WO2014059933A1 - Method and user device for processing virus files - Google Patents
Method and user device for processing virus files Download PDFInfo
- Publication number
- WO2014059933A1 WO2014059933A1 PCT/CN2013/085353 CN2013085353W WO2014059933A1 WO 2014059933 A1 WO2014059933 A1 WO 2014059933A1 CN 2013085353 W CN2013085353 W CN 2013085353W WO 2014059933 A1 WO2014059933 A1 WO 2014059933A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- virus file
- category
- manner
- virus
- user
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/561—Virus type analysis
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/566—Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/03—Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
- G06F2221/034—Test or assess a computer or a system
Definitions
- the present disclosure relates to computer security techniques, and particularly to a method and a user device for processing virus files.
- Anti-virus software generally displays information of a virus to a user soon after the virus is detected to implement a real-time virus report mechanism.
- anti- virus software may display too many virus alerts that the user bearly has time to process one by one. The alerts distract attention of the user continuously and disturb the user using the computer.
- Some anti-virus software may display in a dialog the information of all viruses detected during the period the dialog is being displayed to avoid popping up too many dialogs and disturbing the user. Summary
- a method for processing virus files may include: providing first information of at least one category of virus file and second information of a manner for processing each of the at least one category of virus file; obtaining a category of a virus file when the virus file is identified; obtaining a manner for processing virus files of the category from the first information and the second information and processing the virus file by using the manner without presenting information about the virus file to a user.
- a user device may include: a category obtaining module, configured to obtain a category of a virus file when the virus file is identified without presenting information about the virus file to a user; a manner obtaining module, configured to obtain a manner for processing virus files of the category by using pre-defined first information of at least one category of virus file and second information of a manner for processing each of the at least one category of virus file without presenting information about the virus file to a user; and a processing module, configured to process the virus file according to the manner without presenting the information about the virus file to the user.
- the technical scheme of the present disclosure classifies virus files detected and processes the virus files according to respective categories of the virus files.
- the process is implemented at the background silently, thus avoids prompting the user each time when a virus file is detected.
- the problem of virus alerts disturbing the user is solved, and at the same time, prompt information provided to a user is informative and user-friendly.
- FIG.l is a flowchart illustrating a method for processing virus files according to an example of the present disclosure.
- FIG.2 is a flowchart illustrating a method for processing virus files according to an example of the present disclosure
- FIG.3 is a flowchart illustrating a method for processing virus files according to an example of the present disclosure
- FIG.4 is a schematic diagram illustrating a structure of a user device according to an example of the present disclosure.
- FIG.l is a schematic diagram illustrating an example of a computer.
- computer 100 may be a computing device capable of executing a method and apparatus of present disclosure.
- the computer 100 may, for example, be a device such as a personal desktop computer or a portable device, such as a laptop computer, a tablet computer, a cellular telephone, or a smart phone.
- the computer 100 may also be a server that connects to the above devices locally or via a network.
- the computer 100 may vary in terms of capabilities or features. Claimed subject matter is intended to cover a wide range of potential variations.
- the computer 100 may include a keypad/keyboard 156. It may also comprise a display 154, such as a liquid crystal display (LCD), or a display with a high degree of functionality, such as a touch-sensitive color 2D or 3D display.
- a web-enabled computer 100 may include one or more physical or virtual keyboards, and mass storage medium 130.
- the computer 100 may also include or may execute a variety of operating systems 141, including an operating system, such as a WindowsTM or LinuxTM, or a mobile operating system, such as iOSTM, AndroidTM, or Windows MobileTM.
- the computer 100 may include or may execute a variety of possible applications 142, such as an anti- virus application 145.
- An application 142 may enable processing virus files without presenting alerts to the user of the computer 100.
- the computer 100 may include one or more non-transitory processor-readable storage media 130 and one or more processors 122 in communication with the non-transitory processor-readable storage media 130.
- the non-transitory processor-readable storage media 130 may be a RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a CD-ROM, or any other form of non-transitory storage medium known in the art.
- the one or more non-transitory processor-readable storage media 130 may store sets of instructions, or units and/or modules that comprise the sets of instructions, for conducting operations described in the present application.
- the one or more processors may be configured to execute the sets of instructions and perform the operations in examples of the present application.
- FIG.2 is a flowchart illustrating a method for processing virus files according to an example of the present disclosure.
- the method may be implemented by a user device, e.g., a fixed terminal device or a mobile terminal device.
- the fixed terminal device may be a PC and the like.
- the mobile terminal device may be a smart phone, a tablet computer, a MP3 player, a PDA and the like.
- the method may include the following procedures.
- a category of a virus file is obtained when the virus file is identified.
- the user device may identify a virus file by using various methods, e.g., identifying the virus file by using an anti-virus engine installed in the user device or by using an anti-virus engine in a cloud and so on, and this is not limited in the present disclosure.
- the category of the virus file may be determined by at least one of the directory in which the virus file is located, a process accessing the virus file (i.e., an object being infected), the infection manner and the like.
- a virus file may belong to multiple categories, e.g., the virus file may belong to a category of system directories when the virus file is located in a system directory; the virus file may belong to a category of extraction of a compressed archive when the virus file is a file obtained by extracting a compressed archive. Describing a virus file by using several category s enables viewing the virus file from multiple aspects.
- the virus file may be processed in different manners corresponding to the different category s.
- a manner for processing virus files of the category is obtained.
- the method of obtaining the manner may include: (1) storing a manner for each category in the user device and/or in a server in a cloud in advance, obtaining the manner corresponding to the category when the category is identified; (2) when the category is identified, judging whether there is a manner associated with the category in the user device or in the server in the cloud, and obtaining the manner associated with the category in response to a determination that there is a manner associated with the category in the user device or in the server in the cloud, or obtaining a manner selected by a user in response to a determination that no manner is associated with the category in the user device or in the server in the cloud.
- Several options may be provided for the user to choose from.
- the virus file is processed according to the manner.
- the processing of a virus file may include, but not limited to, deleting the virus, deleting the virus file completely, isolating the virus file, and the like.
