CN106778240A - A kind of virtual machine virus method method and device - Google Patents
A kind of virtual machine virus method method and device Download PDFInfo
- Publication number
- CN106778240A CN106778240A CN201611019069.4A CN201611019069A CN106778240A CN 106778240 A CN106778240 A CN 106778240A CN 201611019069 A CN201611019069 A CN 201611019069A CN 106778240 A CN106778240 A CN 106778240A
- Authority
- CN
- China
- Prior art keywords
- virtual machine
- data block
- antivirus
- monitor
- disinfection data
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/52—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
- G06F21/53—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by executing in a restricted environment, e.g. sandbox or secure virtual machine
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
The embodiment of the invention discloses a kind of virtual machine virus method and device, it is used to be lifted the overall performance of virtualization system.Monitor of virtual machine is connected with antivirus virtual machine and N number of user virtual machine, and P antivirus engine is deployed with antivirus virtual machine, and be stored with data block in user virtual machine, and the method includes:Monitor of virtual machine determines exist after after disinfection data block in any M user virtual machine of N number of user virtual machine, disinfection data block is treated in acquisition, and will be treated by way of internal memory maps disinfection data block distribute to antivirus virtual machine in Q antivirus engine, and then Q antivirus engine of monitoring treat disinfection data block and killed virus.The embodiment of the present invention disposes special antivirus engine on antivirus virtual machine, so that maintenance only can be updated to the antivirus engine on the antivirus virtual machine, is more suitable for the antivirus pattern of virtualized environment.
Description
Technical field
The present invention relates to field of computer technology, more particularly to a kind of virtual machine virus method and device.
Background technology
In recent years, Intel Virtualization Technology sustainable development, is widely used.In traditional virtual machine antivirus mode of operation
In, the virtual machine of each user is required for installing antivirus software in an operating system, and using the mode of similar non-virtualized,
Checking and killing virus are carried out to virtual machine by the antivirus software in system after virtual machine start.However, adopt in this way, by
Dispose and update in virtual machine in antivirus software, so as to the operational paradigm of overall cluster can be reduced.
To sum up, need a kind of effective virtual machine virus method badly at present, be used to be lifted the overall performance of virtualization system.
The content of the invention
The embodiment of the present invention provides a kind of virtual machine virus method and device, is used to be lifted the globality of virtualization system
Energy.
A kind of virtual machine virus method provided in an embodiment of the present invention, is applied to monitor of virtual machine, the virtual machine prison
Control device is connected with antivirus virtual machine and N number of user virtual machine, and P antivirus engine, the use are deployed with the antivirus virtual machine
Be stored with data block in the virtual machine of family, and methods described includes:
The monitor of virtual machine determines to exist in any M user virtual machine of N number of user virtual machine to wait to kill virus
After data block, disinfection data block is treated described in acquisition;
The monitor of virtual machine treats that disinfection data block distributes to the antivirus void by way of internal memory maps by described
Q antivirus engine in plan machine;N, M, P, Q are integer, and N≤M, Q≤P;
The monitor of virtual machine monitors the Q antivirus engine and treats that disinfection data block is killed virus to described.
The embodiment of the present invention provides a kind of monitor of virtual machine, and the monitor of virtual machine is connected with antivirus virtual machine and N
Individual user virtual machine, is deployed with P antivirus engine in the antivirus virtual machine, be stored with data block in the user virtual machine,
The monitor of virtual machine includes:
Processing module, disinfection data is treated for existing in any M user virtual machine for determining N number of user virtual machine
After block, disinfection data block is treated described in acquisition;
Distribute module, for being mapped internal memory by way of treat that disinfection data block distributes to the antivirus virtual machine by described
In Q antivirus engine;N, M, P, Q are integer, and N≤M, Q≤P;
Monitoring module, treats that disinfection data block is killed virus for monitoring the Q antivirus engine to described.
The embodiment of the present invention disposes special antivirus engine on antivirus virtual machine, so that can only on the antivirus virtual machine
Antivirus engine be updated maintenance, be more suitable for the antivirus pattern of virtualized environment, and distinctive by introducing virtualized environment
Internal memory maps, and can accelerate the efficiency of Miscellaneous Documents transmission during antivirus, and then is obviously improved the globality of virtualization system
Energy.
