WO2014000616A1 - 扫描方法、装置和客户端设备 - Google Patents
扫描方法、装置和客户端设备 Download PDFInfo
- Publication number
- WO2014000616A1 WO2014000616A1 PCT/CN2013/077799 CN2013077799W WO2014000616A1 WO 2014000616 A1 WO2014000616 A1 WO 2014000616A1 CN 2013077799 W CN2013077799 W CN 2013077799W WO 2014000616 A1 WO2014000616 A1 WO 2014000616A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- file
- suspicious
- disk
- information
- scan
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/145—Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
Definitions
- the present invention relates to the field of computer security, and in particular, to a scanning method, apparatus, and client device. Background technique
- Computer Virus refers to a set of computer instructions or program code inserted into a computer program that destroys computer functions or destroys data, affects computer use, and can self-replicate.
- the main task of security software is to protect and scan files in real time.
- Real-time protection generally refers to the use of security software to synchronize the monitoring of the system's running process, such as: An operating mode in which anti-virus software monitors computer memory and calls system files. That is, when the security software is in real-time protection, in order to discover possible viruses, the application in the security software will scan the object before it is accessed. If a virus is found, the application will remove or block the infected object. access.
- File scanning generally refers to the use of security software to check the files on the disk and memory in the computer system. Based on the judgment of the security software, it is used to identify whether the files in the disk and the memory meet the security standards of the security software.
- the real-time protection and file scanning provided by the security software work independently of each other, that is, the security tasks responsible for real-time protection and the security of file scanning. There is no communication in the task.
- This mode of work facilitates the management and application of security software, but it makes some viruses take advantage of it.
- Hazardous behaviors such as breaking a computer or stealing user information.
- the current security software is difficult to completely clean up such a virus, that is, it can only clean up the sub-programs or sub-files released by the virus, and the parent file hidden somewhere on the computer cannot be checked and processed effectively. So when users use security software, they will encounter such situations: (1) After the real-time protection function finds a threat and processes it, it can discover the threat again; (2) After the file scan finds a threat and processes it, The threat can be discovered again; (3) The file scan finds and processes a threat, and can again find a similar threat; (4) After the real-time protection intercepts a threat and processes it, the file scan can still scan the threat.
- the existing file scanning causes the virus in the computer system to be completely removed, which seriously affects the ability to clean up the threat, making the virus searching and cleaning process inefficient. Summary of the invention
- embodiments of the present invention provide a scanning method, apparatus, and client device.
- the technical solution is as follows:
- a scanning method comprising:
- the at least one disk file in the corresponding area of the specified scan is enumerated; and the scan file queue is determined according to the at least one disk file and at least one suspicious file acquired in the real-time protection process;
- the determined scan file queue is scanned according to the virus scan engine.
- Determining a scan file queue according to the at least one disk file and at least one suspicious file acquired in the real-time protection process including:
- the at least one disk file is loaded into the scan file queue.
- Obtaining a file information includes a file involved in a file activity of a suspicious file of a file name of any one of the at least one disk file, and including the at least one magnetic file A suspicious file of a file name of any of the disk files in the disk file, a file involved in performing the file activity, and the at least one disk file are loaded into the scan file queue.
- Determining a scan file queue according to the at least one disk file and at least one suspicious file obtained during the real-time protection process previously comprising:
- the suspicious file is obtained, and the file information of the suspicious file is saved to a specified area, and the file information includes at least the file activity of the suspicious file.
- the suspicious file is obtained, and the file information of the suspicious file is saved to the specified area, and the file information includes at least the file activity of the suspicious file, and then includes:
- the file information of the suspicious file is deleted from the designated area.
- a scanning device the device comprising:
- An enumeration module configured to: when the specified scan is started, enumerate at least one disk file in the corresponding area of the specified scan;
- a queue determining module configured to determine a scan file queue according to the at least one disk file and at least one suspicious file acquired in a real-time protection process
- the scanning module is configured to scan the determined scan file queue according to the virus scanning engine.
- the queue determination module includes:
- a determining unit configured to determine, according to the file information of the at least one suspicious file, whether the file information of the at least one suspicious file includes a file name of any one of the at least one disk file;
- a loading unit configured to include, in file information of the at least one suspicious file, a file name of any one of the at least one disk file, the file information including a file name of any one of the at least one disk file Suspicious files and the at least one disk file are loaded into the scan file queue;
- the loading unit is further configured to: when the file information of the at least one suspicious file does not include a file name of any one of the at least one disk file, load the at least one disk file into the scan file queue .
- the loading unit is further configured to acquire, by the file information, a suspicious file including any one of the at least one disk file that includes a file name of any one of the at least one disk file, a file involved in performing the file activity, and the file At least one disk file is loaded into the scan file queue.
- the device also includes:
- the obtaining module is configured to obtain a suspicious file during the real-time protection process, and save the file information of the suspicious file to a specified area, where the file information includes at least the file activity of the suspicious file.
- the device also includes:
- an uploading module configured to upload the file information of the suspicious file to the server, so that the server performs analysis according to the file information of the suspicious file.
- the device also includes:
- the first processing module is configured to delete the file information of the suspicious file from the designated area when it is determined that the file information of the suspicious file is successfully uploaded.
- the device also includes:
- a client device configured to compress the file information of the suspicious file when it is determined that the file information of the suspicious file fails to be uploaded.
- a client device the client device includes:
- One or more processors are One or more processors.
- the memory stores one or more programs, the one or more programs being configured to be executed by the one or more processors, the one or more programs including instructions for: When the scan is specified, enumerating at least one disk file in the corresponding area of the specified scan; determining the scan file queue according to the at least one disk file and at least one suspicious file acquired in the real-time protection process;
- the determined scan file queue is scanned according to the virus scan engine.
- an instruction for performing the following operations is further included;
- the file information of the at least one suspicious file Whether the file information includes the file name of any one of the at least one disk file; if yes, the file information includes the suspicious file of the file name of any one of the at least one disk file and the at least a disk file is loaded into the scan file queue;
- the at least one disk file is loaded into the scan file queue.
- an instruction for performing the following operations is also included:
- a suspicious file of the file name of the disk file, a file involved in performing the file activity, and the at least one disk file are loaded into the scan file queue.
- an instruction for performing the following operations is also included:
- the suspicious file is obtained, and the file information of the suspicious file is saved to a specified area, and the file information includes at least the file activity of the suspicious file.
- an instruction for performing the following operations is also included:
- an instruction for performing the following operations is also included:
- the file information of the suspicious file is deleted from the designated area.
- an instruction for performing the following operations is also included:
- the file information of the suspicious file is compressed.
- the embodiment of the present invention can combine the real-time protection process and the file scanning process, thereby avoiding that the suspicious files acquired in the real-time protection process are ignored due to the specified scanning, thereby effectively avoiding the limitation due to the specified scanning.
- the virus has not been completely removed.
- the scan queue is re-determined, so as to comprehensively scan the threat that may be generated, and the file is thoroughly checked and compared, compared with the prior art.
- FIG. 1 is a flowchart of a scanning method according to an embodiment of the present invention
- FIG. 2 is a flowchart of a scanning method according to an embodiment of the present invention.
- FIG. 3 is a schematic structural diagram of a scanning apparatus according to an embodiment of the present invention.
- FIG. 4 is a schematic structural diagram of a scanning apparatus according to an embodiment of the present invention.
- FIG. 5 is a schematic structural diagram of a scanning apparatus according to an embodiment of the present disclosure.
- FIG. 6 is a schematic structural diagram of a client device according to an embodiment of the present invention. detailed description
- FIG. 1 is a flowchart of a scanning method according to an embodiment of the present invention.
- the execution body of the scanning method of this embodiment is a client device, and the client device may be a computer.
- the scanning method of this embodiment may specifically include the following steps:
- the specified scan generally refers to a partial scan of the device, rather than a full scan, and the designated scan may be a secure task scan or a file scan.
- Security task scanning refers to the scanning of memory and / or critical disk, the corresponding scanning area is memory and / or critical disk, the scanning object is the disk file of memory and / or key disk, for example, the key disk is
- the corresponding scan area of the security task scan is the memory and the C drive
- the scan target is the disk file of the memory and the disk file in the C drive.
- a file scan is a scan of a file on a specified disk and/or a specified disk location.
- the corresponding scan area is the specified disk and/or the specified disk location.
- the scan object is the disk file that specifies the disk and/or the specified disk location. For example, if the specified disk is the D disk, the corresponding scanning area of the file scanning is the D disk.
- the scanned object is the disk file in the D drive.
- the corresponding scan area of the security task scan can be set by a technician, and is adjusted by the user in use, and the corresponding scan area of the file scan can also be set in the same manner, which is not specifically limited in the embodiment of the present invention.
- the suspicious file acquired during the real-time protection process may not be located in the corresponding area of the specified scan, the suspicious file may be ignored. Create a security risk. Therefore, it is necessary to combine at least one suspicious file acquired in the real-time protection process on the basis of at least one of the enumerated disk files, so as to re-determine the scan file queue and ensure the scanning efficiency.
- the virus scanning engine may be a local engine, or may be a cloud virus scanning engine, for comparing the files in the scan file queue during scanning, to check and match the virus characteristics in the virus scanning engine. file.
- the scanning method provided in this embodiment is to enumerate at least one disk file in the corresponding scanning area by starting the specified scanning; according to the at least one disk file and at least obtained in the real-time protection process.
- the scan queue is re-determined, so as to comprehensively scan the threat that may be generated, and the file is thoroughly checked and compared, compared with the prior art.
