Application security detection method, device, equipment and storage medium
By obtaining program behavior specification data and current operation data, and combining application safety inspection, the problem of ignoring program behavior in the application production process in the existing technology is solved, and the accuracy of safety inspection is significantly improved.
Patent Information
- Application Number
- CN202011275067.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-12
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2040-11-12
AI Technical Summary
In the existing application security detection process, the focus is on known attack behaviors, and the program behavior in the application production process is ignored, resulting in inaccurate security detection results.
When receiving the user's application security detection instruction, the program behavior specification data is obtained from the preset behavior data set according to the application identifier to be detected, and the application security detection is performed in combination with the current running data.
It significantly improves the accuracy of application security detection results, and provides the most comprehensive program behavior detection by combining program behavior specification data and current operating data.
Smart Images

Figure CN114491521B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security detection technology, and in particular to an application security detection method, device, equipment and storage medium. Background Art
[0002] At present, application security testing is carried out by first running the target application to obtain static and dynamic information during the operation of the target application, then matching the static and dynamic information during the operation with the existing attack behavior information, and finally judging whether the target application has abnormal behavior based on the matching results to determine whether the application is safe. However, the existing application security testing process focuses on known attack behaviors and ignores the program behavior during the application production process, resulting in inaccurate application security testing results.
[0003] The above contents are only used to assist in understanding the technical solution of the present invention and do not constitute an admission that the above contents are prior art. Summary of the invention
[0004] The main purpose of the present invention is to provide an application security detection method, device, equipment and storage medium, aiming to solve the technical problem of inaccurate application security detection results.
[0005] To achieve the above object, the present invention provides an application security detection method, which comprises the following steps:
[0006] Upon receiving an application security detection instruction from a user, determining an application to be detected and a corresponding application identifier to be detected according to the application security detection instruction;
[0007] Acquire corresponding program behavior specification data from a preset behavior data set according to the application identifier to be detected;
[0008] Calling the application to be detected to obtain current running data of the application to be detected;
[0009] An application security check is performed on the application to be checked according to the program behavior specification data and the current running data.
[0010] Optionally, before the step of determining the application to be detected and the corresponding identification of the application to be detected according to the application security detection instruction when receiving the application security detection instruction from the user, the method further includes:
[0011] Acquire application development data, and determine program behavior specification data based on the application development data;
[0012] Establishing a mapping relationship between the program behavior specification data and the corresponding application;
[0013] generating an application identifier of the application according to the mapping relationship;
[0014] A preset behavior data set is constructed according to the program behavior specification data and the application identifier.
[0015] Optionally, the step of obtaining application development data and determining program behavior specification data according to the application development data includes:
[0016] Get application development data;
[0017] Processing the application development data to obtain target application development data;
[0018] The program behavior specification data is determined according to the target application development data through a preset program behavior model.
[0019] Optionally, the step of performing data processing on the application development data to obtain target application development data includes:
[0020] Clean the application development data according to a preset data cleaning algorithm to obtain the application development data to be processed;
[0021] Determining a performance indicator data sequence of the application development data according to the performance indicator data characteristics;
[0022] The application development data to be processed is subjected to data fuzzification processing according to the performance indicator data sequence to obtain target application development data.
[0023] Optionally, the step of performing data cleaning on the application development data according to a preset data cleaning algorithm to obtain the application development data to be processed includes:
[0024] Obtaining a connection rate time series of the application development data according to a preset data cleaning algorithm;
[0025] The application development data is cleaned according to the connection rate time series to obtain the application development data to be processed.
[0026] Optionally, the step of performing data cleaning on the application development data according to the connection rate time series to obtain the application development data to be processed includes:
[0027] Determine whether the connection rate time series is greater than a preset cleaning threshold;
[0028] Determine the application development data to be cleaned whose connection rate time series is greater than the preset cleaning threshold in the application development data;
[0029] The application development data to be cleaned is removed from the application development data to obtain the application development data to be processed.
