Malicious file detection system, method, and apparatus, electronic device, medium, and product
By applying identity services and a multi-engine file detection architecture, unified identity authentication and malicious file detection are achieved across cloud platforms, solving the security deficiencies of object storage systems in multi-cloud environments and realizing comprehensive detection and security management of malicious files.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-07-22
- Publication Date
- 2026-04-02
AI Technical Summary
Existing technologies cannot effectively detect malicious files in object storage systems of different cloud service providers in multi-cloud scenarios, resulting in insufficient security and reliability.
It adopts an application identity service and multi-engine file detection architecture. The application identity service provides unified identity authentication across cloud platforms, and the multi-engine file detection engine performs multi-dimensional detection on target files to identify malicious files.
It enables comprehensive and in-depth malicious file detection for object storage systems in multi-cloud environments, improving file security and integrity, building a robust protective barrier, and reducing channels for hacker attacks.
Smart Images

Figure CN2025109794_02042026_PF_FP_ABST
Abstract
Description
Malicious file detection system, method, device, electronic equipment, medium and product
[0001] The present disclosure claims priority to Chinese Patent Application No. 202411350162.8, filed on September 25, 2024 with the Chinese Patent Office, entitled "Malicious file detection system, method, device, electronic equipment, medium and product", the entire contents of which are incorporated herein by reference. TECHNICAL FIELD
[0002] The present disclosure relates to the technical field of cloud security, and particularly relates to a malicious file detection system, method, device, electronic equipment, medium and product. BACKGROUND
[0003] With the development of cloud technology, users will store files in a cloud environment. Under the cloud environment, there are various storage methods for files, such as storing on a host of a cloud service provider or storing in an object storage system of the cloud service provider. In order to ensure the safety of user data, it is necessary to detect malicious files in the cloud environment. A malicious file refers to a file that poses a threat to network security, including malicious binary files, malicious script files, and website backdoor files.
[0004] Due to considerations of reliability, flexibility and cost, more and more users will store files in object storage systems of different cloud service providers. At present, most cloud service providers generally detect malicious files on the host, but cannot detect malicious files in their object storage systems, and even less can detect malicious files in object storage systems of other cloud service providers. Therefore, in a multi-cloud scenario, how to detect malicious files in object storage systems of different cloud service providers has become a problem that needs to be solved. SUMMARY
[0005] The present disclosure provides a malicious file detection system, method, device, electronic equipment, medium and product, which can detect malicious files stored in object storage systems of different cloud service providers in a multi-cloud scenario. The technical solution is as follows:
[0006] In a first aspect, a malicious file detection system is provided, the system comprising a first subsystem and a second subsystem, and a communication connection is established between the first subsystem and the second subsystem.
[0007] The first subsystem provides an application identity service, which can access identity authentication systems of different cloud platforms and associate identity authentication accounts of the same user on different cloud platforms with application identity accounts. The first subsystem can access object storage systems corresponding to different cloud platforms based on the application identity service and obtain files stored in the object storage systems of the same user on different cloud platforms.
[0008] The second subsystem integrates at least one file detection engine capable of performing at least one type of malicious file detection on files. The second subsystem can perform at least one type of malicious file detection on the files obtained by the first subsystem by invoking the at least one file detection engine and determine whether the files are malicious files according to the detection results.
[0009] In a second aspect, a malicious file detection method is provided. The method is applied to the first subsystem of the first aspect and includes the following steps:
[0010] In response to a first detection request for a target file of a target user, file information of the target file is obtained based on a target application identity account of the target user. The target application identity account is associated with identity authentication accounts of the target user on multiple cloud platforms. The target file is a file stored in a target object storage system of a target cloud platform of the target user. The target cloud platform is all or part of the multiple cloud platforms.
[0011] The target file is obtained from the target object storage system based on the file information of the target file.
[0012] A second detection request is sent to the second subsystem. The second detection request is used to request the second subsystem to detect the target file to determine whether the target file is a malicious file.
[0013] In a third aspect, a malicious file detection method is provided. The method is applied to the second subsystem of the first aspect and includes the following steps:
[0014] A second detection request for a target file sent by a first subsystem is received. The second detection request is sent by the first subsystem in response to a first detection request for a target file related to a target application identity account. The first detection request is based on the target application identity account to obtain file information of the target file. The second detection request is based on the file information of the target file to obtain the target file from a target object storage system. The target file is a file stored in a target object storage system of a target cloud platform of the target application identity account. The target cloud platform is all or part of multiple cloud platforms. The multiple cloud platforms are platforms related to the target application identity account in terms of identity authentication accounts.
[0015] detecting the target file to obtain a detection result of the target file;
[0016] determining whether the target file is a malicious file based on the detection result of the target file.
[0017] In a fourth aspect, a malicious file detection apparatus is provided, which is arranged in the first subsystem of the first aspect, and includes:
[0018] a first obtaining module, configured to, in response to a first detection request for a target file related to a target application identity account, obtain file information of the target file based on the target application identity account, the target file being a file stored in a target object storage system of a target cloud platform by the target application identity account, the target cloud platform being all or part of a plurality of cloud platforms, the plurality of cloud platforms being platforms related to the target application identity account by an identity authentication account;
[0019] a second obtaining module, configured to obtain the target file from the target object storage system based on the file information of the target file;
[0020] a sending module, configured to send a second detection request to the second subsystem, the second detection request being used to request the second subsystem to detect the target file to determine whether the target file is a malicious file.
[0021] In a fifth aspect, a malicious file detection apparatus is provided, which is arranged in the second subsystem of the first aspect, and includes:
[0022] a receiving module, configured to receive a second detection request for a target file sent by the first subsystem, the second detection request being sent by the first subsystem in response to a first detection request for a target file related to a target application identity account, the first detection request being obtained based on the target application identity account, and the target file being obtained from a target object storage system based on file information of the target file, the target file being a file stored in a target object storage system of a target cloud platform by the target application identity account, the target cloud platform being all or part of a plurality of cloud platforms, the plurality of cloud platforms being platforms related to the target application identity account by an identity authentication account;
[0023] a detection module, configured to detect the target file to obtain a detection result of the target file;
[0024] a determination module, configured to determine whether the target file is a malicious file based on the detection result of the target file.
[0025] In a sixth aspect, an electronic device is provided, including a processor and a memory; the memory stores at least one program code; the at least one program code is used to be invoked and executed by the processor to implement the malicious file detection method in the first aspect or the malicious file detection method in the second aspect.
[0026] In a seventh aspect, a computer readable storage medium is provided, and the computer readable storage medium stores at least one computer program; the at least one computer program is executed by a processor to implement the malicious file detection method in the first aspect or the malicious file detection method in the second aspect.
[0027] In a seventh aspect, a computer program product is provided, and the computer program product includes a computer program; the computer program is executed by a processor to implement the malicious file detection method in the first aspect or the malicious file detection method in the second aspect.
