CN106778240A - A kind of virtual machine virus method method and device - Google Patents

A kind of virtual machine virus method method and device Download PDF

Info

Publication number
CN106778240A
CN106778240A CN201611019069.4A CN201611019069A CN106778240A CN 106778240 A CN106778240 A CN 106778240A CN 201611019069 A CN201611019069 A CN 201611019069A CN 106778240 A CN106778240 A CN 106778240A
Authority
CN
China
Prior art keywords
virtual machine
data block
antivirus
monitor
disinfection data
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201611019069.4A
Other languages
Chinese (zh)
Inventor
陈煜文
褚洪洋
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Space Star Technology Co Ltd
Original Assignee
Space Star Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Space Star Technology Co Ltd filed Critical Space Star Technology Co Ltd
Priority to CN201611019069.4A priority Critical patent/CN106778240A/en
Publication of CN106778240A publication Critical patent/CN106778240A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/52Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
    • G06F21/53Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by executing in a restricted environment, e.g. sandbox or secure virtual machine
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Virology (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

The embodiment of the invention discloses a kind of virtual machine virus method and device, it is used to be lifted the overall performance of virtualization system.Monitor of virtual machine is connected with antivirus virtual machine and N number of user virtual machine, and P antivirus engine is deployed with antivirus virtual machine, and be stored with data block in user virtual machine, and the method includes:Monitor of virtual machine determines exist after after disinfection data block in any M user virtual machine of N number of user virtual machine, disinfection data block is treated in acquisition, and will be treated by way of internal memory maps disinfection data block distribute to antivirus virtual machine in Q antivirus engine, and then Q antivirus engine of monitoring treat disinfection data block and killed virus.The embodiment of the present invention disposes special antivirus engine on antivirus virtual machine, so that maintenance only can be updated to the antivirus engine on the antivirus virtual machine, is more suitable for the antivirus pattern of virtualized environment.

