CN102819694B - The equipment of a kind of TCM chip, virus investigation method and operation TCM chip - Google Patents

The equipment of a kind of TCM chip, virus investigation method and operation TCM chip Download PDF

Info

Publication number
CN102819694B
CN102819694B CN201110153684.5A CN201110153684A CN102819694B CN 102819694 B CN102819694 B CN 102819694B CN 201110153684 A CN201110153684 A CN 201110153684A CN 102819694 B CN102819694 B CN 102819694B
Authority
CN
China
Prior art keywords
virus
detected
content
input
tcm chip
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201110153684.5A
Other languages
Chinese (zh)
Other versions
CN102819694A (en
Inventor
王正鹏
朱贺新
付月朋
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nationz Technologies Inc
Original Assignee
Nationz Technologies Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nationz Technologies Inc filed Critical Nationz Technologies Inc
Priority to CN201110153684.5A priority Critical patent/CN102819694B/en
Publication of CN102819694A publication Critical patent/CN102819694A/en
Application granted granted Critical
Publication of CN102819694B publication Critical patent/CN102819694B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Test And Diagnosis Of Digital Computers (AREA)
  • Storage Device Security (AREA)

Abstract

The invention discloses the equipment of a kind of TCM chip, virus investigation method and operation TCM chip.Described TCM chip comprises input/output module, memory module, microcontroller, and described TCM chip also comprises hardware virus scan module; Described input/output module is used for virus base characteristic information and content to be detected to input described hardware virus scan module; Described hardware virus scan module is used for the virus base characteristic information according to input, and the resource called in described memory module and microcontroller carrys out the content to be detected of scanning t test, obtains the scanning result of content to be detected; Described input/output module is also for exporting described scanning result.Application the present invention, virus scanning engine self can be avoided by virus infections or the risk of distorting, and TCM chip can know in content to be detected whether there is virus according to scanning result, thus make TCM chip have virus investigation ability, enhance the function of TCM chip.

