Summary of the invention
In view of this, the present invention provides the safety protecting method and device of a kind of virtual platform, main purpose is to solve
The problem of certainly virtual platform cannot effectively being protected in the prior art.
According to the present invention on one side, a kind of safety protecting method of virtual platform is provided, comprising:
Target instruction target word is received, the target instruction target word is used to indicate virtual platform and executes processing operation;
Whether the source for judging the target instruction target word is virtual platform;
If it is judged that be it is yes, then judge whether the corresponding instruction behavior of the target instruction target word is stored in preset virtualization
In platform behavior library;
If the target instruction target word is not held in the preset virtual platform behavior library, stop executing the target
Instruction.
Further, whether the source for judging the target instruction target word is virtual platform, comprising:
Generate the memory stack call instruction of the target instruction target word;
The memory stack call instruction is sent to host, obtains the memory sequence with the memory stack call instruction,
The host refers to the equipment for carrying the virtual platform;
Search the command source mark of the memory sequence;
According to described instruction source identification, judge whether the source of the target instruction target word is virtual platform.
Further, described according to described instruction source identification, judge whether the source of the target instruction target word is virtualization
Platform, comprising:
Judge whether described instruction source identification and preset virtual platform command identification are identical;
If it is judged that being yes, it is determined that the source of the target instruction target word is the virtual platform;
If it is judged that being no, it is determined that the source of the target instruction target word is not the virtual platform.
Further, described to judge whether the corresponding instruction behavior of the target instruction target word is stored in preset virtual platform row
Before in library, the method also includes:
Virtual platform behavior library, the virtual platform behavior are established in local system and cloud system respectively
Library is for saving instruction behavior all in the virtual platform.
It is further, described to establish virtual platform behavior library in local system and cloud system respectively, comprising:
Obtain the executable instruction of the virtual platform;
Search the corresponding instruction behavior of the executable instruction;
Described instruction behavior is counted, virtual platform behavior library is generated.
Further, the executable instruction for obtaining the virtual platform, comprising:
From the execution journal of the virtual platform, the executable instruction of the virtual platform is obtained.
Further, it is described judge whether the target instruction target word is stored in preset virtual platform behavior library after, institute
State method further include:
If the target instruction target word is stored in the preset virtual platform behavior library, the target instruction target word is executed.
According to the present invention on the other hand, a kind of safety device of virtual platform is provided, comprising:
Receiving unit, for receiving target instruction target word, the target instruction target word is used to indicate virtual platform and executes processing operation;
Judging unit, for judging whether the source of the target instruction target word is virtual platform;
The judging unit, be also used to if it is judged that be it is yes, then judge the corresponding instruction behavior of the target instruction target word
Whether it is stored in preset virtual platform behavior library;
Stop unit stops if be not held in the preset virtual platform behavior library for the target instruction target word
Only execute the target instruction target word.
According to another aspect of the invention, a kind of storage medium is provided, at least one is stored in the storage medium can
It executes instruction, the executable instruction makes processor execute the corresponding operation of safety protecting method such as above-mentioned virtual platform.
In accordance with a further aspect of the present invention, a kind of computer equipment is provided, comprising: processor, memory, communication interface
And communication bus, the processor, the memory and the communication interface complete mutual lead to by the communication bus
Letter;
For the memory for storing an at least executable instruction, it is above-mentioned that the executable instruction executes the processor
The corresponding operation of the safety protecting method of virtual platform.
By above-mentioned technical proposal, technical solution provided in an embodiment of the present invention is at least had the advantage that
The present invention provides a kind of safety protecting method of virtual platform and devices, receive target instruction target word first, then
Whether the source for judging target instruction target word is virtual platform, then judges whether target instruction target word is stored in preset virtual platform behavior
In library, finally stop performance objective instruction if target instruction target word is not held in preset virtual platform behavior library.With it is existing
Technology is compared, and whether the embodiment of the present invention is stored in by the source of target instruction target word and the corresponding instruction behavior of target instruction target word
It is dual to judge whether target instruction target word is safe, and virtual platform execute in preset virtual platform behavior library, it can be to virtualization
Platform is effectively protected.