- a method for processing virus files obtains the category of a virus file when the virus file is identified, obtains a manner for processing virus files of the category and processes the virus file by using the manner.
- the technical scheme of the present disclosure classifies virus files detected and processes the virus files according to the categorys of the virus files. The process is implemented at the background silently, thus avoids prompting the user each time when a virus file is detected. The mechanism avoids disturbing user by too many virus alerts, and prompt information provided to the user is informative and user- friendly.
- the method of obtaining the category of the virus file when the virus file is identified in block 201 may include: obtaining the category of the virus file at least by using the directory in which the virus file is located and/or a process accessing the virus file when the virus file is identified.
- the category of the virus file may be configured by a technician in advance, or may be configured during the process the user uses the device at least according to the directory in which the virus file is located and/or the process accessing the virus file.
- the anti-virus software may detect a large amount of viruses. By classifying files in one directory into the same category, the user may decide not to have information of all viruses found in the directory presented. Therefore, information of a virus file is not presented when the virus file is in the same directory.
- the anti-virus software may also detect a lot of virus files.
- files extracted by the same data compression software may be classified into the same category so that the user may decide not to have virus information detected in files extracted from one de-compression process presented. As such, information of a virus file may not be displayed when the virus file is extracted in the same de-compression process.
- Virus files may be classified according to any classification rule to obtain a category.
- a virus file may also be classified by using at least the above two manners to obtain at least two categories, i.e., multi-dimensional classfication, to increase the chance of the virus file having a processing manner associated with the category of the virus file, and thus to further reduce the need of displaying prompt information for the virus file.
- the method of obtaining the category of the virus file at least by using the directory in which the virus file is located and/or the process accessing the virus file may at least include any of the following procedures 201a and 201b.
- a first category of the virus file is obtained by classifying the directory where the virus file is located by using a directory classifier when the virus file is identified.
- a directory classifier is used to determine the category of the virus file by using the directory in which the virus file is located.
- the category of the virus file obtained by using a directory classifier is referred to as the first category of the virus file for simplicity.
- a second category of the virus file is obtained by classifying the process accessing the virus file using a process classifier when the virus file is identified.
- a process classifier is used to determine the category of the virus file by using the process accessing the virus file.
- the category of the virus file obtained by using a process classifier is referred to as the second category of the virus file for simplicity.
- the above examples classify a virus file by using the directory in which the virus file is located and/or the process accessing the virus file.
- Other examples may also classify the virus file by using other parameters, such as a name suffix of the virus file and the like, and are not elaborated here.
- classifiers are merely an example. Other classifiers may be adopted in other examples to classify the virus file.
- the classification process may classify a virus file which does not belong to any of pre-configued categorys into an unknown category, then present information of the virus file of the unknown category to the user to make the user select a manner for processing the virus file of the unknown category.
- the method of obtaining a manner for processing virus files of the category in block 202 of FIG.2 may include the following procedures.
- procedure 202a it is judged whether there is a manner that is associated with the category of the virus file.
- Categorys and associated processing manners may be stored in the user device in advance, and are either configured by a technician or determined and saved by the user during the process of the using the user device.
- the user device may store the decision.
- the step of presenting information of the virus may be skipped and an operation selected by the user is directly performed so as not to disturb the user.
- the judging in procedure 202a may be performed by using categories and associated processing manners stored in a server in the cloud, or by using categories and associated processing manners stored in the user device and categories and associated processing manners stored in the server in the cloud.
- the step of presenting the information of the virus file may be skipped and the operation required by the user is directly performed so as not to disturb the user.
- procedure 202b when there is a manner associated with the category of the virus file, the manner associated with the category of the virus file is obtained.
- the processing manner is obtained.
- the classification process and the process of obtaining the category involve no virus alert presented to the user, thus reduce virus alerts by using selections of the user stored in the user device and/or experiences stored in the server in the cloud.
- procedure 202c in response to a determination that no manner is associated with the category of the virus file, information of the virus file is presented to a user, a manner selected by the user is obtained and associated with the category of the virus file.
- the user device may associate the manner with the category of the virus file so that the operation selected by the user can be directly performed on a virus of the same category detected the next time and the step of presenting virus information can be skipped to avoid disturbing the user.
- the processing manner selected by the user may be stored.
- the user device may store the decision, skip the step of presenting virus information the next time when a virus of the category is detected and directly perform the operation selected by the user so avoid disturbing the user.
- no processing manner is associated with the category of a virus file, it means the user has not explicitly provided a manner for processing viruses of the category, thus information of the virus file is to be presented to the user.
- the anti-virus software may not only guide the user to process the current virus file, but also prompt the user to decide whether to adopt the same processing manner for viruses of the same category in the future without presenting virus alerts. For example, a check box presenting "remember my choice, and remind me no more" may be displayed.
- the step of presenting information of the virus file to the user and obtaining and associating a processing manner selected by the user with the category of the virus file in procedure 202c may include: presenting information of the virus file to the user, obtaining a processing manner selected by the user; associating the processing manner selected by the user with the category of the virus file in response to a determination that the number of times the processing manner is selected by the user for the category of the virus file exceeds a pre-defined threshold.
- a decision as to whether the selected processing manner is saved may be obtained from the user.
- the processing manner is associated with the category of the virus file.
- the number of times a processing manner is selected by the user for the category of the virus file may be counted, and the processing manner is associated with the category of the virus file in response to a determination that the number of times the processing manner is selected by the user for the category of the virus file reaches a pre-defined threshold.
- a method for processing virus files obtains the category of a virus file when the virus file is identified, obtains a manner for processing the category of the virus file and processes the virus file by using the manner.
- the technical scheme of the present disclosure classifies virus files detected and processes the virus files according to the categorys of the virus files. The process is implemented at the background silently, thus avoids prompting the user each time when a virus file is detected. The problem of virus alerts disturbing the user is solved, and at the same time, prompt information provided to a user is informative and user-friendly. [0059] Any of the above examples may be combined to form a technical scheme, and all the available technical scheme are not listed herein.
- FIG.3 is a flowchart illustrating a method for processing virus files according to an example of the present disclosure.
- FIG.3 provides a more detailed example of the method with reference to the content as shown in FIG.2.