[0028] The technical scheme provided by the embodiments of the present disclosure has the following beneficial effects:
[0029] The present disclosure provides a malicious file detection system, which includes a first subsystem and a second subsystem. The first subsystem provides an identity application service with an identity authentication system capability of accessing different cloud platforms. Based on the application identity service, the first subsystem can access the object storage systems corresponding to different cloud platforms and obtain the files stored in the object storage systems of different cloud platforms by the same user. The second subsystem integrates at least one file detection engine, and by invoking the at least one file detection engine, the second subsystem can perform at least one type of malicious file detection on the files. The system provided by the present disclosure combines the application identity service with the file detection capability in the object storage system, and realizes the detection of malicious files in the object storage systems of multiple cloud service providers. Specifically, the first subsystem associates the target application identity account of a user with the identity authentication account on the cloud platforms of multiple cloud service providers. After receiving a first detection request for a target file of the target application identity account, the first subsystem associates the target application identity account with the temporary security credential for identity authentication on each cloud platform, obtains the file information of the target file, obtains the target file from the target object storage system based on the file information of the target file, and sends a second detection request for the target file to the second subsystem. After receiving the second detection request, the second subsystem performs malicious file detection on the target file, obtains the detection result of the target file, and determines whether the target file is a malicious file based on the detection result of the target file. The present disclosure provides a cross-cloud platform file solution for users based on the application identity service, and realizes the unified management and detection of files of users on different cloud platforms in a multi-cloud scenario. BRIEF DESCRIPTION OF DRAWINGS
[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following will briefly introduce the drawings needed to be used in the embodiments. Obviously, the drawings in the following description only constitute some embodiments of the present disclosure, and for those skilled in the art, other drawings can also be obtained from these drawings without creative effort.
[0031] FIG. 1 is an architecture diagram of a malicious file detection system according to an embodiment of the present disclosure;
[0032] FIG. 2 is a flowchart of a malicious file detection method according to an embodiment of the present disclosure;
[0033] FIG. 3 is a flowchart of a malicious file detection method according to an embodiment of the present disclosure;
[0034] FIG. 4 is a flowchart of a malicious file detection method according to an embodiment of the present disclosure;
[0035] FIG. 5 is a structural schematic diagram of a malicious file detection apparatus according to an embodiment of the present disclosure;
[0036] FIG. 6 is a structural schematic diagram of a malicious file detection apparatus according to an embodiment of the present disclosure;
[0037] FIG. 7 shows a structural block diagram of an electronic device according to an example embodiment of the present disclosure. DETAILED DESCRIPTION
[0038] In order to make the objects, technical solutions and advantages of the present disclosure clearer, the following will further describe the embodiments of the present disclosure in detail with reference to the drawings.
[0039] It can be understood that the terms "each", "multiple", "any" and the like used in the embodiments of the present disclosure include two or more, each refers to each of the corresponding multiple, and any refers to any one of the corresponding multiple. For example, multiple words include 10 words, and each word refers to each of the 10 words, and any word refers to any one of the 10 words.
[0040] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present disclosure are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation portal for user to choose authorization or refusal.
[0041] Before performing the embodiments of the present disclosure, the terms involved in the embodiments of the present disclosure are first explained.
[0042] Object storage system is a storage architecture that provides high reliability, cross-platform and secure data sharing. It is an architecture for processing data storage. The data managed by the object storage system can be stored as a unit called "object", which has the advantages of flexibility, scalability and simplicity.
[0043] Multi-cloud refers to the use of two or more cloud services provided by two or more cloud service providers by an enterprise.
[0044] Application identity service (IDaas) is an identity service built on the cloud using cloud infrastructure. It solves the complex identity management problem between multiple application systems for users, provides one-stop services such as identity management, unified login, centralized permissions, application management, operation management, account lifecycle management, single sign-on (SSO) for application access, and control of the permissions possessed by the account.
[0045] S3 (Simple Storage Service) protocol is an object storage service protocol that provides a simple, efficient and reliable way for developers to store and manage large amounts of data objects, and has become a standard in the cloud storage field, widely adopted by many cloud service providers.
[0046] Multi-engine file detection architecture refers to an architecture that integrates multiple file detection engines, including cloud service provider's self-developed file detection engines and other commercial file detection engines. By integrating multiple file detection engines, the file detection capability is enhanced.
[0047] Malicious script usually refers to a piece of code used to perform harmful actions on a computer system, network or user.
[0048] Website backdoor refers to a piece of code or an entry left in a website's system by a hacker after hacking into the website to maintain long-term control over the website. Website backdoor allows hackers to access and control the website without authorization, perform various operations such as stealing data, uploading malicious files, modifying website content, etc.
[0049] Malicious binary refers specifically to a compiled executable file containing malicious code or behavior.
[0050] IAM (Identity and Access Management) has the functions of single sign-on, powerful authentication management, centralized authorization and audit based on policy, dynamic authorization, enterprise manageability, etc.
[0051] Nan Gu is to refer to the centralized management of resources, dynamic allocation, intelligent monitoring and efficient operation, so as to improve resource utilization, reduce operation and maintenance cost, etc. Network nan Gu refers to the process of centralized management and monitoring of network equipment through network management system. Nan Gu can help network administrators remotely log in to network equipment without going to the device location for operation, improving management efficiency.
[0052] Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, network, etc. in a wide area network or local area network to realize data calculation, storage, processing and sharing. Cloud technology is a general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on cloud computing business model application, which can form a resource pool, and can be used on demand, flexibly and conveniently. Cloud computing technology will become an important support. The background service of the technical network system needs a large amount of calculation and storage resources, such as video websites, picture websites and more portal websites. With the high development and application of the Internet industry, every item may have its own identification mark in the future, which needs to be transmitted to the background system for logical processing. Different levels of data will be processed separately, and various industry data need strong system support, which can only be realized through cloud computing.
[0053] The scheme provided by the present disclosure relates to cloud security in cloud technology. Cloud security refers to a general term for security software, hardware, users, institutions, and security cloud platforms based on cloud computing business model application. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and unknown virus behavior judgment, and through the abnormal monitoring of software behavior in the network by a large number of clients in a network, the latest information of Internet trojans and malicious programs is obtained and sent to the server for automatic analysis and processing, and the solutions for viruses and trojans are distributed to each client.
[0054] The main research directions of cloud security include the following aspects:
[0055] 1. Cloud computing security, mainly researches how to protect the security of cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, compliance audit, etc.
[0056] 2. Cloudification of security infrastructure, mainly researches how to build and integrate security infrastructure resources by using cloud computing, optimize security protection mechanism, including building a super large-scale security event, information collection and processing platform through cloud computing technology, realizing the collection and correlation analysis of massive information, and improving the network security event control ability and risk control ability;
[0057] 3. Cloud security service, mainly researches various security services provided by cloud computing platforms for users, such as antivirus services and the like.