The above description is only an overview of the technical scheme of the present invention, in order to better understand the technical means of the present invention,
And it can be implemented in accordance with the contents of the specification, and in order to allow above and other objects of the present invention, feature and advantage can
It is clearer and more comprehensible, the followings are specific embodiments of the present invention.
Specific embodiment
Exemplary embodiments of the present disclosure are described in more detail below with reference to accompanying drawings.Although showing the disclosure in attached drawing
Exemplary embodiment, it being understood, however, that may be realized in various forms the disclosure without should be by embodiments set forth here
It is limited.On the contrary, these embodiments are provided to facilitate a more thoroughly understanding of the present invention, and can be by the scope of the present disclosure
It is fully disclosed to those skilled in the art.
The embodiment of the invention provides a kind of safety protecting methods of virtual platform, as shown in Figure 1, this method comprises:
101, target instruction target word is received.
Virtual platform refers to the Infrastructure platform constructed using virtualization technology, realizes that multiple operating systems share
Hardware, common hardware are exactly the host of virtual platform.Virtual platform is real on common hardware by executing various instructions
Now to the processing of various instructions.Target instruction target word is used to indicate virtual platform and executes processing operation, appoints in embodiments of the present invention
The instruction that meaning virtual platform is able to carry out can be target instruction target word.Target instruction target word, can be by user on virtual platform
Operation generates, and can be operated and be generated on control virtual platform by remote controlled manner by user, can also be by third party
Virtual platform simulated operation is invaded by internet to generate.The security protection of virtual platform be exactly in order to prevent third party enter
Virtualization operations platform is invaded, the operational order that third party generates is executed, steals the data of virtual platform, or is flat to virtualization
Platform even host is destroyed.
102, whether the source for judging target instruction target word is virtual platform.
If target instruction target word threatens to the safety of virtual platform, target instruction target word can from virtual platform
Energy property is smaller, so whether this step causes virtual platform as screening target instruction target word to the first step of security threat.With
Family operates the target instruction target word of generation on virtual platform, usually some routine operations, for example, creation list, statistical data,
Data etc. are transmitted, security risk will not be caused to virtual platform.
In the judgment process, judged according to the source of target instruction target word.The source of target instruction target word, can be in target instruction target word
Searched in corresponding log, the mode that can gradually date back initial position since target instruction target word is searched, mesh can also be saved
It marks and is searched in the memory sequence of instruction.In embodiments of the present invention without limitation to the lookup mode in target instruction target word source.
103, if it is judged that be it is yes, then judge whether the corresponding instruction behavior of target instruction target word is stored in preset virtualization
In platform behavior library.
If the source of target instruction target word is virtual platform, secondary judgement is carried out to target instruction target word, judges target instruction target word
Whether corresponding instruction behavior is stored in preset virtual platform behavior library.Instruction behavior refer to and target instruction target word relative to
Concrete operations with special object and execution condition, for example be repeated continuously and execute creation list operation, delete host
Environmental parameter.
In preset virtual platform behavior library, the behavior for allowing virtual platform to execute is saved.If target instruction target word pair
The instruction behavior answered is stored in preset virtual platform behavior library, then operational objective instruction is to virtual platform without safety
Hidden danger.If the corresponding instruction behavior of target instruction target word is not held in preset virtual platform behavior library, operational objective instruction
To virtual platform, there are security risks.
The case where source for target instruction target word is not virtual platform, does not inquire into inventive embodiments.
If 104, target instruction target word is not held in preset virtual platform behavior library, stop performance objective instruction.
