WO2014194803A1 - 基于云安全的文件处理方法及装置 - Google Patents
基于云安全的文件处理方法及装置 Download PDFInfo
- Publication number
- WO2014194803A1 WO2014194803A1 PCT/CN2014/079076 CN2014079076W WO2014194803A1 WO 2014194803 A1 WO2014194803 A1 WO 2014194803A1 CN 2014079076 W CN2014079076 W CN 2014079076W WO 2014194803 A1 WO2014194803 A1 WO 2014194803A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- file
- unknown program
- program file
- signature
- server
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/06—Protocols specially adapted for file transfer, e.g. file transfer protocol [FTP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/10—Protocols in which an application is distributed across nodes in the network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/145—Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
Definitions
- the present invention relates to the field of information security, and in particular, to a file processing method and apparatus based on cloud security. Background technique
- the cloud security technologies in the prior art mostly adopt a combination of a client local engine and a cloud security server side, and specifically kill and kill malicious programs by the following methods:
- the client local engine scans according to its built-in scanning location, and sends the unknown program file features that are not recognized locally to the cloud security server.
- the cloud security server compares the received program file features and determines whether it is a malicious program. For a malicious program, the client local engine processes the malicious program according to its preset malicious program processing method.
- the present invention provides a cloud security based file processing method and apparatus to overcome the above problems or at least partially solve the above problems.
- a file security method based on cloud security comprising: generating a signature identifier uniquely corresponding to an unknown program file according to signature related information of an unknown program file downloaded locally;
- obtaining the signature related information and the file characteristics including:
- the file feature comprises at least one of the following: MD5 (Message Digest Algorithm 5), SHA1 (Secure Hash Algorithm), and the extracted feature values from the file.
- MD5 Message Digest Algorithm 5
- SHA1 Secure Hash Algorithm
- generating a signature identifier uniquely corresponding to the unknown program file according to the signature related information of the unknown program file downloaded locally including:
- performing subsequent processing according to the feedback message including:
- the signature identifier receives the killing method corresponding to the signature identifier fed back by the server when the server side matches successfully.
- the method includes:
- the judgment result is uploaded to the server, and subsequent processing is performed according to the instructions of the server.
- the detection condition includes at least one of the following:
- performing subsequent processing according to instructions of the server side including:
- the interface triggers the killing instruction the unknown program file is checked and killed by the server.
- the killing method comprises: scanning/determining actions and/or repairing actions.
- a cloud security-based file processing method comprising: receiving a query request from a client, wherein the query request includes a signature identifier of an unknown program file and part or all of the unknown program file Document characteristics
- sending a feedback message to the client including:
- the database includes: a local database and/or a cloud database.
- the method before receiving the query request from the client, includes: receiving a file feature of the unknown program file from the client.
- the method further includes:
- sending a corresponding instruction according to the detection result including:
- Sending an unknown program file according to the detection result may infect a malicious program reminder message to the client; and/or sending a corresponding command according to the detection result, wherein the corresponding command includes a killing command for killing the unknown program file, and, for the security file The command to release.
- a cloud security-based file processing apparatus comprising: a generating module configured to generate a signature uniquely corresponding to an unknown program file according to signature related information of a locally downloaded unknown program file Identification
- the query module is configured to send a query request to the server to query whether the unknown program file is a malicious program, where the query request carries a signature identifier of the unknown program file and a part or all file features of the unknown program file;
- the processing module is configured to receive a feedback message from the server, and perform subsequent processing on the unknown program file according to the feedback message, where the server generates a feedback message according to the signature identifier and the file feature.
- the foregoing apparatus further includes:
- An extraction module configured to scan an unknown program file to obtain a file feature; and extract signature related information from the file feature.
- the file feature comprises at least one of the following: MD5, SHA1, a feature value calculated by extracting part of the content from the file.
- the generating module is further configured to:
- processing module is further configured to:
- the signature identifier corresponding to the signature identifier is received by the server. Killing methods.
- processing module is further configured to:
- the judgment result is uploaded to the server, and subsequent processing is performed according to the instructions of the server.
- processing module is further configured to:
- a cloud security-based file processing apparatus configured to receive a query request from a client, wherein the query request includes a signature identifier of an unknown program file and an unknown Some or all of the file characteristics of the program file;
- the sending module is configured to generate a feedback message according to the signature identifier and the file feature, and send the feedback message to the client, where the client performs subsequent processing on the unknown program file according to the feedback message.
- the sending module includes:
- a matching unit configured to match the signature identifier in the database
- the sending unit is configured to send the matched killing method to the client.
- the database includes: a local database and/or a cloud database.
- the receiving module is further configured to receive file characteristics of the unknown program file from the client.
- the sending module is further configured to send a preset detection condition for the information parameter of the unknown program file to the client;
- the receiving module is further configured to receive the detection result from the client;
- the sending module is further configured to send a corresponding instruction according to the detection result.
- the sending module is further configured to:
- Sending an unknown program file according to the detection result may infect a malicious program reminder message to the client; and/or sending a corresponding command according to the detection result, wherein the corresponding command includes a killing command for killing the unknown program file, and, for the security file The command to release.
- a computer program comprising computer readable code, when the computer readable code is run on a computing device, causing the computing device to perform any of claims 1-9 A cloud security-based file processing method as described, and/or a cloud security-based file processing method according to any one of claims 10-15.
- a computer readable medium wherein the storage is as described above Computer program.
- the beneficial effects of the present invention are as follows:
- the present invention provides a cloud security based file processing method and apparatus.
- the client can obtain the local unknown program file in time, and generate a signature identifier uniquely corresponding to the program file and send it to the server, and the server can obtain the corresponding feedback message according to the received signature label and return it to the client.
- the client processes the unknown program file according to the feedback message.
- the method and the device provided by the present invention enable the client to obtain the processing method for the unknown program file from the server side in real time and dynamically, and can detect and kill the malicious program in time, thereby solving the breakthrough in the prior art by using the Trojan horse.
- the problem of cloud killing compared with the prior art, the invention also reduces the time from the discovery of a malicious program to the detection of a malicious program by upgrading the local signature database and the engine program file to detect and kill the new malicious program, thereby speeding up the new life.
- the speed of attack by malicious programs also reduces the amount of information stored on the server, thus ensuring the security of the client program.
- FIG. 1 shows a flow chart of a cloud security based file processing method according to an embodiment of the present invention
- FIG. 2 shows another cloud security based file processing according to an embodiment of the present invention.
- FIG. 3 is a flow chart of a cloud security-based file processing method according to another embodiment of the present invention
- FIG. 4 is a block diagram showing a structure of a cloud security-based file processing device according to an embodiment of the present invention
- 5 is a block diagram showing the structure of another cloud security-based file processing apparatus according to an embodiment of the present invention
- Figure 6 is a block diagram schematically showing a computing device for performing a cloud security based file processing method in accordance with the present invention
- Fig. 7 schematically shows a storage unit for holding or carrying program code implementing the cloud security based file processing method according to the present invention. detailed description
- the invention is applicable to computer systems/servers that can operate with numerous other general purpose or special purpose computing system environments or configurations.
- Examples of well-known computing systems, environments, and/or configurations suitable for use with computer systems/servers include, but are not limited to: personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, based on Microprocessor systems, set-top boxes, programmable consumer electronics, networked personal computers, small computer systems, large computer systems, and distributed cloud computing technology environments including any of the above, and the like.
- the computer system/server can be described in the general context of computer system executable instructions (such as a program module) executed by a computer system.
- program modules may include routines, programs, target programs, components, logic, data structures, and the like, which perform particular tasks or implement particular abstract data types.
- the computer system/server can be implemented in a distributed cloud computing environment where tasks are performed by remote processing devices connected through a communication network.
- program modules may be located on a local or remote computing system storage medium including storage devices.
- FIG. 1 shows a flow chart of a cloud security based file processing method according to an embodiment of the present invention.
- the client for processing the local program is improved, and the method specifically includes steps S 102 to S 106 o
- S104 Send a query request to the server, and query whether the unknown program file is a malicious program.
- the query request carries a signature identifier of an unknown program file and some or all of the file characteristics of the unknown program file.
- the file feature in this embodiment may include an MD5 value, a SHA1 value of the file, or a feature value calculated by extracting part of the content from the file. It may also include DLL (Dynamic Link Library) information and DLL description information that may be loaded by the file, whether the file is infected by the Trojan into a file with unknown security or danger; or whether the specified file/directory is judged whether Exists, whether the file attribute satisfies the condition (such as whether the MD5 of the file is the specified value), whether the registry key/value exists, whether the registry key/value content satisfies the condition, whether the specified process/service exists, and so on.
- DLL Dynamic Link Library
- the server side pre-stores the correspondence between the file feature value and the security level information, and the security level information determined by the server may be customized, for example, including security, danger, unknown, etc., or may be adopted. Level 1, level 2, level 3, etc. to distinguish, as long as it can reflect whether each module is safe.
- the security level information includes: a security level, an unknown level, a suspicious level, a highly suspicious level, and a malicious level, wherein the malicious level is the highest level and the security level is the lowest level. For example, it can be set to a security level when the level is 10-20, an unknown level when the level is 30-40, a suspicious level and a highly suspicious level when the level is 50-60, and a malicious level when the level is greater than 70.
- S106 Receive a feedback message from the server, and perform subsequent processing on the unknown program file according to the feedback message.
- the server generates a feedback message according to the signature identifier and the file characteristics.
- the feedback message is a killing method corresponding to the signature identifier fed back by the server, so that the client can process the unknown file according to the killing method.
- the cloud security-based file processing method provided by the embodiment of the present invention enables the client to obtain the local unknown program file in time, and generates a signature identifier uniquely corresponding to the program file, and sends the signature to the server, and obtains the corresponding information from the server. The message is fed back, and the unknown program file is processed accordingly according to the feedback message.
- the method provided by the embodiment of the present invention enables the client to obtain the processing method for the unknown program file from the server side in real time and dynamically, and can detect and kill the malicious program in time, thereby solving the breakthrough in the prior art by using the Trojan horse.
- the problem of cloud killing compared with the prior art, by upgrading the local signature database and the engine program file to detect and kill the new malicious program, the method also reduces the time from the discovery of the malicious program to the detection of the malicious program, thereby accelerating the new life.
- the speed of attack by malicious programs also reduces the amount of information stored on the server, thus ensuring the security of the client program.
- Figure 2 illustrates a flow chart of another cloud security based file processing method in accordance with one embodiment of the present invention.
- the server for detecting a malicious program is improved, and the server is a cloud security server of the client, and the method specifically includes steps S202 to S206.
- S202 Receive a query request from a client.
- the query request includes a signature identifier of the unknown program file and some or all of the file characteristics of the unknown program file.
- the file features in this embodiment have been specifically described in the above methods, and are not described herein again.