[0058] The technical solution provided by the present disclosure mainly relates to the cloud security service direction in cloud security, and mainly aims at the detection problem of malicious files in the object storage system of different cloud service providers in a multi-cloud environment.
[0059] With the development of cloud technology, more and more users store files in the cloud environment. There are many ways to store files in the cloud environment, including storing in the host of the cloud service provider and storing in the object storage system of the cloud service provider. In order to improve the security of user data, it is necessary to detect malicious files in the cloud environment. At present, cloud service providers mainly focus on detecting malicious files written in the host, although these malicious files cover malicious binary files, malicious script files and website backdoors, but most service providers do not have the ability to detect malicious files in the object storage system in their own cloud environment, so they can only detect malicious files related to host write operations, and lack effective detection means for malicious files that do not involve host write operations (for example, hackers directly write files into the object storage system), which constitutes a blind spot in security protection and affects the security and reliability of the host running environment.
[0060] With the highlighting of storage advantages in a multi-cloud environment, more and more users adopt multi-cloud storage strategies to balance stability and cost efficiency. However, at present, various cloud service providers do not have the ability to detect malicious files in the object storage system of other cloud service providers across cloud platforms, resulting in that the security and reliability of files in the object storage system cannot be fully guaranteed under a multi-cloud architecture, thereby forming a relatively weak cross-cloud security protection in a multi-cloud scenario.
[0061] In order to be able to detect malicious files stored in object storage systems of different cloud service providers in a multi-cloud scenario, the embodiment of the present disclosure provides a malicious file detection method which combines application identity verification technology and a multi-engine file detection architecture, and aims to provide comprehensive file security detection for diversified storage solutions in a multi-cloud environment. Specifically, the application identity service is adopted to manage the file assets in the object storage system of the third-party cloud service provider through the target application identity account. Based on the multi-engine file detection architecture, the malicious binary files, malicious script files and website backdoors in the files in the object storage system of the third-party cloud service provider are detected in multiple dimensions, so as to ensure that the file media can be deeply and effectively screened in the object storage system of any cloud platform, so as to timely discover malicious files in different cloud environments, reduce hacker attack means and paths, and ensure the security and integrity of the files in the object storage system in the multi-cloud environment, thereby effectively building a strong defense line, effectively resisting potential attackers from using the object storage system as a channel to spread malicious files, and building a safety barrier for cloud assets.
[0062] FIG. 1 shows an architecture diagram of a malicious file detection system provided by the embodiment of the present disclosure, referring to FIG. 1, the malicious file detection system 100 includes a first subsystem 101 and a second subsystem 102, and a communication connection is established between the first subsystem 101 and the second subsystem 102.
[0063] The first subsystem 101 is also referred to as a multi-account hosting and identity authentication subsystem. The first subsystem 101 can provide an application identity service, which is a middleware or a service that integrates and bridges identity authentication systems of different cloud platforms, thereby accessing the identity authentication systems of the different cloud platforms. For example, as shown in FIG. 1, the application identity service integrates and bridges identity authentication systems of cloud platform one, cloud platform two, cloud platform three, and identity authentication systems of other cloud platforms. Through the integration and bridging of the identity authentication systems of the different cloud platforms, the application identity service can access the identity authentication systems of the different cloud platforms. Based on the application identity service, a user can register an application identity account. After registering the target application identity account in the application identity service, the user can input, in the application identity service, identity authentication accounts of the user registered on different cloud platforms, thereby associating the identity authentication accounts of the same user on the different cloud platforms with the application identity account, so that the user can safely access resources of multiple cloud service providers without separately managing access keys for each cloud service provider, thereby realizing unified identity authentication and authorization management across cloud platforms. After the user completes identity authentication through the application identity service, the first subsystem 101 can access object storage systems corresponding to the different cloud platforms by using the permission bridge established with the identity authentication systems of the cloud service providers, thereby obtaining file information of files stored in the object storage systems of the different cloud platforms, such as file directory structures, file lists, and source data information, thereby helping the user to establish a cross-cloud-platform file asset map for subsequent management and analysis. Further, based on the obtained file information of the files stored in the object storage systems of the different cloud platforms, the first subsystem 101 can obtain the corresponding files.
[0064] The second subsystem 102 can be a multi-engine file detection subsystem, and the second subsystem 102 integrates at least one file detection engine, including a file detection engine developed by a cloud service provider and other commercial file detection engines, such as file detection engine one, file detection engine two, file detection engine three, file detection engine four, and other file detection engines.
[0065] The embodiments of the present disclosure provide a malicious file detection method. Taking the first subsystem and the second subsystem as an example, referring to FIG. 2, the method provided by the embodiments of the present disclosure includes the following steps.
[0066] 201, in response to a first detection request for a target file related to a target application identity account, the first subsystem obtains file information of the target file based on the target application identity account.
[0067] The target application identity account is a unified management account registered by a target user based on an application identity service, and the target identity application account is associated with an identity authentication account of the target user on multiple cloud platforms. The identity authentication account can be a login account registered by the target user on the cloud platform. Each cloud platform corresponds to a cloud service provider, which is a platform for providing user use and management of resources on the cloud. Each cloud platform corresponds to an object storage system, which is used to store files of each user on the cloud platform. Each object storage system provides an API (Application Programming Interface, application programming interface) interface, and the files in the object storage system can be quickly obtained by calling the API interface. Each object storage system can use the S3 protocol to ensure smooth connection of storage systems of major cloud vendors. The target cloud platform can be all or part of the multiple cloud platforms applied for by the target user, and can be one or more. The object storage system corresponding to the target cloud platform is referred to as the target object storage system. The target file is a file stored by the target application identity account in the target object storage system of the target cloud platform, and the target file can be one or more. The first detection request is used to trigger the first subsystem to perform malicious file detection on the target file stored by the target user in the target object storage system of the target cloud platform. The first detection request can include the target application identity account of the target user, and the identifier of the target cloud platform. In response to the first detection request for the target file related to the target application identity account, the first subsystem can obtain file information of the target file based on the target application identity account of the target user, and the file information includes file directory structure, file list, and metadata information.
[0068] Specifically, the first subsystem obtains the file information of the target file based on the target application identity account, which can use the following method:
[0069] 2011. The first subsystem obtains the identity authentication account of the target cloud platform associated with the target application identity account from the identity authentication accounts of the respective cloud platforms associated with the target application identity account.
[0070] In the embodiments of the present disclosure, the target application identity account of the target user is associated with the identity authentication accounts of the target user on the multiple cloud platforms, and the first subsystem can obtain the identity authentication account of the target cloud platform associated with the target application identity account based on the identity authentication accounts of the respective cloud platforms associated with the target application identity account and the identifier of the target cloud platform.