Halt instruction target instruction target word prevents performance objective instruction from causing security risk to virtual platform.In halt instruction
After target instruction target word, it can also will stop the reason of performance objective instructs and be sent to virtual platform, it should to remind user to execute
The risk of target instruction target word.After making safety instruction, it independently can be chosen whether to continue to hold by user according to the demand of user
Row target instruction target word or delete target instruction.
The present invention provides a kind of safety protecting method of virtual platform, then reception target instruction target word first judges mesh
Whether the source of mark instruction is virtual platform, then judges whether target instruction target word is stored in preset virtual platform behavior library,
Finally stop performance objective instruction if target instruction target word is not held in preset virtual platform behavior library.With prior art phase
Than whether the embodiment of the present invention is stored in preset void by the source of target instruction target word and the corresponding instruction behavior of target instruction target word
In quasi-ization platform behavior library, it is dual judge target instruction target word whether safety, can virtual platform execute, can to virtual platform into
Row effectively protects.
The embodiment of the invention provides the safety protecting methods of another virtual platform, as shown in Fig. 2, this method packet
It includes:
201, target instruction target word is received.
Virtual platform is that it is hard to realize that more operating systems share using the basis instrument platform of virtualization technology building
Part, common hardware are exactly the host of virtual platform.Target instruction target word is used to indicate virtual platform and executes processing operation, including
The operation such as replicated, deleted, being modified to the data in virtual platform, system, software.
202, the memory stack call instruction of target instruction target word is generated.
Memory stack call instruction is used to indicate the corresponding memory sequence of process of host invocation target instruction.Process is
Program in computer is that system carries out the substantially single of Resource Distribution and Schedule about the primary operation activity on certain data acquisition system
Position, is the basis of operating system configuration.Process is primary fortune of the program with standalone feature about some data acquisition system
Row activity.It can apply for and possess system resource, be a dynamic concept, be a movable entity.It is more than journey
The code of sequence further includes current activity, is indicated by the value of program counter and the content of processing register.So target
The process of instruction is the state to be carried in the practical execution of the target instruction target word, can find the practical mesh of target instruction target word
's.The specific data for being related to process are stored in memory sequence, so this step generates the memory stack call instruction of target instruction target word,
To indicate the corresponding memory sequence of process of host invocation target instruction.
203, memory stack call instruction is sent to host, obtains the memory sequence with memory stack call instruction.
The equipment that host refers to carrying virtual platform, is the common hardware of virtual platform.Host is according to memory
Stack call instruction transfers corresponding memory sequence.Virtual platform obtains the memory sequence.Obtain the acquisition side of memory sequence
Formula can be and carry return call result instruction when sending memory stack call instruction, can send memory stack call instruction
Send the execution for obtaining memory sequence again later, in embodiments of the present invention without limitation to the acquisition modes of memory sequence.
204, the command source mark of memory sequence is searched.
Memory sequence is actually a string of characters, and each character in memory sequence has specific meaning, according to
The corresponding meaning of each character of preset memory sequence searches the command source mark in memory sequence.Pass through command source mark
It is virtualization process or host process that knowledge, which can distinguish the corresponding process of target instruction target word,.
205, it is identified according to command source, judges whether the source of target instruction target word is virtual platform.
Preset virtual platform command identification refers to and can be identified for that coming for the process on the process identification (PID) position of memory sequence
Source is the identifier of virtual platform.Judge target instruction target word source whether be virtual platform process, specifically include: judging institute
It states command source mark and whether preset virtual platform command identification is identical;If it is judged that being yes, it is determined that the mesh
The source of mark instruction is the virtual platform;If it is judged that being no, it is determined that the source of the target instruction target word is not institute
State virtual platform.Source for target instruction target word is not the situation of virtual platform, is not discussed in embodiments of the present invention.
206, virtual platform behavior library is established in local system and cloud system respectively.