- the client ThunderPlatform.exe loads minizip.dll (minizip.dll is replaced by a Trojan;), and detects a minizip non-white file (also a white program or a trusted program),
- minizip non-white file also a white program or a trusted program
- the server returns the command to delete the Trojan, and performs the operation of repairing the Thunder software, which can be performed by the client.
- the cloud security-based file processing method provided by the embodiment of the present invention enables the server to obtain a corresponding feedback message according to the signature label of the unknown program file sent by the client, and returns the information to the client, and the client sends the unknown message according to the feedback message.
- the program files are processed accordingly.
- the method provided by the embodiment of the present invention enables the server to acquire the client for the real-time and dynamic
- the processing method of the unknown program file is detected, and the malicious program is checked and killed by the client, which solves the problem of using the Trojan to break through the cloud in the prior art.
- the method also reduces the time from the discovery of the malicious program to the detection of the malicious program, thereby accelerating the new life.
- the speed of attack by malicious programs also reduces the amount of information stored on the server, thus ensuring the security of the client program.
- This embodiment is a specific application scenario of the foregoing first embodiment. With the embodiment, the method provided by the present invention can be more clearly and specifically illustrated.
- FIG. 3 shows a flow chart of a cloud security based file processing method according to an embodiment of the present invention. The method specifically includes steps S302 to S3 16.
- the client generates a signature identifier uniquely corresponding to the unknown program file according to the signature related information of the unknown program file downloaded locally.
- the client when executing the local program file, the client determines whether each program file is a locally known program file, so as to ensure the client's knowledge of the local program, and also ensures the local program. safety.
- the client files are stored in the program file list. When the scanned program file is not in the program file list, the client determines that the program file is an unknown program file.
- the specific implementation manner of the step includes:
- the signature related information is extracted from the acquired file features.
- the signature related information is a computable field of the file feature, and the computable field includes a PE check file, a signature segment, and a remaining portion of the signature content in the PE file.
- the obtained file length does not reach an integral multiple of 8
- the digits of the difference are complemented by 0, so as to be calculated.
- the computable field is used as the digest value, and the SHA1 algorithm is used to calculate the signature, and the signature identifier uniquely corresponding to the unknown program file is obtained.
- step S304 is performed, that is, the query request is sent to the server.
- the query request carries the signature identifier of the unknown program file and some or all of the file characteristics of the unknown program file.
- step S306 After receiving the query request, the server performs step S306, that is, matching the signature identifier in the query request in the database, and obtaining a killing method corresponding to the signature identifier.
- the database in this embodiment includes a local database and/or a cloud database.
- the killing method in this embodiment may include a scan/decision action, a repair action, and the like.
- the scanning/determining action includes scanning and determining the context of the program file attribute and the program file, and determining When it is determined to be a malicious program, perform the corresponding repair operation.
- the repair operation may include deleting the specified registry key/value, modifying the registry key/value, specifying the content, deleting the specified system service item, repairing/deleting the specified program file, and the like, and guiding the user to start the first aid kit, etc.
- the malicious program is checked and killed, and the computer basic input/output system ⁇ hard disk master boot record ⁇ operating system driver layer ⁇ operating system application layer multi-layer detection and clearing mode is adopted, and the virus is started from the bottom layer.
- Detection and removal processing ensures that viruses that exist in the application layer to the driver layer are completely removed, improving the ability to detect and remove computer viruses, and ensuring the security of the computer system.
- the server sends the matched killing method to the client.
- step S310 downloads the detection condition of the information parameter of the unknown program file from the server side.
- the detection condition is generated by the server side according to the received unknown program file information parameter (such as file characteristics).
- step S312 is performed to determine whether the unknown program file satisfies the detection condition, and the determination result is sent to the server.
- the detection condition in this embodiment includes at least one of the following:
- the specific driver module or device object refers to the driver module or device object loaded by the local unknown program.
- the process chain includes all the parent and child processes running the program operation.
- an example of a process chain is: Process 1 ⁇ Process 2 - Process 3, that is, the process 2 is the parent process of the process 3, and the process 1 is the process 2 of the process 2.
- the parent process, process 2 is the child process of process 1, and process 3 is the child process of process 2. Extract the names of all processes on the process chain to determine if there are locally unknown files.
- the function that is created is the child process that created the function.
- the process information may also include other information such as session ID, priority, owned thread, user ID, handle, process memory counter, process path, process command line parameter, process name, process creator, creation time, exit Time, kernel time, etc., the present invention will not be described in detail.
- the process chain corresponding to the current process is traced, and the parent process of each process of the process is searched in the process chain, and the file level of the parent process is obtained; The file level thus knows whether there is a locally unknown file in the process chain loaded by the PE.
- StormUpdate.exe loads StormUpdate.dll
- StormUpdated.dll has the signature information of "Beijing Storm Internet Technology Co., Ltd.”.
- the kernel32.dll internal name is kernel32
- the company name is microsoft
- the product name is Microsoft@Windows@Operating System.
- the shutdown callback hook function is one or more callback functions that are called when the Windows is shut down, and after the Trojan is registered, it can write itself from the memory to the disk when the computer is shut down. And set the self-starting, so that it can still be loaded the next time you boot.
- a common Trojan horse Unifade is repeatedly infected by registering a shutdown callback hook.
- svchost.exe is a common system service process for detecting whether a specific driver module or device object exists in the above system, and the Trojan will remotely inject its own module into the process, and delete its own file to reach For stealth purposes, write itself to disk when shutting down for the next boot.
- the analyst can extract some binary strings based on the characteristics of the Trojan, and use these binary strings to match the memory of the svchost.exe process to find the Trojan.
- a specific registry such as a ghost Trojan infected with the fips.sys driver
- the fips driver is through HKLM ⁇
- the SYSTEM ⁇ CurrentControlSet ⁇ Services ⁇ Fips key is loaded, so that the fips.sys is detected to be infected, and the ⁇ 014 ⁇ 1 ⁇ 5 object exists at the same time, which can be used as a judgment condition for the existence of the ghost Trojan virus. and many more.
- step S314 is performed, that is, the corresponding instruction is obtained according to the detection result, and the instruction is sent to the client.
- the server side stores an instruction list or a command database, and stores processing instructions for different detection results.
- the server may send an alert message that the unknown program file may be infected to the malicious program to the client, and may also send an instruction for killing the unknown program file.
- the server determines that the unknown program file is a secure file according to the received detection result, the server sends a security file to the client to release the command.
- step S316 After receiving the instruction sent by the server, the client performs step S316 to perform subsequent processing on the unknown program file according to the obtained instruction.
- the prompt information that the unknown program file may be infected by the malicious program may be displayed to the user, so that the user is convenient for the program.
- the file is operated. For example, the user may select to check and kill the program file according to the prompt message.
- the client submits the program file to the server side for killing. It reduces the client's killing operation on files and increases the processing speed of the client.
- the unknown program file is directly checked and killed according to the instruction, thereby ensuring timely detection and killing of the malicious program.
- the invention provides a cloud security based file processing method.
- the client can enable the client to The local unknown file is obtained in time, and a signature corresponding to the program file is generated and sent to the server.
- the server can obtain the corresponding feedback message according to the received signature label and return it to the client.
- the client responds according to the feedback message.
- the unknown program file is processed accordingly.
- the method provided by the embodiment of the present invention enables the client to obtain the processing method for the unknown program file from the server side in real time and dynamically, and can detect and kill the malicious program in time, thereby solving the breakthrough in the prior art by using the Trojan horse.
- the problem of cloud killing For example, it solves the problem that the Trojan uses DLL hijacking technology to package the Trojan DLL with a trusted white program. When the user executes the white program, the Trojan DLL will be loaded.
- the method also reduces the time from the discovery of the malicious program to the detection of the malicious program, thereby accelerating the new life.
- the speed of attack by malicious programs also reduces the amount of information stored on the server, thus ensuring the security of the client program.
- the method can be effectively applied to the virus infected by the application layer or the driver layer, and the viruses that can be processed include computer viruses (including general infectious viruses, Word and Excel macro viruses, boot sector viruses, script viruses, Trojans, backdoors, keyboards). Loggers, password stealers, etc.) collectively referred to as "computer viruses”.
- FIG. 4 is a block diagram showing the structure of a cloud security-based file processing apparatus according to an embodiment of the present invention.
- the device is executed in the engine of the client.
- the device 0 of the device security unknown includes a generating module 410 configured to generate a signature identifier uniquely corresponding to the unknown program file according to the signature related information of the unknown program file downloaded locally;
- the query module 420 is coupled to the generating module 410, configured to send a query request to the server, and query whether the unknown program file is a malicious program, where the query request carries a signature identifier of the unknown program file and part or all of the unknown program file.
- the processing module 430 is coupled to the generating module 420, configured to receive a feedback message from the server, and perform subsequent processing on the unknown program file according to the feedback message, where the server generates a feedback message according to the signature identifier and the file feature.
- the foregoing apparatus further includes:
- An extraction module 440 coupled to the generating module 410, configured to scan an unknown program file to obtain a file feature
- the file features include at least one of the following -
- MD5 MD5
- SHA1 extract the feature values calculated from the file.
- the generating module 410 is further configured to:
- the calculated field is a PE file, except the PE check segment, the signature segment, and the rest of the signature content; Calculate the computable field and use the result as a signature.
- processing module 430 is further configured to:
- the signature identifier receives the killing method corresponding to the signature identifier fed back by the server when the server side matches successfully.
- processing module 430 is further configured to:
- the judgment result is uploaded to the server, and subsequent processing is performed according to the instructions of the server.
- processing module 430 is further configured to:
- FIG. 5 is a block diagram showing the structure of another cloud security-based file processing apparatus according to an embodiment of the present invention.
- the device is executed in the peer server of the above client.
- the apparatus 500 includes:
- the receiving module 510 is configured to receive a query request from the client, where the query request includes a signature identifier of the unknown program file and some or all of the file characteristics of the unknown program file;
- the sending module 520 is coupled to the receiving module 510, configured to generate a feedback message according to the signature identifier and the file feature, and send the feedback message to the client, where the client performs subsequent processing on the unknown program file according to the feedback message.
- the sending module 520 includes:
- the matching unit 521 is configured to match the signature identifier in the database
- the sending unit 522 is configured to send the matched killing method to the client.
- the database includes: a local database and/or a cloud database.
- the receiving module 510 is further configured to receive a file feature of an unknown program file from the client.
- the sending module 520 is further configured to send, to the client, a detection condition for an information parameter of an unknown program file;
- the receiving module 510 is further configured to receive a detection result from the client.
- the sending module 520 is further configured to send a corresponding command according to the detection result.
- the sending module 520 is further configured to:
- Sending an unknown program file according to the detection result may infect a malicious program reminder message to the client; and/or sending a corresponding command according to the detection result, wherein the corresponding command includes killing the unknown program file The kill command, and the command to release the security file.