[0071] 2012. The first subsystem sends a query request to the target cloud platform based on the identity authentication account of the target cloud platform.
[0072] When the identity authentication account of the target user on the target cloud platform is acquired, the first subsystem can send a query request to the target cloud platform based on the pre-established application identity service and the permission bridge of the target cloud platform, and the query request includes the identity authentication account of the target user on the target cloud platform. When the query request is received, the target cloud platform acquires the file information of the file stored by the target user in the target object storage system from the target object storage system based on the identity authentication account of the target user, and then returns the file information of the file stored by the target user in the target object storage system to the first subsystem.
[0073] 2013, the first subsystem receives the file information of the target file sent by the target cloud platform.
[0074] It should be noted that, since the number of target cloud platforms can be one or multiple, when the number of target cloud platforms is one, the first subsystem can send a query request to the one cloud platform, and correspondingly, the file information of the target file received by the first subsystem is the file information of the file stored by the target user in the object storage system corresponding to the one cloud platform returned by the one cloud platform; when the number of target cloud platforms is multiple, the first subsystem can send a query request to each of the multiple cloud platforms, and correspondingly, the file information of the target file received by the application service is the file information of the file stored by the target user in the object storage system corresponding to each of the multiple cloud platforms returned by each of the multiple cloud platforms.
[0075] 202, the first subsystem acquires the target file from the target object storage system based on the file information of the target file.
[0076] In the application embodiment, when the file information of the target file is acquired, the first subsystem can acquire the target file from the target object storage system based on the file information of the target file.
[0077] Further, in order to facilitate the management of the target file, the first subsystem can add the target file to a file bucket, and the file bucket is used to store the file stored by the target application identity account in the target object storage system. Optionally, if the number of target object storage systems is multiple and the target files come from different object storage systems, the target files coming from the same object storage system can be added to the same file bucket according to the source of the target files, for example, the target object storage systems include an object storage system 1 and an object storage system 2, the object storage system 1 corresponds to a file bucket 1 and a file bucket 2, and the object storage system 2 corresponds to a file bucket 3; the files of the target user acquired from the object storage system 1 can be added to the file bucket 1 or the file bucket 2, and the files of the target user acquired from the object storage system 2 can be added to the file bucket 3.
[0078] 203、the first subsystem sends a second detection request to the second subsystem.
[0079] In the embodiments of the present disclosure, the first subsystem does not have the capability of malicious file detection, while the second subsystem has the capability. Therefore, after obtaining the target file, the first subsystem can send a second detection request to the second subsystem to request the second subsystem to perform malicious file detection on the target file, so as to determine whether the target file is a malicious file. The second detection request can include the file identifier and storage location of the target file.
[0080] 204、the second subsystem receives the second detection request for the target file sent by the first subsystem, detects the target file, and obtains a detection result of the target file.
[0081] The second subsystem of the present disclosure adopts a multi-engine file detection architecture, which integrates multiple file detection engines, including but not limited to self-developed file detection engines and commercial security scanning engines (such as ClamAV, Sophos, etc.). Each file detection engine is configured with detection rules and signature libraries, which are used to indicate the fields, signatures, etc. of malicious files. Based on the pre-configured detection rules and signature libraries, it can be identified whether the file contains malicious content. The detection rules and signature libraries are for at least one type of malicious file. By calling the file detection engine, at least one type of malicious file detection can be performed on the file, so as to identify different types of threats, such as WebShell scripts, malware, viruses, illegal content, etc. The types of malicious files that can be detected by each file detection engine can be the same or different. For example, the multi-engine file detection architecture includes file detection engine one, file detection engine two and file detection engine three. The file detection engine one can detect malicious binary files and malicious script files, the file detection engine two can detect malicious binary files, and the file detection engine three can detect website backdoors.
[0082] When receiving the second detection request for the target file sent by the first subsystem, the second subsystem can call at least one file detection engine to perform malicious file detection on the target file and obtain a detection result of the target file. With the help of each file detection engine in the multi-engine file detection architecture, the target file is detected in multiple dimensions, and whether the target file is a malicious file can be determined comprehensively and accurately.
[0083] Specifically, the second subsystem calls at least one file detection engine to perform malicious file detection on the target file and obtains a detection result of the target file, which can adopt the following method:
[0084] 2041、call any file detection engine to detect the target file in the file bucket.
[0085] In a possible implementation, if the number of target files is multiple and the target files are from one object storage system, in other words, the target files are stored in one file bucket, the files in the file bucket can be detected in series. The so-called series detection refers to calling the file detection engine to detect the files in the file bucket one by one, when one file detection is completed, another file is detected, and until the detection of all the files in the file bucket is completed. By detecting the files in the file bucket in series, each file in the file bucket can be detected, and the comprehensiveness of detection is improved.
[0086] In another possible implementation, if the number of target files is multiple and the target files are from different object storage systems, in other words, the target files are stored in different file buckets, the files in different file buckets can be detected in parallel, and the files in the same file bucket can be detected in series. The so-called parallel detection refers to calling the same file detection engine to detect the files in multiple file buckets at the same time. By detecting the files in multiple file buckets in parallel, the file detection efficiency is improved.
[0087] When calling any file detection engine to detect any file, whether the file includes malicious content in the detection rule and the signature library corresponding to the file detection engine can be detected based on the detection rule and the signature library, if yes, it is determined that the detection result of the file detection engine is that the file is a malicious file, if not, it is determined that the detection result of the file detection engine is that the file is not a malicious file. Further, when each file detection engine is used to determine whether each file is a malicious file, the corresponding malicious file type of each file can be given, thereby facilitating subsequent statistics and analysis.
[0088] 2042、When the target files are detected by at least one file detection engine, the detection result of each file detection engine on the target file is obtained.
[0089] When any file detection engine is called to detect the target file, another file detection engine is called to detect the target file, until the target file is detected by at least one file detection engine, and the detection result of each file detection engine on the target file is obtained. During the detection process, at least one file detection engine can be called to detect the target file in the file bucket at the same time, so as to improve the detection efficiency of the target file.
[0090] After the target file is obtained, the engine file detection architecture is used to initiate parallel or serial deep scanning on the target file, each engine judges whether the target file contains malicious content according to its detection rule and signature library. This process is highly automated, which can improve the detection efficiency and accuracy, and reduce false positives and false negatives.
[0091] 205、the second subsystem determines whether the target file is a malicious file based on the detection result of the target file.
[0092] The embodiments of the present disclosure adopt at least one file detection engine to perform malicious file detection on a target file. The target file is detected by at least one file detection engine, and at least one detection result under at least one file detection engine can be obtained. Since the detection rules and signature libraries of different file detection engines can be different, the detection results of the target file by different file detection engines can be the same or different. To improve the accuracy of the file detection result, whether the target file is a malicious file can be determined based on the detection result of the target file by each file detection engine.