Brief description of the drawings
Technical scheme in order to illustrate more clearly the embodiments of the present invention, below will be to that will make needed for embodiment description
Accompanying drawing is briefly introduced, it should be apparent that, drawings in the following description are only some embodiments of the present invention, for this
For the those of ordinary skill in field, without having to pay creative labor, it can also be obtained according to these accompanying drawings
His accompanying drawing.
Fig. 1 is monitor of virtual machine and antivirus virtual machine and the connection diagram of user virtual machine;
Fig. 2 is a kind of corresponding schematic flow sheet of virtual machine virus method provided in an embodiment of the present invention;
Fig. 3 be the embodiment of the present invention in for user virtual machine distribute antivirus engine schematic diagram;
Fig. 4 is a kind of structural representation of monitor of virtual machine provided in an embodiment of the present invention.
Specific embodiment
In order that the object, technical solutions and advantages of the present invention are clearer, below in conjunction with accompanying drawing the present invention is made into
One step ground is described in detail, it is clear that described embodiment is only a part of embodiment of the invention, rather than whole implementation
Example.Based on the embodiment in the present invention, what those of ordinary skill in the art were obtained under the premise of creative work is not made
All other embodiment, belongs to the scope of protection of the invention.
Virtual machine virus method provided in an embodiment of the present invention can be applied to monitor of virtual machine.Monitor of virtual machine can be even
Antivirus virtual machine and N number of user virtual machine are connected to, as shown in figure 1, for monitor of virtual machine is virtual with antivirus virtual machine and user
The connection diagram of machine.
At least one antivirus engine can be deployed with antivirus virtual machine, be disposed in virtual machine of being killed virus in the embodiment of the present invention
The quantity of antivirus engine can increase and decrease according to actual needs, not limit specifically.
The operating system that user uses exists in the form of virtual machine, and the object of antivirus virtual machine antivirus is operating system
In partial document or all files in operating system, in operating system file correspondence user virtual machine in store number
According to block.
Above-mentioned antivirus virtual machine can be the virtual machine for being deployed with antivirus engine, and user virtual machine can be the data that are stored with
The virtual machine of block.
Fig. 2 is a kind of corresponding schematic flow sheet of virtual machine virus method provided in an embodiment of the present invention.As shown in Fig. 2
The method includes:
Step 201, monitor of virtual machine determines to exist in any M user virtual machine of N number of user virtual machine to treat
After disinfection data block, disinfection data block is treated described in acquisition;
Step 202, monitor of virtual machine treats that disinfection data block distributes to described killing by way of internal memory maps by described
Q antivirus engine in malicious virtual machine;N, M, P, Q are integer, and N≤M, Q≤P;
Step 203, monitor of virtual machine monitors the Q antivirus engine and treats that disinfection data block is killed virus to described.
The embodiment of the present invention disposes special antivirus engine on antivirus virtual machine, so that can only on the antivirus virtual machine
Antivirus engine be updated maintenance, be more suitable for the antivirus pattern of virtualized environment, and distinctive by introducing virtualized environment
Internal memory maps, and can accelerate the efficiency of Miscellaneous Documents transmission during antivirus, and then is obviously improved the globality of virtualization system
Energy.
Specifically, in step 201, the monitor of virtual machine is determined as follows any M user
Exist in virtual machine and treat disinfection data block:
The monitor of virtual machine receives the reporting information of any M user virtual machine;Any M user is empty
The reporting information of any user virtual machine in plan machine includes the mark for treating disinfection data block in any user virtual machine
Knowledge information;The monitor of virtual machine determines to exist in any M user virtual machine and waits to kill virus according to the reporting information
Data block.
