CN106355087A - Virus detection result monitoring method and device - Google Patents

Virus detection result monitoring method and device Download PDF

Info

Publication number
CN106355087A
CN106355087A CN201510422884.4A CN201510422884A CN106355087A CN 106355087 A CN106355087 A CN 106355087A CN 201510422884 A CN201510422884 A CN 201510422884A CN 106355087 A CN106355087 A CN 106355087A
Authority
CN
China
Prior art keywords
checked
module
task
packet
webpage
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201510422884.4A
Other languages
Chinese (zh)
Inventor
姚潮生
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Tencent Technology Shenzhen Co Ltd
Original Assignee
Tencent Technology Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Tencent Technology Shenzhen Co Ltd filed Critical Tencent Technology Shenzhen Co Ltd
Priority to CN201510422884.4A priority Critical patent/CN106355087A/en
Publication of CN106355087A publication Critical patent/CN106355087A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/554Detecting local intrusion or implementing counter-measures involving event detection and direct action
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • G06F21/566Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities

Abstract

A virus detection result monitoring method includes the steps that data packages of a to-be-detected installation package file are pulled periodically, the to-be-detected installation package file is submitted to a detection webpage for virus detection by calling a preset automatic testing program, whether target characters are included or not is detected in the webpage feeding back a virus detection result, if yes, information related to pre-warning information is read and sent from configuration files included in the preset automatic testing program, and the pre-warning information is sent according to the obtained related information. Meanwhile, the invention further provides a virus detection result monitoring device. The to-be-detected installation package file is automatically submitted to the detection webpage for virus detection and whether the target characters are included in the virus detection result is automatically monitored, so virus pre-warning is conducted in time, and monitoring efficiency is improved.