[0093] Specifically, a preset analysis strategy can be used to analyze the detection result of the target file by each file detection engine to obtain an analysis result, and then whether the target file is a malicious file can be determined based on the analysis result. The preset analysis strategy can be a voting strategy or a risk score. For example, the multi-engine file detection architecture includes file detection engine one, file detection engine two, file detection engine three, and file detection engine four. The detection results of file detection engine one, file detection engine two, and file detection engine three are that the target file is a malicious file, and the detection result of file detection engine three is that the target file is a safe file. Assuming that the preset analysis strategy is a voting strategy, and assuming that the probability value of a file being a malicious file is greater than 0.6, the file can be determined to be a malicious file. Since the detection results of file detection engine one, file detection engine two, and file detection engine three are that the target file is a malicious file, and the detection result of file detection engine three is that the file is a safe file, the probability value of the file being a malicious file is 0.75, which is greater than 0.6. Therefore, the target file can be determined to be a malicious file. Assuming that the preset analysis strategy is a risk score, and assuming that the risk score of a file is greater than 60 points, the file can be determined to be a malicious file. When the risk score of the target file is calculated based on the detection results of file detection engine one, file detection engine two, file detection engine three, and file detection engine four, the risk score is 80 points, which is greater than 60 points. Therefore, the target file can be determined to be a malicious file.
[0094] The embodiments of the present disclosure can accurately determine whether the target file is a malicious file by adopting a preset analysis strategy to analyze the detection result of the target file, thereby improving the accuracy of the detection result.
[0095] Further, when it is determined that the target file is a malicious file, the target file can be marked to facilitate subsequent processing of the target file.
[0096] Considering that the malicious files have different degrees of threat to the network and user data security, different risk levels can be set for the malicious files according to the degrees of threat, such as high, medium, low, and the like, and different security response modes can be set for different risk levels, such as isolation, deletion, alarm notification of administrator, or triggering of automatic repair process, and the like. Based on the set risk levels and security response modes, when it is determined that the target file is a malicious file, the risk level of the target file can be determined according to the analysis result, and then the security response mode corresponding to the risk level of the target file is used to process the target file. When determining the risk level of the target file, different probability value ranges or risk score ranges can be set for different risk levels, and then the risk level of the target file is determined according to the probability value or risk score of the target file determined by the scoring result.
[0097] For the analysis result determined based on the voting strategy, the probability value range corresponding to the high risk level can be set to be greater than or equal to a first probability value, the probability value range corresponding to the medium risk level can be set to be greater than or equal to a second probability value and less than the first probability value, and the probability value range corresponding to the low risk level can be set to be greater than or equal to a third probability value and less than the second probability value. The first probability value is greater than the second probability value, and the second probability value is greater than the third probability value, for example, the first probability value can be 0.9, the second probability value can be 0.8, and the third probability value can be 0.7. If the analysis result of the target file is that the probability value of the target file being a malicious file is 0.75, it can be determined that the risk level of the target file is low; if the analysis result of the target file is that the probability value of the target file being a malicious file is 0.85, it can be determined that the risk level of the target file is medium, and if the analysis result of the target file is that the probability value of the target file being a malicious file is 0.95, it can be determined that the risk level of the target file is high.
[0098] For the analysis result determined based on the risk score, the risk score range corresponding to the high risk level can be set to be greater than or equal to a first risk score, the risk score range corresponding to the medium risk level can be set to be greater than or equal to a second risk score and less than the first risk score, and the risk score range corresponding to the low risk level can be set to be greater than or equal to a third risk score and less than the second risk score. The first risk score is greater than the second risk score, and the second risk score is greater than the third risk score, for example, the first risk score can be 90 points, the second risk score can be 80 points, and the third risk score can be 70 points. If the analysis result of the target file is that the risk score of the target file is 75 points, it can be determined that the risk level of the target file is low; if the analysis result of the target file is that the risk score of the target file is 85 points, it can be determined that the risk level of the target file is medium; and if the analysis result of the target file is that the risk score of the target file is 95 points, it can be determined that the risk level of the target file is high.
[0099] The embodiment of the disclosure sets different risk levels according to the threat degree of the malicious file, and sets different processing modes for different risk levels, so that different processing modes can be taken for processing when it is determined that the file is a malicious file, thereby ensuring the safety of user data while providing more processing options.
[0100] Further, after determining the malicious file from the files stored by the target user in the target object storage system, and determining the risk level of the malicious file and the corresponding security response mode, the embodiment of the disclosure will also generate detailed analysis logs to record the detection process of the malicious file, the problems found and the response mode taken for subsequent review and analysis.
[0101] To sum up, the embodiment of the disclosure adopts application identity service to realize cross-cloud identity authentication and permission management. By integrating at least one file detection engine, efficient and comprehensive security scanning of files is realized, and then instant security response is implemented based on the detection result, thereby providing a strong protection barrier for file assets in the cloud environment.
[0102] In summary, the present disclosure adopts an innovative malicious file detection mechanism, which does not rely on the traditional host file landing process, but integrates an account authentication system and an object storage service system, uses efficient file list grabbing technology to realize file asset management. At the same time, with the help of powerful file API interface, any file in the storage system can be directly executed for deep detection operation, greatly improving the detection efficiency and flexibility.
[0103] In order to realize the wide compatibility of cross-cloud platforms, the present disclosure seamlessly interfaces with the application identity service, which enables users to cross different cloud service provider boundaries and uniformly obtain and manage various identity account authentications. Further, by following the industry standard S3 protocol, smooth interfacing with storage systems of major cloud vendors is ensured. On this basis, using safe and efficient API authentication technology, file asset details from different cloud environments can be comprehensively obtained and reviewed, providing a centralized, cross-platform file management and security detection solution for users, and truly realizing the boundless interconnection and deep insight of data management.
[0104] All the optional technical solutions described above can be combined in any way to form optional embodiments of the present disclosure, which will not be described here.
[0105] The embodiment of the disclosure provides a malicious file detection method, taking the first subsystem and the second subsystem as an example, referring to FIG. 3, the method provided by the embodiment of the disclosure includes:
[0106] 301、The first subsystem obtains a target application identity account registered in an application identity service.
[0107] In a multi-cloud scenario, a target user can apply for resources on multiple cloud platforms to store files in multiple object storage systems corresponding to the multiple cloud platforms. In a traditional scheme, the target user needs to register an identity authentication account on each cloud platform, and when accessing any cloud platform, the target user logs in to the cloud platform using the identity authentication account on the cloud platform. This method requires managing an identity authentication account for each cloud platform, and the operation process is complex. To reduce the complexity of managing identity authentication accounts on multiple cloud platforms and the operation complexity of the target user, the present embodiment provides an application identity service. Based on the identity application service, the target user can register a target application identity account, and the target application identity account can host identity authentication information such as identity authentication accounts of different cloud service providers. By entering the identity authentication accounts of the target user applied for on each cloud service provider, the target application identity account can implement identity authentication of different cloud service providers. That is, only one authentication of the target application identity account is required to implement identity authentication of different cloud service providers.
