus solving the technical problem in related technologies that the high delay in detecting malware on terminals through cloud systems leads to low malware detection efficiency.

[0122] Optionally, in the malware detection device provided in the embodiment of the present disclosure, the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is a detection strategy, the first determination component includes: a first matching sub-component, used to match in the malicious file library according to the target value to obtain a first matching result; a first determination sub-component, used to determine the target detection result based on the record detection result contained in the record if the first matching result is that there is a record with the same target value in the malicious file library; a second determination sub-component, used to receive the software file uploaded by the cloud edge node if the first matching result is that there is no record with the same target value in the malicious file library, and detect the software file content through multiple detection engines to obtain multiple detection results, and determine the target detection result based on the multiple detection results.

[0123] Optionally, in the malware detection device provided in the embodiment of the present disclosure, the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is a defense strategy, the first determination component includes: a second matching sub-component, used to match in the malicious file library according to the target value to obtain a second matching result; a third determination sub-component, used to determine the target detection result based on the record detection result contained in the record if the second matching result is that there is a record with the same target value in the malicious file library; a fourth determination sub-component, used to notify the cloud edge node to release the pause of the software startup process if the second matching result is that there is no record with the same target value in the malicious file library, and receive the software files uploaded by the cloud edge node, asynchronously detect the software file content through multiple detection engines, obtain multiple detection results, and determine the target detection result based on the multiple detection results.

[0124] Optionally, in the malware detection device provided in the embodiment of the present disclosure, the device also includes: a first processing component for detecting whether the software is malware based on the target processing strategy and the target value when the target processing strategy is a detection strategy, and after obtaining the target detection result, if the target detection result is that the software is malware, generating an alarm message based on the file information of the software, and sending the alarm message to the console; a second processing component for storing the target value and target detection result in the malicious file library if the target detection result is that the software is malware or the target detection result is that the software is non-malware, and sending the target detection result to the cloud edge node.

[0125] Optionally, in the malware detection device provided in the embodiment of the present disclosure, the device also includes: a third processing component for detecting whether the software is malware based on the target processing strategy and the target value when the target processing strategy is a defense strategy, and after obtaining the target detection result, if the target detection result is that the software is malware, then ending the startup process to prohibit the software from starting; a fourth processing component for storing the target value and the target detection result in the malicious file library if the target detection result is that the software is malware or the target detection result is that the software is non-malware, and sending the target detection result to the cloud edge node.

[0126] It should be noted that the first receiving component 501 and the first determining component 502 described above correspond to steps S201 to S202 in Example 1. The examples and application scenarios implemented by the above components and corresponding steps are the same, but are not limited to the contents disclosed in the above embodiment. It should be noted that the above components, as part of the device, can be run in the computer terminal 10 provided in the embodiment.

[0127] It should be noted that the preferred implementation scheme involved in the above embodiments of the present disclosure is the same as the solution provided in Example 1, as well as the application scenario and implementation process, but is not limited to the solution provided in Example 1.

[0128] According to an embodiment of the present disclosure, a malware detection device for implementing the above malware detection method is also provided. As shown in FIG6 , the device includes: a second receiving component 601 , a second determining component 602 , and a first sending component 603 .

[0129] A second receiving component 601 is configured to receive, via a cloud edge node, a first request sent by a terminal node, wherein the first request includes at least a target processing strategy and a target value, the target processing strategy being one of the following: a detection strategy and a defense strategy, the detection strategy and the defense strategy corresponding to different software states, and the target value being used to identify a software file;

[0130] A second determining component 602 is configured to detect whether the software is malware based on the target processing strategy and the target value, and obtain a first detection result;

[0131] The first sending component 603 is used to send a target request to the cloud center node to receive the target detection result returned by the cloud center node when the first detection result indicates that it is impossible to determine whether the software is malware.