Virtual platform behavior library is for saving instruction behavior all in the virtual platform.It specifically includes: obtaining
The executable instruction of virtual platform;Search the corresponding instruction behavior of executable instruction;Instruction behavior is counted, it is flat to generate virtualization
Platform behavior library.Wherein, behavior command is the instruction that operating system executes concrete behavior, such as is replicated, and is pasted, typing, read etc.,
The embodiment of the present invention is not specifically limited.From the execution journal of virtual platform, the executable instruction of virtual platform is obtained.
The executable instruction of virtual platform can search in the execution journal of virtual platform, can also use phase according to other
It is searched in execution journal in the virtual platform of biconditional operation system.In embodiments of the present invention, to obtain all can be performed
Instruction be target, to obtain executable instruction acquisition modes without limitation.
It should be noted that in order to improve the inquiry accuracy of instruction behavior, and ensure the advisability of instruction behavior, it needs
Virtual platform behavior library is established respectively in local system and cloud system respectively, also, due to virtual platform library
Method for building up is to be established, therefore, local system and cloud system according to the executable instruction for getting virtual platform
In the instruction that can be performed it is different, the virtual platform library of foundation is also different.In the embodiment of the present invention, it is preferred that for virtualization
The executable instruction of platform is searched from the virtual platform library established in local system first, when inquiry not then, then
Virtual platform library in request cloud system is inquired, and if it exists, is then obtained by request, the embodiment of the present invention pair
The instruction behavior stored in virtual platform library is not specifically limited.
207, if it is judged that be it is yes, then judge whether the corresponding instruction behavior of target instruction target word is stored in preset virtualization
In platform behavior library.
Whether successively compare instruction behavior instruction behavior corresponding with target instruction target word in preset virtual platform behavior library
It is identical, judge whether the corresponding instruction behavior of target instruction target word is stored in preset virtual platform behavior library with this.
If 208, target instruction target word is not held in preset virtual platform behavior library, stop performance objective instruction.
Arranged side by side with step 208, if target instruction target word is stored in preset virtual platform behavior library, performance objective refers to
It enables.If the source of target instruction target word is virtual platform, and the corresponding instruction behavior of target instruction target word is stored in preset virtualization and puts down
In platform behavior library, it can determine that target instruction target word generates in virtual platform really and is lawful acts, then performance objective refers to
Order be it is safe, i.e., when the source of instruction is virtual platform and the corresponding behavior of instruction is in preset virtual platform behavior
It was saved in library, behavior corresponding to such instruction is safe.Opposite, when the source of instruction is not that virtualization is flat
This instruction and corresponding behavior are directly determined as source that is unsafe, or working as instruction without carrying out secondary judgement by platform
For virtual platform, but corresponding behavior is instructed to be not held in preset virtual platform library, such instruction and corresponding
Behavior is also unsafe.It is achieved in the security protection to virtual platform.For example, if target instruction target word be not held in it is preset
In virtual platform behavior library, then illustrating that the corresponding instruction behavior of target instruction target word is not belonging to the instruction of normal virtual platform
Behavior stops performance objective instruction to guarantee the safety of virtual platform.
The present invention provides a kind of safety protecting method of virtual platform, then reception target instruction target word first judges mesh
Whether the source of mark instruction is virtual platform, then judges whether target instruction target word is stored in preset virtual platform behavior library,
Finally stop performance objective instruction if target instruction target word is not held in preset virtual platform behavior library.With prior art phase
Than whether the embodiment of the present invention is stored in preset void by the source of target instruction target word and the corresponding instruction behavior of target instruction target word
In quasi-ization platform behavior library, it is dual judge target instruction target word whether safety, can virtual platform execute, can to virtual platform into
Row effectively protects.
Further, as the realization to method shown in above-mentioned Fig. 1, the embodiment of the invention provides a kind of virtual platforms
Safety device, as shown in figure 3, the device includes:
Receiving unit 31, for receiving target instruction target word, the target instruction target word is used to indicate virtual platform and executes processing behaviour
Make;
Judging unit 32, for judging whether the source of the target instruction target word is virtual platform;
The judging unit 32, be also used to if it is judged that be it is yes, then judge the corresponding dos command line DOS of the target instruction target word
Whether to be stored in preset virtual platform behavior library;
Stop unit 33, if be not held in the preset virtual platform behavior library for the target instruction target word,
Stop executing the target instruction target word.