[0108] 302、After the target application identity account is registered, the first subsystem obtains the identity authentication accounts on the multiple cloud platforms entered in the identity application service, and binds the target application identity account and the entered identity authentication accounts on the multiple cloud platforms.
[0109] After the target application identity account is registered, the target user can enter the identity authentication accounts of the target user on the multiple cloud platforms in the identity application service, and the application identity service obtains the identity authentication accounts of the target user on the multiple cloud platforms entered by the target user, and binds the target application identity account and the entered identity authentication accounts on the multiple cloud platforms.
[0110] 303、In response to a first detection request for a target file related to the target application identity account, the first subsystem obtains file information of the target file based on the target application identity account.
[0111] The implementation of this step is the same as the implementation mode of step 201 described above. For details, refer to step 201 described above, which will not be repeated here.
[0112] 304、The first subsystem obtains the target file from the target object storage system based on the file information of the target file.
[0113] The implementation of this step is the same as the implementation mode of step 202 described above. For details, refer to step 202 described above, which will not be repeated here.
[0114] 305、The first subsystem sends a second detection request to the second subsystem.
[0115] This step is implemented in the same way as the implementation of step 203 described above. For details, please refer to step 203 described above, which will not be repeated here.
[0116] 306、The second subsystem receives the second detection request for the target file sent by the first subsystem, detects the target file, and obtains a detection result of the target file.
[0117] This step is implemented in the same way as the implementation of step 204 described above. For details, please refer to step 204 described above, which will not be repeated here.
[0118] 307、The second subsystem determines whether the target file is a malicious file based on the detection result of the target file.
[0119] This step is implemented in the same way as the implementation of step 205 described above. For details, please refer to step 205 described above, which will not be repeated here.
[0120] The present embodiment provides a malicious file detection method. Taking the first subsystem and the second subsystem as an example, referring to FIG. 4, the method provided by the present embodiment includes:
[0121] 401、The first subsystem obtains a target application identity account registered in an application identity service.
[0122] This step is implemented in the same way as the implementation of step 301 described above. For details, please refer to step 301 described above, which will not be repeated here.
[0123] 402、After the registration of the target application identity account is completed, the first subsystem obtains identity authentication accounts on multiple cloud platforms input in the identity application service, and binds the target application identity account and the input identity authentication accounts on the multiple cloud platforms.
[0124] This step is implemented in the same way as the implementation of step 302 described above. For details, please refer to step 302 described above, which will not be repeated here.
[0125] 403、When it is detected that the target application identity account logs in the application identity service, the first subsystem verifies the target application identity account.
[0126] In the embodiments of the present disclosure, when the target user completes the registration of the target application identity account, the application identity service of the first subsystem can store the target application identity account of the target user. In actual application, when it is detected that the target user logs in the application identity service through the target application identity account, the first subsystem can verify the target application identity account used by the target user this time based on the stored target application identity account of the target user. If the stored target application identity account of the target user is the same as the target application identity account used by the target user this time, it is determined that the target application identity account used by the target user this time passes the verification, and then step 404 is performed. Otherwise, if the stored target application identity account of the target user is not the same as the target application identity account used by the target user this time, it is determined that the target application identity account used by the target user this time does not pass the verification, and then the current login is rejected.
[0127] 404. When the target application identity account passes the verification, in response to triggering of a specified event, the first subsystem generates a first detection request for a target file related to the target application identity account.
[0128] The specified event is an event triggering the generation of the first detection request for the target file related to the target application identity account. The specified event can be a preset detection time. In the embodiments of the present disclosure, when the target user inputs the identity authentication account on each cloud platform on the application identity service, the target user can set the detection time for performing malicious file detection on the files stored in the object storage system of each cloud platform. When the detection time corresponding to a certain cloud platform is reached, the first subsystem can generate the first detection request for the target file related to the target application identity account. The specified event can also be a triggering operation of a file detection control. In the embodiments of the present disclosure, when the target user logs in the application identity service, the application identity service of the first subsystem can provide a file detection control for detecting the target file stored in the target object storage system of the target cloud platform by the target user. When it is detected that the target user triggers the file detection control, the first detection request for the target file related to the target application identity account can be generated.
[0129] 405. In response to the first detection request for the target file related to the target application identity account, the first subsystem acquires file information of the target file based on the target application identity account.
[0130] The implementation of this step is the same as the implementation mode of step 201 described above. For details, refer to step 201 described above, which will not be repeated here.
[0131] 406. The first subsystem acquires the target file from the target object storage system based on the file information of the target file.
[0132] This step is implemented in the same way as the implementation of step 202 described above. For details, please refer to step 202 described above, which will not be repeated here.
[0133] 407. The first subsystem sends a second detection request to the second subsystem.
[0134] This step is implemented in the same way as the implementation of step 203 described above. For details, please refer to step 203 described above, which will not be repeated here.
[0135] 408. The second subsystem receives the second detection request for the target file sent by the first subsystem, detects the target file, and obtains the detection result of the target file.
[0136] This step is implemented in the same way as the implementation of step 204 described above. For details, please refer to step 204 described above, which will not be repeated here.
[0137] 409. The second subsystem determines whether the target file is a malicious file based on the detection result of the target file.
[0138] This step is implemented in the same way as the implementation of step 205 described above. For details, please refer to step 205 described above, which will not be repeated here.
[0139] The present disclosure innovatively integrates application identity services and file security detection services in a multi-cloud environment, achieving security supervision breadth and depth. It abandons the limitations of traditional single cloud environment, dynamically obtains and utilizes temporary security credentials across third-party cloud platforms through intelligent interface with identity authentication service system, effectively unlocking the key to access file storage systems of various cloud service providers, and paving the way for comprehensive perspective of distributed file asset details in a multi-cloud environment.
[0140] On this basis, an advanced multi-engine file detection architecture is integrated, which has strong compatibility and expandability and can flexibly carry multiple file detection engines. This integration not only greatly broadens the coverage of threat detection, but also ensures the accuracy and efficiency of detection through multi-dimensional and deep file scanning and analysis.
[0141] In summary, the present disclosure successfully builds a secure monitoring system that spans multiple cloud platforms and efficiently cooperates through the innovative application of identity authentication and credential management of application identity services and the deep integration of various security technologies. It not only significantly reduces the blind area of security monitoring in a multi-cloud environment, but also provides a more solid and reliable cloud security protection network by strengthening real-time monitoring and response capabilities, effectively improving the security and resilience of the overall cloud environment.