[0030] Optionally, the step of performing data fuzzification processing on the to-be-processed application development data according to the performance indicator data sequence to obtain target application development data includes:
[0031] Acquiring developer behavior information according to the application development data to be processed;
[0032] Constructing a behavior frequency time series according to the developer behavior information;
[0033] The behavior frequency time series is subjected to data fuzzification processing according to the performance indicator data series to obtain target application development data.
[0034] Optionally, the step of performing data fuzzification processing on the behavior frequency time series according to the performance indicator data series to obtain target application development data includes:
[0035] Performing differential stabilization processing on the behavior frequency time series according to the performance indicator data series to obtain a stabilized behavior frequency time series;
[0036] Target application development data is constructed based on the stable behavior frequency time series.
[0037] Optionally, before the step of obtaining the application development data and determining the program behavior specification data according to the application development data, the step further includes:
[0038] Obtaining a code development task for the application to be detected;
[0039] Obtaining code development activity information corresponding to the code development task;
[0040] Acquire code submission behavior data of the code development activity according to the development flow corresponding to the code development activity information;
[0041] The code submission behavior data is used as application development data.
[0042] Optionally, after the step of obtaining the code development task of the application to be detected, the method further includes:
[0043] Determining the current program development stage according to the code development task;
[0044] Matching the current program development stage with a preset program development stage;
[0045] When the current program development stage successfully matches the preset program development stage, a step of acquiring code development activity information corresponding to the code development task is performed.
[0046] Optionally, the step of performing application security detection on the application to be detected according to the program behavior specification data and the current running data includes:
[0047] Matching the program behavior specification data with the current running data to obtain a behavior matching result;
[0048] Filter the current operation data according to the behavior matching result to obtain abnormal behavior information;
[0049] An application security detection is performed on the application to be detected according to the abnormal behavior information.
[0050] Optionally, the step of performing application security detection on the application to be detected according to the program behavior specification data and the current running data includes:
[0051] Matching the program behavior specification data with the current operation data to obtain an operation behavior matching result;
[0052] Matching the current running data with the attack behavior information in a preset blacklist to obtain an attack behavior matching result;
[0053] The current operation data is screened according to the attack behavior matching result and the operation behavior matching result to obtain abnormal behavior information;
[0054] An application security detection is performed on the application to be detected according to the abnormal behavior information.
[0055] In addition, to achieve the above-mentioned purpose, the present invention further proposes an application security detection device, the application security detection device comprising:
[0056] A determination module, configured to determine the application to be detected and the corresponding identification of the application to be detected according to the application security detection instruction when receiving the application security detection instruction from the user;
[0057] An acquisition module, configured to acquire corresponding program behavior specification data from a preset behavior data set according to the application identifier to be detected;
[0058] A calling module, used for calling the application to be detected and obtaining the current running data of the application to be detected;
[0059] The detection module is used to perform application security detection on the application to be detected according to the program behavior specification data and the current running data.
[0060] Optionally, the application security detection device further includes: a generation module;
[0061] The generating module is used to obtain application development data and determine program behavior specification data according to the application development data;
[0062] Establishing a mapping relationship between the program behavior specification data and the corresponding application;
[0063] generating an application identifier of the application according to the mapping relationship;
[0064] A preset behavior data set is constructed according to the program behavior specification data and the application identifier.
[0065] Optionally, the generating module is further used to obtain application development data;
[0066] Processing the application development data to obtain target application development data;
[0067] The program behavior specification data is determined according to the target application development data through a preset program behavior model.
[0068] Optionally, the generating module is further used to clean the application development data according to a preset data cleaning algorithm to obtain the application development data to be processed;
[0069] Determining a performance indicator data sequence of the application development data according to the performance indicator data characteristics;
[0070] The application development data to be processed is subjected to data fuzzification processing according to the performance indicator data sequence to obtain target application development data.
[0071] Optionally, the generating module is further used to obtain a connection rate time series of the application development data according to a preset data cleaning algorithm;
[0072] The application development data is cleaned according to the connection rate time series to obtain the application development data to be processed.
[0073] Optionally, the generating module is further used to determine whether the connection rate time series is greater than a preset cleaning threshold;
[0074] Determine the application development data to be cleaned whose connection rate time series is greater than the preset cleaning threshold in the application development data;
[0075] The application development data to be cleaned is removed from the application development data to obtain the application development data to be processed.