[0132] In the malware detection device provided by the embodiment of the present disclosure, the first request sent by the terminal node is received through the cloud edge node by the second receiving component 601, wherein the first request includes at least a target processing strategy and a target value, and the target processing strategy is one of the following: detection strategy, defense strategy, the detection strategy and the defense strategy correspond to different software states, and the target value is used to identify the software file of the software; the second determination component 602 detects whether the software is malware based on the target processing strategy and the target value, and obtains a first detection result; the first sending component 603 sends a target request to the cloud center node when the first detection result indicates that it is impossible to determine whether the software is malware, so as to receive the target detection result returned by the cloud center node. In this solution, malware detection and defense are performed based on multi-layer collaboration of cloud, edge and terminal (cloud center-cloud edge-terminal), and the proximal advantages of the terminal are used to perform non-performance-consuming detection and collection work to complete the low-latency, low-cost first-layer protection. The rules sent to the terminal can identify basic malware behaviors, and directly generate alarms and software-initiated interception actions, thereby avoiding large amounts of data transmission. Then, the software detection results are cached for cloud edge nodes at different levels, and a single engine with only partial detection rules is deployed to perform file comparison in the cloud edge node. Then, a multi-engine architecture is adopted in the cloud center to provide more complete detection capabilities, detect files reported to the cloud center, and synchronize the results to the cloud edge node to enhance the filtering capability of the cloud edge node. The purpose of reducing request delays and enhancing overall availability through multi-layer collaboration of cloud, edge and terminal is achieved, thereby achieving the technical effect of reducing delays and improving malware detection efficiency, and thus solving the technical problem in related technologies that the high delay in detecting malware on terminals through cloud systems leads to low malware detection efficiency.

[0133] Optionally, in the malware detection device provided in the embodiment of the present disclosure, the cloud edge node is deployed with a malicious file sub-database and a sub-detection engine. When the target processing strategy is the detection strategy, the second determination component includes: a third matching sub-component, used to match in the malicious file sub-database according to the target value to obtain a third matching result; a fifth determination sub-component, used to determine the first detection result based on the record detection result contained in the record if the third matching result is that there is a record with the same target value in the malicious file sub-database; a sixth determination sub-component, used to receive the software file uploaded by the terminal node if the third matching result is that there is no record with the same target value in the malicious file sub-database, and detect the software file content through the sub-detection engine. When the sub-detection engine cannot determine whether the software file content contains malicious behavior, it will not be able to determine whether the software is malware as the first detection result.

[0134] Optionally, in the malware detection device provided in the embodiment of the present disclosure, the cloud edge node is deployed with a malicious file sub-database. When the target processing strategy is a defense strategy, the second determination component includes: a fourth matching sub-component, used to match in the malicious file sub-database according to the target value to obtain a fourth matching result; a seventh determination sub-component, used to determine the first detection result based on the record detection result contained in the record if the fourth matching result is that there is a record with the same target value in the malicious file sub-database; an eighth determination sub-component, used to determine whether the software is malware as the first detection result if the fourth matching result is that there is no record with the same target value in the malicious file sub-database.

[0135] It should be noted that the second receiving component 601, the second determining component 602, and the first sending component 603 described above correspond to steps S401 to S403 in Example 2. The examples and application scenarios implemented by the above components and corresponding steps are the same, but are not limited to the contents disclosed in the above embodiment. It should be noted that the above components, as part of the device, can be run in the computer terminal 10 provided in the embodiment.

[0136] It should be noted that the preferred implementation scheme involved in the above embodiments of the present disclosure is the same as the solution provided in Example 2, as well as the application scenario and implementation process, but is not limited to the solution provided in Example 2.

[0137] The embodiment of the present disclosure may provide a computer terminal, which may be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the computer terminal may also be replaced by a terminal device such as a mobile terminal.

[0138] Optionally, in this embodiment, the computer terminal may be located in at least one network device among a plurality of network devices of a computer network.