Description

The equipment of a kind of TCM chip, virus investigation method and operation TCM chip
Technical field
The present invention relates to trust computing field, specifically, particularly relate to the equipment of a kind of TCM chip, virus investigation method and operation TCM chip.
Background technology
Along with the generally use of computer equipment, computer equipment is deep into each corner of daily life.Such as, PC, server, workstation, data center, industry control, net book etc. bring great convenience to people's Working Life, change the life style of people.Computer equipment also brings new problem, the computer virus namely known by people provide easily to people while.Computer virus is the batch processing or instruction set that can destroy computer resource, and it has unique replication capacity.And widely using along with network, network becomes the main carriers of Computer Virus Spread, and network worm then becomes main and that destructive power is maximum new virus.Along with the differentiation of technology, the combination of wooden horse and virus technology, thus occur obviously with the wooden horse of virus characteristic or the virus of Trojan characteristics.Computer virus progressively controls and consume system resources, takies or destroys, cause loss difficult to the appraisal to user software, hardware, data, information, resource.
In order to effectively check the harm of virus or wooden horse, so create antivirus technique and antivirus software.But because virus all has camouflage ability of hiding, can not show effect under usual condition, be difficult to find, therefore how identify that virus then becomes key problem and the difficult point place of antivirus technique.Conventional virus method starts a set of antivirus software, a virus scanning engine is furnished with in this antivirus software, this scanning engine is responsible for content to be detected to scan according to certain way (by file, by sector etc.), thus judges whether content to be detected is comprised virus.
Virus scanning engine is the core of whole antivirus software, and in prior art, virus scanning engine is all one section of software program, and software inherently exists by virus infections or the risk of distorting.If this kind of software virus scanning engine self is by virus infections, then it just cannot play the due effect of antivirus software effectively.Further, existing software virus scanning engine also cannot scanning computer operating system nucleus, cannot ensure the security of computer operating system kernel.
Summary of the invention
The main technical problem to be solved in the present invention is, provides a kind of TCM chip, virus method and runs the equipment of TCM chip, virus scanning engine self can be avoided by virus infections and the risk of distorting, make TCM chip have virus investigation function.
For solving the problems of the technologies described above, present invention employs following technical scheme:
A kind of TCM chip, comprise input/output module, memory module, microcontroller, it is characterized in that, described TCM chip also comprises hardware virus scan module; Described input/output module is used for virus base characteristic information and content to be detected to input described hardware virus scan module; Described hardware virus scan module is used for the virus base characteristic information according to input, and the resource called in described memory module and microcontroller carrys out the content to be detected of scanning t test, obtains the scanning result of content to be detected; Described input/output module is also for exporting described scanning result.
In an embodiment of the present invention, described hardware virus scan module comprises input/output interface, virus base input interface, engine operation interface and scanning engine; Described input interface is for receiving described content to be detected; Described virus base input interface is for receiving described virus base characteristic information; Described scanning engine is used for according to described virus base characteristic information, scans described content to be detected, obtain the scanning result of content to be detected by the resource in memory module described in engine operation interface interchange and microcontroller; Described output interface is for exporting described scanning result.
In an embodiment of the present invention, described TCM chip also comprises enciphering/deciphering module, and described enciphering/deciphering module is connected with described hardware virus scan module, for carrying out enciphering/deciphering to described virus base characteristic information.
In an embodiment of the present invention, described scanning result comprises brief introduction to be detected and judged result; Wherein, described brief introduction to be detected comprises data length and the summary of content to be detected; Whether described judged result comprises content to be detected has virus, and corresponding Virus Type, viral site.
In an embodiment of the present invention, described hardware virus scan module judges that the whether virulent method of described content to be detected is feature code method, or is School Affairs method, or is behavioral value method.
Meanwhile, present invention also offers a kind of virus investigation method, comprise the following steps:
The virus base characteristic information that hardware virus scan module inputs according to input/output module, the resource called in memory module and microcontroller carrys out the content to be detected of scanning t test output module input, obtain the scanning result of content to be detected, and export described scanning result by input/output module.