Description

A kind of virtual machine virus method method and device
Technical field
The present invention relates to field of computer technology, more particularly to a kind of virtual machine virus method and device.
Background technology
In recent years, Intel Virtualization Technology sustainable development, is widely used.In traditional virtual machine antivirus mode of operation In, the virtual machine of each user is required for installing antivirus software in an operating system, and using the mode of similar non-virtualized, Checking and killing virus are carried out to virtual machine by the antivirus software in system after virtual machine start.However, adopt in this way, by Dispose and update in virtual machine in antivirus software, so as to the operational paradigm of overall cluster can be reduced.
To sum up, need a kind of effective virtual machine virus method badly at present, be used to be lifted the overall performance of virtualization system.
The content of the invention
The embodiment of the present invention provides a kind of virtual machine virus method and device, is used to be lifted the globality of virtualization system Energy.
A kind of virtual machine virus method provided in an embodiment of the present invention, is applied to monitor of virtual machine, the virtual machine prison Control device is connected with antivirus virtual machine and N number of user virtual machine, and P antivirus engine, the use are deployed with the antivirus virtual machine Be stored with data block in the virtual machine of family, and methods described includes:
The monitor of virtual machine determines to exist in any M user virtual machine of N number of user virtual machine to wait to kill virus After data block, disinfection data block is treated described in acquisition;
The monitor of virtual machine treats that disinfection data block distributes to the antivirus void by way of internal memory maps by described Q antivirus engine in plan machine;N, M, P, Q are integer, and N≤M, Q≤P;
The monitor of virtual machine monitors the Q antivirus engine and treats that disinfection data block is killed virus to described.
The embodiment of the present invention provides a kind of monitor of virtual machine, and the monitor of virtual machine is connected with antivirus virtual machine and N Individual user virtual machine, is deployed with P antivirus engine in the antivirus virtual machine, be stored with data block in the user virtual machine, The monitor of virtual machine includes:
Processing module, disinfection data is treated for existing in any M user virtual machine for determining N number of user virtual machine After block, disinfection data block is treated described in acquisition;
Distribute module, for being mapped internal memory by way of treat that disinfection data block distributes to the antivirus virtual machine by described In Q antivirus engine;N, M, P, Q are integer, and N≤M, Q≤P;
Monitoring module, treats that disinfection data block is killed virus for monitoring the Q antivirus engine to described.
The embodiment of the present invention disposes special antivirus engine on antivirus virtual machine, so that can only on the antivirus virtual machine Antivirus engine be updated maintenance, be more suitable for the antivirus pattern of virtualized environment, and distinctive by introducing virtualized environment Internal memory maps, and can accelerate the efficiency of Miscellaneous Documents transmission during antivirus, and then is obviously improved the globality of virtualization system Energy.
Brief description of the drawings
Technical scheme in order to illustrate more clearly the embodiments of the present invention, below will be to that will make needed for embodiment description Accompanying drawing is briefly introduced, it should be apparent that, drawings in the following description are only some embodiments of the present invention, for this For the those of ordinary skill in field, without having to pay creative labor, it can also be obtained according to these accompanying drawings His accompanying drawing.
Fig. 1 is monitor of virtual machine and antivirus virtual machine and the connection diagram of user virtual machine;
Fig. 2 is a kind of corresponding schematic flow sheet of virtual machine virus method provided in an embodiment of the present invention;
Fig. 3 be the embodiment of the present invention in for user virtual machine distribute antivirus engine schematic diagram;
Fig. 4 is a kind of structural representation of monitor of virtual machine provided in an embodiment of the present invention.
Specific embodiment
In order that the object, technical solutions and advantages of the present invention are clearer, below in conjunction with accompanying drawing the present invention is made into One step ground is described in detail, it is clear that described embodiment is only a part of embodiment of the invention, rather than whole implementation Example.Based on the embodiment in the present invention, what those of ordinary skill in the art were obtained under the premise of creative work is not made All other embodiment, belongs to the scope of protection of the invention.
Virtual machine virus method provided in an embodiment of the present invention can be applied to monitor of virtual machine.Monitor of virtual machine can be even Antivirus virtual machine and N number of user virtual machine are connected to, as shown in figure 1, for monitor of virtual machine is virtual with antivirus virtual machine and user The connection diagram of machine.