- the ability to scan files thoroughly improves the ability to clean up threats and improve the efficiency of the virus discovery and cleanup process.
- step 101 “determining a scan file queue according to the at least one disk file and at least one suspicious file acquired in the real-time protection process” may specifically include :
- the file information of the suspicious file in this embodiment includes at least the file activity of the suspicious file, and the file activity refers to the operation, loading, generation or modification of the suspicious file.
- the file information of the suspicious file contains the file name of the disk file
- the disk file is related to the file activity of the suspicious file.
- the parent file and the subfile relationship are between the suspicious file and the disk file, and the parent information or the subfile information in the file activity of the suspicious file is the file name of the disk file.
- the file information of the suspicious file B includes the file name of the load file B-plus, which means that when the file of the suspicious file B is active, the disk file B-plus in at least one disk file is loaded, and the suspicious file is known.
- B is associated with the disk file B-plus.
- the suspicious file is C-plus
- the source information of the suspicious file in the file information of the suspicious file C-plus is the disk file C, that is, when the disk file C is active, the suspicious file C-plus is loaded, It is known that the suspicious file C-plus is associated with the disk file C.
- the suspicious file is A
- the subfile information in the file information of the suspicious file A is the disk file A-1
- the suspicious file A is the parent file of A-1
- the suspicious file A is in the at least one disk file. Disk file A-1 is associated.
- the file information of the suspicious file can be obtained in the real-time protection process and saved to a designated area for later reading.
- the file information of the at least one suspicious file includes a file name of any one of the at least one disk file
- the file information includes a file of any one of the at least one disk file a suspicious file of the name and the at least one disk file are loaded into the scan file queue
- the file information of the at least one suspicious file includes the file name of any one of the at least one disk file
- determining that at least one suspicious file is included in any one of the at least one disk file Suspicious files associated with the file are loaded into the scan file queue.
- the suspicious file that contains the file name of any one of the at least one disk file in the file information may be one or more, which is not specifically limited in the embodiment of the present invention.
- step (2) in step 101 “is suspicious of the file name of the file file included in the at least one disk file in the file information.
- Loading the file and the at least one disk file into the scan file queue may include: obtaining a suspicious file containing a file name of any one of the at least one disk file in the file information involved in performing file activity a file, and loading, in the file information, a suspicious file containing a file name of any one of the at least one disk file, a file involved in performing the file activity, and the at least one disk file into the scan file queue .
- the file activity may also involve other files. Therefore, in order to completely remove the threat, files related to the file activity of the suspicious file are also loaded into the scan file queue.
- the file information includes a suspicious file of a file name of any one of the at least one disk file, and a file B-plus of the at least one disk file is loaded when the file of the suspicious file B is active.
- the disk files B-1 and B-2 located on the E disk are also loaded, and when the load is performed, the suspicious file B, the disk files B-1 and B-2, and at least one disk file are loaded into the scan file queue.
- the file information of the suspicious file containing the file name of any one of the at least one disk file in the file information can be obtained in a real-time protection process and saved to a designated area for subsequent scanning. Read.
- the file information of the suspicious file may also include the file source of the suspicious file, the subfile name, and the parent file information name. Therefore, by the judgment of (1) in step 101, it is also known whether at least one suspicious file contains a subfile or a parent file of any of the disk files in the disk file.
- the file source of the suspicious file is a disk file, or
- the parent file of the suspicious file is a disk file, or the suspicious file is a file source of the disk file, or the suspicious file is a parent file of the disk file, etc., determining that at least one suspicious file includes any one of the at least one disk file Subfile or parent file.
- the file information of the suspicious file can be sent by the server and saved in the designated area.
- the step 102: determining the scan file queue according to the at least one disk file and the at least one suspicious file acquired in the real-time protection process may also include: (a) in the real-time protection process, obtaining a suspicious file, and saving the file information of the suspicious file to a designated area, the file information including at least the file activity of the suspicious file.
- the real-time protection is started; the file activity of the disk file is detected; when the suspicious file is obtained according to the file activity of the disk file, it is determined whether the suspicious file has been recorded; if yes, the process ends; if not, the suspicious file is recorded As a suspicious file, and save the file information of the suspicious file to the specified implementation manner, the present invention does not describe it.
- the designated area refers to an area on the disk for storing file information of the suspicious file, and the file information of the suspicious file is acquired and saved in the real-time protection process, and the location and capacity of the designated area can be
- the file activity of the suspicious file includes but is not limited to any of the following file activities: (i) releasing the subfile, and correspondingly, the file information includes at least one of a subfile name, a subfile storage path, a subfile modification time, and a subfile creation time. . (ii) loading the file, and accordingly, the file information includes at least one of a loaded file name and a loaded file path. (iii) establishment or modification of a suspicious file, correspondingly, the file information includes at least one of a creation time or a modification time of the suspicious file, a parent file information of the suspicious file, and a parent file path.
- the file information that needs to be saved in the real-time protection process may be set or adjusted by a technician, and the setting and the adjustment may be implemented by using a software update, which is not specifically limited in the embodiment of the present invention.
- step (a) in the real-time protection process, obtaining a suspicious file, and saving the file information of the suspicious file to a designated area, where the file information is at least
- the file activity including the suspicious file includes: (b) uploading the file information of the suspicious file to the server, so that the server performs analysis according to the file information of the suspicious file.
- the server in this embodiment may be a cloud server.
- the technician may analyze the file activity of the suspicious file and the virus characteristics according to the file information of the uploaded suspicious file, so as to analyze
- the embodiment does not specifically limit the processing.
- the file information of the suspicious file is uploaded to the file information of the service device; if yes, the file information of the suspicious file is not uploaded; if not, the file information of the suspicious file is continuously uploaded.
- the uploading process of the uploading process may be periodic. The uploading may be performed at the end of each real-time protection process, and may also be uploaded after the file information of the suspicious file is detected to be updated, which is not specifically limited in this embodiment.
- the file information of the suspicious file is uploaded to the server, and then includes:
- the file information of the suspicious file is deleted. It should be noted that determining whether the file information is successfully uploaded is an existing technology, and details are not described herein again.
- the file information of the suspicious file is uploaded to the server, and then: when determining that the file information of the suspicious file is uploaded fails , compressing the file information of the suspicious file.
- step (b) If the user network is abnormal or the like may cause the upload of step (b) to fail, the file information is compressed in order to retain the file information without wasting disk resources. Further, after the user's network is restored to normal, the file information of the suspicious file is uploaded to the server, and the file information is deleted locally.
- the foregoing embodiment can combine the real-time protection process and the file scanning process, thereby avoiding the problem that the suspicious file acquired in the real-time protection process is ignored due to the limitation of the scanning range of the specified scan, thereby effectively avoiding The virus was not completely removed due to the limitations of the parent file or the specified scan.
- the scan queue is re-determined, so as to comprehensively scan the threat that may be generated, and the file is thoroughly checked and compared, compared with the prior art.
- the ability to scan files thoroughly improves the ability to clean up threats and improve the efficiency of the virus discovery and cleanup process.
- FIG. 2 is a flowchart of a scanning method according to an embodiment of the present invention.
- the scanning of this embodiment takes the above all the optional technical solutions as an example, and introduces the technical solutions of the present invention in more detail.
- the scanning method of this embodiment may specifically include the following steps:
- obtaining a suspicious file saving the file information of the suspicious file to a specified area, the file information including at least the file activity of the suspicious file; 201, uploading the file information of the suspicious file to the server, so that the server performs analysis according to the file information of the suspicious file;
- uploading the file information of the suspicious file to the server and then: deleting the file information of the suspicious file from the designated area when it is determined that the file information of the suspicious file is successfully uploaded.
- uploading the file information of the suspicious file to the server and then: compressing the file information of the suspicious file when it is determined that the file information of the suspicious file fails to be uploaded.
- FIG. 3 is a schematic structural diagram of a scanning apparatus according to an embodiment of the present invention.
- the scanning device may specifically include: an enumeration module 10, a queue determination module 11 and a scanning module 12.
- the enumeration module 10 is configured to enumerate at least one disk file in the corresponding scan area when the specified scan is started; the enumeration module 10 and the queue determination module 11 are connected, and the queue determination module 11 is configured to a disk file and at least one suspicious file acquired in the real-time protection process, determining a scan file queue; the queue determination module 11 and the scan module 12 are connected, and the scan module 12 is used for the root According to the virus scanning engine, the scan file queue determined by the queue determination module 11 is scanned.
- the scanning device of the present embodiment is the same as the implementation of the related method embodiment by using the above-mentioned module.
- the scanning device of the present embodiment is the same as the implementation of the related method embodiment by using the above-mentioned module.
- the scanning device of the embodiment can combine the real-time protection process and the file scanning process, thereby avoiding the problem that the suspicious file acquired in the real-time protection process is ignored due to the limitation of the scanning range of the specified scanning, thereby effectively avoiding the problem.
- the virus was not completely removed due to the restriction of the parent file or the specified scan.
- the scan queue is re-determined according to the suspicious file in the real-time protection process acquired in advance, so as to perform a comprehensive scan on the threat that may be generated, and the file is thoroughly checked and compared, compared with the prior art.
- the ability to scan files thoroughly improves the ability to clean up threats and improve the efficiency of the virus discovery and cleanup process.
- the scanning device of this embodiment may further include the following technical solutions on the basis of the foregoing embodiment shown in FIG. 3.
- the queue determining module 11 includes: a determining unit and a loading unit (not shown), and a determining unit and a loading unit.