[0139] In this embodiment, the above-mentioned computer terminal can execute the program code of the following steps in the malware detection method: receiving a target request sent by a cloud edge node through a cloud center node, wherein the target request includes at least a target processing strategy and a target value, and the target processing strategy is one of the following: detection strategy, defense strategy, the detection strategy and the defense strategy correspond to different software states, and the target value is used to identify the software file of the software; detecting whether the software is malware based on the target processing strategy and the target value to obtain a target detection result.

[0140] The above-mentioned computer terminal can also execute the program code of the following steps in the malware detection method: the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is the detection strategy, the software is detected as malware based on the target processing strategy and the target value to obtain a target detection result, including: matching in the malicious file library based on the target value to obtain a first matching result; if the first matching result is that there is a record with the same target value in the malicious file library, then the target detection result is determined based on the record detection result contained in the record; if the first matching result is that there is no record with the same target value in the malicious file library, then the software file uploaded by the cloud edge node is received, and the software file content is detected by multiple detection engines to obtain multiple detection results, and the target detection result is determined based on the multiple detection results.

[0141] The above-mentioned computer terminal can also execute the program code of the following steps in the malware detection method: the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is a defense strategy, the software is detected to be malicious software based on the target processing strategy and the target value to obtain a target detection result, including: matching in the malicious file library based on the target value to obtain a second matching result; if the second matching result is that there is a record with the same target value in the malicious file library, then the target detection result is determined based on the record detection result contained in the record; if the second matching result is that there is no record with the same target value in the malicious file library, then the cloud edge node is notified to release the pause of the software startup process, and the software file uploaded by the cloud edge node is received, and the software file content is asynchronously detected by multiple detection engines to obtain multiple detection results, and the target detection result is determined based on the multiple detection results.

[0142] The above-mentioned computer terminal can also execute the program code of the following steps in the malware detection method: when the target processing strategy is the detection strategy, after detecting whether the software is malware based on the target processing strategy and the target value, and obtaining the target detection result, if the target detection result is that the software is malware, an alarm information is generated based on the file information of the software, and the alarm information is sent to the console; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, the target value and the target detection result are stored in the malicious file library, and the target detection result is sent to the cloud edge node.

[0143] The above-mentioned computer terminal can also execute the program code of the following steps in the malware detection method: when the target processing strategy is a defense strategy, after detecting whether the software is malware based on the target processing strategy and the target value, and obtaining the target detection result, if the target detection result is that the software is malware, then end the startup process to prohibit the software from starting; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, then store the target value and target detection result in the malicious file library, and send the target detection result to the cloud edge node.

[0144] Optionally, Figure 7 is a block diagram of a computer terminal according to an embodiment of the present disclosure. As shown in Figure 7, the computer terminal 10 may include: one or more (only one is shown in Figure 7) processors 102 and a memory 104. The computer terminal 10 may also include a memory controller to control and manage the memory 104; the computer terminal 10 may also include a peripheral interface to connect to radio frequency components, audio components, and a display screen, etc.

[0145] Among them, the memory can be used to store software programs and components, such as the program instructions / components corresponding to the malware detection method and device in the embodiments of the present disclosure. The processor executes various functional applications and data processing by running the software programs and components stored in the memory, that is, realizing the above-mentioned malware detection method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely located relative to the processor, and these remote memories can be connected to the terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0146] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: receiving a target request sent by the cloud edge node through the cloud center node, wherein the target request includes at least a target processing strategy and a target value, and the target processing strategy is one of the following: detection strategy, defense strategy, the detection strategy and the defense strategy correspond to different software states, and the target value is used to identify the software file of the software; detecting whether the software is malware based on the target processing strategy and the target value to obtain a target detection result.