Description

A kind of monitoring method of Viral diagnosis result and device
Technical field
The present invention relates to Internet technical field, particularly to a kind of monitoring method of Viral diagnosis result And device.
Background technology
Application market also known as applies shop, exclusively for mobile terminals such as mobile device mobile phone, panel computers Charge or free application are provided, the electronic application shop of application download service is provided.Developer is permissible The application that oneself is developed uploads to application market and supplies user to download, and application market can be to ARIXTRA (android) installation kit (apk, android package) is checked, detects whether it contains Sensitive and unsafe method call, if it is checked that coming, can carry out report poison, representing that this application is not inconsistent Close safety criterion.
The at present report poison condition monitoring to apk, can only the detection webpage specified of manual unlocking, submit to Apk bag, the malicious result of waiting report, then carry out manual analyses, judge whether the apk submitting to hits report Malicious content, if it is, notify apk project team to be processed.Above flow process is longer and needs each Step is required for manpower intervention, and efficiency is extremely low, can not possibly all arrange special messenger to carry out report poison daily simultaneously Detection, the malicious situation of report being so again likely to result in new apk bag cannot notify project team in time, The apk leading to outside channel is coated the malicious risk extension of report.
Content of the invention
In view of this, the present invention provides a kind of monitoring method of Viral diagnosis result and device, in order to certainly Dynamic monitoring Viral diagnosis result corresponding transmission early warning information, in order to make in time by the malicious early warning of report, carry High monitoring efficiency.
The embodiment of the present invention provides a kind of monitoring method of Viral diagnosis result, comprising:
Timing pulls the packet of installation package file to be checked;Call preset automatic test program, with Described installation package file to be checked is submitted to carry out Viral diagnosis to detection webpage;Returning Viral diagnosis result Webpage in detect whether to comprise target printed words;If so, then from described preset automatic test program In the configuration file comprising, read the information related to sending described early warning information, and according to described phase The information closed sends described early warning information.
The embodiment of the present invention provides a kind of supervising device of Viral diagnosis result, comprising:
Pull module, for regularly pulling the packet of installation package file to be checked;Submit module to, be used for Call preset automatic test program, to submit to described installation package file to be checked to carry out to detection webpage Viral diagnosis;Detection module, for detecting whether to comprise mesh in the webpage returning Viral diagnosis result Marking-up sample;Read module, if detect for described detection module comprising described target printed words, from In the configuration file that described preset automatic test program bag contains, read and send described early warning information Related information;Sending module, the described related information for being read according to described read module is sent out Send described early warning information.
The monitoring method of the Viral diagnosis result according to above-described embodiment and device, by the timing of system Task automatically triggers to be submitted to installation package file to be checked and detects that webpage carries out Viral diagnosis, and automatically examines When in the testing result that survey returns containing target printed words, send early warning information from trend related personnel, carry High monitoring efficiency so that related personnel processes this installation package file to be checked in time, thus reducing this installation APMB package is reported the risk of poison.
It is that the above and other objects, features and advantages of the present invention can be become apparent, cited below particularly Preferred embodiment, and coordinate institute's accompanying drawings, it is described in detail below.
Brief description
The monitoring method schematic flow sheet of the Viral diagnosis result that Fig. 1 provides for first embodiment of the invention;
The monitoring method schematic flow sheet of the Viral diagnosis result that Fig. 2 provides for second embodiment of the invention;
The supervising device structural representation of the Viral diagnosis result that Fig. 3 provides for third embodiment of the invention;
The supervising device structural representation of the Viral diagnosis result that Fig. 4 provides for fourth embodiment of the invention.
Specific embodiment
For further illustrating that the present invention is to realize technological means and the work(that predetermined goal of the invention is taken Effect, below in conjunction with accompanying drawing and preferred embodiment, to according to the specific embodiment of the present invention, structure, Feature and its effect, after describing in detail such as.
The monitoring method of Viral diagnosis result provided in an embodiment of the present invention, for will be automatic for apk to be checked It is submitted to detection webpage carries out whether containing mesh in Viral diagnosis, and the testing result of automatic detection return Marking-up sample, if having, illustrates that testing result is that detection webpage has done report poison process to this apk to be checked, Then send early warning information from trend related personnel, point out this apk to be checked to be reported poison, should process in time.
Refer to Fig. 1, the monitoring method of the Viral diagnosis result in first embodiment of the invention includes:
101st, regularly pull the packet of installation package file to be checked;
The instruction of receive user, will pull the task of the packet of this installation package file to be checked, is added to In the task-set of the calculated timing automatic daily execution of operating system task.
The packet pulling every time is the latest data bag of this apk to be checked.Delete both deposited this is to be checked The old packet of akp, and the latest data bag of the apk to be checked pulling is carried out renaming, pass through Dos order corresponding with renaming change this apk to be checked title so that after modification title should Apk to be checked directly can be processed by this preset automatic test program.
102nd, call preset automatic test program, to submit this installation package file to be checked to detection net Page carries out Viral diagnosis;
The task scheduling function of being carried by windows in the present embodiment, realizes timing automatic daily holding Row timing pulls the packet of installation package file to be checked and calls preset automatic test program.
Specifically, the task of the packet of apk to be detected will be pulled, and call preset automatization The task write run.bat autoexec of test program, it is fixed that this run.bat autoexec is added into In the task scheduling that carries of windows of phase execution, and the appointed task triggered time, when reaching this During the business triggered time, triggering executes this task, runs run.bat.
This preset automatic test program can be selenium automatic test program.selenium It is by the technological frame of web page operation automatization, be an instrument being used for weblication test, Selenium test runs directly in browser, just as real user is in operation.