In an embodiment of the present invention, described hardware virus scan module comprises input/output interface, virus base input interface, engine operation interface and scanning engine; The virus base characteristic information that described hardware virus scan module inputs according to input/output module, the resource called in memory module and microcontroller carrys out the content to be detected of scanning t test output module input, obtain the scanning result of content to be detected, and comprised further by the step that input/output module exports described scanning result:
Described input interface receives described content to be detected, and described virus base input interface receives described virus base characteristic information;
Described scanning engine, according to described virus base characteristic information, scans described content to be detected by the resource in memory module described in engine operation interface interchange and microcontroller, obtains the scanning result of content to be detected;
Described output interface exports described scanning result.
Meanwhile, present invention also offers a kind of equipment running TCM chip, in described equipment, be integrated with above-mentioned arbitrary described TCM chip.
In an embodiment of the present invention, described equipment is computing machine, consumes the cpu resource in described TCM chip when described TCM chip carries out virus investigation scanning.
In an embodiment of the present invention, described equipment is computing machine, and described TCM chip is welded on the mainboard of described computing machine.
The invention has the beneficial effects as follows: utilize the hardware virus scan module in TCM chip, according to the virus base characteristic information of input, the content to be detected that the resource called in memory module and microcontroller carrys out scanning t test obtains the scanning result of content to be detected.Design like this, because TCM chip utilizes hardware virus scan module scans content to be detected, thus virus scanning engine self can be avoided by virus infections or the risk of distorting, and, TCM chip can know in content to be detected whether there is virus according to scanning result, thus make TCM chip have virus investigation ability, enhance the function of TCM chip.
If by TCM integrated chip in the equipment that can run TCM chip, then can promote the security of user environment.Such as, by TCM integrated chip in computer equipment, computing machine can being made when searching virus, the resource of host CPU in computing machine can not be taken, thus the whole work efficiency of high computing machine can be provided.
Accompanying drawing explanation
Fig. 1 is the composition schematic diagram of the TCM chip of an embodiment of the present invention;
Fig. 2 is the composition schematic diagram of the hardware virus scan module of an embodiment of the present invention;
Fig. 3 is the composition schematic diagram of the TCM chip of the another kind of embodiment of the present invention;
Fig. 4 is the method flow diagram of the another kind of embodiment of the present invention.
Embodiment
By reference to the accompanying drawings the present invention is described in further detail below by embodiment.
The virus scanning engine existed in existing antivirus technique also exists itself by virus infections or may be distorted, and effectively can not play the problem that antivirus software should be powerful.For solving this technical problem, central scope of the present invention is: form virus scanning engine being made hardware, and virus scanning engine like this self then by virus infections or can not be distorted, and thus can effectively avoid virus scanning engine itself by the risk of virus infections.
But, if hardware virus scanning engine needs normally to run, just need to build minimum hardware system, particularly, need the basic elements of character such as microprocessor, storer, input/output control unit (I/O controller).As can be seen here, the entity cost realizing separately a hardware virus scanning engine will costly, thus cannot use widely in current computer environment.
In prior art, TCM chip (credible password module, TrustedCryptographyModule) have the independently module such as microprocessor, storer, hash algorithm engine, input/output control unit (I/O controller), symmetry algorithm and asymmetric arithmetic engine, the trustability of computing machine, completeness of platform, data security can be improved.By the mode independent of computer system, and ensure the safety of bottom hardware and user data based on theory trusty.The most important function of TCM chip is to provide an environment trusty, on this basis, realizes the safety applications of each links such as authentication, digital signature, file encryption-decryption, HD encryption, VPN/PKI certification, WIFI certification.TCM chip can also generate encryption key, realizes the storage of key and the reduction etc. of enciphered data.Current TCM chip uses on a large scale at PC, notebook, server etc.
As can be seen here, TCM chip has a minimum hardware system.Just think, if by inner transformation, hardware virus scanning engine is integrated in TCM chip, can not be very large on the production cost impact of TCM chip.Now hardware virus scanning engine just can share the resources such as microprocessor, storer, input/output control unit with the internal module in TCM chip, works together with other modules.
So, the virus scanning engine then solving software form in prior art is easily by virus infections or the problem such as to distort, and hardware virus scanning engine is integrated in TCM chip, also makes TCM chip have the ability of virus investigation, thus the function of existing TCM chip can be strengthened.
Conceived by foregoing invention, the present invention proposes a kind of TCM chip and virus investigation method.
Because a hardware system is wanted normally to run, comprise 5 elements, i.e. I/O part, storage area, calculating section, specific procedure runs part.