At least one antivirus engine can be deployed with antivirus virtual machine, be disposed in virtual machine of being killed virus in the embodiment of the present invention The quantity of antivirus engine can increase and decrease according to actual needs, not limit specifically.
The operating system that user uses exists in the form of virtual machine, and the object of antivirus virtual machine antivirus is operating system In partial document or all files in operating system, in operating system file correspondence user virtual machine in store number According to block.
Above-mentioned antivirus virtual machine can be the virtual machine for being deployed with antivirus engine, and user virtual machine can be the data that are stored with The virtual machine of block.
Fig. 2 is a kind of corresponding schematic flow sheet of virtual machine virus method provided in an embodiment of the present invention.As shown in Fig. 2 The method includes:
Step 201, monitor of virtual machine determines to exist in any M user virtual machine of N number of user virtual machine to treat After disinfection data block, disinfection data block is treated described in acquisition;
Step 202, monitor of virtual machine treats that disinfection data block distributes to described killing by way of internal memory maps by described Q antivirus engine in malicious virtual machine;N, M, P, Q are integer, and N≤M, Q≤P;
Step 203, monitor of virtual machine monitors the Q antivirus engine and treats that disinfection data block is killed virus to described.
The embodiment of the present invention disposes special antivirus engine on antivirus virtual machine, so that can only on the antivirus virtual machine Antivirus engine be updated maintenance, be more suitable for the antivirus pattern of virtualized environment, and distinctive by introducing virtualized environment Internal memory maps, and can accelerate the efficiency of Miscellaneous Documents transmission during antivirus, and then is obviously improved the globality of virtualization system Energy.
Specifically, in step 201, the monitor of virtual machine is determined as follows any M user Exist in virtual machine and treat disinfection data block:
The monitor of virtual machine receives the reporting information of any M user virtual machine;Any M user is empty The reporting information of any user virtual machine in plan machine includes the mark for treating disinfection data block in any user virtual machine Knowledge information;The monitor of virtual machine determines to exist in any M user virtual machine and waits to kill virus according to the reporting information Data block.
In the embodiment of the present invention, triggering user virtual machine has various to the mode of monitor of virtual machine reporting information, for example, User can be during using user virtual machine, the partial document in selection operation system, actively initiates antivirus request;Pipe Reason person can select specific user virtual machine by corresponding management platform, and whole user virtual machine is killed virus, or The file fixed to the sorting of user virtual machine middle part is killed virus;Or, or by system background automatically initiate for choosing File in fixed user virtual machine or user virtual machine is killed virus.It is chosen to need the file correspondence user for being killed virus empty Data block in plan machine, and then user virtual machine can will treat the identification-information reporting of disinfection data block to monitor of virtual machine.
It should be noted that swept according to setting cycle or in real time by monitor of virtual machine in the embodiment of the present invention Each user virtual machine is retouched, and then is determined and is treated disinfection data block;Or, automatic antivirus is set by management platform by keeper Rule, monitor of virtual machine kills virus according to setting cycle or according to specified conditions to virtual machine.
In step 202, by authorizing, user virtual machine is set up in mapping to monitor of virtual machine and the antivirus of antivirus engine place is empty Shared drive between plan machine, will treat disinfection data block be mapped to the antivirus engine where antivirus virtual machine in, and distribute to Q Individual antivirus engine.
Specifically, monitor of virtual machine treats that disinfection data block distributes to the antivirus virtually by described in the following way Q antivirus engine in machine:
The monitor of virtual machine treats the quantity of disinfection data block for K is individual described in determining, K is integer;The virtual machine prison Control device treated for K in disinfection data block it is any treat disinfection data block, calculate any cryptographic Hash for treating disinfection data block, The quantity of the antivirus engine in any cryptographic Hash for treating disinfection data block and the antivirus virtual machine, it is determined that described One treats the corresponding target antivirus engine of disinfection data block, and any treats that disinfection data block is distributed to the target antivirus and drawn by described Hold up.