Specifically, call selenium automatic test program to open browser, and beaten by browser Open the detection webpage detecting this apk to be measured, upload this apk to be checked and carry out virus to this detection webpage Detection.
103rd, detect whether to comprise target printed words in the webpage returning testing result;
The webpage returning testing result detects whether to comprise target printed words, if comprising this target printed words, Then judge that this apk to be checked can be by report poison.
104th, if so, then from the configuration file that this preset automatic test program bag contains, read with Send the related information of this early warning information, and this early warning information is sent according to this related information.
If in returning the webpage to the testing result that this apk to be checked carries out Viral diagnosis, bag is detected Containing this target printed words, then send early warning information, for pointing out to include by this detection in this apk to be checked Webpage thinks sensitive and unsafe method call.
Specifically, from the configuration file that this preset automatic test program bag contains, read and send The related information of this early warning information, for example, sends form, the content of this early warning information, and receives The information such as the title of the target person of this early warning information, email address and client account.According to this phase The information closed, this early warning information is sent mail by this email address or this client account sends and disappears The mode of breath, is sent to target person so as to the testing result to this apk to be checked can be obtained early And processed.
In the embodiment of the present invention, by the timed task of system, installation package file to be checked is carried by triggering automatically It is sent to detection webpage to carry out containing target printed words in Viral diagnosis, and the testing result of automatic detection return When, send early warning information from trend related personnel, improve monitoring efficiency so that related personnel locates in time Manage this installation package file to be checked, thus reducing the risk that this installation package file is reported poison.
Refer to Fig. 2, the monitoring method of the Viral diagnosis result in second embodiment of the invention includes:
201st, the instruction of receive user, will pull the task of the packet of installation package file to be checked, adds To in the task-set of the calculated timing automatic daily execution of operating system task, and task triggering is set Time;
In windows system, carry task scheduling function, can be by any script, program or literary composition Shelves are arranged in the operation of certain time.Task scheduling function each start windows system when from Move and start (acquiescence task scheduler service is to open) and in running background.Using task scheduling Can complete following task: plan allow task daily, per week, monthly or some moment (for example During system start-up) run;The plan of change task;The task of rest schedule;Certain task self-defined In the method for operation sometime.User can customize task scheduling.
The task scheduling function of being carried by windows in the present embodiment, realizes daily execution automatically right The monitoring of the Viral diagnosis result of apk packet to be detected.Specifically, receive receive user setting to appoint The instruction of business plan, will pull the task of the packet of installation package file to be checked, is added to windows In the task-set of timing automatic daily execution in the task scheduling of operating system, and task triggering is set Time.
Specifically it is achieved in that, the task write run.bat file that will execute, by this run.bat literary composition Part adds in the Mission Planning Program of windows, and start by set date runs this run.bat file, realizes each The automatic execution of task.
202nd, when reaching this task triggered time, pull the packet of this installation package file to be checked;
The task of the packet of installation package file to be checked will be pulled, be added to operating system task in the works The task-set of timing automatic daily execution in after, when reach setting this task triggered time, hold Row pulls the task of the packet of installation package file to be checked.Specifically can be by providing the service of apk source bag Device platform pulls the packet of this installation package file to be checked.
203rd, the title of packet that pulled by dos order modification is so that amended title Meet the rule that preset automatic test Automatic Program is processed;
Dos order is the order of disc operating system (dos, disk operating system), is A kind of operational order towards disk, main include directory operation class order, disk operating class order, File operation class order and other order.
After the title of the packet of the apk to be checked being pulled by dos order modification is so that change Title meet the rule that preset automatic test Automatic Program is processed, i.e. after modification title, should The packet of apk to be checked can be processed by this preset automatic test Automatic Program.For example, should be certainly Dynamicization test program is set to comprise date on the same day and to be checked in the title of certain packet when detecting The title of apk, then automatically process this packet, then, the amended title of this packet can comprise The title of date on the same day and apk to be checked is so that this preset automatic test program can to it certainly Dynamic process.
204th, the automatic test program calling this preset opens browser, and opens this by browser Detection webpage;
This preset automatic test program can be selenium automatic test program.selenium It is by the technological frame of web page operation automatization, be an instrument being used for weblication test, Selenium test runs directly in browser, just as real user is in operation.
Specifically, by calling selenium automatic test program, open browser, and by clear The detection webpage detecting this apk to be measured opened by device of looking at.
205th, this installation package file to be checked is uploaded by the document uploading control of this detection webpage and carry out virus Detection;
This apk to be checked is uploaded by the document uploading control of this detection webpage, i.e. navigate to this detection This document uploading control in webpage, inputs this apk to be checked to be uploaded in local store path name, And click on upload, upload to this detection webpage and carry out Viral diagnosis.
206th, detect whether to comprise target printed words in the webpage returning testing result;
The webpage returning testing result detects whether to comprise target printed words, for example, to apk to be checked Carry out in the returning result page of Viral diagnosis, analyze testing result information line by line, checking in every row is The no printed words for droidrooter for the testing result that there is key viral storehouse ikarus.
If so, then execution step 207;If it is not, then disregarding.It is then turned off browser.
207th, from the configuration file that this preset automatic test program bag contains, read that this is pre- with transmission The related information of alarming information;
If detecting and comprise this target printed words in the webpage returning testing result, from this preset from In the configuration file that dynamicization test program comprises, read the information related to sending this early warning information, tool Body ground, the information related to sending this early warning information can be form, the content sending this early warning information, And receive the information such as title, email address and the client account of the target person of this early warning information.