- the method may include the following procedures.
- a user device performs virus scan.
- the virus scan may be performed through an anti-virus application or the like, and this is not limited in the present disclosure.
- the category of a virus file is obtained by using at least one of a directory where the virus file is located and a process accessing the virus file when the virus file is identified.
- One or multiple categories of the virus file may be obtained.
- the procedure in block 303 is performed in response to a determination that there is a manner associated with the category of the virus file.
- the procedure in block 304 is performed in response to a determination that no manner is associated with the category of the virus file.
- the user device obtains a manner for processing virus files of the category, and the procedure in block 305 is performed.
- the user device presents information of the virus file to the user and obtains a manner selected by the user, and the procedure in block 305 is performed.
- the manner selected by the user is associated with the category of the virus file in response to a determination that the number of times the manner is selected by user for the category of the virus file reaches a pre-defined threshold.
- the example merely provides one method of storing a processing manner.
- the processing manner is associated with the category of the virus file as long as the processing manner is selected by the user. When a virus of the same category is detected the next time, the step of presenting information of the virus is skipped and an operation selected by the user is directly performed so as not to disturb the user.
- the virus file is processed by using the manner.
- FIG.4 is a schematic diagram illustrating a structure of a user device according to an example of the present disclosure.As shown in FIG.4, the user device may include the following components.
- a category obtaining module 10 is configured to obtain a category of a virus file when the virus file is identified.
- a manner obtaining module 20 is configured to obtain a manner for processing virus files of the category.
- a processing module 30 is configured to process the virus file according to the manner.
- the category obtaining module 10 may obtain the category of the virus file by using at least one of a directory where the virus file is located and a process accessing the virus file when the virus file is identified.
- the category obtaining module 10 may obtain a first category of the virus file by classifying the directory in which the virus file is located by using a directory classifier; and/or obtain a second category of the virus file by classifying the process visiting the virus file by using a process classifier.
- the manner obtaining module 20 may include:
- a judging unit configured to judge whether there is a manner that is associated with the category of the virus file
- an obtaining unit configured to obtain the manner associated with the category of the virus file in response to a determination that there is a manner associated with the category of the virus file; and to present information of the virus file to a user in response to a determination that no manner is associated with the category of the virus file, obtain a manner selected by the user, and associate the manner selected by the user with the category of the virus file.
- the obtaining unit may present the information of the virus file to the user, obtain a manner selected by the user; associate the manner with the category of the virus file in response to a determination that the number of times the manner is selected by the user exceeds a pre-defined threshold.
- the user device including the above components as shown in FIG.3 is merely an example.
- a user device may include any combination of features in the above examples as long as the combined scheme is feasible.
- the user device implements obtaining a category of a virus file and a processing manner for processing the category of the virus file by using the above modules in the same manner of the above method embodiment. Details of the implementation can be found in the above desciption in connection with the above method, and will not be described further herein.
- a hardware module may be implemented mechanically or electronically.
- a hardware module may comprise dedicated circuitry or logic that is permanently configured (e.g., as a special-purpose processor, such as a field programmable gate array (FPGA) or an application-specific integrated circuit (ASIC)) to perform certain operations.
- a hardware module may also comprise programmable logic or circuitry (e.g., as encompassed within a general-purpose processor or other programmable processor) that is temporarily configured by software to perform certain operations.lt will be appreciated that the decision to implement a hardware module mechanically, in dedicated and permanently configured circuitry, or in temporarily configured circuitry (e.g., configured by software) may be driven by cost and time considerations.
- a machine-readable storage medium is also provided, which is to store instructions to cause a machine to execute a method as described herein.
- a system or apparatus having a storage medium which stores machine -readable program codes for implementing functions of any of the above examples and which may make the system or the apparatus (or CPU or MPU) read and execute the program codes stored in the storage medium.
- instructions of the program codes may cause an operating system running in a computer to implement part or all of the operations.
- the program codes implemented from a storage medium are written in a storage device in an extension board inserted in the computer or in a storage in an extension unit connected to the computer.
- a CPU in the extension board or the extension unit executes at least part of the operations according to the instructions based on the program codes to realize the technical scheme of any of the above examples.
- the storage medium for providing the program codes may include floppy disk, hard drive, magneto-optical disk, compact disk (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tape drive, Flash card, ROM and so on.
- the program code may be downloaded from a server computer via a communication network.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Virology (AREA)
- Health & Medical Sciences (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- General Health & Medical Sciences (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
- User Interface Of Digital Computer (AREA)
- Document Processing Apparatus (AREA)
Abstract
The present disclosure provides a method and a user device for processing virus files. First information of at least one category of virus file and second information of a manner for processing each of the at least one category of virus file are provided. A category of a virus file when the virus file is identified. A manner of processing viruses of the category from the first information and the second information is obtained and the virus file is processed by using the manner without information about the virus file being presented to a user.
Description
METHOD AND USER DEVICE FOR PROCESSING VIRUS
FILES
Related documents
[0001] The present disclosure claims priority of Chinese patent application No. 201210395070.2 titled "method and user device for processing virus files" and filed on October 17, 2012 with the Patent Office of the People's Republic of China, the disclosure of which is incorporated by reference in its entirety.
Technical Field
[0002] The present disclosure relates to computer security techniques, and particularly to a method and a user device for processing virus files.
Background
[0003] Anti-virus software generally displays information of a virus to a user soon after the virus is detected to implement a real-time virus report mechanism. When there is a virus outbreak in a user device, anti- virus software may display too many virus alerts that the user bearly has time to process one by one. The alerts distract attention of the user continuously and disturb the user using the computer.
[0004] Some anti-virus software may display in a dialog the information of all viruses detected during the period the dialog is being displayed to avoid popping up too many dialogs and disturbing the user. Summary
[0005] Various examples of the present disclosure provide a method and a user device for processing virus files. The technical schemes are as follows.
[0006] A method for processing virus files may include: providing first information of at least one category of virus file and second information of a manner for processing each of the at least one category of virus file; obtaining a category of a virus file when the virus file is identified;
obtaining a manner for processing virus files of the category from the first information and the second information and processing the virus file by using the manner without presenting information about the virus file to a user.