[0076] In addition, to achieve the above-mentioned purpose, the present invention also proposes an application security detection device, which includes: a memory, a processor, and an application security detection program stored in the memory and executable on the processor, wherein the application security detection program is configured with steps for implementing the application security detection method described above.
[0077] In addition, to achieve the above-mentioned purpose, the present invention further proposes a storage medium, on which an application security detection program is stored, and when the application security detection program is executed by a processor, the steps of the application security detection method described above are implemented.
[0078] The present invention determines the application to be detected and the corresponding application identifier to be detected according to the application security detection instruction when receiving the application security detection instruction from the user; obtains the corresponding program behavior specification data from the preset behavior data set according to the application identifier to be detected; calls the application to be detected and obtains the current running data of the application to be detected; and performs application security detection on the application to be detected according to the program behavior specification data and the current running data. In the present invention, the program behavior specification data and the current running data of the application are combined to detect whether there are security problems in the terminal application. The program behavior specification data comes from the program developer, provides the most comprehensive program behavior detection, significantly improves the accuracy of the application security detection results, and solves the technical problem of inaccurate application security detection results in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS
[0079] Figure 1 It is a structural diagram of an application security detection device for a hardware operating environment involved in an embodiment of the present invention;
[0080] Figure 2 A schematic diagram of a flow chart of a first embodiment of a safety detection method for application of the present invention;
[0081] Figure 3 A schematic diagram of a flow chart of a second embodiment of the application safety detection method of the present invention;
[0082] Figure 4 A schematic diagram of a flow chart of a third embodiment of the application safety detection method of the present invention;
[0083] Figure 5 This is a structural block diagram of the first embodiment of the safety detection device applied in the present invention.
[0084] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0085] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0086] Reference Figure 1 , Figure 1 It is a schematic diagram of the structure of an application security detection device for a hardware operating environment involved in an embodiment of the present invention.
[0087] like Figure 1 As shown, the application security detection device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the optional user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a wireless fidelity (WIreless-FIdelity, WI-FI) interface). The memory 1005 may be a high-speed random access memory (Random Access Memory, RAM) memory, or a stable non-volatile memory (Non-Volatile Memory, NVM), such as a disk memory. The memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0088] Those skilled in the art will understand that Figure 1 The structure shown in the figure does not constitute a limitation on the application security detection device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0089] like Figure 1 As shown, the memory 1005 as a storage medium may include an operating system, a network communication module, a user interface module, and an application security detection program.
[0090] exist Figure 1 In the application security detection device shown, the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in the application security detection device of the present invention can be set in the application security detection device, and the application security detection device calls the application security detection program stored in the memory 1005 through the processor 1001, and executes the application security detection method provided by the embodiment of the present invention.
[0091] The present invention provides an application security detection method. Figure 2 , Figure 2The figure is a flow chart of a first embodiment of an application security detection method of the present invention.
[0092] In this embodiment, the application security detection method includes the following steps:
[0093] Step S10: upon receiving an application security detection instruction from a user, determining an application to be detected and a corresponding application identifier to be detected according to the application security detection instruction.
[0094] It should be noted that the executor of this embodiment is the application security detection device, wherein the application security detection device can be a detection terminal on a computer, a detection terminal on a mobile phone, a detection terminal on an IoT device, etc., and can also be other devices that can achieve the same or similar functions. This embodiment does not limit this. In this embodiment, the detection terminal on the mobile phone is taken as an example, wherein receiving the user's application security detection instruction can be the user clicking on the application that needs to be security checked on the mobile phone. The application security detection instruction can also be other means, which is not limited by this embodiment.
[0095] It should be understood that when receiving the user's application security detection instruction, it means that the user wants to perform a security detection on the application to be detected. Therefore, the application to be detected can be directly determined according to the application security detection instruction. In order to obtain the program behavior specification data corresponding to the application to be detected for security detection, the application identification corresponding to the application to be detected stored in advance can also be obtained, and then the program behavior specification data can be obtained through the application identification.
[0096] Step S20: Acquire corresponding program behavior specification data from a preset behavior data set according to the application identifier to be detected.