[0147] Optionally, the above-mentioned processor can also execute the program code of the following steps: the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is the detection strategy, the software is detected as malware based on the target processing strategy and the target value to obtain the target detection result, including: matching in the malicious file library based on the target value to obtain a first matching result; if the first matching result is that there is a record with the same target value in the malicious file library, then the target detection result is determined based on the record detection result contained in the record; if the first matching result is that there is no record with the same target value in the malicious file library, then the software file uploaded by the cloud edge node is received, and the software file content is detected by multiple detection engines to obtain multiple detection results, and the target detection result is determined based on the multiple detection results.

[0148] Optionally, the above-mentioned processor can also execute the program code of the following steps: the cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is a defense strategy, the software is detected to see if it is malware based on the target processing strategy and the target value, and the target detection result is obtained, including: matching in the malicious file library based on the target value to obtain a second matching result; if the second matching result is that there is a record with the same target value in the malicious file library, the target detection result is determined based on the record detection result contained in the record; if the second matching result is that there is no record with the same target value in the malicious file library, the cloud edge node is notified to release the pause of the software startup process, and the software file uploaded by the cloud edge node is received, the software file content is asynchronously detected by multiple detection engines to obtain multiple detection results, and the target detection result is determined based on the multiple detection results.

[0149] Optionally, the above-mentioned processor can also execute the program code of the following steps: when the target processing strategy is a detection strategy, after detecting whether the software is malware based on the target processing strategy and the target value, and obtaining the target detection result, if the target detection result is that the software is malware, an alarm message is generated based on the file information of the software, and the alarm message is sent to the console; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, the target value and target detection result are stored in the malicious file library, and the target detection result is sent down to the cloud edge node.

[0150] Optionally, the above-mentioned processor can also execute the program code of the following steps: when the target processing strategy is a defense strategy, after detecting whether the software is malware based on the target processing strategy and the target value, and obtaining the target detection result, if the target detection result is that the software is malware, then end the startup process to prohibit the software from starting; if the target detection result is that the software is malware or the target detection result is that the software is non-malware, then store the target value and target detection result in the malicious file library, and send the target detection result to the cloud edge node.

[0151] Those skilled in the art will appreciate that the structure shown in FIG7 is merely illustrative, and that the computer terminal may also be a smartphone (e.g., an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile internet device (MID), a PAD, or other terminal device. FIG7 does not limit the structure of the aforementioned electronic devices. For example, the computer terminal 10 may include more or fewer components (e.g., a network interface, a display device, etc.) than those shown in FIG7 , or may have a configuration different from that shown in FIG7 .

[0152] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0153] The embodiment of the present disclosure further provides a computer-readable storage medium. Optionally, in this embodiment, the storage medium can be used to store program codes executed by the malware detection method provided in the embodiment.

[0154] Optionally, in this embodiment, the storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.

[0155] The present disclosure also provides a computer program product, including a computer program, which implements any one of the above-mentioned malware detection methods when executed by a processor.

[0156] An embodiment of the present disclosure further provides a computer program product, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the computer program implements any one of the above-mentioned malware detection methods.

[0157] The embodiments of the present disclosure further provide a computer program product, which, when executed by a processor, implements any one of the above-mentioned malware detection methods.

[0158] The serial numbers of the above-mentioned embodiments of the present disclosure are for description only and do not represent the advantages or disadvantages of the embodiments.

[0159] In the above embodiments of the present disclosure, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0160] In the several embodiments provided in this disclosure, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the components is only a logical function division. In actual implementation, there may be other division methods, such as multiple components or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of components or components, which can be electrical or other forms.

[0161] The components described as separate parts may or may not be physically separate, and the components shown as components may or may not be physical components, that is, they may be located in one place or distributed across multiple network components. Some or all of these components may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0162] In addition, the functional components in the various embodiments of the present disclosure may be integrated into a single processing component, each component may exist physically separately, or two or more components may be integrated into a single component. The aforementioned integrated components may be implemented in the form of hardware or software functional components.

[0163] If the integrated components are implemented in the form of software functional components and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present disclosure is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present disclosure. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, ROM, RAM, mobile hard drives, magnetic disks or optical disks.