For example, monitor of virtual machine calculating treats that the cryptographic Hash of disinfection data block a is hash (object), using the value to working as The quantity P modulus of preceding antivirus engine, according to result sel=hash (object) %N, the sel antivirus engine of selection is used as treating The corresponding target antivirus engines of disinfection data block a, and will treat that disinfection data block a distributes to the sel antivirus engine and killed virus.
In the embodiment of the present invention, monitor of virtual machine can also be connected with log server, as shown in fig. 1.Correspondingly, In step 203, monitor of virtual machine monitors the Q antivirus engine and treats that disinfection data block is killed virus to described, including:For Any antivirus engine in the Q antivirus engine, if monitor of virtual machine determines to distribute to any antivirus engine Treat that disinfection data block is multiple, then monitor any antivirus engine and treat disinfection data to the multiple according to preset order rule Block is killed virus.Wherein, preset order rule can be FIFO rule.And, monitor of virtual machine determines that the Q is killed Malicious engine after disinfection data block completes antivirus, the antivirus daily record that the Q antivirus engine is generated is reflected by internal memory to described The mode penetrated is transmitted to the log server.Wherein, log server can only have one, for receiving all antivirus engines Antivirus daily record.
Specifically, Q antivirus engine treats that disinfection data block is killed virus to distribution respectively, and is existed according to antivirus result Corresponding antivirus daily record is generated in antivirus virtual machine, monitor of virtual machine is set up where the antivirus engine by authorizing mapping The shared drive of antivirus virtual machine and the log server, antivirus daily record is mapped in the log server, is united One filing management, and log query service can be provided to system manager.
It should be noted that in the embodiment of the present invention, each user virtual machine is not bound with antivirus engine, also It is to say, user virtual machine may perform antivirus during being killed virus every time by different antivirus engines.Such as Fig. 3 institutes Show there may be a distribute module in monitor of virtual machine, for distributing corresponding antivirus engine for user virtual machine.
It is of the invention mainly to be drawn by building one or more antivirus being deployed in antivirus virtual machine in virtualized environment Hold up, and a log server for storage antivirus daily record.Monitor of virtual machine, antivirus engine and log server are mutually assisted Together, the antivirus work to user virtual machine is completed.
For above method flow, the embodiment of the present invention also provides a kind of monitor of virtual machine, the monitor of virtual machine Particular content is referred to above method implementation.
Fig. 4 is a kind of structural representation of monitor of virtual machine provided in an embodiment of the present invention.The monitor of virtual machine Antivirus virtual machine and N number of user virtual machine are connected with, P antivirus engine is deployed with the antivirus virtual machine, the user is empty Be stored with data block in plan machine, as shown in figure 4, the monitor of virtual machine includes:
Processing module 401, waits to kill virus for existing in any M user virtual machine for determining N number of user virtual machine After data block, disinfection data block is treated described in acquisition;
Distribute module 402, for being mapped internal memory by way of to treat that disinfection data block distributes to the antivirus empty by described Q antivirus engine in plan machine;N, M, P, Q are integer, and N≤M, Q≤P;
Monitoring module 403, treats that disinfection data block is killed virus for monitoring the Q antivirus engine to described.
Alternatively, the monitor of virtual machine is also associated with log server;
The monitoring module 403 specifically for:
Determine the Q antivirus engine to it is described after disinfection data block complete antivirus after, by the Q antivirus engine generate Antivirus daily record internal memory map by way of transmit to the log server.
Alternatively, the processing module 401 is specifically for being determined as follows any M user virtual machine Disinfection data block is treated in middle presence:
Receive the reporting information of any M user virtual machine;Any user in any M user virtual machine The reporting information of virtual machine includes the identification information for treating disinfection data block in any user virtual machine;
According to the reporting information, determine to exist in any M user virtual machine and treat disinfection data block.
Alternatively, the distribute module 402 by described specifically for treating that disinfection data block distributes to institute in the following way State Q antivirus engine in antivirus virtual machine:
It is determined that the quantity for treating disinfection data block is K, K is integer;