The present invention provides a kind of safety device of virtual platform, then reception target instruction target word first judges mesh
Whether the source of mark instruction is virtual platform, then judges whether target instruction target word is stored in preset virtual platform behavior library,
Finally stop performance objective instruction if target instruction target word is not held in preset virtual platform behavior library.With prior art phase
Than whether the embodiment of the present invention is stored in preset void by the source of target instruction target word and the corresponding instruction behavior of target instruction target word
In quasi-ization platform behavior library, it is dual judge target instruction target word whether safety, can virtual platform execute, can to virtual platform into
Row effectively protects.
Further, as the realization to method shown in above-mentioned Fig. 2, the embodiment of the invention provides another kind virtualization is flat
The safety device of platform, as shown in figure 4, the device includes:
Receiving unit 41, for receiving target instruction target word, the target instruction target word is used to indicate virtual platform and executes processing behaviour
Make;
Judging unit 42, for judging whether the source of the target instruction target word is virtual platform;
The judging unit 42, be also used to if it is judged that be it is yes, then judge the corresponding dos command line DOS of the target instruction target word
Whether to be stored in preset virtual platform behavior library;
Stop unit 43, if be not held in the preset virtual platform behavior library for the target instruction target word,
Stop executing the target instruction target word.
Further, the judging unit 42, comprising:
Generation module 421, for generating the memory stack call instruction of the target instruction target word;
Module 422 is obtained, for the memory stack call instruction to be sent to host, obtains and is called with the memory stack
The memory sequence of instruction, the host refer to the equipment for carrying the virtual platform;
Searching module 423, the command source for searching the memory sequence identify;
Judgment module 424, for judging whether the source of the target instruction target word is virtual according to described instruction source identification
Change platform.
Further, the judgment module 424, comprising:
Judging submodule 4241, for judge described instruction source identification and preset virtual platform command identification whether phase
Together;
Submodule 4242 is determined, for if it is judged that being yes, it is determined that the source of the target instruction target word is the void
Quasi-ization platform;
The determining submodule 4242 is also used to if it is judged that being no, it is determined that the source of the target instruction target word is not
It is the virtual platform.
Further, described device further include:
Unit 44 is established, judges whether the corresponding instruction behavior of the target instruction target word is stored in preset virtualization for described
Before in platform behavior library, virtual platform behavior library is established in local system and cloud system respectively, it is described virtual
Change platform behavior library for saving instruction behavior all in the virtual platform.
It is further, described to establish unit 44, comprising:
Module 441 is obtained, for obtaining the executable instruction of the virtual platform;
Searching module 442, for searching the corresponding instruction behavior of the executable instruction;
Statistical module 443 generates virtual platform behavior library for counting described instruction behavior.
Further, the acquisition module 441, is used for:
From the execution journal of the virtual platform, the executable instruction of the virtual platform is obtained.
Further, described device further include:
Execution unit 45 judges whether the target instruction target word is stored in it in preset virtual platform behavior library for described
Afterwards, if the target instruction target word is stored in the preset virtual platform behavior library, the target instruction target word is executed.
The present invention provides a kind of safety device of virtual platform, then reception target instruction target word first judges mesh
Whether the source of mark instruction is virtual platform, then judges whether target instruction target word is stored in preset virtual platform behavior library,
Finally stop performance objective instruction if target instruction target word is not held in preset virtual platform behavior library.With prior art phase
Than whether the embodiment of the present invention is stored in preset void by the source of target instruction target word and the corresponding instruction behavior of target instruction target word
In quasi-ization platform behavior library, it is dual judge target instruction target word whether safety, can virtual platform execute, can to virtual platform into
Row effectively protects.
