The invention discloses a malicious code type detection method based on a cloud mode. The method comprises the following steps that: a cloud terminal carries out
processing and analysis on a malicious code family to generate an initial classification
database, generates a representative
feature set for each category of malicious code family in the initial classification
database, an access or execution operation of a program is intercepted at a
client, an only identity value of the intercepted program is calculated, whether the only identity value exists in a local
database or not is determined, if not, a specific feature document of the intercepted program is extracted, the only identity value and a specific feature document of the intercepted program is uploaded to the cloud terminal by the
client, whether the only identity value exists in a cloud terminal database or whether the feature document belongs to a classification is determined, a final determination result is returned to the
client, and the only identity value and the final determination result are written into the cloud terminal database and a client database respectively. According to the method, the
rapid expansion of a feature
library can be slowed down, the upload of suspicious programs is reduced, and the killing prevention efficiency of cloud security is raised.