[0007] A user device may include: a category obtaining module, configured to obtain a category of a virus file when the virus file is identified without presenting information about the virus file to a user; a manner obtaining module, configured to obtain a manner for processing virus files of the category by using pre-defined first information of at least one category of virus file and second information of a manner for processing each of the at least one category of virus file without presenting information about the virus file to a user; and a processing module, configured to process the virus file according to the manner without presenting the information about the virus file to the user.
[0008] The technical scheme of the present disclosure classifies virus files detected and processes the virus files according to respective categories of the virus files. The process is implemented at the background silently, thus avoids prompting the user each time when a virus file is detected. The problem of virus alerts disturbing the user is solved, and at the same time, prompt information provided to a user is informative and user-friendly.
Brief Description of the Drawings
[0009] Features of the present disclosure are illustrated by way of example and not limited in the following figures, in which like numerals indicate like elements, in which:
[0010] FIG.l is a flowchart illustrating a method for processing virus files according to an example of the present disclosure.
[0011] FIG.2 is a flowchart illustrating a method for processing virus files according to an example of the present disclosure; [0012] FIG.3 is a flowchart illustrating a method for processing virus files according to an example of the present disclosure;
[0013] FIG.4 is a schematic diagram illustrating a structure of a user device according to an example of the present disclosure.
Detailed Descriptions
[0014] For simplicity and illustrative purposes, the present disclosure is described by referring mainly to an example thereof. In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. It will be readily apparent however, that the present disclosure may be practiced without limitation to these specific details. In other instances, some methods and structures have not been described in detail so as not to unnecessarily obscure the present disclosure. As used herein, the term "includes" means includes but not limited to, the term "including" means including but not limited to. The term "based on" means based at least in part on. Due to characteristics of the Chinese language, quantities of an element, unless specifically mentioned, may be one or a plurality of, or at least one.
[0015] In an example, a computer may execute methods and software systems of the present application. FIG.l is a schematic diagram illustrating an example of a computer. As shown in FIG.l, computer 100 may be a computing device capable of executing a method and apparatus of present disclosure. The computer 100 may, for example, be a device such as a personal desktop computer or a portable device, such as a laptop computer, a tablet computer, a cellular telephone, or a smart phone. The computer 100 may also be a server that connects to the above devices locally or via a network.
[0016] The computer 100 may vary in terms of capabilities or features. Claimed subject matter is intended to cover a wide range of potential variations. For example, the computer 100 may include a keypad/keyboard 156. It may also comprise a display 154, such as a liquid crystal display (LCD), or a display with a high degree of functionality, such as a touch-sensitive color 2D or 3D display. In contrast, however, as another example, a web-enabled computer 100 may include one or more physical or virtual keyboards, and mass storage medium 130. [0017] The computer 100 may also include or may execute a variety of operating systems 141, including an operating system, such as a WindowsTM or LinuxTM, or a mobile operating system, such as iOSTM, AndroidTM, or Windows MobileTM. The computer 100 may include or may execute a variety of possible applications 142, such as an anti- virus application 145. An application 142 may enable processing virus files without presenting alerts to the user of the computer 100.
[0018] Further, the computer 100 may include one or more non-transitory processor-readable storage media 130 and one or more processors 122 in communication
with the non-transitory processor-readable storage media 130. For example, the non-transitory processor-readable storage media 130 may be a RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a CD-ROM, or any other form of non-transitory storage medium known in the art. The one or more non-transitory processor-readable storage media 130 may store sets of instructions, or units and/or modules that comprise the sets of instructions, for conducting operations described in the present application. The one or more processors may be configured to execute the sets of instructions and perform the operations in examples of the present application. [0019] FIG.2 is a flowchart illustrating a method for processing virus files according to an example of the present disclosure. In the example, the method may be implemented by a user device, e.g., a fixed terminal device or a mobile terminal device. The fixed terminal device may be a PC and the like. The mobile terminal device may be a smart phone, a tablet computer, a MP3 player, a PDA and the like. As shown in FIG.2, the method may include the following procedures.
[0020] In block 201, a category of a virus file is obtained when the virus file is identified.
[0021] The user device may identify a virus file by using various methods, e.g., identifying the virus file by using an anti-virus engine installed in the user device or by using an anti-virus engine in a cloud and so on, and this is not limited in the present disclosure.
[0022] In an exmaple, the category of the virus file may be determined by at least one of the directory in which the virus file is located, a process accessing the virus file (i.e., an object being infected), the infection manner and the like. [0023] A virus file may belong to multiple categories, e.g., the virus file may belong to a category of system directories when the virus file is located in a system directory; the virus file may belong to a category of extraction of a compressed archive when the virus file is a file obtained by extracting a compressed archive. Describing a virus file by using several category s enables viewing the virus file from multiple aspects. The virus file may be processed in different manners corresponding to the different category s.
[0024] In block 202, a manner for processing virus files of the category is obtained.
[0025] The method of obtaining the manner may include: (1) storing a manner for each category in the user device and/or in a server in a cloud in advance, obtaining the manner corresponding to the category when the category is identified; (2) when the category is identified, judging whether there is a manner associated with the category in the user device or in the server in the cloud, and obtaining the manner associated with the category in response to a determination that there is a manner associated with the category in the user device or in the server in the cloud, or obtaining a manner selected by a user in response to a determination that no manner is associated with the category in the user device or in the server in the cloud. Several options may be provided for the user to choose from.
[0026] When the manner for processing virus files of the category is obtained, no alert is prompted to the user, and the virus file is directly processed at the background.
[0027] In block 203, the virus file is processed according to the manner.
[0028] In various examples, the processing of a virus file may include, but not limited to, deleting the virus, deleting the virus file completely, isolating the virus file, and the like.
[0029] In an example, a method for processing virus files obtains the category of a virus file when the virus file is identified, obtains a manner for processing virus files of the category and processes the virus file by using the manner. The technical scheme of the present disclosure classifies virus files detected and processes the virus files according to the categorys of the virus files. The process is implemented at the background silently, thus avoids prompting the user each time when a virus file is detected. The mechanism avoids disturbing user by too many virus alerts, and prompt information provided to the user is informative and user- friendly.