- the embodiment of the invention provides a file security device based on cloud security.
- the device enables the client to obtain the local unknown program file in time, and generates a signature identifier uniquely corresponding to the program file to be sent to the server, and the server can obtain the corresponding feedback message according to the received signature label and return it to the client.
- the client processes the unknown program file according to the feedback message.
- the device provided by the embodiment of the present invention enables the client to obtain the processing method for the unknown program file from the server side in real time and dynamically, and can detect and kill the malicious program in time, thereby solving the breakthrough in the prior art by using the Trojan horse.
- the problem of cloud killing compared with the prior art, by upgrading the local signature database and the engine program file to detect and kill the new malicious program, the device also reduces the time from the discovery of the malicious program to the detection of the malicious program, thereby accelerating the new life.
- the speed of attack by malicious programs also reduces the amount of information stored on the server, thus ensuring the security of the client program.
- modules in the devices of the embodiments can be adaptively changed and placed in one or more devices different from the embodiment.
- the modules or units or components of the embodiments may be combined into one module or unit or component, and further they may be divided into a plurality of sub-modules or sub-units or sub-components.
- any combination of the features disclosed in the specification, including the accompanying claims, the abstract and the drawings, and any methods so disclosed, or All processes or units of the device are combined.
- Each feature disclosed in the specification (including the accompanying claims, the abstract and the drawings) may be replaced by an alternative feature that provides the same, equivalent or similar purpose.
- the various component embodiments of the present invention may be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof.
- a microprocessor or digital signal processor (DSP) is used in practice to implement some or all of the functionality of some or all of the components of the cloud security based file processing apparatus in accordance with embodiments of the present invention.
- DSP digital signal processor
- the invention can also be implemented as a device or device program (e.g., a computer program and a computer program product) for performing some or all of the methods described herein.
- Such a program implementing the invention may be stored on a computer readable medium or may be in the form of one or more signals. Such signals may be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.
- the present invention shows a computing device, such as a client, and a computing device that can implement a second cloud security-based file processing method in accordance with the present invention, which can implement the first cloud security-based file processing method in accordance with the present invention.
- Devices such as popular application servers.
- a computing device conventionally includes a processor 610 and a computer program product or computer readable medium in the form of a memory 620.
- Memory 620 can be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read Only Memory), EPROM, hard disk or ROM.
- Memory 620 has a memory space 630 for program code 631 for performing any of the method steps described above.
- storage space 630 for program code can include various program code 631 for implementing various steps in the above methods, respectively.
- the program code can be read from or written to one or more computer program products.
- These computer program products include program code carriers such as hard disks, compact disks (CDs), memory cards or floppy disks.
- Such a computer program product is typically a portable or fixed storage unit as described with reference to Figure 7.
- the storage unit may have a storage section, a storage space, and the like arranged similarly to the storage 620 in the server of Fig. 6.
- the program code can be compressed, for example, in an appropriate form.
- the storage unit includes computer readable code 631 ', ie, code readable by a processor, such as 610, that when executed by a computing device causes the computing device to perform each of the methods described above step.
- an embodiment or “an embodiment,” or “one or more embodiments” as used herein means that the particular features, structures, or characteristics described in connection with the embodiments are included in at least one embodiment of the invention.
- the phrase “in one embodiment” herein does not necessarily refer to the same embodiment.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Storage Device Security (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
- Information Transfer Between Computers (AREA)
- Debugging And Monitoring (AREA)
Abstract
一种基于云安全的文件处理方法及装置。该方法包括:根据本地下载的未知程序文件的签名相关信息,生成与未知程序文件唯一对应的签名标识;发送査询请求至服务器端,査询未知程序文件是否是恶意程序,其中,査询请求携带有未知程序文件的签名标识以及未知程序文件的部分或全部文件特征;接收来自服务器端的反馈消息,并根据反馈消息对未知程序文件进行后续处理,其中,服务器端根据签名标识以及文件特征生成反馈消息。解决了现有技术中利用木马突破云査杀的问题,同时也能够减少由发现恶意程序到査收恶意程序的时间,从而加快了对新生恶意程序的打击速度,也减少了服务器的信息存储量,进而保证了客户端程序的安全。
Description
基于云安全的文件处理方法及装置 技术领域
本发明涉及信息安全领域, 具体涉及基于云安全的文件处理方法及装置。 背景技术
目前, 随着恶意程序的不断增长, 传统的基于特征码查杀和定期更新病毒库的 杀毒方式已经无法应对这种局面, 这就促使了大量客户端跟踪、 查杀恶意程序的云 安全技术的兴起。