In the embodiment of the present invention, triggering user virtual machine has various to the mode of monitor of virtual machine reporting information, for example,
User can be during using user virtual machine, the partial document in selection operation system, actively initiates antivirus request;Pipe
Reason person can select specific user virtual machine by corresponding management platform, and whole user virtual machine is killed virus, or
The file fixed to the sorting of user virtual machine middle part is killed virus;Or, or by system background automatically initiate for choosing
File in fixed user virtual machine or user virtual machine is killed virus.It is chosen to need the file correspondence user for being killed virus empty
Data block in plan machine, and then user virtual machine can will treat the identification-information reporting of disinfection data block to monitor of virtual machine.
It should be noted that swept according to setting cycle or in real time by monitor of virtual machine in the embodiment of the present invention
Each user virtual machine is retouched, and then is determined and is treated disinfection data block;Or, automatic antivirus is set by management platform by keeper
Rule, monitor of virtual machine kills virus according to setting cycle or according to specified conditions to virtual machine.
In step 202, by authorizing, user virtual machine is set up in mapping to monitor of virtual machine and the antivirus of antivirus engine place is empty
Shared drive between plan machine, will treat disinfection data block be mapped to the antivirus engine where antivirus virtual machine in, and distribute to Q
Individual antivirus engine.
Specifically, monitor of virtual machine treats that disinfection data block distributes to the antivirus virtually by described in the following way
Q antivirus engine in machine:
The monitor of virtual machine treats the quantity of disinfection data block for K is individual described in determining, K is integer;The virtual machine prison
Control device treated for K in disinfection data block it is any treat disinfection data block, calculate any cryptographic Hash for treating disinfection data block,
The quantity of the antivirus engine in any cryptographic Hash for treating disinfection data block and the antivirus virtual machine, it is determined that described
One treats the corresponding target antivirus engine of disinfection data block, and any treats that disinfection data block is distributed to the target antivirus and drawn by described
Hold up.
For example, monitor of virtual machine calculating treats that the cryptographic Hash of disinfection data block a is hash (object), using the value to working as
The quantity P modulus of preceding antivirus engine, according to result sel=hash (object) %N, the sel antivirus engine of selection is used as treating
The corresponding target antivirus engines of disinfection data block a, and will treat that disinfection data block a distributes to the sel antivirus engine and killed virus.
In the embodiment of the present invention, monitor of virtual machine can also be connected with log server, as shown in fig. 1.Correspondingly,
In step 203, monitor of virtual machine monitors the Q antivirus engine and treats that disinfection data block is killed virus to described, including:For
Any antivirus engine in the Q antivirus engine, if monitor of virtual machine determines to distribute to any antivirus engine
Treat that disinfection data block is multiple, then monitor any antivirus engine and treat disinfection data to the multiple according to preset order rule
Block is killed virus.Wherein, preset order rule can be FIFO rule.And, monitor of virtual machine determines that the Q is killed
Malicious engine after disinfection data block completes antivirus, the antivirus daily record that the Q antivirus engine is generated is reflected by internal memory to described
The mode penetrated is transmitted to the log server.Wherein, log server can only have one, for receiving all antivirus engines
Antivirus daily record.
Specifically, Q antivirus engine treats that disinfection data block is killed virus to distribution respectively, and is existed according to antivirus result
Corresponding antivirus daily record is generated in antivirus virtual machine, monitor of virtual machine is set up where the antivirus engine by authorizing mapping
The shared drive of antivirus virtual machine and the log server, antivirus daily record is mapped in the log server, is united
One filing management, and log query service can be provided to system manager.
It should be noted that in the embodiment of the present invention, each user virtual machine is not bound with antivirus engine, also
It is to say, user virtual machine may perform antivirus during being killed virus every time by different antivirus engines.Such as Fig. 3 institutes
Show there may be a distribute module in monitor of virtual machine, for distributing corresponding antivirus engine for user virtual machine.
It is of the invention mainly to be drawn by building one or more antivirus being deployed in antivirus virtual machine in virtualized environment
Hold up, and a log server for storage antivirus daily record.Monitor of virtual machine, antivirus engine and log server are mutually assisted
Together, the antivirus work to user virtual machine is completed.
For above method flow, the embodiment of the present invention also provides a kind of monitor of virtual machine, the monitor of virtual machine
Particular content is referred to above method implementation.
