US2018082061A1PendingUtilityA1

Scanning device, cloud management device, method and system for checking and killing malicious programs

Assignee: BEIJING QIHOO TECHNOLOGY COPriority: Nov 30, 2012Filed: Nov 27, 2017Published: Mar 22, 2018
Est. expiryNov 30, 2032(~6.3 yrs left)· nominal 20-yr term from priority
H04L 63/145G06F 2221/033G06F 21/56
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The disclosure includes a scanning device, a cloud management device, a method and system for checking and killing a malicious program. Therein, a cloud management device for checking and killing a malicious program comprises: a processor, a transmission interface; a first indicator to generate, by the processor, a first scanning content indication according to characteristics of a newborn malicious program and system environment information transmitted by a client device; a first matcher to obtain, by the processor via the transmission interface, feature data of the unknown program file transmitted by the client device, and perform matching in known records of feature data of malicious programs; and a second indicator to generate, by the processor, a second scanning content indication when the first matcher fails to match to a known record, the generating the second scanning content indication comprising scanning a specified attribute of the unknown program file and/or a specified attribute of contextual environment of the unknown program file, and transmit the same to the client device through the transmission interface.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A cloud management device for checking and killing a malicious program comprising:
 a transmission interface to transmit, by a processor, information to a client device and receive information transmitted by the client device;   a first indicator to generate, by the processor, a first scanning content indication according to characteristics of a newborn malicious program and system environment information transmitted by the client device, the generating the first scanning content indication comprising scanning content at a specified position of the content and identifying scanned feature data of an unknown program file, and transmit the first scanning content indication to the client device via the transmission interface;   a first matcher to obtain, by the processor via the transmission interface, the feature data of the unknown program file transmitted by the client device and perform matching in known records of feature data of malicious programs; and   a second indicator to generate, by the processor, a second scanning content indication when the first matcher fails to match to a known record, the generating the second scanning content indication comprising scanning a specified attribute of the unknown program file and/or a specified attribute of contextual environment of the unknown program file, and transmit the second scanning content indication to the client device via the transmission interface.   
     
     
         2 . The cloud management device as claimed in  claim 1 , wherein:
 the second indicator is configured to obtain via the transmission interface the scanning result obtained by the client device after scanning according to the second scanning content indication, judge whether the unknown program file is a malicious program, and transmit a judgment result to the client device via the transmission interface; or   the second indicator is configured to transmit a judgment logic related to the second scanning content indication together to the client device via the transmission interface, wherein the judgment logic is a logic for judging whether the unknown program file is a malicious program.   
     
     
         3 . The cloud management device as claimed in  claim 1 , wherein
 the second indicator is configured to obtain via the transmission interface the scanning result obtained by the client device after scanning according to the second scanning content indication, perform matching in a known database for checking and killing malicious programs according to the scanning result obtained by the client device after scanning according to the second scanning content indication, and if a fixing logic matching the scanning result is found, transmit the matching fixing logic to the client device via the transmission interface; or,   the second indicator is configured to perform matching in a known database for checking and killing malicious programs according to the second scanning content indication, and transmit a matched fixing logic related to the second scanning content indication together with the second scanning content indication to the client device via the transmission interface.   
     
     
         4 . The cloud management device as claimed in  claim 3 , wherein the matching fixing logic comprises one or more of the following: deleting a specified registry key and/or key value, modifying a registry key and/or key value as specified content, deleting a specified system service item, and fixing/deleting a specified program file. 
     
     
         5 . The cloud management device as claimed in  claim 1 , wherein the characteristics of a newborn malicious program comprise: feature information in which the newborn malicious program utilizes a specific position to hide and/or attack. 
     
     
         6 . The cloud management device as claimed in  claim 1 , wherein the first scanning content indication is an indication with a condition attached, and the condition comprises one or more of the following: whether a specified file exists, whether a specified directory exists, whether an attribute of a program file meets a specified condition, whether a specified registry key exists, whether a specified registry key value exists, whether content of a registry key meets a specified condition, whether content of a registry key value meets a specified condition, whether a specified process exists, and whether a specified service exists. 
     
     
         7 . The cloud management device as claimed in  claim 1 , wherein
 the feature data of the unknown program file comprises one or more of the following: data obtained employing a specific algorithm for all or part of the key content of the unknown program file and a file name; and   the specified attribute of the unknown program file comprises one or more of the following: feature data, file size, signature information, and version information.   
     
     
         8 . The cloud management device as claimed in  claim 1 , wherein the attribute of the contextual environment of the unknown program file comprises one or more of the following: information on a directory where the unknown program file is located, security level information, information on a startup position in a registry, attribute information of other file under the same directory as the program file or a specified directory, and a running state of a specified process. 
     
     
         9 . A cloud management method for checking and killing a malicious program, comprising:
 generating, by a processor, a first scanning content indication according to characteristics of a newborn malicious program and system environment information transmitted by a client device, the generating the first scanning content indication comprising scanning content at a specified position of the content and identifying scanned feature data of an unknown program file, and transmitting the first scanning content indication to the client device;   obtaining, by the processor, the feature data of the unknown program file transmitted by the client device, and performing matching in a known database for checking and killing malicious programs; and   generating, by the processor, a second scanning content indication when a known record fails to be matched to the feature data of the unknown program file, the generating the second scanning content indication comprising scanning a specified attribute of the unknown program file and/or a specified attribute of contextual environment of the unknown program file, and transmitting the second scanning content indication to the client device.   
     