Treated for K in disinfection data block it is any treat disinfection data block, calculate any Kazakhstan for treating disinfection data block Uncommon value, the quantity of the antivirus engine in any cryptographic Hash for treating disinfection data block and the antivirus virtual machine, it is determined that It is described it is any treat the corresponding target antivirus engine of disinfection data block, and any treat that disinfection data block distributes to the target by described Antivirus engine.
Alternatively, the monitoring module 403 specifically for:
It is directed to any antivirus engine in the Q antivirus engine, however, it is determined that distribute to any antivirus engine Treat that disinfection data block is multiple, then monitor any antivirus engine and treat disinfection data to the multiple according to preset order rule Block is killed virus.
It can be seen from the above:Virus method in the embodiment of the present invention can be applied to monitor of virtual machine, virtually Monitor unit is connected with antivirus virtual machine and N number of user virtual machine, and P antivirus engine, Yong Huxu are deployed with antivirus virtual machine Be stored with data block in plan machine, and the method includes:Monitor of virtual machine determines that any M user of N number of user virtual machine is virtual Exist in machine after after disinfection data block, disinfection data block is treated in acquisition, and will treat disinfection data block point by way of internal memory maps Q antivirus engine in dispensing antivirus virtual machine, and then Q antivirus engine of monitoring treat disinfection data block and killed virus.This hair Bright embodiment disposes special antivirus engine on antivirus virtual machine, so as to only can enter to the antivirus engine on the antivirus virtual machine Row updating maintenance, is more suitable for the antivirus pattern of virtualized environment, and is mapped by introducing the distinctive internal memory of virtualized environment, can The efficiency of Miscellaneous Documents transmission during accelerating to kill virus, and then it is obviously improved the overall performance of virtualization system.
It should be understood by those skilled in the art that, embodiments of the invention can be provided as method or computer program product. Therefore, the present invention can be using the embodiment in terms of complete hardware embodiment, complete software embodiment or combination software and hardware Form.And, the present invention can be used to be can use in one or more computers for wherein including computer usable program code and deposited The shape of the computer program product implemented on storage media (including but not limited to magnetic disk storage, CD-ROM, optical memory etc.) Formula.
The present invention is the flow with reference to method according to embodiments of the present invention, equipment (system) and computer program product Figure and/or block diagram are described.It should be understood that every first-class during flow chart and/or block diagram can be realized by computer program instructions The combination of flow and/or square frame in journey and/or square frame and flow chart and/or block diagram.These computer programs can be provided The processor of all-purpose computer, special-purpose computer, Embedded Processor or other programmable data processing devices is instructed to produce A raw machine so that produced for reality by the instruction of computer or the computing device of other programmable data processing devices The device of the function of being specified in present one flow of flow chart or multiple one square frame of flow and/or block diagram or multiple square frames.
These computer program instructions may be alternatively stored in can guide computer or other programmable data processing devices with spy In determining the computer-readable memory that mode works so that instruction of the storage in the computer-readable memory is produced and include finger Make the manufacture of device, the command device realize in one flow of flow chart or multiple one square frame of flow and/or block diagram or The function of being specified in multiple square frames.
These computer program instructions can be also loaded into computer or other programmable data processing devices so that in meter Series of operation steps is performed on calculation machine or other programmable devices to produce computer implemented treatment, so as in computer or The instruction performed on other programmable devices is provided for realizing in one flow of flow chart or multiple flows and/or block diagram one The step of function of being specified in individual square frame or multiple square frames.
, but those skilled in the art once know basic creation although preferred embodiments of the present invention have been described Property concept, then can make other change and modification to these embodiments.So, appended claims are intended to be construed to include excellent Select embodiment and fall into having altered and changing for the scope of the invention.
Obviously, those skilled in the art can carry out various changes and modification without deviating from essence of the invention to the present invention God and scope.So, if these modifications of the invention and modification belong to the scope of the claims in the present invention and its equivalent technologies Within, then the present invention is also intended to comprising these changes and modification.