Fig. 4 is a kind of structural representation of monitor of virtual machine provided in an embodiment of the present invention.The monitor of virtual machine
Antivirus virtual machine and N number of user virtual machine are connected with, P antivirus engine is deployed with the antivirus virtual machine, the user is empty
Be stored with data block in plan machine, as shown in figure 4, the monitor of virtual machine includes:
Processing module 401, waits to kill virus for existing in any M user virtual machine for determining N number of user virtual machine
After data block, disinfection data block is treated described in acquisition;
Distribute module 402, for being mapped internal memory by way of to treat that disinfection data block distributes to the antivirus empty by described
Q antivirus engine in plan machine;N, M, P, Q are integer, and N≤M, Q≤P;
Monitoring module 403, treats that disinfection data block is killed virus for monitoring the Q antivirus engine to described.
Alternatively, the monitor of virtual machine is also associated with log server;
The monitoring module 403 specifically for:
Determine the Q antivirus engine to it is described after disinfection data block complete antivirus after, by the Q antivirus engine generate
Antivirus daily record internal memory map by way of transmit to the log server.
Alternatively, the processing module 401 is specifically for being determined as follows any M user virtual machine
Disinfection data block is treated in middle presence:
Receive the reporting information of any M user virtual machine;Any user in any M user virtual machine
The reporting information of virtual machine includes the identification information for treating disinfection data block in any user virtual machine;
According to the reporting information, determine to exist in any M user virtual machine and treat disinfection data block.
Alternatively, the distribute module 402 by described specifically for treating that disinfection data block distributes to institute in the following way
State Q antivirus engine in antivirus virtual machine:
It is determined that the quantity for treating disinfection data block is K, K is integer;
Treated for K in disinfection data block it is any treat disinfection data block, calculate any Kazakhstan for treating disinfection data block
Uncommon value, the quantity of the antivirus engine in any cryptographic Hash for treating disinfection data block and the antivirus virtual machine, it is determined that
It is described it is any treat the corresponding target antivirus engine of disinfection data block, and any treat that disinfection data block distributes to the target by described
Antivirus engine.
Alternatively, the monitoring module 403 specifically for:
It is directed to any antivirus engine in the Q antivirus engine, however, it is determined that distribute to any antivirus engine
Treat that disinfection data block is multiple, then monitor any antivirus engine and treat disinfection data to the multiple according to preset order rule
Block is killed virus.
It can be seen from the above:Virus method in the embodiment of the present invention can be applied to monitor of virtual machine, virtually
Monitor unit is connected with antivirus virtual machine and N number of user virtual machine, and P antivirus engine, Yong Huxu are deployed with antivirus virtual machine
Be stored with data block in plan machine, and the method includes:Monitor of virtual machine determines that any M user of N number of user virtual machine is virtual
Exist in machine after after disinfection data block, disinfection data block is treated in acquisition, and will treat disinfection data block point by way of internal memory maps
Q antivirus engine in dispensing antivirus virtual machine, and then Q antivirus engine of monitoring treat disinfection data block and killed virus.This hair
Bright embodiment disposes special antivirus engine on antivirus virtual machine, so as to only can enter to the antivirus engine on the antivirus virtual machine
Row updating maintenance, is more suitable for the antivirus pattern of virtualized environment, and is mapped by introducing the distinctive internal memory of virtualized environment, can
The efficiency of Miscellaneous Documents transmission during accelerating to kill virus, and then it is obviously improved the overall performance of virtualization system.
It should be understood by those skilled in the art that, embodiments of the invention can be provided as method or computer program product.
Therefore, the present invention can be using the embodiment in terms of complete hardware embodiment, complete software embodiment or combination software and hardware
Form.And, the present invention can be used to be can use in one or more computers for wherein including computer usable program code and deposited
The shape of the computer program product implemented on storage media (including but not limited to magnetic disk storage, CD-ROM, optical memory etc.)
Formula.