As shown in Figure 1, the TCM chip 1 in the present invention, comprises a minimum hardware system, namely comprises input/output module 14, memory module 12, microcontroller 13; This TCM chip also comprises hardware virus scan module 11, and wherein, input/output module 14 is for inputing to hardware virus scan module 11 by virus base characteristic information and content to be detected.Hardware virus scan module 11 is for receiving virus base characteristic information and content to be detected, and according to the virus base characteristic information inputted, the resource called in memory module 12 and microcontroller 13 carrys out the content to be detected of scanning t test, obtain the scanning result of content to be detected, and the scanning result of input/output module 14 also for obtaining exports.Wherein, hardware virus scan module 11 is integrated in TCM chip, so, hardware virus scan module 11 just can together with other module in TCM chip, share the hardware device such as input/output module, memory module, microcontroller in TCM chip, thus ensure that the normal operation of hardware virus scan module 11.Wherein, input/output module also for transferring command word, the startup of control hardware virus scan module 11 and the execution of work, and memory module 12 can also be used for some hardware parameter information of storage hardware virus scan module itself.
Utilize the hardware virus scan module in TCM chip of the present invention, Detection of content can be treated and carry out virus scan, so, then avoid virus scan module self by virus infections or distort may, effectively can play the due function of hardware virus scan module.And, by hardware virus scan module integration in TCM chip, the resource of the input/output module of TCM chip, memory module, microcontroller is shared with other module in TCM chip, treat Detection of content to scan, thus make TCM chip be provided with the ability of virus investigation, enhance the function of TCM chip afterwards.Further, when production this kind of improvement TCM chip, do not need to carry out larger change to existing TCM chip, the TCM chip therefore in the present invention has the low advantage of production cost.
As shown in Figure 2, in one embodiment, hardware virus scan module 11 comprises input interface 111, virus base input interface 112, engine operation interface 113 and output interface 114, and scanning engine 115; Particularly, input interface 111 is for receiving the content to be detected of input/output module input; Virus base input interface 112 is for receiving the virus base characteristic information of input/output module input; Scanning engine 115 then according to the virus base characteristic information of input, scans described content to be detected by engine operation interface 113 resource called in memory module 12 and microcontroller 13, and analyzes its content, obtain the scanning result of content to be detected; Output interface 114 is for exporting the scanning result of content to be detected.Wherein, may be used for receiving the different virus base characteristic information being input to scanning engine 115 by virus base input interface 112.
As shown in Figure 3, in one embodiment, TCM chip 1 also comprises TCM chip and also comprises enciphering/deciphering module 15, enciphering/deciphering module 15 is connected with hardware virus scan module 11, to the virus base characteristic information encryption received, and just decipher when hardware virus scan module 11 needs, so, then ensure that the correctness of virus base characteristic information.Also ensure that TCM chip is in subsequent processes, the correctness of the virus found.It should be noted that, content to be detected is the killing object of TCM chip, and the content-form that content to be detected comprises is very abundant, such as, content to be detected can for being stored in the content in file, or for being stored in the content in disk, also can for being stored in the content in logical block.Particularly, the position of hardware virus scan module scans content to be detected and size.
Similarly, the content of virus base characteristic information then comprises position feature and the version feature of virus, and namely this kind of virus belongs to that version, that Virus Type, and its particular location etc.
In one embodiment, the scanning result of content to be detected comprises two parts, i.e. brief introduction to be detected and judged result.Wherein, brief introduction to be detected comprises data length and the summary of content to be detected, and whether judged result then comprises content to be detected has virus, and Virus Type, viral site etc.If the scanning engine in TCM chip judges that content to be detected comprises virus, then in the scanning result of output interface output, show the conclusion that content to be detected comprises virus, and describe out the type of this virus particularly, and the position etc. described in it.
Certainly, the hardware virus scan module in TCM chip judges that the whether virulent method of content to be detected has a variety of.Such as, feature code method can be used, or use School Affairs method, or usage behavior detection method.Wherein, feature code method detects the simplest, the method that expense is minimum of known viruse.The title that the method detects accurately fast, identifiable design is viral, false alarm rate are low, foundation testing result, can do Detoxified treatment.
In an embodiment of the present invention, use feature code method to carry out virus investigation for TCM chip to be described in detail.