Claims (10)

1. a kind of virtual machine virus method, it is characterised in that be applied to monitor of virtual machine, the monitor of virtual machine is connected with Antivirus virtual machine and N number of user virtual machine, are deployed with P antivirus engine, in the user virtual machine in the antivirus virtual machine Be stored with data block, and methods described includes:
The monitor of virtual machine determines to exist in any M user virtual machine of N number of user virtual machine to treat disinfection data After block, disinfection data block is treated described in acquisition;
The monitor of virtual machine treats that disinfection data block distributes to the antivirus virtual machine by way of internal memory maps by described In Q antivirus engine;N, M, P, Q are integer, and N≤M, Q≤P;
The monitor of virtual machine monitors the Q antivirus engine and treats that disinfection data block is killed virus to described.
2. method according to claim 1, it is characterised in that the monitor of virtual machine is also associated with log server;
The monitor of virtual machine monitors the Q antivirus engine and treats that disinfection data block is killed virus to described, including:
The monitor of virtual machine determine the Q antivirus engine to described after disinfection data block completes antivirus, by the Q The antivirus daily record of antivirus engine generation is transmitted to the log server by way of internal memory maps.
3. method according to claim 1, it is characterised in that the monitor of virtual machine is determined as follows described Exist in any M user virtual machine and treat disinfection data block:
The monitor of virtual machine receives the reporting information of any M user virtual machine;Any M user virtual machine In any user virtual machine the reporting information mark for the treating disinfection data block letter that includes in any user virtual machine Breath;
The monitor of virtual machine determines there is number to be killed virus in any M user virtual machine according to the reporting information According to block.
4. method according to claim 1, it is characterised in that the monitor of virtual machine is treated described in the following way Disinfection data block distributes to Q antivirus engine in the antivirus virtual machine:
The monitor of virtual machine treats the quantity of disinfection data block for K is individual described in determining, K is integer;
The monitor of virtual machine treated for K in disinfection data block it is any treat disinfection data block, calculate and described any wait to kill The cryptographic Hash of malicious data block, according to the antivirus engine in any cryptographic Hash for treating disinfection data block and the antivirus virtual machine Quantity, determine it is described it is any treat the corresponding target antivirus engine of disinfection data block, and any treat disinfection data block point by described Target antivirus engine described in dispensing.
5. the method according to any one of claim 1-4, it is characterised in that the monitor of virtual machine monitors the Q Individual antivirus engine treats that disinfection data block is killed virus to described, including:
Any antivirus engine in the Q antivirus engine, the monitor of virtual machine are directed to if it is determined that distributing to described appointing One antivirus engine treat disinfection data block for multiple, then monitor any antivirus engine according to preset order rule to described many It is individual to treat that disinfection data block is killed virus.
6. a kind of monitor of virtual machine, it is characterised in that the monitor of virtual machine is connected with antivirus virtual machine and N number of user is empty Plan machine, is deployed with P antivirus engine in the antivirus virtual machine, be stored with data block in the user virtual machine, described virtual Monitor unit includes:
Processing module, disinfection data block is treated for existing in any M user virtual machine for determining N number of user virtual machine Afterwards, disinfection data block is treated described in obtaining;
Distribute module, for being mapped internal memory by way of by it is described treat disinfection data block distribute to it is described antivirus virtual machine in Q antivirus engine;N, M, P, Q are integer, and N≤M, Q≤P;
Monitoring module, treats that disinfection data block is killed virus for monitoring the Q antivirus engine to described.
7. monitor of virtual machine according to claim 6, it is characterised in that the monitor of virtual machine is also associated with daily record Server;
The monitoring module specifically for:
Determine the Q antivirus engine to it is described after disinfection data block complete antivirus after, by the Q antivirus engine generation kill Malicious daily record is transmitted to the log server by way of internal memory maps.
8. monitor of virtual machine according to claim 6, it is characterised in that the processing module is specifically for by such as Under type determines to exist in any M user virtual machine treats disinfection data block:
Receive the reporting information of any M user virtual machine;Any user in any M user virtual machine is virtual The reporting information of machine includes the identification information for treating disinfection data block in any user virtual machine;
According to the reporting information, determine to exist in any M user virtual machine and treat disinfection data block.
9. monitor of virtual machine according to claim 6, it is characterised in that the distribute module is specifically for by such as Under type by it is described treat disinfection data block distribute to it is described antivirus virtual machine in Q antivirus engine:
It is determined that the quantity for treating disinfection data block is K, K is integer;
Treated for K in disinfection data block it is any treat disinfection data block, calculate any cryptographic Hash for treating disinfection data block, The quantity of the antivirus engine in any cryptographic Hash for treating disinfection data block and the antivirus virtual machine, it is determined that described One treats the corresponding target antivirus engine of disinfection data block, and any treats that disinfection data block is distributed to the target antivirus and drawn by described Hold up.
10. the monitor of virtual machine according to any one of claim 6-9, it is characterised in that the monitoring module is specific For:
Be directed to any antivirus engine in the Q antivirus engine, however, it is determined that distribute to any antivirus engine wait kill Malicious data block is multiple, then monitor any antivirus engine and treat that disinfection data block enters to the multiple according to preset order rule Row antivirus.
CN201611019069.4A 2016-11-18 2016-11-18 A kind of virtual machine virus method method and device Pending CN106778240A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201611019069.4A CN106778240A (en) 2016-11-18 2016-11-18 A kind of virtual machine virus method method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201611019069.4A CN106778240A (en) 2016-11-18 2016-11-18 A kind of virtual machine virus method method and device