The present invention is the flow with reference to method according to embodiments of the present invention, equipment (system) and computer program product
Figure and/or block diagram are described.It should be understood that every first-class during flow chart and/or block diagram can be realized by computer program instructions
The combination of flow and/or square frame in journey and/or square frame and flow chart and/or block diagram.These computer programs can be provided
The processor of all-purpose computer, special-purpose computer, Embedded Processor or other programmable data processing devices is instructed to produce
A raw machine so that produced for reality by the instruction of computer or the computing device of other programmable data processing devices
The device of the function of being specified in present one flow of flow chart or multiple one square frame of flow and/or block diagram or multiple square frames.
These computer program instructions may be alternatively stored in can guide computer or other programmable data processing devices with spy
In determining the computer-readable memory that mode works so that instruction of the storage in the computer-readable memory is produced and include finger
Make the manufacture of device, the command device realize in one flow of flow chart or multiple one square frame of flow and/or block diagram or
The function of being specified in multiple square frames.
These computer program instructions can be also loaded into computer or other programmable data processing devices so that in meter
Series of operation steps is performed on calculation machine or other programmable devices to produce computer implemented treatment, so as in computer or
The instruction performed on other programmable devices is provided for realizing in one flow of flow chart or multiple flows and/or block diagram one
The step of function of being specified in individual square frame or multiple square frames.
, but those skilled in the art once know basic creation although preferred embodiments of the present invention have been described
Property concept, then can make other change and modification to these embodiments.So, appended claims are intended to be construed to include excellent
Select embodiment and fall into having altered and changing for the scope of the invention.
Obviously, those skilled in the art can carry out various changes and modification without deviating from essence of the invention to the present invention
God and scope.So, if these modifications of the invention and modification belong to the scope of the claims in the present invention and its equivalent technologies
Within, then the present invention is also intended to comprising these changes and modification.
Claims (10)
1. a kind of virtual machine virus method, it is characterised in that be applied to monitor of virtual machine, the monitor of virtual machine is connected with
Antivirus virtual machine and N number of user virtual machine, are deployed with P antivirus engine, in the user virtual machine in the antivirus virtual machine
Be stored with data block, and methods described includes:
The monitor of virtual machine determines to exist in any M user virtual machine of N number of user virtual machine to treat disinfection data
After block, disinfection data block is treated described in acquisition;
The monitor of virtual machine treats that disinfection data block distributes to the antivirus virtual machine by way of internal memory maps by described
In Q antivirus engine;N, M, P, Q are integer, and N≤M, Q≤P;
The monitor of virtual machine monitors the Q antivirus engine and treats that disinfection data block is killed virus to described.
2. method according to claim 1, it is characterised in that the monitor of virtual machine is also associated with log server;
The monitor of virtual machine monitors the Q antivirus engine and treats that disinfection data block is killed virus to described, including:
The monitor of virtual machine determine the Q antivirus engine to described after disinfection data block completes antivirus, by the Q
The antivirus daily record of antivirus engine generation is transmitted to the log server by way of internal memory maps.
3. method according to claim 1, it is characterised in that the monitor of virtual machine is determined as follows described
Exist in any M user virtual machine and treat disinfection data block:
The monitor of virtual machine receives the reporting information of any M user virtual machine;Any M user virtual machine
In any user virtual machine the reporting information mark for the treating disinfection data block letter that includes in any user virtual machine
Breath;
The monitor of virtual machine determines there is number to be killed virus in any M user virtual machine according to the reporting information
According to block.
4. method according to claim 1, it is characterised in that the monitor of virtual machine is treated described in the following way
Disinfection data block distributes to Q antivirus engine in the antivirus virtual machine:
The monitor of virtual machine treats the quantity of disinfection data block for K is individual described in determining, K is integer;
The monitor of virtual machine treated for K in disinfection data block it is any treat disinfection data block, calculate and described any wait to kill
The cryptographic Hash of malicious data block, according to the antivirus engine in any cryptographic Hash for treating disinfection data block and the antivirus virtual machine
Quantity, determine it is described it is any treat the corresponding target antivirus engine of disinfection data block, and any treat disinfection data block point by described
Target antivirus engine described in dispensing.