[0030] In an example, the method of obtaining the category of the virus file when the virus file is identified in block 201 may include: obtaining the category of the virus file at least by using the directory in which the virus file is located and/or a process accessing the virus file when the virus file is identified.
[0031] In this example, the category of the virus file may be configured by a technician in advance, or may be configured during the process the user uses the device at least according to the directory in which the virus file is located and/or the process accessing the virus file.
[0032] During an outbreak of viruses, a lot of files in one directory may all have got infected. When a user performs an operation on the directory such as copy or cut the directory and so on, the anti-virus software may detect a large amount of viruses. By classifying files in one directory into the same category, the user may decide not to have information of all viruses found in the directory presented. Therefore, information of a virus file is not presented when the virus file is in the same directory.
[0033] When a user decompresses a compressed archive which includes a large amount of viruses, the anti-virus software may also detect a lot of virus files. Thus, files extracted by the same data compression software may be classified into the same category so that the user may decide not to have virus information detected in files extracted from one de-compression process presented. As such, information of a virus file may not be displayed when the virus file is extracted in the same de-compression process.
[0034] Virus files may be classified according to any classification rule to obtain a category. In an example, a virus file may also be classified by using at least the above two manners to obtain at least two categories, i.e., multi-dimensional classfication, to increase the chance of the virus file having a processing manner associated with the category of the virus file, and thus to further reduce the need of displaying prompt information for the virus file.
[0035] In an example, other schemes for classifying and removing duplicated virus alerts may be designed for some typical scenarios by analyzing possible situations where a large amount of viruses may be detected by a technician or a user. When the user has explicitly expressed his/her unwillingness to receive prompt information for a certain category, the amount of alerts displayed can be reduced.
[0036] In an example, the method of obtaining the category of the virus file at least by using the directory in which the virus file is located and/or the process accessing the virus file may at least include any of the following procedures 201a and 201b.
[0037] In procedure 201a, a first category of the virus file is obtained by classifying the directory where the virus file is located by using a directory classifier when the virus file is identified. [0038] When the classifying method is configured to be classification based on the directory in which the virus file is located, a directory classifier is used to determine the
category of the virus file by using the directory in which the virus file is located. The category of the virus file obtained by using a directory classifier is referred to as the first category of the virus file for simplicity.
[0039] In procedure 201b, a second category of the virus file is obtained by classifying the process accessing the virus file using a process classifier when the virus file is identified.
[0040] When the classifying method is configured to be classification based on the process accessing the virus file, a process classifier is used to determine the category of the virus file by using the process accessing the virus file. The category of the virus file obtained by using a process classifier is referred to as the second category of the virus file for simplicity.
[0041] The above examples classify a virus file by using the directory in which the virus file is located and/or the process accessing the virus file. Other examples may also classify the virus file by using other parameters, such as a name suffix of the virus file and the like, and are not elaborated here.
[0042] The above mentioned classifiers are merely an example. Other classifiers may be adopted in other examples to classify the virus file.
[0043] In an example, the classification process may classify a virus file which does not belong to any of pre-configued categorys into an unknown category, then present information of the virus file of the unknown category to the user to make the user select a manner for processing the virus file of the unknown category.
[0044] In an example, the method of obtaining a manner for processing virus files of the category in block 202 of FIG.2 may include the following procedures.
[0045] In procedure 202a, it is judged whether there is a manner that is associated with the category of the virus file.
[0046] Categorys and associated processing manners may be stored in the user device in advance, and are either configured by a technician or determined and saved by the user during the process of the using the user device.
[0047] When the user decides not to have virus alert for a category of viruses, the user device may store the decision. When a virus of the same category is detected the next
time, the step of presenting information of the virus may be skipped and an operation selected by the user is directly performed so as not to disturb the user.
[0048] In an example, the judging in procedure 202a may be performed by using categories and associated processing manners stored in a server in the cloud, or by using categories and associated processing manners stored in the user device and categories and associated processing manners stored in the server in the cloud.
[0049] When a processing manner associated with the category of the virus category is obtained from pre- stored information, the step of presenting the information of the virus file may be skipped and the operation required by the user is directly performed so as not to disturb the user.
[0050] In procedure 202b, when there is a manner associated with the category of the virus file, the manner associated with the category of the virus file is obtained.
[0051] In response to a determination that there is a processing manner associated with the category of the virus file in the user device and/or in a server in the cloud, the processing manner is obtained. The classification process and the process of obtaining the category involve no virus alert presented to the user, thus reduce virus alerts by using selections of the user stored in the user device and/or experiences stored in the server in the cloud.
[0052] In procedure 202c, in response to a determination that no manner is associated with the category of the virus file, information of the virus file is presented to a user, a manner selected by the user is obtained and associated with the category of the virus file.
[0053] When the user selects a manner for processing the virus file, the user device may associate the manner with the category of the virus file so that the operation selected by the user can be directly performed on a virus of the same category detected the next time and the step of presenting virus information can be skipped to avoid disturbing the user.
[0054] When the user selects to have no virus alert for the category of the virus file, the processing manner selected by the user may be stored. When receiving the decision of the user for not presenting alerts for the category of virus, the user device may store the decision, skip the step of presenting virus information the next time when a virus of the category is detected and directly perform the operation selected by the user so avoid disturbing the user.
[0055] When no processing manner is associated with the category of a virus file, it means the user has not explicitly provided a manner for processing viruses of the category, thus information of the virus file is to be presented to the user. When presenting the information, the anti-virus software may not only guide the user to process the current virus file, but also prompt the user to decide whether to adopt the same processing manner for viruses of the same category in the future without presenting virus alerts. For example, a check box presenting "remember my choice, and remind me no more" may be displayed.
[0056] In an example, the step of presenting information of the virus file to the user and obtaining and associating a processing manner selected by the user with the category of the virus file in procedure 202c may include: presenting information of the virus file to the user, obtaining a processing manner selected by the user; associating the processing manner selected by the user with the category of the virus file in response to a determination that the number of times the processing manner is selected by the user for the category of the virus file exceeds a pre-defined threshold.