Publications (1)

Publication Number Publication Date
CN106778240A true CN106778240A (en) 2017-05-31

Family

ID=58969025

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201611019069.4A Pending CN106778240A (en) 2016-11-18 2016-11-18 A kind of virtual machine virus method method and device

Country Status (1)

Country Link
CN (1) CN106778240A (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107545183A (en) * 2017-09-15 2018-01-05 郑州云海信息技术有限公司 A kind of virus method, apparatus and system
CN109948341A (en) * 2019-04-02 2019-06-28 深信服科技股份有限公司 A kind of file scanning method, system, device, medium

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102081714A (en) * 2011-01-25 2011-06-01 潘燕辉 Cloud antivirus method based on server feedback
CN102523215A (en) * 2011-12-15 2012-06-27 北京海云捷迅科技有限公司 Virtual machine (VM) online antivirus system based on KVM virtualization platform
CN105117649A (en) * 2015-07-30 2015-12-02 中国科学院计算技术研究所 Anti-virus method and anti-virus system for virtual machine
CN105320884A (en) * 2015-11-02 2016-02-10 南京安贤信息科技有限公司 Security protection method and system for virtual machine
CN105528543A (en) * 2015-12-23 2016-04-27 北京奇虎科技有限公司 Remote antivirus method, client, console and system

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102081714A (en) * 2011-01-25 2011-06-01 潘燕辉 Cloud antivirus method based on server feedback
CN102523215A (en) * 2011-12-15 2012-06-27 北京海云捷迅科技有限公司 Virtual machine (VM) online antivirus system based on KVM virtualization platform
CN105117649A (en) * 2015-07-30 2015-12-02 中国科学院计算技术研究所 Anti-virus method and anti-virus system for virtual machine
CN105320884A (en) * 2015-11-02 2016-02-10 南京安贤信息科技有限公司 Security protection method and system for virtual machine
CN105528543A (en) * 2015-12-23 2016-04-27 北京奇虎科技有限公司 Remote antivirus method, client, console and system

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107545183A (en) * 2017-09-15 2018-01-05 郑州云海信息技术有限公司 A kind of virus method, apparatus and system
CN109948341A (en) * 2019-04-02 2019-06-28 深信服科技股份有限公司 A kind of file scanning method, system, device, medium
CN109948341B (en) * 2019-04-02 2023-02-03 深信服科技股份有限公司 File scanning method, system, device and medium

Similar Documents

Publication Publication Date Title
JP6522707B2 (en) Method and apparatus for coping with malware
CN102262557B (en) Method for constructing virtual machine monitor by bus architecture and performance service framework
DE112019005604T5 (en) FUNCTION-AS-A-SERVICE SYSTEM IMPROVEMENTS (FAAS SYSTEM IMPROVEMENTS)
US8752034B2 (en) Memoization configuration file consumed at runtime
CN107944232A (en) A kind of design method and system of the Active Defending System Against based on white list technology
US20130074055A1 (en) Memoization Configuration File Consumed at Compile Time
CN103902885A (en) Virtual machine security isolation system and method oriented to multi-security-level virtual desktop system
CN103679039B (en) Secure storage method of data and device
CN109815698A (en) Malware is determined using firmware
US8813229B2 (en) Apparatus, system, and method for preventing infection by malicious code
CN103618652A (en) Audit and depth analysis system and audit and depth analysis method of business data
CN110083604A (en) A kind of data really weigh method and device
CN103701783A (en) Preprocessing unit, data processing system consisting of same, and processing method
CN106453311A (en) Register and login system and method for biological characteristic distributed identity authentication
KR102022058B1 (en) Method and system for detecting counterfeit of web page
CN106778240A (en) A kind of virtual machine virus method method and device
Deng et al. A secure container placement strategy using deep reinforcement learning in cloud
KR101994664B1 (en) Vulnerability checking system based on cloud service
CN110889112B (en) Software operation unified control system and method based on white list mechanism
CN106101086A (en) The cloud detection method of optic of program file and system, client, cloud server
CN113138838B (en) Virtual machine placement method based on artificial bee colony algorithm
CN103677769B (en) Instruction recombination method and device
CN106850641A (en) A kind of information transmission and control method and system based on cloud computing safety management platform
US10997287B2 (en) Real-time monitoring and alerting for directory object update processing
CN112333025A (en) Network security simulation training method, device and system

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20170531