Unknown virus infection tracing method, device and system
An unknown virus and virus technology, applied in the computer field, can solve the problems of unable to find information system weaknesses, affecting information system reinforcement, unable to trace unknown virus sources and transmission paths, etc.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0027] refer to figure 1 , the embodiment of the present invention provides an unknown virus infection tracing method, wherein, when applied to an unknown virus infection tracing engine, may include the following steps:
[0028] Step S101, receiving the file content of the monitoring file sent by the terminal, and extracting the first feature and the second feature from the file content; wherein, the first feature is the MD5 feature of the overall file content, and the second feature is the MD5 feature of the partial file content ;
[0029]In the embodiment of the present invention, the embodiment of the present invention extracts the file content of the monitoring file in two situations, and obtains the MD5 features of the two file contents. In case 1, the overall file content of the monitoring file is extracted to obtain the MD5 feature of the overall file content; in case 2, the partial file content of the monitoring file is extracted to obtain the MD5 feature of the parti...
Embodiment 2
[0053] refer to image 3 , an embodiment of the present invention provides an unknown virus infection tracing device, which is applied to an unknown virus infection tracing engine, including:
[0054] The receiving module 11 is used to receive the file content of the monitoring file sent by the terminal, and extract the first feature and the second feature from the file content; wherein, the first feature is the MD5 feature of the overall file content, and the second feature is the partial file content MD5 characteristics;
[0055] Judging module 12, for judging whether the monitored file is a suspected unknown virus file based on the first feature and the second feature;
[0056] Processing judging module 13, for if, then put suspected unknown virus file in the sandbox and process, judge whether suspected unknown virus file has virus behavior characteristic;
[0057] Determining module 14, for if having, then the suspected unknown virus file with virus behavior characterist...
Embodiment 3
[0070] refer to Figure 5 , the embodiment of the present invention provides an unknown virus infection tracing system, which includes: an unknown virus infection tracing engine 30, at least one terminal 40 and a visual presentation system 50; wherein the terminal 40 is used to provide the unknown virus infection tracing engine with The file content and file operation of the monitoring file on the terminal; the unknown virus infection tracing engine 30 is used to receive the file content and file operation, and based on the file content and file operation, form the transmission path of the unknown virus; the visual presentation system 50 is used to Displays the propagation path.
[0071] In the embodiment of the present invention, the unknown virus infection traceability engine 30 receives the file feature data reported by each terminal 40, and forms traceability results after global data analysis. The first machine and the propagation path of the unknown virus file, where th...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com