现有技术中的云安全技术大多采用客户端本地引擎与云安全服务器侧相结合的 方式, 具体通过如下方式对恶意程序进行查杀:
客户端本地引擎根据其内置的扫描位置进行扫描, 并把本地无法识别的未知程 序文件特征发送给云安全服务器, 由云安全服务器对接收到的程序文件特征进行对 比并判断是否为恶意程序, 若为恶意程序, 再由客户端本地引擎根据其预置的恶意 程序处理方法对该恶意程序进行相应处理。
然而, 恶意程序的作者在对抗安全软件时, 恶意软件为了躲避安全防护软件的 检测, 会找到操作系统中新的可利用点或者找到安全软件所忽视的点, 从而绕过安 全软件的检测和查杀。 这就需要安全厂商需要针对新兴的恶意程序样本进行分析, 以对客户端安全软件进行更新。 但是, 在对安全软件升级的程中, 恶意程序已经广 泛蔓延。 可见, 现有技术的方法, 并不能及时地对恶意程序进行检测和查杀。 发明内容
鉴于上述问题, 本发明提供一种基于云安全的文件处理方法及装置, 以便克服 上述问题或者至少部分地解决上述问题。
依据本发明的一个方面, 提供了一种基于云安全的文件处理方法, 该方法包括: 根据本地下载的未知程序文件的签名相关信息, 生成与未知程序文件唯一对应 的签名标识;
发送查询请求至服务器端, 查询未知程序文件是否是恶意程序, 其中, 查询请 求携带有未知程序文件的签名标识以及未知程序文件的部分或全部文件特征;
接收来自服务器端的反馈消息, 并根据反馈消息对未知程序文件进行后续处理, 其中, 服务器端根据签名标识以及文件特征生成反馈消息。
可选地, 按照如下步骤获得签名相关信息以及文件特征, 包括:
扫描未知程序文件, 获取文件特征;
从文件特征中提取签名相关信息。
可选地, 文件特征包括下列至少之一:
MD5 (Message Digest Algorithm 5 , 消息摘要算法) 、 SHA1 ( Secure Hash Algorithm, 哈希算法) 、 从文件中抽取部分内容计算出的特征值。
可选地, 根据本地下载的未知程序文件的签名相关信息, 生成与未知程序文件 唯一对应的签名标识, 包括:
获取可移植的执行体 PE文件的可计算字段, 可计算字段为 PE文件中除去 PE 校验段、 签名段以及签名内容剩余部分;
对可计算字段进行计算, 将计算结果作为签名标识。
可选地, 根据反馈消息进行后续处理, 包括:
签名标识在服务器端匹配成功时, 接收服务器端反馈的、 与签名标识相对应的 查杀方法。
可选地, 接收服务器端反馈的查杀方式之后, 包括:
从服务器端下载预设的、 针对未知程序文件的信息参数的检测条件, 判断未知 程序文件是否满足检测条件;
将判断结果上传服务器端, 并根据服务器端的指令执行后续处理。
可选地, 检测条件包括下列至少一项:
PE加载的特定文件是否具有特定公司的有效签名;
PE加载的特定文件的内部名称、 产品名称及公司名称是否为指定的名称; 系统中是否挂有特定的钩子;
特定的进程中是否具有特定的填充数据 Shellcode;
系统中是否有特定驱动模块或者设备对象存在;
特定的注册表是否指向特定的文件或者特定的唯一标识 CLSID或者匹配特定的 模式;
PE加载的进程链中是否存在安全性未知的文件。
可选地, 根据服务器端的指令执行后续处理, 包括:
接收来自服务器端的未知程序文件可能感染恶意程序的提醒消息; 和 /或 接收来自服务器端的对未知程序文件进行查杀的查杀命令时, 对未知程序文件 进行查杀; 和 /或在接收到用户界面触发的查杀指令时, 通过服务端对未知程序文件 进行查杀。
可选地, 查杀方法包括: 扫描 /判定动作和 /或修复动作。
依据本发明的一个方面, 还提供了一种基于云安全的文件处理方法, 该方法包 括- 接收来自客户端的查询请求, 其中, 查询请求包括未知程序文件的签名标识以 及未知程序文件的部分或全部文件特征;
根据签名标识以及文件特征生成反馈消息;
将反馈消息发送至客户端, 其中, 客户端根据反馈消息对未知程序文件进行后
续处理。
可选地, 将反馈消息发送至客户端, 包括:
在数据库中, 对签名标识进行匹配;
将匹配得到的查杀方法返回给客户端。
可选地, 数据库包括: 本地数据库和 /或云端数据库。
可选地, 接收来自客户端的查询请求之前, 包括: 接收来自客户端的、 未知程 序文件的文件特征。
可选地, 将匹配得到的查杀方法返回给客户端之后, 还包括:
将预设的、 针对未知程序文件的信息参数的检测条件发送至客户端; 以及 接收来自客户端的检测结果;
根据检测结果发送相应指令。
可选地, 根据检测结果发送相应指令, 包括:
根据检测结果发送未知程序文件可能感染恶意程序的提醒消息至客户端; 和 /或 根据检测结果发送相应命令, 其中, 相应命令包括对未知程序文件进行查杀的 查杀命令, 以及, 对安全文件进行放行的命令。 根据本发明的另一方面, 提供了一种基于云安全的文件处理装置, 该装置包括: 生成模块, 配置为根据本地下载的未知程序文件的签名相关信息, 生成与未知 程序文件唯一对应的签名标识;
查询模块, 配置为发送查询请求至服务器端, 查询未知程序文件是否是恶意程 序, 其中, 查询请求携带有未知程序文件的签名标识以及未知程序文件的部分或全 部文件特征;
处理模块, 配置为接收来自服务器端的反馈消息, 并根据反馈消息对未知程序 文件进行后续处理, 其中, 服务器端根据签名标识以及文件特征生成反馈消息。
可选地, 上述装置还包括:
提取模块, 配置为扫描未知程序文件, 获取文件特征; 从文件特征中提取签名 相关信息。
可选地, 文件特征包括下列至少之一- MD5、 SHA1、 从文件中抽取部分内容计算出的特征值。
可选地, 生成模块还配置为:
获取可移植的执行体 PE文件的可计算字段, 可计算字段为 PE文件中除去 PE 校验段、 签名段以及签名内容剩余部分;
对可计算字段进行计算, 将计算结果作为签名标识。
可选地, 处理模块还配置为:
签名标识在服务器端匹配成功时, 接收服务器端反馈的、 与签名标识相对应的
查杀方法。
可选地, 处理模块还配置为:
从服务器端下载预设的、 针对未知程序文件的信息参数的检测条件, 判断未知 程序文件是否满足检测条件;
将判断结果上传服务器端, 并根据服务器端的指令执行后续处理。
可选地, 处理模块还配置为:
接收来自服务器端的未知程序文件可能感染恶意程序的提醒消息; 和 /或 接收来自服务器端的对未知程序文件进行查杀的查杀命令时, 对未知程序文件 进行查杀; 和 /或
在接收到用户界面触发的查杀指令时, 通过服务端对未知程序文件进行查杀。 可选地, 查杀方法包括: 对未知程序文件进行扫描 /判定动作和 /或修复动作。 根据本发明的另一方面, 还提供了一种基于云安全的文件处理装置, 该装置包 括- 接收模块, 配置为接收来自客户端的查询请求, 其中, 查询请求包括未知程序 文件的签名标识以及未知程序文件的部分或全部文件特征;
发送模块, 配置为根据签名标识以及文件特征生成反馈消息, 并将反馈消息发 送至客户端, 其中, 客户端根据反馈消息对未知程序文件进行后续处理。
可选地, 发送模块包括:
匹配单元, 配置为在数据库中, 对签名标识进行匹配;
发送单元, 配置为将匹配得到的查杀方法发送给客户端。
可选地, 数据库包括: 本地数据库和 /或云端数据库。
可选地, 接收模块还配置为接收来自客户端的、 未知程序文件的文件特征。 可选地, 发送模块, 还配置为预设的、 针对未知程序文件的信息参数的检测条 件发送至客户端; 以及
接收模块, 还配置为接收来自客户端的检测结果;
发送模块, 还配置为根据检测结果发送相应指令。
可选地, 发送模块还配置为:
根据检测结果发送未知程序文件可能感染恶意程序的提醒消息至客户端; 和 /或 根据检测结果发送相应命令, 其中, 相应命令包括对未知程序文件进行查杀的 查杀命令, 以及, 对安全文件进行放行的命令。
根据本发明的又一个方面, 提供了一种计算机程序, 包括计算机可读代码, 当 所述计算机可读代码在计算设备上运行时, 导致所述计算设备执行根据权利要求 1-9 中的任一个所述的基于云安全的文件处理方法, 和 /或, 根据权利要求 10-15任一个 所述的基于云安全的文件处理方法。
根据本发明的再一个方面, 提供了一种计算机可读介质, 其中存储了如上所述
的计算机程序。
本发明的有益效果为- 本发明提供的了一种基于云安全的文件处理方法及装置。 通过本发明, 使得客 户端能够及时获取到本地的未知程序文件, 并生成与该程序文件唯一对应的签名标 识发送给服务器端, 服务器端能够根据接收的签名标签获取对应的反馈消息并返回 给客户端, 客户端根据反馈消息对该未知程序文件进行相应地处理。
可见, 本发明提供的方法及装置使得客户端能够实时地、 动态地从服务器侧获 取针对未知程序文件的处理方法, 并能够及时地对恶意程序进行查杀, 解决了现有 技术中利用木马突破云查杀的问题。 另外, 与现有技术中, 通过升级本地特征库和 引擎程序文件才能检测并查杀新生恶意程序相比, 本发明还减少了由发现恶意程序 到查杀恶意程序的时间, 从而加快了对新生恶意程序的打击速度, 也减少了服务器 的信息存储量, 进而保证了客户端程序的安全。
上述说明仅是本发明技术方案的概述, 为了能够更清楚了解本发明的技术手段, 而可依照说明书的内容予以实施, 并且为了让本发明的上述和其它目的、 特征和优 点能够更明显易懂, 以下特举本发明的具体实施方式。 附图说明
通过阅读下文优选实施方式的详细描述, 各种其他的优点和益处对于本领域普 通技术人员将变得清楚明了。 附图仅用于示出优选实施方式的目的, 而并不认为是 对本发明的限制。 而且在整个附图中, 用相同的参考符号表示相同的部件。 在附图 中- 图 1示出了根据本发明一个实施例的一种基于云安全的文件处理方法流程图; 图 2示出了根据本发明一个实施例的另一种基于云安全的文件处理方法流程图 以及
图 3示出了根据本发明另一个实施例的一种基于云安全的文件处理方法流程图; 图 4示出了根据本发明一个实施例的一种基于云安全的文件处理装置结构框图; 图 5示出了根据本发明一个实施例的另一种基于云安全的文件处理装置结构框 图;
图 6示意性地示出了用于执行根据本发明的基于云安全的文件处理方法的计算 设备的框图; 以及
图 7示意性地示出了用于保持或者携带实现根据本发明的基于云安全的文件处 理方法的程序代码的存储单元。 具体实施方式
下面结合附图和具体的实施方式对本发明作进一步的描述。
在此提供的算法和显示不与任何特定计算机、 虚拟系统或者其它设备固有相关。 各种通用系统也可以与基于在此的示教一起使用。 根据上面的描述, 构造这类系统 所要求的结构是显而易见的。 此外, 本发明也不针对任何特定编程语言。 应当明白, 可以利用各种编程语言实现在此描述的本发明的内容, 并且上面对特定语言所做的 描述是为了披露本发明的最佳实施方式。
本发明可以应用于计算机系统 /服务器, 其可与众多其它通用或专用计算系统环 境或配置一起操作。 适于与计算机系统 /服务器一起使用的众所周知的计算系统、 环 境和 /或配置的例子包括但不限于: 个人计算机系统、 服务器计算机系统、 瘦客户机、 厚客户机、 手持或膝上设备、 基于微处理器的系统、 机顶盒、 可编程消费电子产品、 网络个人电脑、 小型计算机系统、 大型计算机系统和包括上述任何系统的分布式云 计算技术环境, 等等。
计算机系统 /服务器可以在由计算机系统执行的计算机系统可执行指令 (诸如程 序模块) 的一般语境下描述。 通常, 程序模块可以包括例程、 程序、 目标程序、 组 件、 逻辑、 数据结构等等, 它们执行特定的任务或者实现特定的抽象数据类型。 计 算机系统 /服务器可以在分布式云计算环境中实施, 分布式云计算环境中, 任务是由 通过通信网络连接的远程处理设备执行的。 在分布式云计算环境中, 程序模块可以 位于包括存储设备的本地或远程计算系统存储介质上。 实施例一
图 1出示了根据本发明一个实施例的一种基于云安全的文件处理方法流程图。 在该方法中, 对用于处理本地程序的客户端进行了改进, 该方法具体包括步骤 S 102 至 S 106 o
S 102, 根据本地下载的未知程序文件的签名相关信息, 生成与未知程序文件唯 一对应的签名标识。
S 104, 发送查询请求至服务器端, 查询未知程序文件是否是恶意程序。 其中, 查询请求携带有未知程序文件的签名标识以及未知程序文件的部分或全部文件特 征。
其中, 本实施例中的文件特征可以包括文件的 MD5值、 SHA1值, 或者是从文 件中抽取部分内容计算出的特征值。 还可以包括该文件可能加载的 DLL ( Dynamic Link Library, 动态链接库) 信息及 DLL的描述信息, 该文件是否被木马感染成一个 安全性未知的或者危险的文件; 或者包括判断指定文件 /目录是否存在, 文件属性是 否满足条件 (如文件的 MD5是否为指定的值) , 指定注册表键 /值是否存在, 注册表 键 /值内容是否满足条件, 指定进程 /服务是否存在等。
其中, 服务器端预先保存有文件特征值和安全级别信息的对应关系, 服务器端 确定的安全级别信息可以自定义, 例如包括安全、 危险、 未知等级别, 也可以采用