- a connection unit configured to determine, according to the file information of the at least one suspicious file, whether the file information of the at least one disk file includes a file name of any one of the at least one disk file;
- the file information of the at least one disk file is included in the file information of the at least one suspicious file, and the file information includes a suspicious file name of any one of the at least one disk file
- the file and the at least one disk file are loaded into the scan file queue;
- the loading unit is further configured to: when the file information of the at least one suspicious file does not include the file of any one of the at least one disk file Name, loading the at least one disk file into the scan file queue.
- FIG. 4 is a schematic structural diagram of a scanning apparatus according to an embodiment of the present invention. As shown in FIG. 4, the scanning device of this embodiment may further include the following technical solutions on the basis of the embodiment shown in FIG.
- the scanning apparatus of this embodiment further includes an obtaining module 13, and the obtaining module 13 is connected to the queue determining module 11, and the obtaining module 13 is configured to obtain a suspicious file during the real-time protection process, and the suspicious file is obtained.
- File information is saved to a specified area, and the file information includes at least the suspicious File activity of the file.
- FIG. 5 is a schematic structural diagram of a scanning apparatus according to an embodiment of the present invention. As shown in FIG. 5, the scanning device of this embodiment may further include the following technical solutions on the basis of the foregoing embodiment shown in FIG.
- the scanning device of this embodiment further includes an uploading module 14 that is connected to the obtaining module 13.
- the uploading module 14 is configured to upload the file information of the suspicious file to the server, so that the server is configured according to the server.
- the file information of the suspicious file is analyzed.
- the scanning apparatus of the embodiment further includes a first processing module (not shown), configured to delete the suspicious file from the designated area when determining that the file information of the suspicious file is successfully uploaded. File information.
- the scanning device of the embodiment further includes a second processing module (not shown) for compressing the file information of the suspicious file when it is determined that the file information of the suspicious file fails to be uploaded.
- a second processing module (not shown) for compressing the file information of the suspicious file when it is determined that the file information of the suspicious file fails to be uploaded.
- the scanning device of the present embodiment is the same as the implementation of the related method embodiment by using the above-mentioned module.
- the scanning device of the present embodiment is the same as the implementation of the related method embodiment by using the above-mentioned module.
- the scanning device of the embodiment can combine the real-time protection process and the file scanning process, thereby avoiding the problem that the suspicious file acquired in the real-time protection process is ignored due to the limitation of the scanning range of the specified scanning, thereby effectively avoiding the problem.
- the virus was not completely removed due to the restriction of the parent file or the specified scan.
- the scan queue is re-determined according to the suspicious file in the real-time protection process acquired in advance, so as to perform a comprehensive scan on the threat that may be generated, and the file is thoroughly checked and compared, compared with the prior art.
- the ability to scan files thoroughly improves the ability to clean up threats and improve the efficiency of the virus discovery and cleanup process.
- the scanning device provided by the foregoing embodiment is only illustrated by dividing the above functional modules. In actual applications, the function distribution may be completed by different functional modules according to requirements, that is, the device is The internal structure is divided into different functional modules to perform all or part of the functions described above.
- the scanning device provided by the foregoing embodiment is the same as the scanning method embodiment, and the specific implementation process is described in detail in the method embodiment, and details are not described herein again.
- FIG. 6 is a schematic structural diagram of a client device according to an embodiment of the present invention.
- the client device 600 can be a conventional desktop or laptop notebook, the client 600 including a central processing unit (CPU) 601, a system memory 604 including random access memory (RAM) 602 and read only memory (ROM) 603, and System memory 604 and system bus 605 of central processing unit 601 are coupled.
- the client device 600 also includes a basic input/output system (I/O system) 606 that facilitates transfer of information between various devices within the computer, and a large storage system 613, applications 614, and other program modules 615. Capacity storage device 607.