     
         10 . The cloud management method for checking and killing a malicious program as claimed in  claim 9 , further comprise:
 obtaining via the transmission interface the scanning result obtained by the client device after scanning according to the second scanning content indication, judging whether the unknown program file is a malicious program and transmitting a judgment result to the client device via the transmission interface; or   transmitting a judgment logic related to the second scanning content indication together to the client device via the transmission interface, wherein the judgment logic is a logic for judging whether the unknown program file is a malicious program.   
     
     
         11 . The cloud management method for checking and killing a malicious program as claimed in  claim 9 , further comprise:
 obtaining via the transmission interface the scanning result obtained by the client device after scanning according to the second scanning content indication, performing matching in a known database for checking and killing malicious programs according to the scanning result obtained by the client device after scanning according to the second scanning content indication, and if a fixing logic matching the scanning result is found, transmitting it to the client device via the transmission interface; or,   performing matching in a known database for checking and killing malicious programs according to the second scanning content indication, and transmitting a matched fixing logic related to the second scanning content indication together with the second scanning content indication to the client device via the transmission interface.   
     
     
         12 . The cloud management method for checking and killing a malicious program as claimed in  claim 11 , wherein the fixing logic comprises one or more of the following: deleting a specified registry key and/or key value, modifying a registry key and/or key value as specified content, deleting a specified system service item, and fixing/deleting a specified program file. 
     
     
         13 . The cloud management method for checking and killing a malicious program as claimed in  claim 9 , wherein the characteristics of a newborn malicious program comprise: feature information in which the newborn malicious program utilizes a specific position to hide and/or attack. 
     
     
         14 . The cloud management method for checking and killing a malicious program as claimed in  claim 9 , wherein the first scanning content indication is an indication with a condition attached, and the condition comprises one or more of the following: whether a specified file exists, whether a specified directory exists, whether an attribute of a program file meets a specified condition, whether a specified registry key exists, whether a specified registry key value exists, whether content of a registry key meets a specified condition, whether content of a registry key value meets a specified condition, whether a specified process exists, and whether a specified service exists. 
     
     
         15 . The cloud management method for checking and killing a malicious program as claimed in  claim 9 , wherein
 the feature data of the unknown program file comprises one or more of the following: the data obtained employing a specific algorithm for all or part of the key content of the unknown program file and a file name; and   the specified attribute of the unknown program file comprises one or more of the following: feature data, file size, signature information and version information.   
     
     
         16 . The cloud management method for checking and killing a malicious program as claimed in  claim 9 , wherein the attribute of the contextual environment of the unknown program file comprises one or more of the following: information on a directory where the unknown program file is located, security level information, information on a startup position in a registry, attribute information of other file under the same directory as the program file or a specified directory, and a running state of a specified process. 
     
     
         17 . A computer readable medium, which stores computer readable code, wherein the computer readable code, when executed on a computing device, cause the computing device to:
 generate a first scanning content indication according to characteristics of a newborn malicious program and system environment information transmitted by a client device, the generating the first scanning content indication comprising scanning content at a specified position of the content and identifying scanned feature data of an unknown program file, and transmit the first scanning content indication to the client device;   obtain the feature data of the unknown program file transmitted by the client device, and perform matching in a known database for checking and killing malicious programs; and   generate a second scanning content indication when a known record fails to be matched to the feature data of the unknown program file, the generating the second scanning content indication comprising scanning a specified attribute of the unknown program file and/or a specified attribute of contextual environment of the unknown program file, and transmit the second scanning content indication to the client device.   
     
     
         18 . The computer readable medium as claimed in  claim 17 , wherein the computing device is further caused to:
 obtain via the transmission interface the scanning result obtained by the client device after scanning according to the second scanning content indication, judge whether the unknown program file is a malicious program and transmit a judgment result to the client device via the transmission interface; or   transmit a judgment logic related to the second scanning content indication together to the client device via the transmission interface, wherein the judgment logic is a logic for judging whether the unknown program file is a malicious program.   
     
     
         19 . The computer readable medium as claimed in  claim 17 , wherein the computing device is further caused to:
 obtain via the transmission interface the scanning result obtained by the client device after scanning according to the second scanning content indication, perform matching in a known database for checking and killing malicious programs according to the scanning result obtained by the client device after scanning according to the second scanning content indication, and if a fixing logic matching the scanning result is found, transmit it to the client device via the transmission interface; or,   perform matching in a known database for checking and killing malicious programs according to the second scanning content indication, and transmit a matched fixing logic related to the second scanning content indication together with the second scanning content indication to the client device via the transmission interface.   
     
     
         20 . The computer readable medium as claimed in  claim 19 , wherein the fixing logic comprises one or more of the following: deleting a specified registry key and/or key value, modifying a registry key and/or key value as specified content, deleting a specified system service item, and fixing/deleting a specified program file.

Join the waitlist — get patent alerts

Track US2018082061A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.