208th, title, the mailbox ground according to the target person receiving this early warning information in this related information Location and the account of client, this early warning information are sent to mailbox or the client of this target person.
The letters such as the title of the target person according to this early warning information of reception, email address and client account Breath, according to the format content of this early warning information, mail is sent to the mailbox of target person, or, Transmit the message to the client account of target person it is also possible to mail, message are sent to mesh simultaneously Mark personnel are so as to can obtaining the testing result to this apk to be checked early and processing.
For example: the project that the apk to be checked of censorship is to be detected is whether to have root function, if having, The result of detection webpage detection is poisonous.Corresponding, the early warning message body being sent to target person can Think:
The malicious result of current data packet interim root report is: poisonous;
Virus characteristic is: ikarus testing result is droidrooter;
Pulling data task is linked as:
http://rdm.wsd.com/dailybuild.html?F=dailybuild#c1.jobid:87@@1429
In the embodiment of the present invention, by the timed task of system, installation package file to be checked is carried by triggering automatically It is sent to detection webpage to carry out containing target printed words in Viral diagnosis, and the testing result of automatic detection return When, send early warning information from trend related personnel, improve monitoring efficiency so that related personnel locates in time Manage this installation package file to be checked, thus reducing the risk that this installation package file is reported poison.
Refer to Fig. 3, third embodiment of the invention provides a kind of supervising device of Viral diagnosis result, This device includes:
Pull module 301, for regularly pulling the packet of installation package file to be checked;
Submit module 302 to, for calling preset automatic test program, to submit this installation kit to be checked to File carries out Viral diagnosis to detection webpage;
Detection module 303, for detecting whether to comprise target word in the webpage returning Viral diagnosis result Sample;
Read module 304, if detect for detection module 303 comprising this target printed words, pre- from this In the configuration file that the automatic test program bag put contains, read the letter related to sending this early warning information Breath;
Sending module 305, for sending this early warning according to this related information that read module 304 reads Information.
Realize the other details of technical scheme with regard to module each in the device of the present embodiment, refer to first The description of embodiment, here is omitted.
In the present embodiment, by the timed task of system, installation package file to be checked is submitted to by triggering automatically When detection webpage carries out containing target printed words in Viral diagnosis, and the testing result of automatic detection return, Send early warning information from trend related personnel, improve monitoring efficiency so that timely process of related personnel should Installation package file to be checked, thus reduce the risk that this installation package file is reported poison.
Refer to Fig. 4, fourth embodiment of the invention provides a kind of supervising device of Viral diagnosis result, This device includes:
Pull module 401, for regularly pulling the packet of installation package file to be checked;
Submit module 402 to, for calling preset automatic test program, to submit this installation kit to be checked to File carries out Viral diagnosis to detection webpage;
Detection module 403, for detecting whether to comprise target word in the webpage returning Viral diagnosis result Sample;
Read module 404, if detect for detection module 403 comprising this target printed words, pre- from this In the configuration file that the automatic test program bag put contains, read the letter related to sending this early warning information Breath;
Sending module 405, for sending this early warning according to this related information that read module 404 reads Information.
Wherein, module 402 is submitted to include:
Open Web page module 4021, for calling this preset automatic test program to open browser, And this detection webpage is opened by browser;
Upper transmission module 4022, for the document uploading control by this detection webpage, uploads this peace to be checked Dress APMB package carries out Viral diagnosis.
Further, pull module 401 also to include:
Add task module 4011, for the instruction of receive user, this installation package file to be checked will be pulled Packet task, be added to the task of the calculated timing automatic daily execution of operating system task Concentrate;
Setup module 4012, for arranging the task triggered time;
Pull submodule 4013, for when reaching this task triggered time, then pulling this installation kit to be checked The packet of file.
This device can further include:
Modification name module 406, the title of the packet for being pulled by dos order modification, Amended title is made to meet the rule that this preset automatic test Automatic Program is processed.
Further, sending module 405, are additionally operable to receive this early warning information according in this related information The title of target person, email address and client account, this early warning information is sent to this The mailbox of target person or client.
Realize the other details of technical scheme with regard to module each in the device of the present embodiment, refer to first And the description of second embodiment, here is omitted.
In the present embodiment, by the timed task of system, installation package file to be checked is submitted to by triggering automatically When detection webpage carries out containing target printed words in Viral diagnosis, and the testing result of automatic detection return, Send early warning information from trend related personnel, improve monitoring efficiency so that timely process of related personnel should Installation package file to be checked, thus reduce the risk that this installation package file is reported poison.
Additionally, the embodiment of the present invention also provides a kind of computer-readable recording medium, it is stored with meter Calculation machine executable instruction, above-mentioned computer-readable recording medium for example, nonvolatile memory is for example CD, hard disk or flash memory.Above-mentioned computer executable instructions are used for allowing computer or similar Arithmetic unit complete the various operations in above-mentioned data processing method.
The above, be only presently preferred embodiments of the present invention, and not the present invention is made with any form On restriction although the present invention is disclosed as above with preferred embodiment, but be not limited to this Bright, any those skilled in the art, in the range of without departing from technical solution of the present invention, on can be utilized The technology contents stating announcement make a little Equivalent embodiments changing or be modified to equivalent variations, as long as being Without departing from technical solution of the present invention content, according to the technical spirit of the present invention, above example is made Any simple modification, equivalent variations and modification, all still fall within the range of technical solution of the present invention.