- I/O system basic input/output system
- the basic input/output system 606 includes a display 608 for displaying information and an input device 609 such as a mouse, keyboard for user input of information.
- the display 608 and input device 609 are both coupled to the central processing unit 601 via an input and output controller 610 coupled to the system bus 605.
- the basic input/output system 606 can also include an input and output controller 610 for receiving and processing input from a plurality of other devices, such as a keyboard, mouse, or electronic stylus.
- input output controller 610 also provides output to a display screen, printer, or other type of output device.
- the mass storage device 607 is connected to a mass storage controller of the system bus 605
- the mass storage device 607 and its associated computer readable medium provide non-volatile storage for the client device 600. That is, the mass storage device 607 can include a computer readable medium such as a hard disk or a CD-ROM drive.
- the computer readable medium can include computer storage media and communication media.
- Computer storage media includes volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data.
- Computer storage media includes RAM, ROM, EPROM, EEPROM, flash memory or other solid state storage technologies, CD-ROM, DVD or other optical storage, tape cartridges, magnetic tape, disk storage or other magnetic storage devices.
- RAM random access memory
- ROM read only memory
- EPROM Erasable programmable read-only memory
- EEPROM electrically erasable programmable read-only memory
- the client device 600 may also be connected to a remote computer on a network via a network such as the Internet. That is, the client device 600 can be connected to the network 612 through a network interface unit 611 connected to the system bus 605, or the network interface unit in can be used to connect to other types of networks or remote computer systems (not shown). Out).
- the memory also includes one or more programs, the one or more programs being stored in a memory and configured to be executed by one or more central processing units 601
- One or more programs include a scanning method provided by the embodiment shown in Fig. 1 and a scanning method provided by the embodiment shown in Fig. 2.
- the storage medium mentioned may be a read only memory, a magnetic disk or an optical disk or the like.
- the computer readable storage medium stores one or more programs, the one or more programs being used by one or more processors to perform the scanning method provided by the embodiment of FIG. 1 and the embodiment shown in FIG. The scanning method provided.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Virology (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Description
说 明 书 扫描方法、 装置和客户端设备
本申请要求于 2012 年 06 月 26 日提交中国专利局、 申请号为 201210213332.9、 发明名称为 "扫描方法和装置" 的中国专利申请的优先权, 其全部内容通过引用结合在本申请中。 技术领域
本发明涉及计算机安全领域,特别涉及一种扫描方法、装置和客户端设备。 背景技术
计算机病毒 ( Computer Virus )是指: 编制者在计算机程序中插入的破坏 计算机功能或者毁坏数据, 影响计算机使用, 并能自我复制的一组计算机指令 或者程序代码。
随着计算机应用的普及以及互联网的快速发展, 计算机病毒正在以惊人的 速度蔓延。 为了保护计算机的资源不受计算机病毒侵害, 现有技术提供了安全 软件, 安全软件是一种可以对病毒、 木马等一切已知的对计算机有危害的程序 代码进行清除的程序工具。
安全软件的主要任务是实时防护和扫描文件。
实时防护, 一般是指利用安全软件对系统运行的过程进行同步的监控, 比 如: 杀毒软件对计算机内存监控并调用系统文件的一种操作模式。 也即, 安全 软件在实时防护时, 为了发现可能存在的病毒, 安全软件中的应用程序将在对 象被访问之前对它进行扫描, 如果发现病毒, 该应用程序会将染毒对象移除或 阻止访问。
文件扫描,一般是指利用安全软件对计算机系统中磁盘和内存中的文件进 行检查, 以安全软件的判断为基础, 来鉴别磁盘和内存中的文件是否符合安全 软件的安全标准。
在实现本发明的过程中, 发明人发现现有技术至少存在以下问题: 安全软件所提供的实时防护和文件扫描是相互独立工作的, 即实时防护所 负责的安全任务和文件扫描所负责的安全任务没有交流, 这种工作模式便于安 全软件的管理和应用, 但是却让一些病毒钻了空子。 比如现有存在一种母体行
病毒, 这种病毒本身具备或者不具备破坏能力, 但是它能释放出一个子程序或 者子文件放到一个看似与之无关或者随机的文件目录下, 而它释放出的这个子 程序或者子文件具有破环计算机或者盗取用户信息等有危害的行为。 目前的安 全软件对于这样的病毒很难做到彻底清理, 即只能清理掉该病毒释放出的子程 序或子文件, 对于这个藏在计算机某处的母体文件不能检查到并有效处理。 以 至于用户在使用安全软件时会遇到这样几种情况: ( 1 )实时防护功能发现了一 个威胁并处理后, 还能再次发现这个威胁; (2 )文件扫描发现了一个威胁并处 理后, 还能再次发现这个威胁; (3 )文件扫描发现并处理了一个威胁, 还能再 次发现一个类似的威胁; (4 )实时防护拦截到一个威胁并处理后, 文件扫描仍 能扫描出这个威胁。现有的文件扫描,导致计算机系统内的病毒不能彻底清除, 严重影响了清理威胁的能力, 使得病毒查找和清理过程效率低。 发明内容
为了彻底清除病毒, 提高病毒查找和清理的效率, 本发明实施例提供了一 种扫描方法、 装置和客户端设备。 所述技术方案如下:
一种扫描方法, 所述方法包括:
当启动指定扫描时, 枚举所述指定扫描相应区域中的至少一个磁盘文件; 根据所述至少一个磁盘文件和实时防护过程中获取的至少一个可疑文件, 确定扫描文件队列;
根据病毒扫描引擎, 对确定的扫描文件队列进行扫描。
根据所述至少一个磁盘文件和实时防护过程中获取的至少一个可疑文件, 确定扫描文件队列, 包括:
根据所述至少一个可疑文件的文件信息, 判断所述至少一个可疑文件的文 件信息中是否包含所述至少一个磁盘文件中任一磁盘文件的文件名;
如果是,将文件信息包含所述至少一个磁盘文件中任一磁盘文件的文件名 的可疑文件和所述至少一个磁盘文件加载至所述扫描文件队列;
如果否, 将所述至少一个磁盘文件加载至所述扫描文件队列。
将文件信息包含所述至少一个磁盘文件中任一磁盘文件的文件名的可疑 文件和所述至少一个磁盘文件加载至所述扫描文件队列, 包括:
获取文件信息包含所述至少一个磁盘文件中任一磁盘文件的文件名的可 疑文件在进行文件活动时涉及的文件, 并将所述文件信息包含所述至少一个磁
盘文件中任一磁盘文件的文件名的可疑文件、进行文件活动时涉及的文件和所 述至少一个磁盘文件加载至所述扫描文件队列。
根据所述至少一个磁盘文件和实时防护过程中获取的至少一个可疑文件, 确定扫描文件队列, 之前包括:
在实时防护过程中, 获取可疑文件, 将所述可疑文件的文件信息保存至指 定区域, 所述文件信息至少包括所述可疑文件的文件活动。
在实时防护过程中, 获取可疑文件, 将所述可疑文件的文件信息保存至指 定区域, 所述文件信息至少包括所述可疑文件的文件活动, 之后包括:
将所述可疑文件的文件信息上传至服务器,使得所述服务器根据所述可疑 文件的文件信息进行分析。
将所述可疑文件的文件信息上传至服务器, 之后包括:
当确定所述可疑文件的文件信息上传成功时,从所述指定区域删除所述可 疑文件的文件信息。
将所述可疑文件的文件信息上传至服务器, 之后包括:
当确定所述可疑文件的文件信息上传失败时,压缩所述可疑文件的文件信 息。 一种扫描装置, 所述装置包括:
枚举模块, 用于当启动指定扫描时, 枚举所述指定扫描相应区域中的至少 一个磁盘文件;
队列确定模块, 用于根据所述至少一个磁盘文件和实时防护过程中获取的 至少一个可疑文件, 确定扫描文件队列;
扫描模块, 用于根据病毒扫描引擎, 对确定的扫描文件队列进行扫描。 所述队列确定模块包括:
判断单元, 用于根据所述至少一个可疑文件的文件信息, 判断所述至少一 个可疑文件的文件信息中是否包含所述至少一个磁盘文件中任一磁盘文件的 文件名;
加载单元, 用于当所述至少一个可疑文件的文件信息中包含所述至少一个 磁盘文件中任一磁盘文件的文件名,将文件信息包含所述至少一个磁盘文件中 任一磁盘文件的文件名的可疑文件和所述至少一个磁盘文件加载至所述扫描 文件队列;