[0164] The above is only a preferred embodiment of the present disclosure. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present disclosure. These improvements and modifications should also be regarded as within the scope of protection of the present disclosure. Industrial Applicability

[0165] The solution provided by the embodiment of the present disclosure can be applied to the malware detection process of the terminal, and adopts a multi-layer collaborative method based on cloud edge (cloud center-cloud edge-terminal) to detect and defend malware, and receives the target request sent by the cloud edge node through the cloud center node, wherein the target request includes at least a target processing strategy and a target value, and the target processing strategy is one of the following: detection strategy, defense strategy, the software status corresponding to the detection strategy and the defense strategy is different, and the target value is used to identify the software file of the software; based on the target processing strategy and the target value, detect whether the software is malware, and obtain a target detection result. The first request sent by the terminal node is received by the cloud edge node, wherein the first request includes at least a target processing strategy and a target value; based on the target processing strategy and the target value, detect whether the software is malware, and obtain a first detection result; when the first detection result indicates that it is impossible to determine whether the software is malware, send a target request to the cloud center node to receive the target detection result returned by the cloud center node. That is, the purpose of reducing the request delay and enhancing the overall availability is achieved through the multi-layer collaboration of the cloud edge, thereby achieving the technical effect of reducing delay and improving the efficiency of malware detection.

Claims

1. A method for detecting malware, wherein: include: Receiving a target request sent by a cloud edge node through a cloud center node, wherein the target request includes at least a target processing strategy and a target value, the target processing strategy is one of the following: a detection strategy and a defense strategy, the detection strategy and the defense strategy correspond to different software states, and the target value is used to identify a software file of the software; Whether the software is malware is detected according to the target processing strategy and the target value, and a target detection result is obtained.

2. The method according to claim 1, wherein: The cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is the detection strategy, whether the software is malware is detected according to the target processing strategy and the target value, and a target detection result is obtained, including: Matching the malicious file library according to the target value to obtain a first matching result; If the first matching result is that there is a record with the same target value in the malicious file library, determining the target detection result according to the record detection result contained in the record; If the first matching result is that there is no record with the same target value in the malicious file library, the software file uploaded by the cloud edge node is received, and the software file content is detected by the multiple detection engines to obtain multiple detection results, and the target detection result is determined based on the multiple detection results.

3. The method according to claim 1, wherein: The cloud center node is deployed with a malicious file library and multiple detection engines. When the target processing strategy is the defense strategy, the software is detected as malware according to the target processing strategy and the target value, and a target detection result is obtained, including: Matching the malicious file library according to the target value to obtain a second matching result; If the second matching result is that there is a record with the same target value in the malicious file library, determining the target detection result according to the record detection result contained in the record; If the second matching result is that there is no record with the same target value in the malicious file library, the cloud edge node is notified to release the pause of the startup process of the software, and the software file uploaded by the cloud edge node is received, and the software file content is asynchronously detected by the multiple detection engines to obtain multiple detection results, and the target detection result is determined based on the multiple detection results.

4. The method according to claim 2, wherein: In the case where the target processing strategy is the detection strategy, after detecting whether the software is malware according to the target processing strategy and the target value and obtaining a target detection result, the method further includes: If the target detection result is that the software is malware, generating warning information according to the file information of the software, and sending the warning information to the console; If the target detection result is that the software is malware or the target detection result is that the software If the malicious file is non-malicious software, the target value and the target detection result are stored in the malicious file library, and the target detection result is sent to the cloud edge node.

5. The method according to claim 3, wherein: In the case where the target processing strategy is the defense strategy, after detecting whether the software is malware according to the target processing strategy and the target value and obtaining a target detection result, the method further includes: If the target detection result is that the software is malware, then terminating the startup process to prohibit the software from starting; If the target detection result is that the software is malware or the target detection result is that the software is non-malware, the target value and the target detection result are stored in the malicious file library, and the target detection result is sent down to the cloud edge node.