[0057] In an example, a decision as to whether the selected processing manner is saved may be obtained from the user. In response to a determination that the user selects to save the processing manner, the processing manner is associated with the category of the virus file. In an example, the number of times a processing manner is selected by the user for the category of the virus file may be counted, and the processing manner is associated with the category of the virus file in response to a determination that the number of times the processing manner is selected by the user for the category of the virus file reaches a pre-defined threshold.
[0058] In an example, a method for processing virus files obtains the category of a virus file when the virus file is identified, obtains a manner for processing the category of the virus file and processes the virus file by using the manner. The technical scheme of the present disclosure classifies virus files detected and processes the virus files according to the categorys of the virus files. The process is implemented at the background silently, thus avoids prompting the user each time when a virus file is detected. The problem of virus alerts disturbing the user is solved, and at the same time, prompt information provided to a user is informative and user-friendly.
[0059] Any of the above examples may be combined to form a technical scheme, and all the available technical scheme are not listed herein.
[0060] FIG.3 is a flowchart illustrating a method for processing virus files according to an example of the present disclosure. FIG.3 provides a more detailed example of the method with reference to the content as shown in FIG.2. As shown in FIG.3, the method may include the following procedures.
[0061] In block 300, a user device performs virus scan.
[0062] The virus scan may be performed through an anti-virus application or the like, and this is not limited in the present disclosure. [0063] In block 301, the category of a virus file is obtained by using at least one of a directory where the virus file is located and a process accessing the virus file when the virus file is identified.
[0064] One or multiple categories of the virus file may be obtained.
[0065] In block 302, it is judged whether there is a manner that is associated with the category of the virus file.
[0066] The procedure in block 303 is performed in response to a determination that there is a manner associated with the category of the virus file.
[0067] The procedure in block 304 is performed in response to a determination that no manner is associated with the category of the virus file. [0068] In block 303, the user device obtains a manner for processing virus files of the category, and the procedure in block 305 is performed.
[0069] In block 304, the user device presents information of the virus file to the user and obtains a manner selected by the user, and the procedure in block 305 is performed.
[0070] In an example, the manner selected by the user is associated with the category of the virus file in response to a determination that the number of times the manner is selected by user for the category of the virus file reaches a pre-defined threshold.
[0071] The example merely provides one method of storing a processing manner. In another example, the processing manner is associated with the category of the virus file as long as the processing manner is selected by the user. When a virus of the same category
is detected the next time, the step of presenting information of the virus is skipped and an operation selected by the user is directly performed so as not to disturb the user.
[0072] In block 305, the virus file is processed by using the manner.
[0073] FIG.4 is a schematic diagram illustrating a structure of a user device according to an example of the present disclosure.As shown in FIG.4, the user device may include the following components.
[0074] A category obtaining module 10 is configured to obtain a category of a virus file when the virus file is identified.
[0075] A manner obtaining module 20 is configured to obtain a manner for processing virus files of the category.
[0076] A processing module 30 is configured to process the virus file according to the manner.
[0077] In an example, the category obtaining module 10 may obtain the category of the virus file by using at least one of a directory where the virus file is located and a process accessing the virus file when the virus file is identified.
[0078] In an example, the category obtaining module 10 may obtain a first category of the virus file by classifying the directory in which the virus file is located by using a directory classifier; and/or obtain a second category of the virus file by classifying the process visiting the virus file by using a process classifier. [0079] In an example, the manner obtaining module 20 may include:
[0080] a judging unit, configured to judge whether there is a manner that is associated with the category of the virus file;
[0081] an obtaining unit, configured to obtain the manner associated with the category of the virus file in response to a determination that there is a manner associated with the category of the virus file; and to present information of the virus file to a user in response to a determination that no manner is associated with the category of the virus file, obtain a manner selected by the user, and associate the manner selected by the user with the category of the virus file.
[0082] In an example, the obtaining unit may present the information of the virus file to the user, obtain a manner selected by the user; associate the manner with the category of
the virus file in response to a determination that the number of times the manner is selected by the user exceeds a pre-defined threshold.
[0083] The user device including the above components as shown in FIG.3 is merely an example. In various examples, a user device may include any combination of features in the above examples as long as the combined scheme is feasible.
[0084] The user device implements obtaining a category of a virus file and a processing manner for processing the category of the virus file by using the above modules in the same manner of the above method embodiment. Details of the implementation can be found in the above desciption in connection with the above method, and will not be described further herein.
[0085] It should be understood that in the above processes and structures, not all of the procedures and modules are necessary. Certain procedures or modules may be omitted according to the needs. The order of the procedures is not fixed, and can be adjusted according to the needs. The modules are defined based on function simply for facilitating description. In implemention, a module may be implemented by multiple modules, and functions of multiple modules may be implemented by the same module. The modules may reside in the same device or distribute in different devices. The "first", "second" in the above descriptions are merely for distinguishing two similar objects, and have no substantial meanings. [0086] In various embodiments, a hardware module may be implemented mechanically or electronically. For example, a hardware module may comprise dedicated circuitry or logic that is permanently configured (e.g., as a special-purpose processor, such as a field programmable gate array (FPGA) or an application-specific integrated circuit (ASIC)) to perform certain operations. A hardware module may also comprise programmable logic or circuitry (e.g., as encompassed within a general-purpose processor or other programmable processor) that is temporarily configured by software to perform certain operations.lt will be appreciated that the decision to implement a hardware module mechanically, in dedicated and permanently configured circuitry, or in temporarily configured circuitry (e.g., configured by software) may be driven by cost and time considerations. [0087] A machine-readable storage medium is also provided, which is to store instructions to cause a machine to execute a method as described herein. Specifically, a
system or apparatus having a storage medium which stores machine -readable program codes for implementing functions of any of the above examples and which may make the system or the apparatus (or CPU or MPU) read and execute the program codes stored in the storage medium.In addition, instructions of the program codes may cause an operating system running in a computer to implement part or all of the operations. In addition, the program codes implemented from a storage medium are written in a storage device in an extension board inserted in the computer or in a storage in an extension unit connected to the computer. In this example, a CPU in the extension board or the extension unit executes at least part of the operations according to the instructions based on the program codes to realize the technical scheme of any of the above examples.