所述加载单元,还用于当所述至少一个可疑文件的文件信息中不包含所述 至少一个磁盘文件中任一磁盘文件的文件名,将所述至少一个磁盘文件加载至 所述扫描文件队列。
所述加载单元还用于获取文件信息包含所述至少一个磁盘文件中任一磁 包含所述至少一个磁盘文件中任一磁盘文件的文件名的可疑文件、进行文件活 动时涉及的文件和所述至少一个磁盘文件加载至所述扫描文件队列。
所述装置还包括:
获取模块, 用于在实时防护过程中, 获取可疑文件, 将所述可疑文件的文 件信息保存至指定区域, 所述文件信息至少包括所述可疑文件的文件活动。
所述装置还包括:
上传模块, 用于将所述可疑文件的文件信息上传至服务器, 使得所述服务 器根据所述可疑文件的文件信息进行分析。
所述装置还包括:
第一处理模块, 用于当确定所述可疑文件的文件信息上传成功时, 从所述 指定区域删除所述可疑文件的文件信息。
所述装置还包括:
第二处理模块, 用于当确定所述可疑文件的文件信息上传失败时, 压缩所 述可疑文件的文件信息。 一种客户端设备, 所述客户端设备包括:
一个或多个处理器; 和
存储器;
所述存储器存储有一个或多个程序, 所述一个或多个程序被配置成由所述 一个或多个处理器执行, 所述一个或多个程序包含用于进行以下操作的指令: 当启动指定扫描时, 枚举所述指定扫描相应区域中的至少一个磁盘文件; 根据所述至少一个磁盘文件和实时防护过程中获取的至少一个可疑文件, 确定扫描文件队列;
根据病毒扫描引擎, 对确定的扫描文件队列进行扫描。
优选地, 还包含用于进行以下操作的指令;
根据所述至少一个可疑文件的文件信息, 判断所述至少一个可疑文件的文
件信息中是否包含所述至少一个磁盘文件中任一磁盘文件的文件名; 如果是,将文件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文 件名的可疑文件和所述至少一个磁盘文件加载至所述扫描文件队列;
如果否, 将所述至少一个磁盘文件加载至所述扫描文件队列。
优选地, 还包含用于进行以下操作的指令:
获取文件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文件名 的可疑文件在进行文件活动时涉及的文件, 并将所述文件信息中包含有所述至 少一个磁盘文件中任一磁盘文件的文件名的可疑文件、进行文件活动时涉及的 文件和所述至少一个磁盘文件加载至所述扫描文件队列。
优选地, 还包含用于进行以下操作的指令:
在实时防护过程中, 获取可疑文件, 将所述可疑文件的文件信息保存至指 定区域, 所述文件信息至少包括所述可疑文件的文件活动。
优选地, 还包含用于进行以下操作的指令:
将所述可疑文件的文件信息上传至服务器,使得所述服务器根据所述可疑 文件的文件信息进行分析。
优选地, 还包含用于进行以下操作的指令:
当确定所述可疑文件的文件信息上传成功时,从所述指定区域删除所述可 疑文件的文件信息。
优选地, 还包含用于进行以下操作的指令:
当确定所述可疑文件的文件信息上传失败时,压缩所述可疑文件的文件信 息。
本发明实施例提供的技术方案带来的有益效果是:
通过当启动指定扫描时,枚举所述指定扫描相应区域中的至少一个磁盘文 件; 根据所述至少一个磁盘文件和实时防护过程中获取的至少一个可疑文件, 确定扫描文件队列; 根据病毒扫描引擎, 对确定的扫描文件队列进行扫描。 本 发明实施例通过采用上述技术方案, 能够将实时防护过程和文件扫描过程结合 起来, 避免了实时防护过程中获取的可疑文件由于指定扫描而被忽略, 从而有 效地避免了由于指定扫描的限制造成的病毒未被彻底清除的现象。 而且采用本 发明实施例中, 根据预先获取的实时防护过程中的可疑文件; 重新确定扫描队 列, 以便对可能产生的威胁进行全面扫描, 实现对文件的彻底查杀, 与现有技 术相比, 能够彻底扫描文件, 提高了清理威胁的能力, 提高病毒查找和清理过
程的效率。 附图说明
为了更清楚地说明本发明实施例中的技术方案, 下面将对实施例描述中所 需要使用的附图作筒单地介绍, 显而易见地, 下面描述中的附图仅仅是本发明 的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下, 还可以根据这些附图获得其他的附图。
图 1为本发明实施例提供的扫描方法的流程图;
图 2为本发明实施例提供的扫描方法的流程图;
图 3为本发明实施例提供的扫描装置的结构示意图;
图 4为本发明实施例提供的扫描装置的结构示意图;
图 5为本发明实施例提供的扫描装置的结构示意图;
图 6为本发明实施例提供的客户端设备的结构示意图。 具体实施方式
为使本发明的目的、 技术方案和优点更加清楚, 下面将结合附图对本发明 实施方式作进一步地详细描述。
图 1为本发明实施例提供的扫描方法的流程图。 如图 1所示, 本实施例的 扫描方法的执行主体为客户端设备, 该客户端设备可以是计算机。 本实施例的 扫描方法, 具体可以包括如下步骤:
100、 当启动指定扫描时, 枚举所述指定扫描相应区域中的至少一个磁盘 文件;
在本实施例中指定扫描泛指对设备进行的部分扫描, 而不是全面扫描, 指 定扫描可以为安全任务扫描或文件扫描。
安全任务扫描是指对内存和 /或关键磁盘的扫描,其相应扫描区域是内存和 /或关键磁盘, 其扫描对象是内存和 /或关键磁盘的磁盘文件, 例如关键磁盘为
C盘, 则安全任务扫描的相应扫描区域为内存和 C盘, 其扫描对象为内存的磁 盘文件和 C盘中的磁盘文件。
而文件扫描是指对指定磁盘上的文件和 /或指定磁盘位置的扫描,其相应扫 描区域是指定磁盘和 /或指定磁盘位置, 其扫描对象是指定磁盘和 /或指定磁盘 位置的磁盘文件, 例如指定磁盘为 D盘, 则文件扫描的相应扫描区域为 D盘,
其扫描对象为 D盘中的磁盘文件。
实际应用中, 安全任务扫描的相应扫描区域可由技术人员设置, 并由用户 在使用中进行调整, 文件扫描的相应扫描区域也可同理设置, 本发明实施例不 做具体限定。
需要说明的是, 本实施例所述的 "至少一个" 是指一个或一个以上。
101、 根据所述至少一个磁盘文件和实时防护过程中获取的至少一个可疑 文件, 确定扫描文件队列;
由于启动指定扫描时, 其扫描的相应区域局限在该指定扫描的相应区域 中, 而实时防护过程中所获取的可疑文件可能不位于指定扫描的相应区域, 则 有可能忽略了该可疑文件, 而产生安全隐患。 因此, 需要在枚举的至少一个磁 盘文件的基础上, 结合至少一个实时防护过程中获取的可疑文件, 以便重新确 定扫描文件队列, 保障扫描的效率。
102、 根据病毒扫描引擎, 对确定的扫描文件队列进行扫描。
在本实施例中病毒扫描引擎可以为本地引擎, 还可以为云端病毒扫描引 擎, 以供扫描时对扫描文件队列中的文件——进行比对, 以查杀与病毒扫描引 擎中病毒特征相符的文件。
综上所述, 本实施例提供的扫描方法, 通过当启动指定扫描时, 枚举所述 指定扫描相应区域中的至少一个磁盘文件; 根据所述至少一个磁盘文件和实时 防护过程中获取的至少一个可疑文件,确定扫描文件队列;根据病毒扫描引擎, 对确定的扫描文件队列进行扫描。 本发明实施例通过采用上述技术方案, 能够 将实时防护过程和文件扫描过程结合起来,避免了实时防护过程中获取的可疑 文件由于指定扫描的扫描范围的局限性而被忽略扫描的问题,从而有效地避免 了由于指定扫描的限制造成的病毒未被彻底清除的现象。 而且采用本发明实施 例中, 根据预先获取的实时防护过程中的可疑文件; 重新确定扫描队列, 以便 对可能产生的威胁进行全面扫描, 实现对文件的彻底查杀, 与现有技术相比, 能够彻底扫描文件,提高了清理威胁的能力,提高病毒查找和清理过程的效率。
可选地, 在上述图 1所示实施例的技术方案的基础上, 其中步骤 101 "根 据所述至少一个磁盘文件和实时防护过程中获取的至少一个可疑文件, 确定扫 描文件队列" 具体可以包括:
( 1 )根据所述至少一个可疑文件的文件信息,判断所述至少一个可疑文件 的文件信息中是否包含所述至少一个磁盘文件中任一磁盘文件的文件名;
在本实施例中的可疑文件的文件信息至少包括该可疑文件的文件活动, 该 文件活动是指该可疑文件的运行、 加载、 生成或修改等。 一旦可疑文件的文件 信息包含磁盘文件的文件名, 则说明该磁盘文件与可疑文件的文件活动相关。 优选地, 可疑文件和磁盘文件之间具有母文件与子文件的关系, 则可疑文件的 文件活动中的母体信息或子文件信息为磁盘文件的文件名。例如可疑文件 B的 文件信息中包含加载文件 B-plus的文件名, 则说明在可疑文件 B的文件活动 时, 会加载至少一个磁盘文件中的磁盘文件 B-plus, 则可获知, 该可疑文件 B 与磁盘文件 B-plus相关联。 又如可疑文件为 C-plus,该可疑文件 C-plus的文件 信息中该可疑文件的来源信息为磁盘文件 C, 也即是磁盘文件 C活动时, 会加 载该可疑文件 C-plus, 则可获知, 该可疑文件 C-plus与磁盘文件 C相关联。 再 如可疑文件为 A, 该可疑文件 A的文件信息中的子文件信息为磁盘文件 A-1 , 则该可疑文件 A为 A-1的母文件, 该可疑文件 A与至少一个磁盘文件中的磁 盘文件 A-1相关联。
需要说明的是, 该可疑文件的文件信息可在实时防护过程中获得并保存至 指定区域, 以供后续扫描过程中读取。
( 2 ) 当所述至少一个可疑文件的文件信息中包含所述至少一个磁盘文件 中任一磁盘文件的文件名时,将文件信息中包含有所述至少一个磁盘文件中任 一磁盘文件的文件名的可疑文件和所述至少一个磁盘文件加载至所述扫描文 件队列;
当确定了所述至少一个可疑文件的文件信息中包含所述至少一个磁盘文 件中任一磁盘文件的文件名时, 即确定了至少一个可疑文件中包括与所述至少 一个磁盘文件中任一磁盘文件相关联的可疑文件。 为了保障查杀效率, 将该文 件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文件名的可疑文件 和至少一个磁盘文件加载至扫描文件队列。
该文件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文件名的 可疑文件可以是一个或多个, 本发明实施例不做具体限定。
( 3 ) 当所述至少一个可疑文件的文件信息中不包含所述至少一个磁盘文 件中任一磁盘文件的文件名时,将所述至少一个磁盘文件加载至所述扫描文件 队列。
需要说明的是, 本发明实施例中将文件加载至扫描文件队列的方法, 详细 可以参考现有技术, 在此不再赘述。
可选地, 在上述图 1所示实施例的技术方案的基础上, 步骤 101中的步骤 ( 2 ) "将文件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文件名 的可疑文件和所述至少一个磁盘文件加载至所述扫描文件队列" 具体可以包 括: 获取文件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文件名的 可疑文件在进行文件活动时涉及的文件, 并将所述文件信息中包含有所述至少 一个磁盘文件中任一磁盘文件的文件名的可疑文件、进行文件活动时涉及的文 件和所述至少一个磁盘文件加载至所述扫描文件队列。
在本实施例中,对于文件信息中包含有所述至少一个磁盘文件中任一磁盘 文件的文件名的可疑文件来说, 其文件活动还可能涉及到其他文件。 因此, 为 了彻底清除威胁, 需将与该可疑文件的文件活动相关的文件也加载至扫描文件 队列。例如文件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文件名 的可疑文件为 B, 在该可疑文件 B的文件活动时, 会加载至少一个磁盘文件中 的磁盘文件 B-plus, 还会加载位于 E盘的磁盘文件 B-1和 B-2, 则在进行加载 时, 将可疑文件 B、 磁盘文件 B-1和 B-2和至少一个磁盘文件加载至扫描文件 队列。
需要说明的是, 该文件信息中包含有所述至少一个磁盘文件中任一磁盘文 件的文件名的可疑文件的文件信息可在实时防护过程中获得并保存至指定区 域, 以供后续扫描过程中读取。