一级、 二级、 三级等方式来进行区分, 只要能够体现出各模块是否安全状态即可。 或者, 所述安全级别信息包括: 安全等级、 未知等级、 可疑等级、 高度可疑等级和 恶意等级, 其中, 恶意等级为最高等级, 安全等级为最低等级。 例如, 可以设置等 级为 10-20时为安全等级, 等级为 30-40时为未知等级, 等级为 50-60时为可疑等级 和高度可疑等级, 等级大于 70时为恶意等级。
S 106, 接收来自服务器端的反馈消息, 并根据反馈消息对未知程序文件进行后 续处理。 其中, 服务器端根据签名标识以及文件特征生成反馈消息。
本实施例中, 反馈消息为服务器端反馈的、 与所述签名标识相对应的查杀方法, 以使客户端能够根据该查杀方法对未知文件进行相应处理。
本发明实施例提供的基于云安全的文件处理方法, 使得客户端能够及时获取到 本地的未知程序文件, 并生成与该程序文件唯一对应的签名标识发送给服务器端, 并从服务器端获取对应的反馈消息, 并根据反馈消息对该未知程序文件进行相应地 处理。
可见, 本发明实施例提供的方法使得客户端能够实时地、 动态地从服务器侧获 取针对未知程序文件的处理方法, 并能够及时地对恶意程序进行查杀, 解决了现有 技术中利用木马突破云查杀的问题。 另外, 与现有技术中, 通过升级本地特征库和 引擎程序文件才能检测并查杀新生恶意程序相比, 本方法还减少了由发现恶意程序 到查杀恶意程序的时间, 从而加快了对新生恶意程序的打击速度, 也减少了服务器 的信息存储量, 进而保证了客户端程序的安全。
相应地, 图 2出示了根据本发明一个实施例的另一种基于云安全的文件处理方 法流程图。 在该方法中, 对用于查杀恶意程序的服务器进行了改进, 该服务器为上 述客户端的云安全服务器, 该方法具体包括步骤 S202至 S206。
S202, 接收来自客户端的查询请求。 其中, 查询请求包括未知程序文件的签名 标识以及未知程序文件的部分或全部文件特征。 本实施例中的文件特征已经在上述 方法中进行过具体介绍, 在此不再赘述。
S204, 根据签名标识以及文件特征生成反馈消息。
S206, 将反馈消息发送至客户端。 其中, 客户端根据反馈消息对未知程序文件 进行后续处理。
例如, 本实施例中, 当客户端迅雷 ThundPlatform.exe加载 minizip. dll(minizip.dll 被替换成木马;), 且检测到 minizip非白文件 (也成白程序或可信程序) , 时, 由服务 器返回删除木马的命令, 执行修复迅雷软件的操作, 可以由客户端执行该操作。
本发明实施例提供的基于云安全的文件处理方法, 使得服务器能够根据客户端 发送的未知程序文件的签名标签获取对应的反馈消息, 且返回给客户端, 并由客户 端根据反馈消息对该未知程序文件进行相应地处理。
可见, 本发明实施例提供的方法使得服务器能够实时地、 动态地获取针对客户
端未知程序文件的处理方法, 并由客户端对恶意程序进行查杀, 解决了现有技术中 利用木马突破云查杀的问题。 另外, 与现有技术中, 通过升级本地特征库和引擎程 序文件才能检测并查杀新生恶意程序相比, 本方法还减少了由发现恶意程序到查杀 恶意程序的时间, 从而加快了对新生恶意程序的打击速度, 也减少了服务器的信息 存储量, 进而保证了客户端程序的安全。 实施例二
本实施例为上述实施例一的一种具体应用场景, 通过本实施例, 能够更加清楚、 具体地阐述本发明所提供的方法。
图 3出示了本发明一个实施例的一种基于云安全的文件处理方法流程图。 该方 法具体包括步骤 S302至 S3 16。
S302, 客户端根据本地下载的未知程序文件的签名相关信息, 生成与未知程序 文件唯一对应的签名标识。
需要说明的是, 本实施例中, 客户端在执行本地程序文件时, 会判断每个程序 文件是否为本地可知程序文件, 以保证客户端对本地程序的可知性, 同时也确保了 本地程序的安全性。 其中, 客户端中会存储有程序文件列表, 当所扫描到的程序文 件不在程序文件列表中时, 客户端判定该程序文件为未知程序文件。
可选地, 该步骤的具体实现方式包括:
首先, 扫描该未知程序文件, 获取其文件特征。
其中, 文件特征已在上述实施例中进行过具体介绍, 在此不再赘述。
其次, 从获取的文件特征中提取签名相关信息。
其中, 签名相关信息为文件特征的可计算字段, 可计算字段包括 PE文件中除去 PE校验段、 签名段以及签名内容剩余部分。 其中, 当获取的上述文件长度未达到 8 的整数倍时, 将其所差的位数用 0补齐, 以便于对其进行计算。
再次, 对可计算字段进行计算, 将计算结果作为签名标识。
可选地, 本实施例中, 将可计算字段作为摘要值, 采用 SHA1算法对其进行计 算, 得到与未知程序文件唯一对应的签名标识。
客户端在生成未知程序文件的签名标识后, 执行步骤 S304, 即发送查询请求至 服务器端。 其中, 查询请求携带有该未知程序文件的签名标识以及该未知程序文件 的部分或全部文件特征。
服务器端接收到查询请求后, 执行步骤 S306 , 即在数据库中对查询请求中的签 名标识进行匹配, 获取与签名标识相对应的查杀方法。
需要说明的是, 本实施例中的数据库包括本地数据库和 /或云端数据库。
可选地, 本实施例中的查杀方法可以包括扫描 /判定动作和修复动作等。 其中, 扫描 /判定动作包括对程序文件属性及程序文件的上下文环境的扫描和判定, 并当判
定为恶意程序时, 执行相应的修复操作。 可选地, 该修复操作可以包括删除指定的 注册表键 /值、 修改注册表键 /值为指定内容、 删除指定系统服务项、 修复 /删除指定程 序文件等, 还包括引导用户启动急救箱等, 例如, 在急救箱的模式下对恶意程序进 行查杀, 采用计算机基本输入输出系统→硬盘主引导记录→操作系统驱动层→操作 系统应用层的多层检测和清除方式, 从底层开始对病毒进行检测和清除处理, 可以 确保彻底清除存在于应用层到驱动层各层中的病毒, 提高了检测和清除计算机病毒 的能力, 保证了计算机系统的安全。
S308, 服务器将匹配得到的查杀方法发送给客户端。
客户端接收到服务器发送的查杀方法后, 执行步骤 S310, 即从服务器侧下载针 对未知程序文件的信息参数的检测条件。 其中, 检测条件由服务器侧根据接收到的 未知程序文件信息参数 (如文件特征) 生成。
客户端下载到检测条件后, 执行步骤 S312, 即判断该未知程序文件是否满足检 测条件, 并将判断结果发送至服务器。
可选地, 本实施例中的检测条件至少包括如下列举的一种:
1 ) PE加载的特定文件是否具有特定公司的有效签名。 2) PE加载的特定文件的 内部名称、产品名称及公司名称是否为指定的名称。 3 )系统中是否挂有特定的钩子。 4) 特定的进程中是否具有特定的填充数据。 5 ) 系统中是否有特定驱动模块或者设 备对象存在, 其中, 特定的驱动模块或者设备对象是指由本地未知程序所加载的驱 动模块或者设备对象。 6)特定的注册表是否指向特定的文件或者特定的 CLSID或者 匹配特定的模式, 其中, 特定的注册表、 特定的文件、 特定的 CLSID及特定的模式 均由未知程序在加载时生成, 当该程序运行时, 由特定的注册表利用该特定的文件 和特定的 CLSID在特定的模式下运行该程序。 7) PE加载的进程链中是否存在本地 未知的文件 (未能判断安全等级是否为可信的文件, 主要根据每个文件对应的文件 安全等级判断) 等。 PE加载的进程链主要是需要分析进程链信息。
进程链包括运行所述程序操作的所有父子进程, 例如, 一种进程链的示例为: 进程 1→进程 2—进程 3, 即所述进程 2为进程 3的父进程, 进程 1为进程 2的父进 程, 进程 2为进程 1的子进程, 进程 3为进程 2的子进程。 提取进程链上所有进程 的名称, 确定是否存在本地未知的文件。 关于父进程和子进程, 创建一个进程时, 被创建的函数就是创建函数的子进程。 所述进程的信息还可以包括其他信息, 例如 会话 ID、 优先级、 拥有的线程、 用户 ID、 句柄、 进程内存计数器、 进程路径、 进程 命令行参数、 进程名称、 进程创建者、 创建时间、 退出时间、 内核时间等, 本发明 对此不再详细介绍。 从当前进程开始, 依据所述创建关系追溯对应所述当前进程的 进程链, 依次在该进程链中查找该进程的每一级父进程, 并获取所述父进程的文件 等级; 根据获取到的文件等级从而可以获知 PE加载的进程链中是否存在本地未知的 文件。
对于上述第一类检测条件, 可以查询到例如暴风影音 StoreUpdate.exe加载 StormUpdate.dll, StormUpdated.dll具有 "北京暴风网际科技有限公司" 的签名信息。
对于上述第二类检测条件, 例如检测到加载 kernel32.dll 内部名称为 kernel32, 公司名称为 microsoft, 产品名称为 Microsoft@Windows@Operating System等。
对于上述系统中是否挂有特定的钩子这种检测条件, 例如关机回调钩子函数, 是 windows关机时会调用的一个或多个回调函数, 木马注册后, 可以在关机时将自 身从内存写到磁盘并设置自启动, 以便下次开机仍然能够加载。 常见的一个木马样 本 Unifade就是通过注册关机回调钩子反复感染的。
又例如, 对于上述系统中是否有特定驱动模块或者设备对象存在的检测条件, svchost.exe 是个常见的系统服务进程, 木马会将自身模块远程注入到该进程中, 并 将自身的文件删除, 达到隐形的目的, 关机时在将自身写入到磁盘中以便下次开机 加载。 分析人员可以根据木马的特征提取一些二进制串, 用这些二进制串和 svchost.exe进程的内存进行匹配从而发现木马。
又例如, 对于上述特定的注册表是否指向特定的文件或者特定的 CLSID或者匹 配特定的模式的检测条件, 特定的注册表, 比如鬼影木马感染 fips.sys驱动程序, fips 驱动程序是通过 HKLM\SYSTEM\CurrentControlSet\Services\Fips键加载的, 从而检 测到 fips.sys被感染, 同时存在\014^1~\ ^5对象, 可以作为鬼影木马病毒存在的判断 条件。 等等。
当服务器接收到检测结果后, 执行步骤 S314, 即根据检测结果获取相应的指令, 并将该指令发送给客户端。
可选地, 服务器侧保存有一个指令列表或指令数据库, 存储有针对不同的检测 结果的处理指令。 例如, 当服务器根据接收到的检测结果判定该未知程序文件为恶 意文件时, 可以发送未知程序文件可能感染恶意程序的提醒消息给客户端, 还可以 发送对该未知程序文件进行查杀的指令。 当服务器根据接收到的检测结果判定该未 知程序文件为安全文件时, 向客户端发送安全文件进行放行的命令。
客户端接收到服务器发送的指令后, 执行步骤 S316, 即根据获取的指令对该未 知程序文件进行后续处理。
可选地, 本实施例中, 当客户端接收到的指令为未知程序文件可能感染恶意程 序的提醒消息时, 可以向用户显示该未知程序文件可能感染恶意程序的提示信息, 便于用户对该程序文件进行操作。 例如, 用户可以根据提示消息选择对该程序文件 进行查杀, 此时, 客户端接收到用户触发的查杀指令后, 将该程序文件交由服务器 侧进行查杀。 减少了客户端对文件的查杀操作, 增加客户端的处理速度。
当客户端接收到的指令为查杀指令时, 直接根据该指令对该未知程序文件进行 查杀, 保证了对恶意程序进行及时地查杀。
本发明提供了一种基于云安全的文件处理方法。 通过该方法, 使得客户端能够
及时获取到本地的未知程序文件, 并生成与该程序文件唯一对应的签名标识发送给 服务器端, 服务器端能够根据接收的签名标签获取对应的反馈消息并返回给客户端, 客户端根据反馈消息对该未知程序文件进行相应地处理。
可见, 本发明实施例提供的方法使得客户端能够实时地、 动态地从服务器侧获 取针对未知程序文件的处理方法, 并能够及时地对恶意程序进行查杀, 解决了现有 技术中利用木马突破云查杀的问题。例如,解决了木马使用 DLL劫持技术将木马 DLL 与可信任的白程序打包在一起, 当用户执行白程序时, 木马 DLL会被加载的问题。
另外, 与现有技术中, 通过升级本地特征库和引擎程序文件才能检测并查杀新 生恶意程序相比, 本方法还减少了由发现恶意程序到查杀恶意程序的时间, 从而加 快了对新生恶意程序的打击速度, 也减少了服务器的信息存储量, 进而保证了客户 端程序的安全。 本方法可有效应用于应用层或者驱动层感染的病毒, 涉及的可以处 理的病毒包括计算机病毒 (包括一般感染性病毒、 Word和 Excel宏病毒、 引导区病 毒、 脚本病毒、 木马、 后门程序、 键盘记录器、 密码盗取者等等) 统称为 "计算机 病毒" 实施例三
图 4出示了本发明一个实施例的一种基于云安全的文件处理装置的结构框图。 该装置执行于客户端的引擎中。 该装置安全性未知的 0包括- 生成模块 410, 配置为根据本地下载的未知程序文件的签名相关信息, 生成与未 知程序文件唯一对应的签名标识;