Claims (10)

1. a kind of monitoring method of Viral diagnosis result is it is characterised in that include:
Timing pulls the packet of installation package file to be checked;
Call preset automatic test program, to submit described installation package file to be checked to detection webpage Carry out Viral diagnosis;
The webpage returning Viral diagnosis result detects whether to comprise target printed words;
If so, then from the configuration file that described preset automatic test program bag contains, read and send out Send described early warning information related information, and described early warning information is sent according to described related information.
2. method according to claim 1 is it is characterised in that described call preset automatization Test program, is included with submitting to described installation package file to be checked to carry out Viral diagnosis to detection webpage:
Call described preset automatic test program to open browser, and opened by browser described Detection webpage;
By the document uploading control of described detection webpage, upload described installation package file to be checked and carry out disease Poison detection.
3. method according to claim 1 is it is characterised in that described timing pulls installation to be checked The packet of APMB package includes:
The instruction of receive user, will pull the task of the packet of described installation package file to be checked, adds To in the task-set of the calculated timing automatic daily execution of operating system task, and task triggering is set Time;
When reaching the described task triggered time, then pull the packet of described installation package file to be checked.
4. method according to claim 1 is it is characterised in that described timing pulls installation to be checked Include after the packet of APMB package:
The title of the packet being pulled by dos order modification is so that amended title meets institute State the rule that preset automatic test Automatic Program is processed.
5. method according to claim 4 it is characterised in that described according to described related letter Breath sends described early warning information and includes:
Title, mailbox ground according to the target person receiving described early warning information in described related information Location and the account of client, described early warning information are sent to mailbox or the client of described target person End.
6. a kind of supervising device of Viral diagnosis result is it is characterised in that include:
Pull module, for regularly pulling the packet of installation package file to be checked;
Submit module to, for calling preset automatic test program, to submit described installation kit to be checked to File carries out Viral diagnosis to detection webpage;
Detection module, for detecting whether to comprise target printed words in the webpage returning Viral diagnosis result;
Read module, if detect for described detection module comprise described target printed words, from described In the configuration file that preset automatic test program bag contains, read related to sending described early warning information Information;
Sending module, the described related information for being read according to described read module sends described pre- Alarming information.
7. device according to claim 6 is it is characterised in that described submission module includes:
Open Web page module, for calling described preset automatic test program to open browser, and Described detection webpage is opened by browser;
Upper transmission module, for the document uploading control by described detection webpage, uploads described peace to be checked Dress APMB package carries out Viral diagnosis.
8. device according to claim 7 is it is characterised in that the described module that pulls includes:
Add task module, for the instruction of receive user, described installation package file to be checked will be pulled The task of packet, is added to the task-set of the calculated timing automatic daily execution of operating system task In;
Setup module, for arranging the task triggered time;
Pull submodule, for when reaching the described task triggered time, then pulling described installation kit to be checked The packet of file.
9. device according to claim 8 is it is characterised in that described device also includes:
Modification name module, for the title of packet pulling is changed by dos order so that Amended title meets the rule that described preset automatic test Automatic Program is processed.
10. device according to claim 9 it is characterised in that
Described sending module, is additionally operable to according to the mesh receiving described early warning information in described related information The account of the title of mark personnel, email address and client, described early warning information is sent to described The mailbox of target person or client.
CN201510422884.4A 2015-07-17 2015-07-17 Virus detection result monitoring method and device Pending CN106355087A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201510422884.4A CN106355087A (en) 2015-07-17 2015-07-17 Virus detection result monitoring method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201510422884.4A CN106355087A (en) 2015-07-17 2015-07-17 Virus detection result monitoring method and device

Publications (1)