[0088] The storage medium for providing the program codes may include floppy disk, hard drive, magneto-optical disk, compact disk (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tape drive, Flash card, ROM and so on. Optionally, the program code may be downloaded from a server computer via a communication network.
[0089] The scope of the claims should not be limited by the embodiments set forth in the examples, but should be given the broadest interpretation consistent with the description as a whole.
Claims
1. A method for processing virus files, comprising: providing first information of at least one category of virus file and second information of a manner for processing each of the at least one category of virus file; obtaining a category of a virus file when the virus file is identified; obtaining a manner of processing viruses of the category from the first information and the second information and processing the virus file by using the manner without presenting information about the virus file to a user.
2. The method of claim 1, wherein obtaining the category of the virus file when the virus file is identified comprises: obtaining the category of the virus file by using at least one of a directory where the virus file is located and a process accessing the virus file when the virus file is identified.
3. The method of claim 2, wherein obtaining the category of the virus file by using at least one of a directory where the virus file is located and a process accessing the virus file comprises: obtaining a first category of the virus file by classifying the directory where the virus file is located by using a directory classifier.
4. The method of claim 2, wherein obtaining the category of the virus file by using at least one of a directory where the virus file is located and a process accessing the virus file comprises: obtaining a second category of the virus file by classifying the process accessing the virus file by using a process classifier when the virus file is identified.
5. The method of claim 1, wherein obtaining the manner for processing virus files of the category comprises: judging whether there is a manner that is associated with the category of the virus file, obtaining the manner associated with the category of the virus file in response to a determination that there is a manner associated with the category of the virus file;
presenting information of the virus file to a user in response to a determination that no manner is associated with the category of the virus file, obtaining a manner selected by the user, and associating the manner selected by the user with the category of the virus file.
6. The method of claim 5, wherein presenting information of the virus file to a user in response to a determination that no manner is associated with the category of the virus file, obtaining a manner selected by the user, and associating the manner selected by the user with the category of the virus file comprise: presenting information of the virus file to the user and obtaining the manner selected by the user; associating the manner selected by the user with the category of the virus file in response to a determination that the number of times the manner is selected by user for the category of the virus file has exceeded a pre-defined threshold.
7. The method of claim 1, wherein obtaining a manner of processing viruses of the category from the first information and the second information and processing the virus file by using the manner without presenting information about the virus file to a user comprises: performing, by a background process, the obtaining step and the processing step.
8. The method of claim 1, wherein obtaining a manner of processing viruses of the category from the first information and the second information and processing the virus file by using the manner without presenting information about the virus file to a user comprises: prohibiting information of the virus file to be presented to the user.
9. A user device for processing virus files, comprising: a category obtaining module, configured to obtain a category of a virus file when the virus file is identified; a manner obtaining module, configured to obtain a manner for processing virus files of the category by using pre-defined first information of at least one category of virus file and second information of a manner for processing each of the at least one category of virus file without presenting information about the virus file to a user;
a processing module, configured to process the virus file according to the manner without presenting the information about the virus file to the user.
10. The user device of claim 9, wherein the category obtaining module is configured to obtain the category of the virus file by using at least one of a directory where the virus file is located and a process accessing the virus file.
11. The user device of claim 10, wherein the category obtaining module is configured to obtain a first category of the virus file by classifying a directory in which the virus file is located by using a directory classifier.
12. The user device of claim 10, wherein the category obtaining module is configured to obtain a second category of the virus file by classifying a process visiting the virus file by using a process classifier.
13. The user device of claim 9, wherein the manner obtaining module comprises: a judging unit, configured to judge whether there is a manner that is associated with the category of the virus file; an obtaining unit, configured to obtain the manner associated with the category of the virus file in response to a determination that there is a manner associated with the category of the virus file; and to present information of the virus file to a user in response to a determination that no manner is associated with the category of the virus file, obtain a manner selected by the user, and associat the manner selected by the user with the category of the virus file.
14. The user device of claim 13, wherein the obtaining unit is further configured to present the information of the virus file to the user, obtain a manner selected by the user; associate the manner with the category of the virus file in response to a determination that the number of times the manner is selected by the user exceeds a pre-defined threshold.
15. The user device of claim 9, wherein the manner obtaining module and/or the processing module is implemented by using a background process.
16. The user device of claim 9, wherein the manner obtaining module and/or the processing module is configured to prohibit information of the virus file to be presented to the user
17. A non-transitory computer-readable storage medium comprising a set of instructions for processing virus files, the set of instructions to direct at least one processor to perform acts of: providing first information of at least one category of virus file and second information of a manner for processing each of the at least one category of virus file; obtaining a category of a virus file when the virus file is identified; obtaining a manner of processing viruses of the category from the first information and the second information and processing the virus file by using the manner without presenting information about the virus file to a user.
18. The non-transitory computer-readable storage medium of claim 17, wherein obtaining the category of the virus file when the virus file is identified comprises: obtaining the category of the virus file by using at least one of a directory where the virus file is located and a process accessing the virus file when the virus file is identified.
19. The non-transitory computer-readable storage medium of claim 18, wherein obtaining the category of the virus file by using at least one of a directory where the virus file is located and a process accessing the virus file comprises: obtaining a first category of the virus file by classifying the directory where the virus file is located by using a directory classifier; and/or obtaining a second category of the virus file by classifying the process accessing the virus file by using a process classifier when the virus file is identified.