Preliminary work, first needs to gather known virus base sample, extracts its feature code, obtain virus base characteristic information.The code extracted needs suitable length, its objective is the uniqueness maintaining feature code on the one hand, on the other hand again without the need for too large spatiotemporal expense.Under the prerequisite keeping uniqueness, make feature code length short, to reduce space and time overhead as far as possible.Gather known viruse sample and extract the Comparision consumes resources that feature code forms virus base characteristic information, generally being provided by antivirus software manufacturer, not requiring to realize with TCM chip herein.TCM chip only needs to search out virus base characteristic information, and can receive and upgrade virus base characteristic information.
Secondly, scanning engine in hardware virus scan module is according to the virus base characteristic information obtained from virus base input interface, for content to be detected, call resource in microprocessor and memory module and whether comprise virus pattern code string in virus base characteristic information or virus characteristic word to search in content to be detected.If find that there is the virus pattern code identical with virus base characteristic information in content to be detected, due to feature code and viral one_to_one corresponding, therefore just can conclude in content to be detected, there is which kind of virus.
Particularly, following steps can be adopted to process:
1, content to be detected is inputted by input interface (ReadPEImage);
2, virus base characteristic information is inputted by virus base input interface (ReadSector);
3, scanning engine is according to virus base characteristic information, and the resource called in memory module and micro-process by engine operation interface (ExtractPE, CompareDB) scans content to be detected, waits for scanning result.
4, the scanning result finally obtained is exported by output interface by scanning engine.
So, TCM chip then according to scanning result, can know in content to be detected whether include virus.The advantage utilizing feature code method to carry out virus investigation is: the title that detection is accurate fast, identifiable design is viral, false alarm rate are low.
Meanwhile, present invention also offers a kind of virus investigation method, comprise the following steps:
The virus base characteristic information that hardware virus scan module inputs according to input/output module, the resource called in memory module and microcontroller carrys out the content to be detected of scanning t test output module input, obtain the scanning result of content to be detected, and export described scanning result by input/output module.
Wherein, hardware virus scan module comprises input/output interface, virus base input interface, engine operation interface and scanning engine.Particularly, virus investigation method can be divided into following steps:
S1, input interface receive content to be detected; Virus base input interface receives virus base characteristic information;
S2, scanning engine, according to virus base characteristic information, scan content to be detected by the resource in engine operation interface interchange memory module and microcontroller, obtain the scanning result of content to be detected;
The scanning result of S3, output interface output detections content.
In addition, present invention also offers a kind of equipment running TCM chip, in this kind of equipment, be integrated with the TCM chip comprising above-mentioned any embodiment.So, this kind of equipment is when running main antivirus applet, utilize the hardware virus scanning engine in TCM chip to scan in content to be detected whether comprise virus, thus avoid virus scanning engine by the risk of virus infections, can effectively search the virus that may exist in equipment.When scanning content to be detected and comprising virus, then utilize main virus killing degree to carry out correspondingly killing, thus ensure that the security of the content stored in equipment, promote the security of user environment.This kind of equipment can be computing machine, notebook, panel computer, mobile phone etc.
Such as, in an embodiment of the present invention, this equipment is specially computing machine, and TCM chip is then welded on the mainboard of computing machine.This kind of computing machine, when running main antivirus applet, can utilize TCM chip hardware scan module to treat Detection of content and carry out virus scan.The benefit of such design is, is that of avoiding hardware virus scanning engine by the risk of virus infections on the one hand, can effectively searches the virus that may exist in computing machine; On the other hand, when TCM chip performs virus scan, what consume is cpu resource in TCM chip, and can not host CPU resource in consumption calculations machine, so, host CPU resource in computing machine now then can go the program running other, after the hardware scanning module in TCM chip obtains scanning result, host CPU resource just processes accordingly according to scanning result, so just reduce taking host CPU resource in viral searching, achieve and can perform the mode of operation scanned by asynchronism and concurrency, improve the whole work efficiency of computing machine.Finally, by TCM chips welding disclosed by the invention on the mainboard of computing machine, so, then the connection of TCM chip and computing machine cannot be cut off physically.Because TCM chip is in the comparatively bottom of computer system, can with BIOS cooperating, thus make this kind of TCM chip at computer starting Prior efforts, the security of computer system can be further ensured.
Above content is in conjunction with concrete embodiment further description made for the present invention, can not assert that specific embodiment of the invention is confined to these explanations.For general technical staff of the technical field of the invention, without departing from the inventive concept of the premise, some simple deduction or replace can also be made, all should be considered as belonging to protection scope of the present invention.