[0097] It is easy to understand that the preset behavior data set can be a data center, and the program behavior specification data is saved in the data center. When security detection is required through the program behavior specification data, the corresponding program behavior specification data can be obtained from the preset behavior data set according to the application identifier to be detected. Among them, the establishment of the data center can be based on a company or a country, etc., and this embodiment does not limit this.
[0098] It should be noted that the program behavior specification data may include call interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information during the operation of the application to be detected. Among them, the call interface information may be Unix system call information or Mach system call information, the file system behavior information may be file system behavior information such as opening, reading, modifying, and creating, the network behavior information may be network behavior information such as TCP, HTTP, and DNS, the inter-process communication behavior information may be information such as the opened inter-process communication service and the called interface. Due to the differences in platforms, for example, the kernel on macOS will also provide RPC services, and the driver behavior information may be the opened driver and the called interface. In addition, the program behavior specification data may also include other behavior information, which may be other than the above-mentioned call interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information, but other behaviors that are meaningful to security detection are not limited in this embodiment.
[0099] Specifically, the process of constructing a preset behavior data set may be: obtaining application development data, determining program behavior specification data based on the application development data; establishing a mapping relationship between the program behavior specification data and the corresponding application; generating an application identifier of the application based on the mapping relationship; and constructing a preset behavior data set based on the program behavior specification data and the application identifier. The application development data may be normal behavior information of the application during the development stage, which may be provided by the program manufacturer or obtained in other ways, and this embodiment does not limit this.
[0100] Step S30: calling the application to be detected and obtaining the current running data of the application to be detected.
[0101] It should be noted that, the application to be detected is called to obtain the current running data of the application to be detected. In a specific implementation, the current running data of the application to be detected may include the calling interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information during the running process of the application to be detected. Among them, the calling interface information may be Unix system call information or Mach system call information, the file system behavior information may be file system behavior information such as opening, reading, modifying, and creating, the network behavior information may be network behavior information such as TCP, HTTP, and DNS, the inter-process communication behavior information may be information such as the opened inter-process communication service and the called interface. Due to the differences in platforms, for example, the kernel on macOS also provides RPC services, and the driver behavior information may be the opened driver and the called interface. In addition, the current running data may also include other behavior information, which may not be the above-mentioned calling interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information, but other behaviors that are meaningful to security detection, and this embodiment does not limit this.
[0102] Furthermore, considering that in actual applications, if the application to be detected is directly called to obtain the current running data of the application to be detected, it is bound to result in too few objects involved in behavior detection and low accuracy. To overcome this defect, when calling the application to be detected, the current installation information of the application to be detected is obtained, and it is determined whether the application to be detected is in the state to be detected based on the current installation information. When the application to be detected is in the state to be detected, behavior detection is performed according to the calling instruction to obtain the current running data.
[0103] Step S40: performing application security detection on the application to be detected according to the program behavior specification data and the current running data.
[0104] It should be understood that the program behavior specification data is matched with the current running data to obtain a behavior matching result; the current running data is screened according to the behavior matching result to obtain abnormal behavior information; and application security detection is performed on the application to be detected based on the abnormal behavior information.
[0105] Specifically, the current running data can be matched with the program behavior specification data, and the obtained behavior matching result can be to determine the information similarity based on the current running data and the program behavior specification data, screen the current running data based on the information similarity, obtain abnormal behavior information, and determine whether the information similarity is greater than a preset threshold. When the information similarity is greater than the preset threshold, it is determined that the behavior information corresponding to the information similarity should not be screened out; when the information similarity is less than or equal to the preset threshold, it is determined that the behavior information corresponding to the information similarity should be screened out and is abnormal behavior information, and application security detection is performed on the application to be detected based on the abnormal behavior information, wherein the preset threshold can be a value preset by the user. The current running data and the program behavior specification data can be matched for: calling interface information, file system behavior information, network behavior information, inter-process communication behavior information, driver behavior information, and other behavior information.