A kind of storage medium is provided according to an embodiment of the present invention, and it is executable that the storage medium is stored at least one
The safety protecting method of the virtual platform in above-mentioned any means embodiment can be performed in instruction, the computer executable instructions.
Fig. 5 shows a kind of structural schematic diagram of the computer equipment provided according to an embodiment of the present invention, the present invention
Specific embodiment does not limit the specific implementation of computer equipment.
As shown in figure 5, the computer equipment may include: processor (processor) 502, communication interface
(Communications Interface) 504, memory (memory) 506 and communication bus 508.
Wherein: processor 502, communication interface 504 and memory 506 complete mutual lead to by communication bus 508
Letter.
Communication interface 504, for being communicated with the network element of other equipment such as client or other servers etc..
Processor 502, for executing program 510, the safety protecting method that can specifically execute above-mentioned virtual platform is real
Apply the correlation step in example.
Specifically, program 510 may include program code, which includes computer operation instruction.
Processor 502 may be central processor CPU or specific integrated circuit ASIC (Application
Specific Integrated Circuit), or be arranged to implement the integrated electricity of one or more of the embodiment of the present invention
Road.The one or more processors that computer equipment includes can be same type of processor, such as one or more CPU;?
It can be different types of processor, such as one or more CPU and one or more ASIC.
Memory 506, for storing program 510.Memory 506 may include high speed RAM memory, it is also possible to further include
Nonvolatile memory (non-volatile memory), for example, at least a magnetic disk storage.
Program 510 specifically can be used for so that processor 502 executes following operation:
Target instruction target word is received, the target instruction target word is used to indicate virtual platform and executes processing operation;
Whether the source for judging the target instruction target word is virtual platform;
If it is judged that be it is yes, then judge whether the corresponding instruction behavior of the target instruction target word is stored in preset virtualization
In platform behavior library;
If the target instruction target word is not held in the preset virtual platform behavior library, stop executing the target
Instruction.
Obviously, those skilled in the art should be understood that each module of the above invention or each step can be with general
Computing device realize that they can be concentrated on a single computing device, or be distributed in multiple computing devices and formed
Network on, optionally, they can be realized with the program code that computing device can perform, it is thus possible to which they are stored
It is performed by computing device in the storage device, and in some cases, it can be to be different from shown in sequence execution herein
Out or description the step of, perhaps they are fabricated to each integrated circuit modules or by them multiple modules or
Step is fabricated to single integrated circuit module to realize.In this way, the present invention is not limited to any specific hardware and softwares to combine.
The foregoing is only a preferred embodiment of the present invention, is not intended to restrict the invention, for the skill of this field
For art personnel, the invention may be variously modified and varied.All within the spirits and principles of the present invention, made any to repair
Change, equivalent replacement, improvement etc., should all include within protection scope of the present invention.
The embodiment of the present invention provides technical solution:
A1, a kind of safety protecting method of virtual platform, comprising:
Target instruction target word is received, the target instruction target word is used to indicate virtual platform and executes processing operation;
Whether the source for judging the target instruction target word is virtual platform;
If it is judged that be it is yes, then judge whether the corresponding instruction behavior of the target instruction target word is stored in preset virtualization
In platform behavior library;
If the target instruction target word is not held in the preset virtual platform behavior library, stop executing the target
Instruction.
Whether A2, method as described in a1, the source for judging the target instruction target word are virtual platform, comprising:
Generate the memory stack call instruction of the target instruction target word;
The memory stack call instruction is sent to host, obtains the memory sequence with the memory stack call instruction,
The host refers to the equipment for carrying the virtual platform;
Search the command source mark of the memory sequence;
According to described instruction source identification, judge whether the source of the target instruction target word is virtual platform.
A3, as described in A2 method, it is described according to described instruction source identification, judge the target instruction target word source whether
For virtual platform, comprising:
Judge whether described instruction source identification and preset virtual platform command identification are identical;
If it is judged that being yes, it is determined that the source of the target instruction target word is the virtual platform;
If it is judged that being no, it is determined that the source of the target instruction target word is not the virtual platform.