Claims (10)

1. a TCM chip, comprises input/output module, memory module, and microcontroller is characterized in that, described TCM chip also comprises hardware virus scan module; Described input/output module is used for virus base characteristic information and content to be detected to input described hardware virus scan module; Described hardware virus scan module is used for the virus base characteristic information according to input, and the resource called in described memory module and microcontroller carrys out the content to be detected of scanning t test, obtains the scanning result of content to be detected; Described input/output module is also for exporting described scanning result.
2. TCM chip as claimed in claim 1, it is characterized in that, described hardware virus scan module comprises input/output interface, virus base input interface, engine operation interface and scanning engine; Described input interface is for receiving described content to be detected; Described virus base input interface is for receiving described virus base characteristic information; Described scanning engine is used for according to described virus base characteristic information, scans described content to be detected, obtain the scanning result of content to be detected by the resource in memory module described in engine operation interface interchange and microcontroller; Described output interface is for exporting described scanning result.
3. TCM chip as claimed in claim 1 or 2, it is characterized in that, described TCM chip also comprises enciphering/deciphering module, and described enciphering/deciphering module is connected with described hardware virus scan module, for carrying out enciphering/deciphering to described virus base characteristic information.
4. TCM chip as claimed in claim 1 or 2, it is characterized in that, described scanning result comprises brief introduction to be detected and judged result; Wherein, described brief introduction to be detected comprises data length and the summary of content to be detected; Whether described judged result comprises content to be detected has virus, and corresponding Virus Type, viral site.
5. TCM chip as claimed in claim 4, it is characterized in that, described hardware virus scan module judges that the whether virulent method of described content to be detected is feature code method, or is School Affairs method, or is behavioral value method.
6. a virus investigation method, is characterized in that, comprises the following steps:
The virus base characteristic information that hardware virus scan module inputs according to input/output module, the resource called in memory module and microcontroller carrys out the content to be detected of scanning t test output module input, obtain the scanning result of content to be detected, and export described scanning result by input/output module.
7. virus investigation method as claimed in claim 6, it is characterized in that, described hardware virus scan module comprises input/output interface, virus base input interface, engine operation interface and scanning engine; The virus base characteristic information that described hardware virus scan module inputs according to input/output module, the resource called in memory module and microcontroller carrys out the content to be detected of scanning t test output module input, obtain the scanning result of content to be detected, and comprised further by the step that input/output module exports described scanning result:
Described input interface receives described content to be detected, and described virus base input interface receives described virus base characteristic information;
Described scanning engine, according to described virus base characteristic information, scans described content to be detected by the resource in memory module described in engine operation interface interchange and microcontroller, obtains the scanning result of content to be detected;
Described output interface exports described scanning result.
8. run an equipment for TCM chip, it is characterized in that, in described equipment, be integrated with the arbitrary described TCM chip of claim 1-6.
9. equipment as claimed in claim 8, it is characterized in that, described equipment is computing machine, consumes the cpu resource in described TCM chip when described TCM chip carries out virus investigation scanning.
10. equipment as claimed in claim 9, it is characterized in that, described TCM chip is welded on the mainboard of described computing machine.
CN201110153684.5A 2011-06-09 2011-06-09 The equipment of a kind of TCM chip, virus investigation method and operation TCM chip Active CN102819694B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201110153684.5A CN102819694B (en) 2011-06-09 2011-06-09 The equipment of a kind of TCM chip, virus investigation method and operation TCM chip