另外, 可疑文件的文件信息还可以包括可疑文件的文件来源、 子文件名称 和母体文件信息名称等。 因此, 通过步骤 101 中 (1 ) 的判断, 还可以获知至 少一个可疑文件中是否包含所述磁盘文件中任一磁盘文件的子文件或母文件。 具体地, 当可疑文件的文件信息中的文件来源、 子文件名称和母体文件信息为 所述至少一个磁盘文件中任一磁盘文件的文件名时, 则该可疑文件的文件来源 为磁盘文件, 或该可疑文件的母体文件为磁盘文件, 或可疑文件为磁盘文件的 文件来源, 或可疑文件为磁盘文件的母体文件等, 则确定至少一个可疑文件中 包含所述至少一个磁盘文件中任一磁盘文件的子文件或母文件。
需要说明的是, 该可疑文件的文件信息可由服务器下发, 并保存在指定区 域。 可选地, 在上述实施例的技术方案的基础上, 其中步骤 102 "根据所述至 少一个磁盘文件和实时防护过程中获取的至少一个可疑文件, 确定扫描文件队 列", 之前还可以包括:
( a )在实时防护过程中, 获取可疑文件, 将所述可疑文件的文件信息保 存至指定区域, 所述文件信息至少包括所述可疑文件的文件活动。
具体地, 启动实时防护; 检测磁盘文件的文件活动; 当根据磁盘文件的文 件活动获取到可疑文件时,判断该可疑文件是否已经被记录;如果是,则结束, 如果否, 则将可疑文件记录为可疑文件, 并将可疑文件的文件信息保存至指定 实现方式, 本发明不——赘述。
在本实施例中指定区域是指在磁盘上划分的用于保存可疑文件的文件信息 的区域, 该可疑文件的文件信息在实时防护过程中获取并保存, 该指定区域的 位置和容量均可以由技术人员、 使用者设置或调整, 本发明实施例不做具体限 定。 可疑文件的文件活动包括但不限于以下任一文件活动: ( i )释放子文件, 相应地, 文件信息包括子文件名称、 子文件存储路径、 子文件修改时间和子文 件建立时间中的至少一种。 ( ii )加载文件, 相应地, 文件信息包括加载的文 件名称和加载的文件路径中的至少一种。 (iii )可疑文件的建立或修改, 相应 地, 文件信息包括可疑文件的建立时间或修改时间、 可疑文件的母体文件信息 和母体文件路径中的至少一种。
需要说明的是, 在实时防护过程中需要保存的文件信息可由技术人员设置 或调整, 该设置和调整均可通过软件更新实现, 本发明实施例不做具体限定。 可选地, 在上述实施例的技术方案的基础上, 在上述步骤(a ) "在实时防 护过程中, 获取可疑文件, 将所述可疑文件的文件信息保存至指定区域, 所述 文件信息至少包括所述可疑文件的文件活动", 之后包括: (b )将所述可疑 文件的文件信息上传至服务器,使得所述服务器根据所述可疑文件的文件信息 进行分析。
本实施例中的服务器可以为云端服务器, 通过将可疑文件的文件信息上传 至云端服务器, 可以使得技术人员根据上传的可疑文件的文件信息对可疑文件 的文件活动以及其病毒特征等进行分析, 以供对病毒扫描引擎进行升级等处 理, 本实施例不做具体限定。 进一步地, 在将可疑文件的文件信息上传服务器 件的文件信息; 如果是, 则不上传该可疑文件的文件信息; 如果否, 则继续上 传该可疑文件的文件信息。 更进一步地, 该上传过程的上传方式可以是周期性
上传, 还可以每次实时保护过程结束时上传, 还可以在检测到可疑文件的文件 信息发生了更新以后上传, 本实施例不做具体限定。 可选地, 在上述实施例的技术方案的基础上, 在上述步骤(b ) "将所述可 疑文件的文件信息上传至服务器", 之后包括:
( C )当确定所述可疑文件的文件信息上传成功时,从所述指定区域删除所 述可疑文件的文件信息。
为了节省磁盘资源, 当确定所述可疑文件的文件信息已经成功上传至服务 器时, 则删除可疑文件的文件信息。 需要说明的是, 确定文件信息是否上传成 功为现有技术, 在此不再赘述。
可选地, 在上述实施例的技术方案的基础上, 在上述步骤(b ) "将所述可 疑文件的文件信息上传至服务器", 之后包括: 当确定所述可疑文件的文件信 息上传失败时, 压缩所述可疑文件的文件信息。
用户网络异常等原因可能导致步骤(b ) 的上传失败, 则为了在不浪费磁 盘资源的情况下保留文件信息, 则对该文件信息做压缩处理。 进一步地, 当用 户的网络恢复正常后, 将该可疑文件的文件信息上传至服务器, 并在本地将该 文件信息做删除处理。
需要说明的是, 上述所有可选技术方案可以采用互相结合的任意方式组成 本发明实施例的可选技术方案, 在此不再——举例。
上述实施例通过采用上述技术方案, 能够将实时防护过程和文件扫描过程 结合起来, 避免了实时防护过程中获取的可疑文件由于指定扫描的扫描范围局 限性而被忽略扫描的问题,从而有效地避免了由于子母文件或指定扫描的限制 造成的病毒未被彻底清除的现象。 而且采用本发明实施例中, 根据预先获取的 实时防护过程中的可疑文件; 重新确定扫描队列, 以便对可能产生的威胁进行 全面扫描, 实现对文件的彻底查杀, 与现有技术相比, 能够彻底扫描文件, 提 高了清理威胁的能力, 提高病毒查找和清理过程的效率。
图 2为本发明实施例提供的扫描方法的流程图。 本实施例的扫描以包括上 述所有可选技术方案为例, 更加详细地介绍本发明的技术方案。 如图 2所示, 本实施例的扫描方法, 具体可以包括如下步骤:
200、 在实时防护过程中, 获取可疑文件, 将所述可疑文件的文件信息保 存至指定区域, 所述文件信息至少包括所述可疑文件的文件活动; 执行 201 ;
201、 将所述可疑文件的文件信息上传至服务器, 使得所述服务器根据所 述可疑文件的文件信息进行分析; 执行 202;
进一步地, 将所述可疑文件的文件信息上传至服务器, 之后包括: 当确定所述可疑文件的文件信息上传成功时,从所述指定区域删除所述可 疑文件的文件信息。
进一步地, 将所述可疑文件的文件信息上传至服务器, 之后包括: 当确定所述可疑文件的文件信息上传失败时,压缩所述可疑文件的文件信 息。
202、 当启动指定扫描时, 枚举所述指定扫描相应区域中的至少一个磁盘 文件; 执行 203;
203、 根据所述至少一个可疑文件的文件信息, 判断所述至少一个可疑文 件的文件信息中是否包含所述至少一个磁盘文件中任一磁盘文件的文件名; 如 果是, 执行 204; 如果否, 执行 205;
204、 将文件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文件 名的可疑文件和所述至少一个磁盘文件加载至所述扫描文件队列, 执行 206;
205、 将所述至少一个磁盘文件加载至所述扫描文件队列, 执行 206;
206、 根据病毒扫描引擎, 对确定的扫描文件队列进行扫描。
本发明实施例通过采用上述技术方案, 能够将实时防护过程和文件扫描过 程结合起来, 避免了实时防护过程中获取的可疑文件由于指定扫描的扫描范围 的局限性而被忽略扫描的问题,从而有效地避免了由于子母文件或指定扫描的 限制造成的病毒未被彻底清除的现象。 而且采用本发明实施例中, 根据预先获 取的实时防护过程中的可疑文件; 重新确定扫描队列, 以便对可能产生的威胁 进行全面扫描, 实现对文件的彻底查杀,与现有技术相比, 能够彻底扫描文件, 提高了清理威胁的能力, 提高病毒查找和清理过程的效率。 图 3为本发明实施例提供的扫描装置的结构示意图。 如图 3所示, 所述扫 描装置, 具体可以包括: 枚举模块 10、 队列确定模块 11和扫描模块 12。
枚举模块 10,用于当启动指定扫描时,枚举所述指定扫描相应区域中的至 少一个磁盘文件; 枚举模块 10和队列确定模块 11连接, 队列确定模块 11 , 用 于根据所述至少一个磁盘文件和实时防护过程中获取的至少一个可疑文件, 确 定扫描文件队列; 队列确定模块 11和扫描模块 12连接, 扫描模块 12, 用于根
据病毒扫描引擎, 对队列确定模块 11确定的扫描文件队列进行扫描。
本实施例的扫描装置, 通过采用上述模块实现文件扫描与上述相关方法实 施例的实现机制相同, 详细可以参考上述相关方法实施例的记载, 在此不再赘 述。
本实施例的扫描装置, 能够将实时防护过程和文件扫描过程结合起来, 避 免了实时防护过程中获取的可疑文件由于指定扫描的扫描范围的局限性而被 忽略扫描的问题,从而有效地避免了由于子母文件或指定扫描的限制造成的病 毒未被彻底清除的现象。 而且采用本发明实施例中, 根据预先获取的实时防护 过程中的可疑文件;重新确定扫描队列,以便对可能产生的威胁进行全面扫描, 实现对文件的彻底查杀, 与现有技术相比, 能够彻底扫描文件, 提高了清理威 胁的能力, 提高病毒查找和清理过程的效率。
本实施例的扫描装置在上述图 3所示实施例的基础上, 进一步可以包括如 下技术方案: 所述队列确定模块 11包括: 判断单元和加载单元(图中未示), 判断单元与加载单元连接, 判断单元, 用于根据所述至少一个可疑文件的文件 信息, 判断所述至少一个可疑文件的文件信息中是否包含所述至少一个磁盘文 件中任一磁盘文件的文件名; 加载单元, 用于当所述至少一个可疑文件的文件 信息中包含所述至少一个磁盘文件中任一磁盘文件的文件名,将文件信息中包 含有所述至少一个磁盘文件中任一磁盘文件的文件名的可疑文件和所述至少 一个磁盘文件加载至所述扫描文件队列; 所述加载单元, 还用于当所述至少一 个可疑文件的文件信息中不包含所述至少一个磁盘文件中任一磁盘文件的文 件名,将所述至少一个磁盘文件加载至所述扫描文件队列。
进一步地, 所述加载单元还用于获取文件信息包含所述至少一个磁盘文件 文件信息包含所述至少一个磁盘文件中任一磁盘文件的文件名的可疑文件、进 行文件活动时涉及的文件和所述至少一个磁盘文件加载至所述扫描文件队列。 图 4为本发明实施例提供的扫描装置的结构示意图。 如图 4所示, 本实施 例的扫描装置在上述图 3所示实施例的基础上,进一步可以包括如下技术方案。
如图 4所示, 本实施例的扫描装置中还包括获取模块 13, 获取模块 13和 队列确定模块 11连接, 获取模块 13用于在实时防护过程中, 获取可疑文件, 将所述可疑文件的文件信息保存至指定区域, 所述文件信息至少包括所述可疑
文件的文件活动。 图 5为本发明实施例提供的扫描装置的结构示意图。 如图 5所示, 本实施 例的扫描装置在上述图 4所示实施例的基础上,进一步可以包括如下技术方案。
如图 5所示, 本实施例的扫描装置中还包括上传模块 14, 上传模块 14和 获取模块 13连接,上传模块 14用于将所述可疑文件的文件信息上传至服务器, 使得所述服务器根据所述可疑文件的文件信息进行分析。
可选地, 本实施例的扫描装置中还包括第一处理模块(图中未示), 用于 当确定所述可疑文件的文件信息上传成功时,从所述指定区域删除所述可疑文 件的文件信息。
可选地, 本实施例的扫描装置中还包括第二处理模块(图中未示), 用于 当确定所述可疑文件的文件信息上传失败时, 压缩所述可疑文件的文件信息。
本实施例的扫描装置, 通过采用上述模块实现文件扫描与上述相关方法实 施例的实现机制相同, 详细可以参考上述相关方法实施例的记载, 在此不再赘 述。
本实施例的扫描装置, 能够将实时防护过程和文件扫描过程结合起来, 避 免了实时防护过程中获取的可疑文件由于指定扫描的扫描范围的局限性而被 忽略扫描的问题,从而有效地避免了由于子母文件或指定扫描的限制造成的病 毒未被彻底清除的现象。 而且采用本发明实施例中, 根据预先获取的实时防护 过程中的可疑文件;重新确定扫描队列,以便对可能产生的威胁进行全面扫描, 实现对文件的彻底查杀, 与现有技术相比, 能够彻底扫描文件, 提高了清理威 胁的能力, 提高病毒查找和清理过程的效率。
需要说明的是: 上述实施例提供的扫描装置在扫描时, 仅以上述各功能模 块的划分进行举例说明, 实际应用中, 可以根据需要而将上述功能分配由不同 的功能模块完成, 即将设备的内部结构划分成不同的功能模块, 以完成以上描 述的全部或者部分功能。 另外, 上述实施例提供的扫描的装置与扫描方法实施 例属于同一构思, 其具体实现过程详见方法实施例, 这里不再赘述。
上述扫描装置可以用于包括但不限于个人计算机的具有杀毒功能的任一 客户端设备。 图 6 是本发明实施例涉及的客户端设备的结构示意图。 所述客户端设备
600可以为常规的台式计算机或者膝上型笔记本, 所述客户端 600包括中央处 理单元( CPU ) 601、 包括随机存取存储器( RAM ) 602和只读存储器( ROM ) 603的系统存储器 604, 以及连接系统存储器 604和中央处理单元 601的系统 总线 605。 所述客户端设备 600还包括帮助计算机内的各个器件之间传输信息 的基本输入 /输出系统(I/O 系统) 606, 和用于存储操作系统 613、 应用程序 614和其他程序模块 615的大容量存储设备 607。