5. the method according to any one of claim 1-4, it is characterised in that the monitor of virtual machine monitors the Q
Individual antivirus engine treats that disinfection data block is killed virus to described, including:
Any antivirus engine in the Q antivirus engine, the monitor of virtual machine are directed to if it is determined that distributing to described appointing
One antivirus engine treat disinfection data block for multiple, then monitor any antivirus engine according to preset order rule to described many
It is individual to treat that disinfection data block is killed virus.
6. a kind of monitor of virtual machine, it is characterised in that the monitor of virtual machine is connected with antivirus virtual machine and N number of user is empty
Plan machine, is deployed with P antivirus engine in the antivirus virtual machine, be stored with data block in the user virtual machine, described virtual
Monitor unit includes:
Processing module, disinfection data block is treated for existing in any M user virtual machine for determining N number of user virtual machine
Afterwards, disinfection data block is treated described in obtaining;
Distribute module, for being mapped internal memory by way of by it is described treat disinfection data block distribute to it is described antivirus virtual machine in
Q antivirus engine;N, M, P, Q are integer, and N≤M, Q≤P;
Monitoring module, treats that disinfection data block is killed virus for monitoring the Q antivirus engine to described.
7. monitor of virtual machine according to claim 6, it is characterised in that the monitor of virtual machine is also associated with daily record
Server;
The monitoring module specifically for:
Determine the Q antivirus engine to it is described after disinfection data block complete antivirus after, by the Q antivirus engine generation kill
Malicious daily record is transmitted to the log server by way of internal memory maps.
8. monitor of virtual machine according to claim 6, it is characterised in that the processing module is specifically for by such as
Under type determines to exist in any M user virtual machine treats disinfection data block:
Receive the reporting information of any M user virtual machine;Any user in any M user virtual machine is virtual
The reporting information of machine includes the identification information for treating disinfection data block in any user virtual machine;
According to the reporting information, determine to exist in any M user virtual machine and treat disinfection data block.
9. monitor of virtual machine according to claim 6, it is characterised in that the distribute module is specifically for by such as
Under type by it is described treat disinfection data block distribute to it is described antivirus virtual machine in Q antivirus engine:
It is determined that the quantity for treating disinfection data block is K, K is integer;
Treated for K in disinfection data block it is any treat disinfection data block, calculate any cryptographic Hash for treating disinfection data block,
The quantity of the antivirus engine in any cryptographic Hash for treating disinfection data block and the antivirus virtual machine, it is determined that described
One treats the corresponding target antivirus engine of disinfection data block, and any treats that disinfection data block is distributed to the target antivirus and drawn by described
Hold up.
10. the monitor of virtual machine according to any one of claim 6-9, it is characterised in that the monitoring module is specific
For:
Be directed to any antivirus engine in the Q antivirus engine, however, it is determined that distribute to any antivirus engine wait kill
Malicious data block is multiple, then monitor any antivirus engine and treat that disinfection data block enters to the multiple according to preset order rule
Row antivirus.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201611019069.4A CN106778240A (en) | 2016-11-18 | 2016-11-18 | A kind of virtual machine virus method method and device |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201611019069.4A CN106778240A (en) | 2016-11-18 | 2016-11-18 | A kind of virtual machine virus method method and device |
Publications (1)
Publication Number | Publication Date |
---|---|
CN106778240A true CN106778240A (en) | 2017-05-31 |
Family
ID=58969025
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201611019069.4A Pending CN106778240A (en) | 2016-11-18 | 2016-11-18 | A kind of virtual machine virus method method and device |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN106778240A (en) |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107545183A (en) * | 2017-09-15 | 2018-01-05 | 郑州云海信息技术有限公司 | A kind of virus method, apparatus and system |