20. The non-transitory computer-readable storage medium of claim 17, wherein obtaining the manner for processing virus files of the category comprises: judging whether there is a manner that is associated with the category of the virus file, obtaining the manner associated with the category of the virus file in response to a determination that there is a manner associated with the category of the virus file; presenting information of the virus file to a user in response to a determination that no manner is associated with the category of the virus file, obtaining a manner selected by
the user, and associating the manner selected by the user with the category of the virus file.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US14/678,046 US9754107B2 (en) | 2012-10-17 | 2015-04-03 | Method and user device for processing virus files |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201210395070.2 | 2012-10-17 | ||
| CN201210395070.2A CN103778370B (en) | 2012-10-17 | 2012-10-17 | Virus document processing method and client device |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US14/678,046 Continuation US9754107B2 (en) | 2012-10-17 | 2015-04-03 | Method and user device for processing virus files |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2014059933A1 true WO2014059933A1 (en) | 2014-04-24 |
Family
ID=50487583
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2013/085353 Ceased WO2014059933A1 (en) | 2012-10-17 | 2013-10-17 | Method and user device for processing virus files |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US9754107B2 (en) |
| CN (1) | CN103778370B (en) |
| WO (1) | WO2014059933A1 (en) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20140366147A1 (en) * | 2013-06-07 | 2014-12-11 | Microsoft Corporation | Automatic mediation of resource access in mobile applications |
| US20230144531A1 (en) * | 2021-11-08 | 2023-05-11 | Cloud Linux Software Inc. | Systems and methods for protecting core files in a content management systems |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20080155691A1 (en) * | 2006-12-17 | 2008-06-26 | Fortinet, Inc. A Delaware Corporation | Detection of undesired computer files using digital certificates |
| CN101382984A (en) * | 2007-09-05 | 2009-03-11 | 江启煜 | Method for scanning and detecting generalized unknown virus |
| CN102194072A (en) * | 2011-06-03 | 2011-09-21 | 奇智软件(北京)有限公司 | Method, device and system used for handling computer virus |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20040039357A (en) * | 2001-09-14 | 2004-05-10 | 컴퓨터 어소시에이츠 싱크, 인코포레이티드 | Virus detection system |
| US20050216770A1 (en) * | 2003-01-24 | 2005-09-29 | Mistletoe Technologies, Inc. | Intrusion detection system |
| CN101226570A (en) * | 2007-09-05 | 2008-07-23 | 江启煜 | Method for monitoring and eliminating generalized unknown virus |
| CN101547126B (en) * | 2008-03-27 | 2011-10-12 | 北京启明星辰信息技术股份有限公司 | Network virus detecting method based on network data streams and device thereof |
| CN102930206B (en) * | 2011-08-09 | 2015-02-25 | 腾讯科技(深圳)有限公司 | Cluster partitioning processing method and cluster partitioning processing device for virus files |
| CN102810138B (en) * | 2012-06-19 | 2015-12-02 | 北京奇虎科技有限公司 | A kind of restorative procedure of user side file and system |
-
2012
- 2012-10-17 CN CN201210395070.2A patent/CN103778370B/en active Active
-
2013
- 2013-10-17 WO PCT/CN2013/085353 patent/WO2014059933A1/en not_active Ceased
-
2015
- 2015-04-03 US US14/678,046 patent/US9754107B2/en active Active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20080155691A1 (en) * | 2006-12-17 | 2008-06-26 | Fortinet, Inc. A Delaware Corporation | Detection of undesired computer files using digital certificates |
| CN101382984A (en) * | 2007-09-05 | 2009-03-11 | 江启煜 | Method for scanning and detecting generalized unknown virus |
| CN102194072A (en) * | 2011-06-03 | 2011-09-21 | 奇智软件(北京)有限公司 | Method, device and system used for handling computer virus |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20140366147A1 (en) * | 2013-06-07 | 2014-12-11 | Microsoft Corporation | Automatic mediation of resource access in mobile applications |
| US9158935B2 (en) * | 2013-06-07 | 2015-10-13 | Microsoft Technology Licensing, Llc | Automatic mediation of resource access in mobile applications |
| US20230144531A1 (en) * | 2021-11-08 | 2023-05-11 | Cloud Linux Software Inc. | Systems and methods for protecting core files in a content management systems |
| US11790084B2 (en) * | 2021-11-08 | 2023-10-17 | Cloud Linux Software, Inc. | Systems and methods for protecting core files in a content management systems |
Also Published As
| Publication number | Publication date |
|---|---|
| CN103778370A (en) | 2014-05-07 |
| US20150213262A1 (en) | 2015-07-30 |
| US9754107B2 (en) | 2017-09-05 |
| CN103778370B (en) | 2016-08-24 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN106664566B (en) | Method and device for notification of SMS scams | |
| CN102867147B (en) | A kind of method and apparatus of file scan | |
| CN104966053B (en) | Face identification method and identifying system | |
| US8844039B2 (en) | Malware image recognition | |
| US20200193024A1 (en) | Detection Of Malware Using Feature Hashing | |
| JP6500086B2 (en) | Two-dimensional code analysis method and apparatus, computer-readable storage medium, computer program, and terminal device | |
| CN104572717B (en) | Information searching method and device | |
| CN107395650B (en) | Method and device for identifying Trojan back connection based on sandbox detection file | |
| US20150143544A1 (en) | Apparatuses, methods, and browsers browser data protection | |
| US10205741B2 (en) | Method and apparatus enabling browsers to perform security scan of devices | |
| WO2015003524A1 (en) | Method and apparatus for increasing security of an electronic payment | |
| CN107302433A (en) | Method of calibration, verification server and the user terminal of electronic signature | |
| WO2014190847A1 (en) | Validating card numbers | |
| US20160321500A1 (en) | Document analysis system, image forming apparatus, and analysis server | |
| US20150135323A1 (en) | Method and device for obtaining virus signatures | |
| WO2015018266A1 (en) | Method and apparatus for determining health state of information system | |
| CN105608216A (en) | Method and device for managing registration information and electronic equipment | |
| CN106776610A (en) | Advertisement popup intercepting method and device | |
| US10860804B2 (en) | Quick text classification model | |
| US9754107B2 (en) | Method and user device for processing virus files | |
| CN107688744B (en) | Malicious file classification method and device based on image feature matching | |
| CN106789973B (en) | Page security detection method and terminal equipment | |
| US11250034B2 (en) | Classification of software based on user interface elements | |
| CN105095343A (en) | Information processing method, information display method and device | |
| US10885070B2 (en) | Data search method and device |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13846680 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 07.09.2015) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 13846680 Country of ref document: EP Kind code of ref document: A1 |