A
virus searching and killing method and
system for distributed
energy security data relates to the field of
virus processing, and comprises the following steps: acquiring an original
feature code of a
virus, splitting the original
feature code into N discontinuous and sequential fixed fragments Fi, calculating an initial offset Si of each fragment Fi relative to a first fragment F1, and constructing a virus feature
database, according to the method, firstly, a
data stream is divided into a plurality of data blocks Bi with the fixed size, scanning and matching association are conducted through a sliding window with the fixed size, and finally threshold judgment is conducted. Original virus feature codes are subjected to fragmentation
processing, and the storage requirement of a virus feature
database is lowered; secondly, sliding window scanning can ensure that any
feature combination is covered, a matching event FPi is recorded instead of
full data, and memory occupation is reduced; by comparing the absolute offset SBi with the expected position, the correct sequence of the fragments in the virus is ensured, the matching progress can be tracked in real time by a state
machine, weights are accumulated only for the fragments with the correct sequence, and the detection credibility is improved.