A4, method as described in a1, it is described to judge whether the corresponding instruction behavior of the target instruction target word is stored in preset void
Before in quasi-ization platform behavior library, the method also includes:
Virtual platform behavior library, the virtual platform behavior are established in local system and cloud system respectively
Library is for saving instruction behavior all in the virtual platform.
A5, the method as described in A4, it is described to establish the virtual platform row in local system and cloud system respectively
For library, comprising:
Obtain the executable instruction of the virtual platform;
Search the corresponding instruction behavior of the executable instruction;
Described instruction behavior is counted, virtual platform behavior library is generated.
A6, method as described in a5, the executable instruction for obtaining the virtual platform, comprising:
From the execution journal of the virtual platform, the executable instruction of the virtual platform is obtained.
A7, method as described in a1, it is described to judge whether the target instruction target word is stored in preset virtual platform behavior library
In after, the method also includes:
If the target instruction target word is stored in the preset virtual platform behavior library, the target instruction target word is executed.
B8, a kind of safety device of virtual platform, comprising:
Receiving unit, for receiving target instruction target word, the target instruction target word is used to indicate virtual platform and executes processing operation;
Judging unit, for judging whether the source of the target instruction target word is virtual platform;
The judging unit, be also used to if it is judged that be it is yes, then judge the corresponding instruction behavior of the target instruction target word
Whether it is stored in preset virtual platform behavior library;
Stop unit stops if be not held in the preset virtual platform behavior library for the target instruction target word
Only execute the target instruction target word.
B9, the device as described in B8, state judging unit, comprising:
Generation module, for generating the memory stack call instruction of the target instruction target word;
Module is obtained, for the memory stack call instruction to be sent to host, obtains and refers to memory stack calling
The memory sequence of order, the host refer to the equipment for carrying the virtual platform;
Searching module, the command source for searching the memory sequence identify;
Judgment module, for judging whether the source of the target instruction target word is virtualization according to described instruction source identification
Platform.
B10, the device as described in B9, the judgment module, comprising:
Judging submodule, for judging whether described instruction source identification and preset virtual platform command identification are identical;
Submodule is determined, for if it is judged that being yes, it is determined that the source of the target instruction target word is the virtualization
Platform;
The determining submodule is also used to if it is judged that being no, it is determined that the source of the target instruction target word is not institute
State virtual platform.
B11, the device as described in B1, described device further include:
Unit is established, judges whether the corresponding instruction behavior of the target instruction target word is stored in preset virtualization and puts down for described
Before in platform behavior library, virtual platform behavior library, the virtualization are established in local system and cloud system respectively
Platform behavior library is for saving instruction behavior all in the virtual platform.
B12, device as described in b11, it is described to establish unit, comprising:
Module is obtained, for obtaining the executable instruction of the virtual platform;
Searching module, for searching the corresponding instruction behavior of the executable instruction;
Statistical module generates virtual platform behavior library for counting described instruction behavior.
B13, as described in B12 device, the acquisition module, are used for:
From the execution journal of the virtual platform, the executable instruction of the virtual platform is obtained.
B14, the device as described in B8, described device further include:
Execution unit judges whether the target instruction target word is stored in it in preset virtual platform behavior library for described
Afterwards, if the target instruction target word is stored in the preset virtual platform behavior library, the target instruction target word is executed.
C15, a kind of storage medium are stored with an at least executable instruction, the executable instruction in the storage medium
The corresponding operation of safety protecting method for the virtual platform for executing processor as described in any one of A1-A7.
D16, a kind of computer equipment, comprising: processor, memory, communication interface and communication bus, the processor,
The memory and the communication interface complete mutual communication by the communication bus;
The memory executes the processor such as storing an at least executable instruction, the executable instruction
The corresponding operation of the safety protecting method of virtual platform described in any one of A1-A7.