[0142] Please refer to FIG. 5, which shows a structural schematic diagram of a malicious file detection apparatus provided by an embodiment of the present disclosure. The apparatus is arranged in the first subsystem shown in FIG. 1. The apparatus can be realized by software, hardware or a combination of both, and become all or part of an electronic device. The apparatus includes:
[0143] The first obtaining module 501 is configured to, in response to a first detection request for a target file related to a target application identity account, obtain file information of the target file based on the target application identity account. The target file is a file stored by the target application identity account in a target object storage system of a target cloud platform. The target cloud platform is all or part of a plurality of cloud platforms. The plurality of cloud platforms are platforms related to the target application identity account by an identity authentication account.
[0144] The second obtaining module 502 is configured to obtain the target file from the target object storage system based on the file information of the target file.
[0145] The sending module 503 is configured to send a second detection request to a second subsystem. The second detection request is used to request the second subsystem to detect the target file to determine whether the target file is a malicious file.
[0146] In another embodiment of the present disclosure, the apparatus further includes:
[0147] The verifying module is configured to verify the target application identity account when detecting that the target application identity account logs in the application identity service.
[0148] The generating module is configured to generate the first detection request in response to triggering of a specified event when the target application identity account passes the verification.
[0149] In another embodiment of the present disclosure, the first obtaining module 501 is configured to obtain an identity authentication account of a target cloud platform associated with the target application identity account from identity authentication accounts of each cloud platform associated with the target application identity account. The first obtaining module 501 is further configured to send a query request to the target cloud platform based on the identity authentication account of the target cloud platform. The query request is used to request the target cloud platform to query the file information of the target file. The first obtaining module 501 is further configured to receive the file information of the target file sent by the target cloud platform.
[0150] In another embodiment of the present disclosure, the apparatus further includes:
[0151] The third obtaining module is configured to obtain the target application identity account registered in the application identity service.
[0152] The binding module is configured to, after the target application identity account registration is completed, acquire identity authentication accounts on a plurality of cloud platforms input in the identity application service, and bind the target application identity account and the input identity authentication accounts on the plurality of cloud platforms.
[0153] In another embodiment of the present disclosure, the device further comprises:
[0154] The joining module is configured to add the target file into a file bucket, where the file bucket is configured to store files stored in the target object storage system by the target application identity account.
[0155] Those skilled in the art can clearly understand the specific working process of the system, device and unit described above for the convenience and brevity of description, which can refer to the corresponding process in the foregoing method embodiments, and will not be described here.
[0156] Please refer to FIG. 6, which shows a structural schematic diagram of a malicious file detection device according to an embodiment of the present disclosure. The device is arranged in the second subsystem shown in FIG. 1, and can be realized by software, hardware or a combination of both, becoming all or part of an electronic device. The device comprises:
[0157] The receiving module 601 is configured to receive a second detection request for a target file sent by the first subsystem. The second detection request is sent by the first subsystem after acquiring the file information of the target file based on the target application identity account and acquiring the target file from the target object storage system based on the file information of the target file, in response to a first detection request for a target file related to the target application identity account. The target file is a file stored in the target object storage system of the target cloud platform by the target application identity account. The target cloud platform is all or part of a plurality of cloud platforms. The plurality of cloud platforms are platforms related to the target application identity account in terms of identity authentication accounts.
[0158] The detection module 602 is configured to detect the target file to obtain a detection result of the target file.
[0159] The determination module 603 is configured to determine whether the target file is a malicious file based on the detection result of the target file.
[0160] In another embodiment of the present disclosure, the detection module 602 is configured to call at least one file detection engine to perform malicious file detection on the target file to obtain a detection result of the target file by the at least one file detection engine. Each file detection engine is configured to perform at least one type of malicious file detection on a file.
[0161] In another embodiment of the present disclosure, the target file is stored in a file bucket used for storing files stored by the target application identity account in the target object storage system, the detection module 602 is configured to invoke any file detection engine to detect the target file in the file bucket, and when the target file is detected by at least one file detection engine, the detection result of the target file by each file detection engine is obtained.
[0162] In another embodiment of the present disclosure, the determination module 603 is configured to analyze the detection result of the target file by using a preset analysis strategy to obtain an analysis result, and determine whether the target file is a malicious file based on the analysis result.
[0163] In another embodiment of the present disclosure, the apparatus further comprises:
[0164] The determination module is configured to determine a risk level of the target file according to the analysis result when it is determined that the target file is a malicious file.
[0165] The processing module is configured to process the target file by using a preset security response mode according to the risk level of the target file.
[0166] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, apparatus and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described herein.
[0167] FIG. 7 shows a structural block diagram of an electronic device 700 according to an example embodiment of the present disclosure. Generally, the electronic device 700 comprises a processor 701 and a memory 702.
[0168] The processor 701 can be implemented in at least one of a hardware form of a DSP (Digital Signal Processing), an FPGA (Field-Programmable Gate Array), a PLA (Programmable Logic Array). The processor 701 can also include a main processor and a coprocessor, the main processor being a processor for processing data in an awake state, and the coprocessor being a low-power processor for processing data in a standby state. In some embodiments, the processor 701 can be integrated with a GPU (Graphics Processing Unit) for rendering and drawing content required to be displayed by the display screen. In some embodiments, the processor 701 can further include an artificial intelligence processor for processing computing operations related to machine learning.
[0169] The memory 702 can include one or more computer-readable storage media that can be non-transitory computer-readable storage media, for example, a CD-ROM (Compact Disc Read-Only Memory), a ROM (Read-Only Memory), a RAM (Random Access Memory), a magnetic tape, a floppy disk, and an optical data storage device, etc. The computer-readable storage medium stores at least one computer program, which, when executed, can implement the above-mentioned malicious file detection method.
[0170] Of course, the above-mentioned electronic device can also include other components, such as an input / output interface, a communication component, etc. The input / output interface provides an interface between the processor and peripheral interface modules, which can be output devices, input devices, etc. The communication component is configured to facilitate wired or wireless communication between the electronic device and other devices.
[0171] Those skilled in the art can understand that the structure shown in FIG. 7 does not constitute a limitation on the electronic device 700, and can include more or fewer components than those shown, or combine certain components, or use different component arrangements.
[0172] The embodiments of the present disclosure provide a computer-readable storage medium, which stores at least one computer program, and the at least one computer program, when executed by a processor, can implement the above-mentioned malicious file detection method.
[0173] The embodiment of the present disclosure provides a computer program product, the computer program product comprises a computer program, the computer program can realize the malicious file detection method when the processor executes.
[0174] The above embodiments are only used to illustrate the technical solutions of the present disclosure, rather than limit them; although the foregoing embodiments of the present disclosure are described in detail, those skilled in the art should understand that the technical solutions recorded in the foregoing embodiments can be modified, or some technical features can be replaced by equivalents; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure.