所述基本输入 /输出系统 606包括有用于显示信息的显示器 608和用于用户 输入信息的诸如鼠标、 键盘之类的输入设备 609。 其中所述显示器 608和输入 设备 609都通过连接到系统总线 605的输入输出控制器 610连接到中央处理单 元 601。所述基本输入 /输出系统 606还可以包括输入输出控制器 610以用于接 收和处理来自键盘、 鼠标、 或电子触控笔等多个其他设备的输入。 类似地, 输 入输出控制器 610还提供输出到显示屏、 打印机或其他类型的输出设备。
所述大容量存储设备 607通过连接到系统总线 605 的大容量存储控制器
(未示出)连接到中央处理单元 601。 所述大容量存储设备 607及其相关联的 计算机可读介质为客户端设备 600提供非易失性存储。 也就是说, 所述大容量 存储设备 607可以包括诸如硬盘或者 CD-ROM驱动器之类的计算机可读介质
(未示出) 。
不失一般性, 所述计算机可读介质可以包括计算机存储介质和通信介质。 计算机存储介质包括以用于存储诸如计算机可读指令、 数据结构、 程序模块或 其他数据等信息的任何方法或技术实现的易失性和非易失性、可移动和不可移 动介质。 计算机存储介质包括 RAM、 ROM, EPROM、 EEPROM、 闪存或其他 固态存储其技术, CD-ROM、 DVD 或其他光学存储、 磁带盒、 磁带、 磁盘存 储或其他磁性存储设备。 当然, 本领域技术人员可知所述计算机存储介质不局 限于上述几种。上述的系统存储器 604和大容量存储设备 607可以统称为存储 器。
根据本发明的各种实施例, 所述客户端设备 600还可以通过诸如因特网等 网络连接到网络上的远程计算机运行。也即客户端设备 600可以通过连接在所 述系统总线 605上的网络接口单元 611连接到网络 612, 或者说, 也可以使用 网络接口单元 in来连接到其他类型的网络或远程计算机系统(未示出 ) 。
所述存储器还包括一个或者一个以上的程序, 所述一个或者一个以上程序 存储于存储器中, 且经配置以由一个或者一个以上中央处理单元 601执行所述
一个或者一个以上程序包含用于执行图 1所示实施例所提供的扫描方法和图 2 所示实施例所提供的扫描方法。
本领域普通技术人员可以理解实现上述实施例的全部或部分步骤可以通 过硬件来完成, 也可以通过程序来指令相关的硬件完成, 所述的程序可以存储 于一种计算机可读存储介质中, 上述提到的存储介质可以是只读存储器, 磁盘 或光盘等。 所述计算机可读存储介质存储有一个或者一个以上程序, 所述一个 或者一个以上程序被一个或者一个以上的处理器用来执行图 1所示实施例所提 供的扫描方法和图 2所示实施例所提供的扫描方法。
以上所述仅为本发明的较佳实施例, 并不用以限制本发明, 凡在本发明的 精神和原则之内, 所作的任何修改、 等同替换、 改进等, 均应包含在本发明的 保护范围之内。
Claims
1、 一种扫描方法, 其特征在于, 所述方法包括:
当启动指定扫描时, 枚举所述指定扫描相应区域中的至少一个磁盘文件; 根据所述至少一个磁盘文件和实时防护过程中获取的至少一个可疑文件, 确定扫描文件队列;
根据病毒扫描引擎, 对确定的扫描文件队列进行扫描。
2、 根据权利要求 1所述的方法, 其特征在于, 根据所述至少一个磁盘文件 和实时防护过程中获取的至少一个可疑文件, 确定扫描文件队列, 包括:
根据所述至少一个可疑文件的文件信息, 判断所述至少一个可疑文件的文 件信息中是否包含所述至少一个磁盘文件中任一磁盘文件的文件名;
如果是, 将文件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文 件名的可疑文件和所述至少一个磁盘文件加载至所述扫描文件队列;
如果否, 将所述至少一个磁盘文件加载至所述扫描文件队列。
3、 根据权利要求 2所述的方法, 其特征在于, 将文件信息包含所述至少一 个磁盘文件中任一磁盘文件的文件名的可疑文件和所述至少一个磁盘文件加载 至所述扫描文件队列, 包括:
获取文件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文件名的 可疑文件在进行文件活动时涉及的文件, 并将所述文件信息中包含有所述至少 一个磁盘文件中任一磁盘文件的文件名的可疑文件、 进行文件活动时涉及的文 件和所述至少一个磁盘文件加载至所述扫描文件队列。
4、 根据权利要求 1-3任一项所述的方法, 其特征在于, 根据所述至少一个 磁盘文件和实时防护过程中获取的至少一个可疑文件, 确定扫描文件队列, 之 前包括:
在实时防护过程中, 获取可疑文件, 将所述可疑文件的文件信息保存至指 定区域, 所述文件信息至少包括所述可疑文件的文件活动。
5、 根据权利要求 4所述的方法, 其特征在于, 在实时防护过程中, 获取可
疑文件, 将所述可疑文件的文件信息保存至指定区域, 所述文件信息至少包括 所述可疑文件的文件活动, 之后包括:
将所述可疑文件的文件信息上传至服务器, 使得所述服务器根据所述可疑 文件的文件信息进行分析。
6、 根据权利要求 5所述的方法, 其特征在于, 将所述可疑文件的文件信息 上传至服务器, 之后包括:
当确定所述可疑文件的文件信息上传成功时, 从所述指定区域删除所述可 疑文件的文件信息。
7、 根据权利要求 5所述的方法, 其特征在于, 将所述可疑文件的文件信息 上传至服务器, 之后包括:
当确定所述可疑文件的文件信息上传失败时, 压缩所述可疑文件的文件信 息。
8、 一种扫描装置, 其特征在于, 所述装置包括:
枚举模块, 用于当启动指定扫描时, 枚举所述指定扫描相应区域中的至少 一个磁盘文件;
队列确定模块, 用于根据所述至少一个磁盘文件和实时防护过程中获取的 至少一个可疑文件, 确定扫描文件队列;
扫描模块, 用于根据病毒扫描引擎, 对确定的扫描文件队列进行扫描。
9、 根据权利要求 8所述的装置, 其特征在于, 所述队列确定模块包括: 判断单元, 用于根据所述至少一个可疑文件的文件信息, 判断所述至少一 个可疑文件的文件信息中是否包含所述至少一个磁盘文件中任一磁盘文件的文 件名;
加载单元, 用于当所述至少一个可疑文件的文件信息中包含所述至少一个 磁盘文件中任一磁盘文件的文件名,将文件信息包含所述至少一个磁盘文件中任 一磁盘文件的文件名的可疑文件和所述至少一个磁盘文件加载至所述扫描文件 队列;
所述加载单元, 还用于当所述至少一个可疑文件的文件信息中不包含所述
至少一个磁盘文件中任一磁盘文件的文件名,将所述至少一个磁盘文件加载至所 述扫描文件队列。
10、 根据权利要求 9所述的装置, 其特征在于, 所述加载单元还用于获取 文件信息包含所述至少一个磁盘文件中任一磁盘文件的文件名的可疑文件在进 行文件活动时涉及的文件, 并将所述文件信息包含所述至少一个磁盘文件中任 一磁盘文件的文件名的可疑文件、 进行文件活动时涉及的文件和所述至少一个 磁盘文件加载至所述扫描文件队列。
11、根据权利要求 8-10任一项所述的装置, 其特征在于, 所述装置还包括: 获取模块, 用于在实时防护过程中, 获取可疑文件, 将所述可疑文件的文 件信息保存至指定区域, 所述文件信息至少包括所述可疑文件的文件活动。
12、 根据权利要求 11所述的装置, 其特征在于, 所述装置还包括: 上传模块, 用于将所述可疑文件的文件信息上传至服务器, 使得所述服务 器根据所述可疑文件的文件信息进行分析。
13、 根据权利要求 12所述的装置, 其特征在于, 所述装置还包括: 第一处理模块, 用于当确定所述可疑文件的文件信息上传成功时, 从所述 指定区域删除所述可疑文件的文件信息。
14、 根据权利要求 13所述的装置, 其特征在于, 所述装置还包括: 第二处理模块, 用于当确定所述可疑文件的文件信息上传失败时, 压缩所 述可疑文件的文件信息。
15、 一种客户端设备, 其特征在于, 所述客户端设备包括:
一个或多个处理器; 和
存储器;
所述存储器存储有一个或多个程序, 所述一个或多个程序被配置成由所述 一个或多个处理器执行, 所述一个或多个程序包含用于进行以下操作的指令: 当启动指定扫描时, 枚举所述指定扫描相应区域中的至少一个磁盘文件;
根据所述至少一个磁盘文件和实时防护过程中获取的至少一个可疑文件, 确定扫描文件队列;
根据病毒扫描引擎, 对确定的扫描文件队列进行扫描。
16、 根据权利要求 15所述的客户端设备, 其特征在于, 还包含用于进行以 下操作的指令;
根据所述至少一个可疑文件的文件信息, 判断所述至少一个可疑文件的文 件信息中是否包含所述至少一个磁盘文件中任一磁盘文件的文件名;
如果是, 将文件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文 件名的可疑文件和所述至少一个磁盘文件加载至所述扫描文件队列;
如果否, 将所述至少一个磁盘文件加载至所述扫描文件队列。
17、 根据权利要求 16所述的客户端设备, 其特征在于, 还包含用于进行以 下操作的指令:
获取文件信息中包含有所述至少一个磁盘文件中任一磁盘文件的文件名的 可疑文件在进行文件活动时涉及的文件, 并将所述文件信息中包含有所述至少 一个磁盘文件中任一磁盘文件的文件名的可疑文件、 进行文件活动时涉及的文 件和所述至少一个磁盘文件加载至所述扫描文件队列。
18、根据权利要求 15-17任一项所述的客户端设备, 其特征在于, 还包含用 于进行以下操作的指令:
在实时防护过程中, 获取可疑文件, 将所述可疑文件的文件信息保存至指 定区域, 所述文件信息至少包括所述可疑文件的文件活动。
19、 根据权利要求 18所述的客户端设备, 其特征在于, 还包含用于进行以 下操作的指令:
将所述可疑文件的文件信息上传至服务器, 使得所述服务器根据所述可疑 文件的文件信息进行分析。
20、 根据权利要求 19所述的客户端设备, 其特征在于, 还包含用于进行以 下操作的指令:
当确定所述可疑文件的文件信息上传成功时, 从所述指定区域删除所述可 疑文件的文件信息。
21、 根据权利要求 19所述的客户端设备, 其特征在于, 还包含用于进行以 下操作的指令:
当确定所述可疑文件的文件信息上传失败时, 压缩所述可疑文件的文件信 息。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US14/581,014 US9819695B2 (en) | 2012-06-26 | 2014-12-23 | Scanning method and device, and client apparatus |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201210213332.9 | 2012-06-26 | ||
| CN201210213332.9A CN102799811B (zh) | 2012-06-26 | 2012-06-26 | 扫描方法和装置 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US14/581,014 Continuation US9819695B2 (en) | 2012-06-26 | 2014-12-23 | Scanning method and device, and client apparatus |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2014000616A1 true WO2014000616A1 (zh) | 2014-01-03 |
Family
ID=47198917
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2013/077799 Ceased WO2014000616A1 (zh) | 2012-06-26 | 2013-06-24 | 扫描方法、装置和客户端设备 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US9819695B2 (zh) |
| CN (1) | CN102799811B (zh) |
| WO (1) | WO2014000616A1 (zh) |