查询模块 420, 与上述生成模块 410相耦合, 配置为发送查询请求至服务器端, 查询未知程序文件是否是恶意程序, 其中, 查询请求携带有未知程序文件的签名标 识以及未知程序文件的部分或全部文件特征;
处理模块 430, 与上述生成模块 420相耦合, 配置为接收来自服务器端的反馈消 息, 并根据反馈消息对未知程序文件进行后续处理, 其中, 服务器端根据签名标识 以及文件特征生成反馈消息。
可选地, 上述装置还包括:
提取模块 440, 与上述生成模块 410相耦合, 配置为扫描未知程序文件, 获取文 件特征;
从文件特征中提取签名相关信息。
可选地, 文件特征包括下列至少之一-
MD5、 SHA1、 从文件中抽取部分内容计算出的特征值。
可选地, 上述生成模块 410还配置为:
获取可移植的执行体 PE文件的可计算字段, 可计算字段为 PE文件中除去 PE 校验段、 签名段以及签名内容剩余部分;
对可计算字段进行计算, 将计算结果作为签名标识。
可选地, 上述处理模块 430还配置为:
签名标识在服务器端匹配成功时, 接收服务器端反馈的、 与签名标识相对应的 查杀方法。
可选地, 上述处理模块 430还配置为:
从服务器端下载预设的、 针对未知程序文件的信息参数的检测条件, 判断未知 程序文件是否满足检测条件;
将判断结果上传服务器端, 并根据服务器端的指令执行后续处理。
可选地, 上述处理模块 430还配置为:
接收来自服务器端的未知程序文件可能感染恶意程序的提醒消息; 和 /或 接收来自服务器端的对未知程序文件进行查杀的查杀命令时, 对未知程序文件 进行查杀; 和 /或
在接收到用户界面触发的查杀指令时, 通过服务端对未知程序文件进行查杀。 可选地,上述查杀方法包括:对未知程序文件进行扫描 /判定动作和 /或修复动作。 图 5出示了本发明一个实施例的另一种基于云安全的文件处理装置的结构框图。 该装置执行于上述客户端的对端服务器中。 该装置 500包括:
接收模块 510, 配置为接收来自客户端的查询请求, 其中, 查询请求包括未知程 序文件的签名标识以及未知程序文件的部分或全部文件特征;
发送模块 520, 与上述接收模块 510相耦合, 配置为根据签名标识以及文件特征 生成反馈消息, 并将反馈消息发送至客户端, 其中, 客户端根据反馈消息对未知程 序文件进行后续处理。
可选地, 上述发送模块 520包括:
匹配单元 521, 配置为在数据库中, 对签名标识进行匹配;
发送单元 522, 配置为将匹配得到的查杀方法发送给客户端。
可选地, 数据库包括: 本地数据库和 /或云端数据库。
可选地, 上述接收模块 510还配置为接收来自客户端的、 未知程序文件的文件 特征。
可选地, 上述发送模块 520, 还配置为预设的、 针对未知程序文件的信息参数的 检测条件发送至客户端; 以及
上述接收模块 510, 还配置为接收来自客户端的检测结果;
上述发送模块 520, 还配置为根据检测结果发送相应指令。
可选地, 上述发送模块 520还配置为:
根据检测结果发送未知程序文件可能感染恶意程序的提醒消息至客户端; 和 /或 根据检测结果发送相应命令, 其中, 相应命令包括对未知程序文件进行查杀的
查杀命令, 以及, 对安全文件进行放行的命令。
本发明实施例提供了一种基于云安全的文件处理装置。 通过该装置, 使得客户 端能够及时获取到本地的未知程序文件, 并生成与该程序文件唯一对应的签名标识 发送给服务器端, 服务器端能够根据接收的签名标签获取对应的反馈消息并返回给 客户端, 客户端根据反馈消息对该未知程序文件进行相应地处理。
可见, 本发明实施例提供的装置使得客户端能够实时地、 动态地从服务器侧获 取针对未知程序文件的处理方法, 并能够及时地对恶意程序进行查杀, 解决了现有 技术中利用木马突破云查杀的问题。 另外, 与现有技术中, 通过升级本地特征库和 引擎程序文件才能检测并查杀新生恶意程序相比, 本装置还减少了由发现恶意程序 到查杀恶意程序的时间, 从而加快了对新生恶意程序的打击速度, 也减少了服务器 的信息存储量, 进而保证了客户端程序的安全。
在此处所提供的说明书中, 说明了大量具体细节。 然而, 能够理解, 本发明的 实施例可以在没有这些具体细节的情况下实践。 在一些实例中, 并未详细示出公知 的方法、 结构和技术, 以便不模糊对本说明书的理解。
类似地, 应当理解, 为了精简本公开并帮助理解各个发明方面中的一个或多个, 在上面对本发明的示例性实施例的描述中, 本发明的各个特征有时被一起分组到单 个实施例、 图、 或者对其的描述中。 然而, 并不应将该公开的方法解释成反映如下 意图: 即所要求保护的本发明要求比在每个权利要求中所明确记载的特征更多的特 征。 更确切地说, 如下面的权利要求书所反映的那样, 发明方面在于少于前面公开 的单个实施例的所有特征。 因此, 遵循具体实施方式的权利要求书由此明确地并入 该具体实施方式, 其中每个权利要求本身都作为本发明的单独实施例。
本领域那些技术人员可以理解, 可以对实施例中的设备中的模块进行自适应性 地改变并且把它们设置在与该实施例不同的一个或多个设备中。 可以把实施例中的 模块或单元或组件组合成一个模块或单元或组件, 以及此外可以把它们分成多个子 模块或子单元或子组件。 除了这样的特征和 /或过程或者单元中的至少一些是相互排 斥之外, 可以采用任何组合对本说明书 (包括伴随的权利要求、 摘要和附图) 中公 开的所有特征以及如此公开的任何方法或者设备的所有过程或单元进行组合。 除非 另外明确陈述, 本说明书 (包括伴随的权利要求、 摘要和附图) 中公开的每个特征 可以由提供相同、 等同或相似目的的替代特征来代替。
此外, 本领域的技术人员能够理解, 尽管在此所述的一些实施例包括其它实施 例中所包括的某些特征而不是其它特征, 但是不同实施例的特征的组合意味着处于 本发明的范围之内并且形成不同的实施例。 例如, 在下面的权利要求书中, 所要求 保护的实施例的任意之一都可以以任意的组合方式来使用。
本发明的各个部件实施例可以以硬件实现, 或者以在一个或者多个处理器上运 行的软件模块实现, 或者以它们的组合实现。 本领域的技术人员应当理解, 可以在
实践中使用微处理器或者数字信号处理器(DSP )来实现根据本发明实施例的基于云 安全的文件处理装置中的一些或者全部部件的一些或者全部功能。 本发明还可以实 现为用于执行这里所描述的方法的一部分或者全部的设备或者装置程序 (例如, 计 算机程序和计算机程序产品) 。 这样的实现本发明的程序可以存储在计算机可读介 质上, 或者可以具有一个或者多个信号的形式。 这样的信号可以从因特网网站上下 载得到, 或者在载体信号上提供, 或者以任何其他形式提供。
例如, 本发明示出了可以实现根据本发明的第一种基于云安全的文件处理方法 的计算设备, 例如客户端, 和可以实现根据本发明的第二种基于云安全的文件处理 方法的计算设备, 例如常用的应用服务器。 参见图 6, 计算设备传统上包括处理器 610和以存储器 620形式的计算机程序产品或者计算机可读介质。存储器 620可以是 诸如闪存、 EEPROM (电可擦除可编程只读存储器) 、 EPROM、 硬盘或者 ROM之 类的电子存储器。 存储器 620具有用于执行上述方法中的任何方法步骤的程序代码 631的存储空间 630。 例如, 用于程序代码的存储空间 630可以包括分别用于实现上 面的方法中的各种步骤的各个程序代码 631。这些程序代码可以从一个或者多个计算 机程序产品中读出或者写入到这一个或者多个计算机程序产品中。 这些计算机程序 产品包括诸如硬盘, 紧致盘 (CD ) 、 存储卡或者软盘之类的程序代码载体。 这样的 计算机程序产品通常为如参考图 7所述的便携式或者固定存储单元。 该存储单元可 以具有与图 6的服务器中的存储器 620类似布置的存储段、 存储空间等。 程序代码 可以例如以适当形式进行压缩。 通常, 存储单元包括计算机可读代码 631 ', 即可以 由例如诸如 610之类的处理器读取的代码, 这些代码当由计算设备运行时, 导致该 计算设备执行上面所描述的方法中的各个步骤。
本文中所称的 "一个实施例" 、 "实施例" 或者 "一个或者多个实施例" 意味 着, 结合实施例描述的特定特征、 结构或者特性包括在本发明的至少一个实施例中。 此外, 请注意, 这里 "在一个实施例中" 的词语例子不一定全指同一个实施例。
应该注意的是上述实施例对本发明进行说明而不是对本发明进行限制, 并且本 领域技术人员在不脱离所附权利要求的范围的情况下可设计出替换实施例。 在权利 要求中, 不应将位于括号之间的任何参考符号构造成对权利要求的限制。 单词 "包 含"不排除存在未列在权利要求中的元件或步骤。 位于元件之前的单词 "一"或 "一 个" 不排除存在多个这样的元件。 本发明可以借助于包括有若干不同元件的硬件以 及借助于适当编程的计算机来实现。 在列举了若干装置的单元权利要求中, 这些装 置中的若干个可以是通过同一个硬件项来具体体现。 单词第一、 第二、 以及第三等 的使用不表示任何顺序。 可将这些单词解释为名称。
此外, 还应当注意, 本说明书中使用的语言主要是为了可读性和教导的目的而 选择的, 而不是为了解释或者限定本发明的主题而选择的。 因此, 在不偏离所附权 利要求书的范围和精神的情况下, 对于本技术领域的普通技术人员来说许多修改和
变更都是显而易见的。 对于本发明的范围, 对本发明所做的公开是说明性的, 而非 限制性的, 本发明的范围由所附权利要求书限定。
Claims
1、 一种基于云安全的文件处理方法, 包括:
根据本地下载的未知程序文件的签名相关信息, 生成与所述未知程序文件唯一 对应的签名标识;
发送查询请求至服务器端, 查询所述未知程序文件是否是恶意程序, 其中, 所 述查询请求携带有所述未知程序文件的签名标识以及所述未知程序文件的部分或全 部文件特征;
接收来自所述服务器端的反馈消息, 并根据所述反馈消息对所述未知程序文件 进行后续处理, 其中, 所述服务器端根据所述签名标识以及所述文件特征生成所述 反馈消息。
2、 根据权利要求 1所述的方法, 按照如下步骤获得所述签名相关信息以及所述 文件特征, 包括:
扫描所述未知程序文件, 获取文件特征;
从所述文件特征中提取签名相关信息。
3、 根据权利要求 1或 2所述的方法, 所述文件特征包括下列至少之一:
MD5、 SHA1、 从文件中抽取部分内容计算出的特征值。
4、 根据权利要求 1至 3任一项所述的方法, 根据本地下载的未知程序文件的签 名相关信息, 生成与所述未知程序文件唯一对应的签名标识, 包括:
获取可移植的执行体 PE文件的可计算字段, 所述可计算字段为 PE文件中除去
PE校验段、 签名段以及签名内容剩余部分;
对所述可计算字段进行计算, 将计算结果作为所述签名标识。
5、 根据权利要求 1至 4任一项所述的方法, 根据所述反馈消息进行后续处理, 包括- 所述签名标识在所述服务器端匹配成功时, 接收所述服务器端反馈的、 与所述 签名标识相对应的查杀方法。
6、根据权利要求 5所述的方法, 接收所述服务器端反馈的查杀方式之后, 包括: 从所述服务器端下载预设的、 针对所述未知程序文件的信息参数的检测条件, 判断所述未知程序文件是否满足所述检测条件;
将判断结果上传所述服务器端, 并根据所述服务器端的指令执行后续处理。
7、 根据权利要求 6所述的方法, 所述检测条件包括下列至少一项:
PE加载的特定文件是否具有特定公司的有效签名;
PE加载的特定文件的内部名称、 产品名称及公司名称是否为指定的名称; 系统中是否挂有特定的钩子;
特定的进程中是否具有特定的填充数据;
系统中是否有特定驱动模块或者设备对象存在;
特定的注册表是否指向特定的文件或者特定的唯一标识 CLSID或者匹配特定的 模式;
PE加载的进程链中是否存在安全性未知的文件。
8、 根据权利要求 6或 7所述的方法, 根据所述服务器端的指令执行后续处理, 包括- 接收来自所述服务器端的所述未知程序文件可能感染恶意程序的提醒消息; 和 / 或
接收来自所述服务器端的对所述未知程序文件进行查杀的查杀命令时, 对所述 未知程序文件进行查杀; 和 /或
在接收到用户界面触发的查杀指令时, 通过服务端对所述未知程序文件进行查 杀。
9、 根据权利要求 5至 8任一项所述的方法, 所述查杀方法包括: 扫描 /判定动作 和 /或修复动作。
10、 一种基于云安全的文件处理方法, 包括:
接收来自客户端的查询请求, 其中, 所述查询请求包括未知程序文件的签名标 识以及所述未知程序文件的部分或全部文件特征;
根据所述签名标识以及所述文件特征生成反馈消息;
将所述反馈消息发送至所述客户端, 其中, 所述客户端根据所述反馈消息对所 述未知程序文件进行后续处理。
11、 根据权利要求 10所述的方法, 其中, 将所述反馈消息发送至所述客户端, 包括- 在数据库中, 对所述签名标识进行匹配;
将匹配得到的查杀方法返回给所述客户端。
12、 根据权利要求 11所述的方法, 其中, 所述数据库包括: 本地数据库和 /或云 端数据库。