6. A method for detecting malware, wherein: include: Receiving, through a cloud edge node, a first request sent by a terminal node, wherein the first request includes at least a target processing strategy and a target value, the target processing strategy being one of the following: a detection strategy and a defense strategy, the detection strategy and the defense strategy corresponding to different software states, and the target value being used to identify a software file of the software; Detecting whether the software is malware according to the target processing strategy and the target value, and obtaining a first detection result; When the first detection result indicates that it is impossible to determine whether the software is malware, a target request is sent to the cloud center node to receive the target detection result returned by the cloud center node.

7. The method according to claim 6, wherein: The cloud edge node is deployed with a malicious file sub-database and a sub-detection engine. When the target processing strategy is the detection strategy, whether the software is malware is detected according to the target processing strategy and the target value, and a first detection result is obtained, including: Matching is performed in the malicious file sub-database according to the target value to obtain a third matching result; If the third matching result is that there is a record with the same target value in the malicious file sub-database, determining the first detection result according to the record detection result contained in the record; If the third matching result is that there is no record identical to the target value in the malicious file sub-database, the software file uploaded by the terminal node is received, and the software file content is detected by the sub-detection engine. If the sub-detection engine cannot determine whether the software file content contains malicious behavior, it will not be possible to determine whether the software is malware as the first detection result.

8. The method according to claim 6, wherein: The cloud edge node is deployed with a malicious file sub-database. When the target processing strategy is the defense strategy, whether the software is malware is detected according to the target processing strategy and the target value, and a first detection result is obtained, including: Matching is performed in the malicious file sub-database according to the target value to obtain a fourth matching result; If the fourth matching result is that there is a record with the same target value in the malicious file sub-database, determining the first detection result according to the record detection result contained in the record; If the fourth matching result is that there is no record identical to the target value in the malicious file sub-database, it will be impossible to determine whether the software is malware as the first detection result.

9. A malware detection device, wherein: include: A first receiving component is used to receive a target request sent by a cloud edge node through a cloud center node, wherein the target request includes at least a target processing strategy and a target value, the target processing strategy is one of the following: a detection strategy and a defense strategy, the detection strategy and the defense strategy correspond to different software states, and the target value is used to identify a software file of the software; The first determination component is used to detect whether the software is malware according to the target processing strategy and the target value, and obtain a target detection result.

10. A malware detection device, wherein: include: a second receiving component, configured to receive, through a cloud edge node, a first request sent by a terminal node, wherein the first request includes at least a target processing strategy and a target value, the target processing strategy being one of the following: a detection strategy and a defense strategy, the detection strategy and the defense strategy corresponding to different software states, and the target value being used to identify a software file of the software; A second determination component is used to detect whether the software is malware according to the target processing strategy and the target value, and obtain a first detection result; The first sending component is used to send a target request to the cloud center node to receive the target detection result returned by the cloud center node when the first detection result indicates that it is impossible to determine whether the software is malware.

11. A computer-readable storage medium, wherein: The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the storage medium is located is controlled to execute the malware detection method according to any one of claims 1 to 8.

12. An electronic device, wherein: include: A memory storing an executable program; A processor is used to run the program, wherein the program executes the malware detection method described in any one of claims 1 to 8 when running.

13. A computer program product, wherein: The invention comprises a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 8.

14. A computer program product, wherein: The invention comprises a non-volatile computer-readable storage medium storing a computer program, wherein the computer program implements the method according to any one of claims 1 to 8 when executed by a processor.

15. A computer program, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Malicious program judging method based on cloud security

    CN102346828A

  • Malicious application detection method and device, storage medium and processor

    CN114021115A

  • Malicious software detection method, device and equipment based on edge computing

    CN115982704A

  • Systems and methods for detecting and disabling malicious script code

    US20070113282A1

  • Network service for the detection, analysis and quarantine of malicious and unwanted files

    US20090044024A1