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201110153684.5A CN102819694B (en) 2011-06-09 2011-06-09 The equipment of a kind of TCM chip, virus investigation method and operation TCM chip

Publications (2)

Publication Number Publication Date
CN102819694A CN102819694A (en) 2012-12-12
CN102819694B true CN102819694B (en) 2015-12-02

Family

ID=47303804

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201110153684.5A Active CN102819694B (en) 2011-06-09 2011-06-09 The equipment of a kind of TCM chip, virus investigation method and operation TCM chip

Country Status (1)

Country Link
CN (1) CN102819694B (en)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103390131A (en) * 2013-07-29 2013-11-13 无锡华御信息技术有限公司 Single computer safety checking system of electronic key based on integrated flash memory
CN105468969B (en) * 2015-11-19 2019-02-01 中科创达软件股份有限公司 A kind of method and system promoting antivirus applications security
CN107547499A (en) * 2017-05-11 2018-01-05 新华三信息安全技术有限公司 Feature database collocation method and device
CN112184212A (en) * 2020-09-17 2021-01-05 深圳市银通商智能卡有限公司 Method for controlling applet operation for IC card

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN200972654Y (en) * 2006-10-18 2007-11-07 何华科技股份有限公司 Universal interface devirus device
CN101382928A (en) * 2008-10-29 2009-03-11 清华大学 Soft computer and implementing method
CN101479706A (en) * 2006-07-03 2009-07-08 英特尔公司 An anti-virus usage model at an exterior panel of a computer
CN101714197A (en) * 2008-09-30 2010-05-26 英特尔公司 Hardware-based anti-virus scan service
CN101901308A (en) * 2009-05-27 2010-12-01 同方股份有限公司 Method for using computer antivirus software

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101479706A (en) * 2006-07-03 2009-07-08 英特尔公司 An anti-virus usage model at an exterior panel of a computer
CN200972654Y (en) * 2006-10-18 2007-11-07 何华科技股份有限公司 Universal interface devirus device
CN101714197A (en) * 2008-09-30 2010-05-26 英特尔公司 Hardware-based anti-virus scan service
CN101382928A (en) * 2008-10-29 2009-03-11 清华大学 Soft computer and implementing method
CN101901308A (en) * 2009-05-27 2010-12-01 同方股份有限公司 Method for using computer antivirus software

Also Published As

Publication number Publication date
CN102819694A (en) 2012-12-12

Similar Documents

Publication Publication Date Title
RU2610254C2 (en) System and method of determining modified web pages
Cen et al. A probabilistic discriminative model for android malware detection with decompiled source code
Babar et al. Proposed embedded security framework for internet of things (iot)
CN104598815B (en) Recognition methods, device and the client of malice advertising program
US20210089684A1 (en) Controlled access to data stored in a secure partition
Ling et al. Secure boot, trusted boot and remote attestation for ARM TrustZone-based IoT Nodes
CN102819694B (en) The equipment of a kind of TCM chip, virus investigation method and operation TCM chip
CN107483422A (en) Leakage of data retroactive method, equipment and computer-readable recording medium
CN100334519C (en) Method for establishing credible input-output channels
CN102819700A (en) Device and method for identifying a plurality of biological characteristics in isolation environment
Wang et al. Android malware detection based on convolutional neural networks
US11520898B2 (en) Intrusion detection
Wu et al. Detection of fake IoT app based on multidimensional similarity
CN103049705B (en) A kind of based on virtualized method for secure storing, terminal and system
CN103984901A (en) Trusted computer system and application method thereof
CN101150459B (en) Method and system for improving safety of information safety device
JP2013222422A (en) Program, information processing device, and information processing method
Rahimi et al. Trends and challenges in ensuring security for low-power and high-performance embedded SoCs
Chen et al. SUIP: An Android malware detection method based on data flow features
CN101924765B (en) Single-system and single-network computer communication method
Raghuvanshi et al. Android Malware Detection Using Machine Learning Techniques
AU2019255300B2 (en) Anti-virus device for industrial control systems
Sun et al. Research on android infiltration technology based on the silent installation of an accessibility service
CN104463028A (en) Safety mode prompting method and movable device for implementing method
US20230237164A1 (en) Monitoring file sharing commands between network equipment to identify adverse conditions

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CB03 Change of inventor or designer information

Inventor after: Liang Jie

Inventor after: Liu Xin

Inventor after: Hou Weixing

Inventor after: Wang Zhengpeng

Inventor after: Zhu Hexin

Inventor after: Fu Yuepeng

Inventor before: Wang Zhengpeng

Inventor before: Zhu Hexin

Inventor before: Fu Yuepeng

COR Change of bibliographic data