Publication Number Publication Date
CN106355087A true CN106355087A (en) 2017-01-25

Family

ID=57842365

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201510422884.4A Pending CN106355087A (en) 2015-07-17 2015-07-17 Virus detection result monitoring method and device

Country Status (1)

Country Link
CN (1) CN106355087A (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109284609A (en) * 2018-08-09 2019-01-29 北京奇虎科技有限公司 A kind of method, apparatus and computer equipment for viral diagnosis
CN109684831A (en) * 2018-06-26 2019-04-26 北京微步在线科技有限公司 A kind of method and apparatus detecting computer network virus

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102801697A (en) * 2011-12-20 2012-11-28 北京安天电子设备有限公司 Malicious code detection method and system based on plurality of URLs (Uniform Resource Locator)
CN103365699A (en) * 2012-12-21 2013-10-23 北京安天电子设备有限公司 System API and running character string extraction method and system based on APK
CN103473509A (en) * 2013-09-30 2013-12-25 清华大学 Android platform malware automatic detecting method
CN103559441A (en) * 2013-10-28 2014-02-05 中国科学院信息工程研究所 Cross-platform detection method and system for malicious files in cloud environment
CN104036189A (en) * 2014-05-16 2014-09-10 北京奇虎科技有限公司 Page distortion detecting method and black link database generating method
CN104715196A (en) * 2015-03-27 2015-06-17 北京奇虎科技有限公司 Static analysis method and system of smart phone application program

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102801697A (en) * 2011-12-20 2012-11-28 北京安天电子设备有限公司 Malicious code detection method and system based on plurality of URLs (Uniform Resource Locator)
CN103365699A (en) * 2012-12-21 2013-10-23 北京安天电子设备有限公司 System API and running character string extraction method and system based on APK
CN103473509A (en) * 2013-09-30 2013-12-25 清华大学 Android platform malware automatic detecting method
CN103559441A (en) * 2013-10-28 2014-02-05 中国科学院信息工程研究所 Cross-platform detection method and system for malicious files in cloud environment
CN104036189A (en) * 2014-05-16 2014-09-10 北京奇虎科技有限公司 Page distortion detecting method and black link database generating method
CN104715196A (en) * 2015-03-27 2015-06-17 北京奇虎科技有限公司 Static analysis method and system of smart phone application program

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109684831A (en) * 2018-06-26 2019-04-26 北京微步在线科技有限公司 A kind of method and apparatus detecting computer network virus
CN109284609A (en) * 2018-08-09 2019-01-29 北京奇虎科技有限公司 A kind of method, apparatus and computer equipment for viral diagnosis
CN109284609B (en) * 2018-08-09 2023-02-17 北京奇虎科技有限公司 Method and device for virus detection and computer equipment

Similar Documents

Publication Publication Date Title
CN106708557B (en) Update processing method and device for terminal application
US10140107B2 (en) Dynamic web application notifications including task bar overlays
US9912698B1 (en) Malicious content analysis using simulated user interaction without user involvement
US8898796B2 (en) Managing network data
US9021469B2 (en) Web application pinning including task bar pinning
US8434135B2 (en) Creating and launching a web application with credentials
EP2580684B1 (en) Creating task sessions
US8595551B2 (en) Web application transitioning and transient web applications
US8863001B2 (en) Web application home button
US11461093B1 (en) Automated generation of release note data objects based at least in part on release-time configuration settings
US20100332280A1 (en) Action-based to-do list
US20140095589A1 (en) Mechanism for initiating behavior in a native client application from a web client application via a custom url scheme
US20110307810A1 (en) List integration
US7908560B2 (en) Method and system for cross-screen component communication in dynamically created composite applications
US20110307794A1 (en) Web application navigation domains
EP2656302A2 (en) Surfacing content including content accessed from jump list tasks and items
CN104268473B (en) Method and device for detecting application programs
EP2410459A1 (en) Unauthorized operation detecting system and unauthorized operation detecting method
CN106355087A (en) Virus detection result monitoring method and device
CN111859231A (en) Webpage monitoring method, equipment, device and computer storage medium
CN103916402B (en) Guard method and the device of file are downloaded to browser
US11914991B1 (en) Modular software application configuration management
CN103019692B (en) A kind of method and apparatus of the process for functional entrance
CN111414525A (en) Data acquisition method and device for small program, computer equipment and storage medium
CN107508807A (en) A kind of web page contents renewal, the method and system of data storage

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20170125