13、 根据权利要求 10至 12任一项所述的方法, 其中, 所述接收来自客户端的 查询请求之前, 包括: 接收来自所述客户端的、 所述未知程序文件的文件特征。
14、 根据权利要求 1 1至 13任一项所述的方法, 其中, 将匹配得到的查杀方法 返回给所述客户端之后, 还包括:
将预设的、 针对所述未知程序文件的信息参数的检测条件发送至所述客户端; 以及
接收来自所述客户端的检测结果;
根据所述检测结果发送相应指令。
15、 根据权利要求 14所述的方法, 其中, 根据所述检测结果发送相应指令, 包
括- 根据所述检测结果发送所述未知程序文件可能感染恶意程序的提醒消息至所述 客户端; 和 /或
根据所述检测结果发送相应命令, 其中, 所述相应命令包括对所述未知程序文 件进行查杀的查杀命令, 以及, 对安全文件进行放行的命令。
16、 一种基于云安全的文件处理装置, 包括:
生成模块, 配置为根据本地下载的未知程序文件的签名相关信息, 生成与所述 未知程序文件唯一对应的签名标识;
查询模块, 配置为发送查询请求至服务器端, 查询所述未知程序文件是否是恶 意程序, 其中, 所述查询请求携带有所述未知程序文件的签名标识以及所述未知程 序文件的部分或全部文件特征;
处理模块, 配置为接收来自所述服务器端的反馈消息, 并根据所述反馈消息对 所述未知程序文件进行后续处理, 其中, 所述服务器端根据所述签名标识以及所述 文件特征生成所述反馈消息。
17、 根据权利要求 16所述的装置, 其中, 还包括:
提取模块, 配置为扫描所述未知程序文件, 获取文件特征; 从所述文件特征中 提取签名相关信息。
18、 根据权利要求 16或 17所述的装置, 其中, 所述文件特征包括下列至少之 MD5、 SHA1、 从文件中抽取部分内容计算出的特征值。
19、 根据权利要求 16至 18任一项所述的装置, 其中, 所述生成模块还配置为: 获取可移植的执行体 PE文件的可计算字段, 所述可计算字段为 PE文件中除去
PE校验段、 签名段以及签名内容剩余部分;
对所述可计算字段进行计算, 将计算结果作为所述签名标识。
20、 根据权利要求 16至 19任一项所述的装置, 其中, 所述处理模块还配置为: 所述签名标识在所述服务器端匹配成功时, 接收所述服务器端反馈的、 与所述 签名标识相对应的查杀方法。
21、 根据权利要求 20所述的装置, 其中, 所述处理模块还配置为:
从所述服务器端下载预设的、 针对所述未知程序文件的信息参数的检测条件, 判断所述未知程序文件是否满足所述检测条件;
将判断结果上传所述服务器端, 并根据所述服务器端的指令执行后续处理。
22、 根据权利要求 21所述的装置, 其中, 所述处理模块还配置为:
接收来自所述服务器端的所述未知程序文件可能感染恶意程序的提醒消息; 和 / 或
接收来自所述服务器端的对所述未知程序文件进行查杀的查杀命令时, 对所述
未知程序文件进行查杀; 和 /或
在接收到用户界面触发的查杀指令时, 通过服务端对所述未知程序文件进行查 杀。
23、 根据权利要求 20至 22任一项所述的装置, 其中, 所述查杀方法包括: 对 所述未知程序文件进行扫描 /判定动作和 /或修复动作。
24、 一种基于云安全的文件处理装置, 包括:
接收模块, 配置为接收来自客户端的查询请求, 其中, 所述查询请求包括未知 程序文件的签名标识以及所述未知程序文件的部分或全部文件特征;
发送模块, 配置为根据所述签名标识以及所述文件特征生成反馈消息, 并将所 述反馈消息发送至所述客户端, 其中, 所述客户端根据所述反馈消息对所述未知程 序文件进行后续处理。
25、 根据权利要求 24所述的装置, 其中, 所述发送模块包括- 匹配单元, 配置为在数据库中, 对所述签名标识进行匹配;
发送单元, 配置为将匹配得到的查杀方法发送给所述客户端。
26、 根据权利要求 25所述的装置, 其中, 所述数据库包括: 本地数据库和 /或云 端数据库。
27、 根据权利要求 24至 26任一项所述的装置, 其中, 所述接收模块还配置为 接收来自所述客户端的、 所述未知程序文件的文件特征。
28、 根据权利要求 24至 27任一项所述的装置, 其中,
所述发送模块, 还配置为预设的、 针对所述未知程序文件的信息参数的检测条 件发送至所述客户端; 以及
所述接收模块, 还配置为接收来自所述客户端的检测结果;
所述发送模块, 还配置为根据所述检测结果发送相应指令。
29、 根据权利要求 28所述的装置, 其中, 所述发送模块还配置为:
根据所述检测结果发送所述未知程序文件可能感染恶意程序的提醒消息至所述 客户端; 和 /或
根据所述检测结果发送相应命令, 其中, 所述相应命令包括对所述未知程序文 件进行查杀的查杀命令, 以及, 对安全文件进行放行的命令。
30、 一种计算机程序, 包括计算机可读代码, 当所述计算机可读代码在计算设 备上运行时,导致所述计算设备执行根据权利要求 1-9中的任一个所述的基于云安全 的文件处理方法, 和 /或, 根据权利要求 10-15任一个所述的基于云安全的文件处理 方法。
31、 一种计算机可读介质, 其中存储了如权利要求 30所述的计算机程序。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US14/896,298 US9948670B2 (en) | 2013-06-04 | 2014-06-03 | Cloud security-based file processing by generating feedback message based on signature information and file features |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201310219053.8A CN103281325B (zh) | 2013-06-04 | 2013-06-04 | 基于云安全的文件处理方法及装置 |
| CN201310219053.8 | 2013-06-04 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2014194803A1 true WO2014194803A1 (zh) | 2014-12-11 |
Family
ID=49063772
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2014/079076 Ceased WO2014194803A1 (zh) | 2013-06-04 | 2014-06-03 | 基于云安全的文件处理方法及装置 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US9948670B2 (zh) |
| CN (1) | CN103281325B (zh) |
| WO (1) | WO2014194803A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20170304485A1 (en) * | 2014-10-01 | 2017-10-26 | 3M Innovative Properties Company | Porous devices, kits, and methods for debridement |
| CN115981746A (zh) * | 2023-01-05 | 2023-04-18 | 深圳软牛科技有限公司 | 基于Windows的任务计划非常规自启动方法、装置及相关介质 |
Families Citing this family (36)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103281325B (zh) * | 2013-06-04 | 2018-03-02 | 北京奇虎科技有限公司 | 基于云安全的文件处理方法及装置 |
| CN104915593B (zh) * | 2014-03-14 | 2018-03-16 | 北京奇虎科技有限公司 | 对软件的去捆绑处理方法及系统 |
| CN105279019B (zh) * | 2014-06-10 | 2018-11-23 | 中国移动通信集团公司 | 一种应用程序的调度方法、装置和终端设备 |
| US9356969B2 (en) * | 2014-09-23 | 2016-05-31 | Intel Corporation | Technologies for multi-factor security analysis and runtime control |
| CN104462968B (zh) * | 2014-12-16 | 2017-11-10 | 北京奇虎科技有限公司 | 恶意应用程序的扫描方法、装置和系统 |
| CN105791250B (zh) * | 2014-12-26 | 2020-10-02 | 北京奇虎科技有限公司 | 应用程序检测方法及装置 |
| CN104537304B (zh) * | 2014-12-31 | 2017-04-12 | 北京奇安信科技有限公司 | 文件查杀方法、装置及系统 |
| CN106934286B (zh) * | 2015-12-31 | 2020-02-04 | 北京金山安全软件有限公司 | 一种安全诊断方法、装置及电子设备 |
| US10599837B2 (en) * | 2016-03-31 | 2020-03-24 | International Business Machines Corporation | Detecting malicious user activity |
| WO2018021163A1 (ja) * | 2016-07-27 | 2018-02-01 | 日本電気株式会社 | シグネチャ作成装置、シグネチャ作成方法、シグネチャ作成プログラムが記録された記録媒体、及び、ソフトウェア判定システム |
| CN107689975B (zh) * | 2016-08-05 | 2020-07-31 | 腾讯科技(深圳)有限公司 | 一种基于云计算的计算机病毒识别方法及系统 |
| CN107085685B (zh) * | 2017-05-16 | 2020-06-30 | 华讯高科股份有限公司 | 一种平台数据的操作方法 |
| CN107633173B (zh) * | 2017-09-06 | 2021-08-17 | 北京金山安全管理系统技术有限公司 | 文件处理方法和装置 |
| CN109800775B (zh) * | 2017-11-17 | 2022-10-28 | 腾讯科技(深圳)有限公司 | 文件聚类方法、装置、设备及可读介质 |
| US10176320B1 (en) * | 2017-12-04 | 2019-01-08 | Honeywell International Inc. | Using machine learning in an industrial control network to improve cybersecurity operations |
| CN108108619B (zh) * | 2017-12-29 | 2021-08-31 | 安天科技集团股份有限公司 | 基于模式匹配对应关系的文件检测方法、系统及存储介质 |
| CN109086608A (zh) * | 2018-07-20 | 2018-12-25 | 西安四叶草信息技术有限公司 | 一种检测文件上传漏洞的方法、终端设备和服务器 |
| CN110955891B (zh) * | 2018-09-26 | 2023-05-02 | 阿里巴巴集团控股有限公司 | 文件检测的方法、装置、系统和数据处理法的方法 |
| US11258789B2 (en) * | 2018-12-04 | 2022-02-22 | Forcepoint Llc | System and method for fingerprint validation |
| CN111030969A (zh) * | 2019-02-26 | 2020-04-17 | 北京安天网络安全技术有限公司 | 基于可视和非可视数据的威胁检测方法、装置及存储设备 |
| CN112084495B (zh) * | 2019-06-14 | 2025-05-16 | 北京奇虎科技有限公司 | 进程链的分析方法及装置 |
| CN110263001B (zh) * | 2019-06-18 | 2024-02-06 | 深圳前海微众银行股份有限公司 | 文件管理方法、装置、系统、设备及计算机可读存储介质 |
| CN110351390A (zh) * | 2019-08-14 | 2019-10-18 | 合肥美菱物联科技有限公司 | 智能冰箱添加功能的方法、智能冰箱、云服务器和系统 |