CN109948341A (en) * | 2019-04-02 | 2019-06-28 | 深信服科技股份有限公司 | A kind of file scanning method, system, device, medium |
Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102081714A (en) * | 2011-01-25 | 2011-06-01 | 潘燕辉 | Cloud antivirus method based on server feedback |
CN102523215A (en) * | 2011-12-15 | 2012-06-27 | 北京海云捷迅科技有限公司 | Virtual machine (VM) online antivirus system based on KVM virtualization platform |
CN105117649A (en) * | 2015-07-30 | 2015-12-02 | 中国科学院计算技术研究所 | Anti-virus method and anti-virus system for virtual machine |
CN105320884A (en) * | 2015-11-02 | 2016-02-10 | 南京安贤信息科技有限公司 | Security protection method and system for virtual machine |
CN105528543A (en) * | 2015-12-23 | 2016-04-27 | 北京奇虎科技有限公司 | Remote antivirus method, client, console and system |
-
2016
- 2016-11-18 CN CN201611019069.4A patent/CN106778240A/en active Pending
Patent Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102081714A (en) * | 2011-01-25 | 2011-06-01 | 潘燕辉 | Cloud antivirus method based on server feedback |
CN102523215A (en) * | 2011-12-15 | 2012-06-27 | 北京海云捷迅科技有限公司 | Virtual machine (VM) online antivirus system based on KVM virtualization platform |
CN105117649A (en) * | 2015-07-30 | 2015-12-02 | 中国科学院计算技术研究所 | Anti-virus method and anti-virus system for virtual machine |
CN105320884A (en) * | 2015-11-02 | 2016-02-10 | 南京安贤信息科技有限公司 | Security protection method and system for virtual machine |
CN105528543A (en) * | 2015-12-23 | 2016-04-27 | 北京奇虎科技有限公司 | Remote antivirus method, client, console and system |
Cited By (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107545183A (en) * | 2017-09-15 | 2018-01-05 | 郑州云海信息技术有限公司 | A kind of virus method, apparatus and system |
CN109948341A (en) * | 2019-04-02 | 2019-06-28 | 深信服科技股份有限公司 | A kind of file scanning method, system, device, medium |
CN109948341B (en) * | 2019-04-02 | 2023-02-03 | 深信服科技股份有限公司 | File scanning method, system, device and medium |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
JP6522707B2 (en) | Method and apparatus for coping with malware | |
CN102262557B (en) | Method for constructing virtual machine monitor by bus architecture and performance service framework | |
DE112019005604T5 (en) | FUNCTION-AS-A-SERVICE SYSTEM IMPROVEMENTS (FAAS SYSTEM IMPROVEMENTS) | |
US8752034B2 (en) | Memoization configuration file consumed at runtime | |
CN107944232A (en) | A kind of design method and system of the Active Defending System Against based on white list technology | |
US20130074055A1 (en) | Memoization Configuration File Consumed at Compile Time | |
CN103902885A (en) | Virtual machine security isolation system and method oriented to multi-security-level virtual desktop system | |
CN103679039B (en) | Secure storage method of data and device | |
CN109815698A (en) | Malware is determined using firmware | |
US8813229B2 (en) | Apparatus, system, and method for preventing infection by malicious code | |
CN103618652A (en) | Audit and depth analysis system and audit and depth analysis method of business data | |
CN110083604A (en) | A kind of data really weigh method and device | |
CN103701783A (en) | Preprocessing unit, data processing system consisting of same, and processing method | |
CN106453311A (en) | Register and login system and method for biological characteristic distributed identity authentication | |
KR102022058B1 (en) | Method and system for detecting counterfeit of web page | |
CN106778240A (en) | A kind of virtual machine virus method method and device | |
Deng et al. | A secure container placement strategy using deep reinforcement learning in cloud | |
KR101994664B1 (en) | Vulnerability checking system based on cloud service | |
CN110889112B (en) | Software operation unified control system and method based on white list mechanism | |
CN106101086A (en) | The cloud detection method of optic of program file and system, client, cloud server | |
CN113138838B (en) | Virtual machine placement method based on artificial bee colony algorithm | |
CN103677769B (en) | Instruction recombination method and device | |
CN106850641A (en) | A kind of information transmission and control method and system based on cloud computing safety management platform | |
US10997287B2 (en) | Real-time monitoring and alerting for directory object update processing | |
CN112333025A (en) | Network security simulation training method, device and system |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
RJ01 | Rejection of invention patent application after publication | ||
RJ01 | Rejection of invention patent application after publication |
Application publication date: 20170531 |