Claims
1. A malicious file detection system, wherein, The system comprises a first subsystem and a second subsystem, and a communication connection is established between the first subsystem and the second subsystem; The first subsystem provides an application identity service, the application identity service can access identity authentication systems of different cloud platforms, and can associate identity authentication accounts of the same user in different cloud platforms with application identity accounts, the first subsystem can access object storage systems corresponding to different cloud platforms based on the application identity service, and can obtain files stored in the object storage systems of the same user in different cloud platforms; The second subsystem integrates at least one file detection engine, the file detection engine can perform at least one type of malicious file detection on files, the second subsystem can perform at least one type of malicious file detection on the files obtained by the first subsystem by calling the at least one file detection engine, and can determine whether the files are malicious files according to the detection results.
2. A malicious file detection method, wherein, The method is applied to the first subsystem of claim 1, and the method comprises: In response to a first detection request for a target file related to a target application identity account, file information of the target file is obtained based on the target application identity account, the target file is a file stored in a target object storage system of a target cloud platform by the target application identity account, the target cloud platform is all or part of a plurality of cloud platforms, and the plurality of cloud platforms are platforms related to the target application identity account through identity authentication accounts; The target file is obtained from the target object storage system based on the file information of the target file; A second detection request is sent to a second subsystem, and the second detection request is used to request the second subsystem to detect the target file to determine whether the target file is a malicious file.
3. The method of claim 2, wherein, The method further comprises: When the target application identity account logs in the application identity service, the target application identity account is verified; When the target application identity account passes the verification, the first detection request is generated in response to triggering of a specified event.
4. The method of claim 2 or 3, wherein, The file information of the target file is obtained based on the target application identity account, comprising: From the identity authentication accounts of each cloud platform associated with the target application identity account, an identity authentication account of a target cloud platform associated with the target application identity account is obtained; Based on the identity authentication account of the target cloud platform, a query request is sent to the target cloud platform, the query request is used to request the target cloud platform to query the file information of the target file; The file information of the target file sent by the target cloud platform is received.
5. The method of claim 4, wherein, Before the identity authentication account of the target cloud platform associated with the target application identity account is obtained from the identity authentication accounts of each cloud platform associated with the target application identity account, the method further comprises: The target application identity account registered in the application identity service is obtained; After the target application identity account registration is completed, identity authentication accounts on multiple cloud platforms input in the identity application service are acquired, and the target application identity account and the input identity authentication accounts on the multiple cloud platforms are bound.
6. The method of any one of claims 2 to 5, wherein, After the target file is acquired, the method further includes: The target file is added to a file bucket, and the file bucket is used to store the file stored by the target application identity account in the target object storage system.
7. A malicious file detection method in which, The method applies the second subsystem of claim 1, and the method includes: receiving a second detection request for a target file sent by the first subsystem, the second detection request being sent by the first subsystem after acquiring the target file from the target object storage system based on file information of the target file acquired based on the target application identity account in response to a first detection request for a target file related to the target application identity account, the target file being a file stored by the target application identity account in a target object storage system of a target cloud platform, the target cloud platform being all or part of multiple cloud platforms, and the multiple cloud platforms being platforms of identity authentication accounts related to the target application identity account; detecting the target file to obtain a detection result of the target file; determining whether the target file is a malicious file based on the detection result of the target file.
8. The method of claim 7, wherein, The detection of the target file to obtain the detection result of the target file includes: calling at least one file detection engine to perform malicious file detection on the target file to obtain a detection result of the target file by the at least one file detection engine, the file detection engine being used to perform at least one type of malicious file detection on a file.
9. The method of claim 8, wherein, The target file is stored in a file bucket, the file bucket being used to store the file stored by the target application identity account in the target object storage system, and the calling of the at least one file detection engine to perform malicious file detection on the target file to obtain the detection result of the target file by the at least one file detection engine includes: calling any file detection engine to detect the target file in the file bucket; after the target file is detected by the at least one file detection engine, acquiring the detection result of the target file by each file detection engine.
10. The method of any one of claims 7 to 9, wherein, The determination of whether the target file is a malicious file based on the detection result of the target file includes: analyzing the detection result of the target file by using a preset analysis strategy to obtain an analysis result; determining whether the target file is a malicious file based on the analysis result.
11. The method of claim 10, wherein, After the determination of whether the target file is a malicious file based on the analysis result, the method further includes: when it is determined that the target file is a malicious file, determining a risk level of the target file according to the analysis result; processing the target file by using a preset security response mode according to the risk level of the target file.
12. A malicious file detection apparatus, wherein, The device is arranged in the first subsystem of claim 1, and the device includes: The first obtaining module is configured to, in response to a first detection request for a target file related to a target application identity account, obtain file information of the target file based on the target application identity account, the target file being a file stored in a target object storage system of a target cloud platform by the target application identity account, the target cloud platform being all or part of a plurality of cloud platforms, the plurality of cloud platforms being platforms related to the target application identity account by an identity authentication account. The second obtaining module is configured to obtain the target file from the target object storage system based on the file information of the target file. The sending module is configured to send a second detection request to a second subsystem, the second detection request being used to request the second subsystem to detect the target file to determine whether the target file is a malicious file.
13. A malicious file detection apparatus, wherein, The device is arranged in the second subsystem of claim 1, and the device comprises: The receiving module is configured to receive a second detection request for a target file sent by a first subsystem, the second detection request being sent by the first subsystem in response to a first detection request for a target file related to a target application identity account, based on the target application identity account to obtain file information of the target file, and based on the file information of the target file to obtain the target file from a target object storage system, the target file being a file stored in a target object storage system of a target cloud platform by the target application identity account, the target cloud platform being all or part of a plurality of cloud platforms, the plurality of cloud platforms being platforms related to the target application identity account by an identity authentication account. The detection module is configured to detect the target file to obtain a detection result of the target file. The determination module is configured to determine whether the target file is a malicious file based on the detection result of the target file.
14. An electronic device, comprising: The device comprises a processor and a memory, the memory stores at least one program code, and the at least one program code is used to be called and executed by the processor to implement the malicious file detection method in any one of claims 2 to 6 or the malicious file detection method in any one of claims 7 to 11.
15. A computer readable storage medium, wherein, The computer readable storage medium stores at least one computer program, and the at least one computer program is executed by the processor to implement the malicious file detection method in any one of claims 2 to 6 or the malicious file detection method in any one of claims 7 to 11.
16. A computer program product, wherein, The computer program product comprises a computer program, and the computer program is executed by the processor to implement the malicious file detection method in any one of claims 2 to 6 or the malicious file detection method in any one of claims 7 to 11.
Citation Information
Patent Citations
Malicious program judging method based on cloud security
CN102346828A
Cross-platform detection method and system for malicious files in cloud environment
CN103559441A
Cloud native multi-cloud management method and system, electronic equipment and storage medium
CN117579291A
System and method for scanning remote services to locate stored objects with malware
US11368475B1