| CN110351392A (zh) * | 2019-08-23 | 2019-10-18 | 易联众智能(厦门)科技有限公司 | 一种多终端物联网的远程控制方法、系统及可读介质 |
| CN111858486B (zh) * | 2020-07-03 | 2024-07-23 | 北京天空卫士网络安全技术有限公司 | 一种文件分类方法和装置 |
| CN111931177B (zh) * | 2020-07-16 | 2023-12-29 | 深信服科技股份有限公司 | 信息处理方法、装置、电子设备和计算机存储介质 |
| CN113971804B (zh) * | 2020-07-24 | 2025-04-29 | 中国移动通信集团浙江有限公司 | 签名伪造的检测装置、方法、计算设备及存储介质 |
| CN112380538A (zh) * | 2020-11-10 | 2021-02-19 | 广东电力信息科技有限公司 | 互联网信息风险提示方法及监测系统 |
| CN114765606B (zh) * | 2020-12-30 | 2023-07-25 | 中国联合网络通信集团有限公司 | 容器镜像传输方法、装置、设备及存储介质 |
| CN114172890B (zh) * | 2021-11-03 | 2024-02-27 | 阿里巴巴(中国)有限公司 | 文件秒传处理方法、装置、存储介质及电子设备 |
| CN114315196B (zh) * | 2021-11-23 | 2023-01-24 | 攀钢集团研究院有限公司 | 一种从碱性含钒液中回收硅磷保温材料的方法 |
| CN114329540B (zh) * | 2021-12-24 | 2025-09-12 | 奇安信科技集团股份有限公司 | 文件分发的处理方法及装置、存储介质、终端 |
| CN114661575A (zh) * | 2022-01-24 | 2022-06-24 | 北京北信源软件股份有限公司 | 程序跟踪方法、装置、设备及计算机可读存储介质 |
| CN114866532B (zh) * | 2022-04-25 | 2023-11-10 | 安天科技集团股份有限公司 | 端点文件安全检查结果信息上传方法、装置、设备及介质 |
| CN114861179A (zh) * | 2022-05-07 | 2022-08-05 | 深圳麦风科技有限公司 | 移动终端应用和文件的风险检测方法、装置、终端及介质 |
| CN120235589B (zh) * | 2025-05-29 | 2025-08-22 | 天津天高普华科技有限公司 | 四性环境下电子档案整理与单套制档案移交方法和系统 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101594248A (zh) * | 2008-05-27 | 2009-12-02 | 奇智软件技术(北京)有限公司 | 信息安全和系统维护的远程协助方法、系统及服务器 |
| CN101719846A (zh) * | 2008-10-09 | 2010-06-02 | 中国移动通信集团天津有限公司 | 安全监控方法、装置及系统 |
| CN102663288A (zh) * | 2012-03-22 | 2012-09-12 | 奇智软件(北京)有限公司 | 病毒查杀方法及装置 |
| CN102693388A (zh) * | 2012-06-07 | 2012-09-26 | 腾讯科技(深圳)有限公司 | 数据安全防护处理系统及方法及存储介质 |
| CN103281325A (zh) * | 2013-06-04 | 2013-09-04 | 北京奇虎科技有限公司 | 基于云安全的文件处理方法及装置 |
Family Cites Families (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7756996B2 (en) * | 2004-01-30 | 2010-07-13 | Finjan, Inc. | Embedding management data within HTTP messages |
| US7490352B2 (en) * | 2005-04-07 | 2009-02-10 | Microsoft Corporation | Systems and methods for verifying trust of executable files |
| US7895651B2 (en) * | 2005-07-29 | 2011-02-22 | Bit 9, Inc. | Content tracking in a network security system |
| US8984636B2 (en) * | 2005-07-29 | 2015-03-17 | Bit9, Inc. | Content extractor and analysis system |
| US8590039B1 (en) * | 2007-11-28 | 2013-11-19 | Mcafee, Inc. | System, method and computer program product for sending information extracted from a potentially unwanted data sample to generate a signature |
| GB2469322B (en) * | 2009-04-09 | 2014-04-16 | F Secure Oyj | Malware determination |
| US8832829B2 (en) * | 2009-09-30 | 2014-09-09 | Fireeye, Inc. | Network-based binary file extraction and analysis for malware detection |
| US8250325B2 (en) * | 2010-04-01 | 2012-08-21 | Oracle International Corporation | Data deduplication dictionary system |
| US8572730B1 (en) * | 2011-02-28 | 2013-10-29 | Symantec Corporation | Systems and methods for revoking digital signatures |
-
2013
- 2013-06-04 CN CN201310219053.8A patent/CN103281325B/zh active Active
-
2014
- 2014-06-03 WO PCT/CN2014/079076 patent/WO2014194803A1/zh not_active Ceased
- 2014-06-03 US US14/896,298 patent/US9948670B2/en active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101594248A (zh) * | 2008-05-27 | 2009-12-02 | 奇智软件技术(北京)有限公司 | 信息安全和系统维护的远程协助方法、系统及服务器 |
| CN101719846A (zh) * | 2008-10-09 | 2010-06-02 | 中国移动通信集团天津有限公司 | 安全监控方法、装置及系统 |
| CN102663288A (zh) * | 2012-03-22 | 2012-09-12 | 奇智软件(北京)有限公司 | 病毒查杀方法及装置 |
| CN102693388A (zh) * | 2012-06-07 | 2012-09-26 | 腾讯科技(深圳)有限公司 | 数据安全防护处理系统及方法及存储介质 |
| CN103281325A (zh) * | 2013-06-04 | 2013-09-04 | 北京奇虎科技有限公司 | 基于云安全的文件处理方法及装置 |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20170304485A1 (en) * | 2014-10-01 | 2017-10-26 | 3M Innovative Properties Company | Porous devices, kits, and methods for debridement |
| US10709807B2 (en) * | 2014-10-01 | 2020-07-14 | 3M Innovative Properties Company | Porous devices, kits, and methods for debridement |
| CN115981746A (zh) * | 2023-01-05 | 2023-04-18 | 深圳软牛科技有限公司 | 基于Windows的任务计划非常规自启动方法、装置及相关介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| US9948670B2 (en) | 2018-04-17 |
| CN103281325B (zh) | 2018-03-02 |
| CN103281325A (zh) | 2013-09-04 |
| US20160119375A1 (en) | 2016-04-28 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN103281325B (zh) | 基于云安全的文件处理方法及装置 | |
| CN102882875B (zh) | 主动防御方法及装置 | |
| CN103077353B (zh) | 主动防御恶意程序的方法和装置 | |
| CN103679031B (zh) | 一种文件病毒免疫的方法和装置 | |
| CN103473501B (zh) | 一种基于云安全的恶意软件追踪方法 | |
| KR101607951B1 (ko) | 클라우드 기술을 사용한 멀웨어에 대한 동적 클리닝 | |
| CN103390130B (zh) | 基于云安全的恶意程序查杀的方法、装置和服务器 | |
| US9135443B2 (en) | Identifying malicious threads | |
| CN103207970B (zh) | 病毒文件扫描方法及装置 | |
| WO2013086289A1 (en) | Predictive heap overflow protection | |
| CN103279707A (zh) | 一种用于主动防御恶意程序的方法、设备及系统 | |
| WO2014082599A1 (zh) | 用于恶意程序查杀的扫描设备、云端管理设备及方法和系统 | |
| CN103136477B (zh) | 文件样本的扫描方法和系统 | |
| CN102999720A (zh) | 程序鉴别方法和系统 | |
| CN102982281A (zh) | 程序状况检测方法和系统 | |
| CN104809391B (zh) | 缓冲区溢出攻击检测装置、方法和安全防护系统 | |
| CN102984134B (zh) | 安全防御系统 | |
| CN105095758A (zh) | 锁屏应用程序处理方法、装置以及移动终端 | |
| CN102857519B (zh) | 主动防御系统 | |
| CN105844161B (zh) | 安全防御方法、装置与系统 | |
| CN105791250A (zh) | 应用程序检测方法及装置 | |
| CN103116724B (zh) | 探测程序样本危险行为的方法及装置 | |
| US10880316B2 (en) | Method and system for determining initial execution of an attack | |
| KR20250168627A (ko) | 실시간 셸코드 검출 및 방지 | |
| WO2016095671A1 (zh) | 一种应用程序的消息处理方法和装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 14807907 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 14896298 Country of ref document: US |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 14807907 Country of ref document: EP Kind code of ref document: A1 |