Families Citing this family (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102799811B (zh) * | 2012-06-26 | 2014-04-16 | 腾讯科技(深圳)有限公司 | 扫描方法和装置 |
| CN102982284B (zh) * | 2012-11-30 | 2016-04-20 | 北京奇虎科技有限公司 | 用于恶意程序查杀的扫描设备、云端管理设备及方法和系统 |
| CN103970766A (zh) * | 2013-01-29 | 2014-08-06 | 腾讯科技(深圳)有限公司 | 一种数据文件处理的方法、装置及终端 |
| CN103390130B (zh) | 2013-07-18 | 2017-04-05 | 北京奇虎科技有限公司 | 基于云安全的恶意程序查杀的方法、装置和服务器 |
| CN104598819B (zh) * | 2015-01-09 | 2017-12-26 | 百度在线网络技术(北京)有限公司 | 一种用于扫描压缩包的方法、装置和系统 |
| US10075453B2 (en) * | 2015-03-31 | 2018-09-11 | Juniper Networks, Inc. | Detecting suspicious files resident on a network |
| US9977905B2 (en) * | 2015-10-06 | 2018-05-22 | Assured Enterprises, Inc. | Method and system for identification of security vulnerabilities |
| CN106934286B (zh) * | 2015-12-31 | 2020-02-04 | 北京金山安全软件有限公司 | 一种安全诊断方法、装置及电子设备 |
| US11636198B1 (en) * | 2019-03-30 | 2023-04-25 | Fireeye Security Holdings Us Llc | System and method for cybersecurity analyzer update and concurrent management system |
| US11288391B2 (en) * | 2019-09-13 | 2022-03-29 | EMC IP Holding Company LLC | Filename-based malware pre-scanning |
| CN112583790A (zh) * | 2020-11-05 | 2021-03-30 | 贵州数安汇大数据产业发展有限公司 | 基于多证据实体的安全威胁智能发现方法 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6968461B1 (en) * | 2000-10-03 | 2005-11-22 | Networks Associates Technology, Inc. | Providing break points in a malware scanning operation |
| US7681237B1 (en) * | 2004-05-13 | 2010-03-16 | Symantec Corporation | Semi-synchronous scanning of modified files in real time |
| CN102012992A (zh) * | 2010-11-19 | 2011-04-13 | 奇智软件(北京)有限公司 | 一种实时防护文件的监控方法及装置 |
| CN102194073A (zh) * | 2011-06-03 | 2011-09-21 | 奇智软件(北京)有限公司 | 一种杀毒软件的扫描方法及装置 |
| CN102799811A (zh) * | 2012-06-26 | 2012-11-28 | 腾讯科技(深圳)有限公司 | 扫描方法和装置 |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7496960B1 (en) * | 2000-10-30 | 2009-02-24 | Trend Micro, Inc. | Tracking and reporting of computer virus information |
| US6836860B2 (en) * | 2001-09-04 | 2004-12-28 | Networks Associates Technology, Inc. | Data scanning for updatable predefined properties |
| US8161556B2 (en) * | 2008-12-17 | 2012-04-17 | Symantec Corporation | Context-aware real-time computer-protection systems and methods |
| CN102915421B (zh) * | 2011-08-04 | 2013-10-23 | 腾讯科技(深圳)有限公司 | 文件的扫描方法及系统 |
-
2012
- 2012-06-26 CN CN201210213332.9A patent/CN102799811B/zh active Active
-
2013
- 2013-06-24 WO PCT/CN2013/077799 patent/WO2014000616A1/zh not_active Ceased
-
2014
- 2014-12-23 US US14/581,014 patent/US9819695B2/en active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6968461B1 (en) * | 2000-10-03 | 2005-11-22 | Networks Associates Technology, Inc. | Providing break points in a malware scanning operation |
| US7681237B1 (en) * | 2004-05-13 | 2010-03-16 | Symantec Corporation | Semi-synchronous scanning of modified files in real time |
| CN102012992A (zh) * | 2010-11-19 | 2011-04-13 | 奇智软件(北京)有限公司 | 一种实时防护文件的监控方法及装置 |
| CN102194073A (zh) * | 2011-06-03 | 2011-09-21 | 奇智软件(北京)有限公司 | 一种杀毒软件的扫描方法及装置 |
| CN102799811A (zh) * | 2012-06-26 | 2012-11-28 | 腾讯科技(深圳)有限公司 | 扫描方法和装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN102799811B (zh) | 2014-04-16 |
| CN102799811A (zh) | 2012-11-28 |
| US9819695B2 (en) | 2017-11-14 |
| US20150113653A1 (en) | 2015-04-23 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2014000616A1 (zh) | 扫描方法、装置和客户端设备 | |
| CN102663288B (zh) | 病毒查杀方法及装置 | |
| Moser et al. | Hunting in the enterprise: Forensic triage and incident response | |
| RU2571723C2 (ru) | Система и способ для снижения нагрузки на операционную систему при работе антивирусного приложения | |
| US8839434B2 (en) | Multi-nodal malware analysis | |
| RU2454705C1 (ru) | Система и способ защиты компьютерного устройства от вредоносных объектов, использующих сложные схемы заражения | |
| EP2860657B1 (en) | Determining a security status of potentially malicious files | |
| US10382477B2 (en) | Identification apparatus, control method therefor, and storage medium | |
| US20110219451A1 (en) | System And Method For Host-Level Malware Detection | |
| US20140365443A1 (en) | Framework for running untrusted code | |
| CN103049695B (zh) | 一种计算机病毒的监控方法和装置 | |
| US8635079B2 (en) | System and method for sharing malware analysis results | |
| US8627404B2 (en) | Detecting addition of a file to a computer system and initiating remote analysis of the file for malware | |
| US11520889B2 (en) | Method and system for granting access to a file | |
| US9929896B2 (en) | Customizable serviceability mechanism | |
| CN103428212A (zh) | 一种恶意代码检测及防御的方法 | |
| CN103679027A (zh) | 内核级恶意软件查杀的方法和装置 | |
| CN110505246B (zh) | 客户端网络通讯检测方法、装置及存储介质 | |
| US9734191B2 (en) | Asynchronous image repository functionality | |
| KR101974989B1 (ko) | 위험 파일에 대응하는 행위 정보를 결정하는 방법 및 장치 | |
| US20140331320A1 (en) | Techniques for detecting malicious activity | |
| CN105930740A (zh) | 软体文件被修改时的来源追溯方法、监测方法、还原方法及系统 | |
| US10200374B1 (en) | Techniques for detecting malicious files | |
| JP2021077373A (ja) | 脅威検出方法及びコンピュータ装置 | |
| CN109784037B (zh) | 文档文件的安全防护方法及装置、存储介质、计算机设备 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13809756 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 02-06-2015) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 13809756 Country of ref document: EP Kind code of ref document: A1 |