Folder Virus Identification via File Name Similarity and Attribute Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for establishing a virus database are complex and error-prone, leading to inefficiencies and unreliability in virus identification, particularly for folder viruses that replicate by modifying folder attributes and names.

Innovation Solution

A method and device that scan files in a designated directory to identify executable files with similar names, determine folder attributes, and classify them as folder viruses based on similarity and invisibility, without relying on pre-existing virus feature information, allowing for automatic database updates and improved identification efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual identification and feature extraction are performed on each folder virus file to establish the virus database, then the virus database can be established, but the operation becomes complex and error-prone, leading to decreased efficiency and reliability

Engineering Contradiction:
Improvereliability of virus identificationVSAvoidcomplexity of virus database establishment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically identifies folder viruses by detecting executable files with names matching folder names and checking for invisible attributes, eliminating the need for manual feature extraction. The virus database is automatically updated with extracted features from detected viruses, making the system self-sufficient and reducing human error.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The invention changes the approach from manual feature extraction to automated detection based on file name similarity and attribute changes. By monitoring parameters such as file name matching and attribute modifications (particularly invisible attributes), the system automatically identifies viruses and updates the database without manual intervention.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If manual identification and feature extraction are performed on each folder virus file to establish the virus database, then the virus database can be established, but the process becomes time-consuming, leading to decreased efficiency

Engineering Contradiction:
Improveefficiency of virus identificationVSAvoidtime required for virus database establishment
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system automatically identifies folder viruses by detecting executable files with names matching folder names and checking for invisible attributes, eliminating the need for manual feature extraction. The virus database is automatically updated with extracted features from detected viruses, making the system self-sufficient and reducing human error.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary scanning of the designated directory to identify executable files before attempting virus identification. By pre-checking file names and attributes, the system can quickly determine potential viruses without requiring time-consuming manual analysis, thus improving efficiency.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If feature matching is performed on a scanned file by using a virus database, then the file can be identified as a folder virus, but the database establishment process is complex and error-prone

Engineering Contradiction:
Improveaccuracy of virus identificationVSAvoidcomplexity of virus database establishment
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically identifies folder viruses by detecting executable files with names matching folder names and checking for invisible attributes, eliminating the need for manual feature extraction. The virus database is automatically updated with extracted features from detected viruses, making the system self-sufficient and reducing human error.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary scanning of the designated directory to identify executable files before attempting virus identification. By pre-checking file names and attributes, the system can quickly determine potential viruses without requiring time-consuming manual analysis, thus improving efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3079091B1Method and device for virus identification, nonvolatile storage medium, and device
Publication Date: 2019.07.10 BAIDU INT TECH (SHENZHEN) CO LTD
  • EP3079091B1 patent drawingFigure 1~2
  • EP3079091B1 patent drawingFigure 3

AI summary

Provided in embodiments of the present invention are a method and device for virus identification, a nonvolatile storage medium, and a device. The embodiments of the present invention, by scanning files in a designated directory, acquire the file name of an executable file, and then determine a file name that is either identical or similar to the file name of the executable file, allow for identification of the executable file as a folder virus on the basis of an attribute of a folder corresponding to the identical or similar file name, obviate the need for relying on virus feature information of folder viruses, are easy to operate and not error-prone, thus increasing the efficiency and reliability of virus identification.