Folder Virus Identification via File Name Similarity and Attribute Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for establishing a virus database are complex and error-prone, leading to inefficiencies and unreliability in virus identification, particularly for folder viruses that replicate by modifying folder attributes and names.
Innovation Solution
A method and device that scan files in a designated directory to identify executable files with similar names, determine folder attributes, and classify them as folder viruses based on similarity and invisibility, without relying on pre-existing virus feature information, allowing for automatic database updates and improved identification efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual identification and feature extraction are performed on each folder virus file to establish the virus database, then the virus database can be established, but the operation becomes complex and error-prone, leading to decreased efficiency and reliability
Solution Approach 1:
The system automatically identifies folder viruses by detecting executable files with names matching folder names and checking for invisible attributes, eliminating the need for manual feature extraction. The virus database is automatically updated with extracted features from detected viruses, making the system self-sufficient and reducing human error.
Solution Approach 2:
The invention changes the approach from manual feature extraction to automated detection based on file name similarity and attribute changes. By monitoring parameters such as file name matching and attribute modifications (particularly invisible attributes), the system automatically identifies viruses and updates the database without manual intervention.
2Productivity
If manual identification and feature extraction are performed on each folder virus file to establish the virus database, then the virus database can be established, but the process becomes time-consuming, leading to decreased efficiency
Solution Approach 1:
The system automatically identifies folder viruses by detecting executable files with names matching folder names and checking for invisible attributes, eliminating the need for manual feature extraction. The virus database is automatically updated with extracted features from detected viruses, making the system self-sufficient and reducing human error.
Solution Approach 2:
The system performs preliminary scanning of the designated directory to identify executable files before attempting virus identification. By pre-checking file names and attributes, the system can quickly determine potential viruses without requiring time-consuming manual analysis, thus improving efficiency.
3Measurement precision
If feature matching is performed on a scanned file by using a virus database, then the file can be identified as a folder virus, but the database establishment process is complex and error-prone
Solution Approach 1:
The system automatically identifies folder viruses by detecting executable files with names matching folder names and checking for invisible attributes, eliminating the need for manual feature extraction. The virus database is automatically updated with extracted features from detected viruses, making the system self-sufficient and reducing human error.
Solution Approach 2:
The system performs preliminary scanning of the designated directory to identify executable files before attempting virus identification. By pre-checking file names and attributes, the system can quickly determine potential viruses without requiring time-consuming manual analysis, thus improving efficiency.
Data Source
Figure 1~2
Figure 3
AI summary
Provided in embodiments of the present invention are a method and device for virus identification, a nonvolatile storage medium, and a device. The embodiments of the present invention, by scanning files in a designated directory, acquire the file name of an executable file, and then determine a file name that is either identical or similar to the file name of the executable file, allow for identification of the executable file as a folder virus on the basis of an attribute of a folder corresponding to the identical or similar file name, obviate the need for relying on virus feature information of folder viruses, are easy to operate and not error-prone, thus increasing the efficiency and reliability of virus identification.