[0106] It should be noted that, in order to further improve the accuracy of application security detection results, it can be achieved by combining the matching results of program behavior specification data with the detection results of blacklist detection, for example: matching the program behavior specification data with the current running data to obtain the running behavior matching results; matching the current running data with the attack behavior information in the preset blacklist to obtain the attack behavior matching results; screening the current running data according to the attack behavior matching results and the running behavior matching results to obtain abnormal behavior information; performing application security detection on the application to be detected according to the abnormal behavior information. Among them, the preset blacklist can be a traditional way of detecting attacks, and this embodiment does not limit this.
[0107] This embodiment determines the application to be detected and the corresponding application identifier to be detected according to the application security detection instruction when receiving the application security detection instruction from the user; obtains the corresponding program behavior specification data from the preset behavior data set according to the application identifier to be detected; calls the application to be detected and obtains the current running data of the application to be detected; and performs application security detection on the application to be detected according to the program behavior specification data and the current running data. In this embodiment, the program behavior specification data and the current running data of the application are combined to detect whether there are security issues in the terminal application. The program behavior specification data comes from the program developer, providing the most comprehensive program behavior detection, significantly improving the accuracy of the application security detection results, and solving the technical problem of inaccurate application security detection results in the existing system.
[0108] refer to Figure 3 , Figure 3 This is a flow chart of a second embodiment of an application security detection method of the present invention. Based on the first embodiment, the application security detection method of this embodiment further includes, before step S10:
[0109] Step S11: Acquire application development data, and determine program behavior specification data according to the application development data.
[0110] It is easy to understand that the application development data may be normal behavior information of the application during the development phase, and may be provided by the program manufacturer or obtained in other ways, which is not limited in this embodiment.
[0111] It should be noted that the program behavior specification data may include call interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information during the operation of the application to be detected. Among them, the call interface information may be Unix system call information or Mach system call information, the file system behavior information may be file system behavior information such as opening, reading, modifying, and creating, the network behavior information may be network behavior information such as TCP, HTTP, and DNS, the inter-process communication behavior information may be information such as the opened inter-process communication service and the called interface. Due to the differences in platforms, for example, the kernel on macOS will also provide RPC services, and the driver behavior information may be the opened driver and the called interface. In addition, the program behavior specification data may also include other behavior information, which may be other than the above-mentioned call interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information, but other behaviors that are meaningful to security detection are not limited in this embodiment.
[0112] It should be understood that in order to further improve the availability of program behavior specification data, it is also necessary to process the application development data. The specific data processing process can be: obtaining application development data; processing the application development data to obtain target application development data; and determining the program behavior specification data through a preset program behavior model based on the target application development data.
[0113] It is easy to understand that the application development data can be the normal behavior information of the application during the development stage, which can be provided by the program manufacturer, or obtained in the following way: obtain the code development task of the application to be detected; obtain the code development activity information corresponding to the code development task; obtain the code submission behavior data of the code development activity according to the development flow corresponding to the code development activity information; and use the code submission behavior data as the application development data.
[0114] Wherein, after obtaining the code development task of the application to be detected, it also includes: determining the current program development stage according to the code development task; matching the current program development stage with the preset program development stage; when the current program development stage successfully matches the preset program development stage, executing the step of obtaining the code development activity information corresponding to the code development task. Wherein, the preset program development stage can be a regression testing stage, and the regression testing stage is a stage of the program development process, including recording program information: program behavior, behavior timing of each thread, whether each behavior depends on user interaction, etc. It should be understood that when the matching result is a successful match, it means that the current program development stage is a regression testing stage, and therefore, the code development activity information corresponding to the code development task can be obtained.
[0115] Step S12: Establishing a mapping relationship between the program behavior specification data and the corresponding application.
[0116] It should be noted that the application development data can be normal behavior information of an application during the development stage, which can be provided by a program manufacturer. The program behavior specification data can be determined based on the application development data. The corresponding program behavior specification data can be obtained through the application development data of different applications provided by different program manufacturers. A mapping relationship between the program behavior specification data and the corresponding application can be established, which facilitates obtaining the program behavior specification data corresponding to the application during security testing.
[0117] Step S13: Generate an application identifier of the application according to the mapping relationship.
[0118] It can be understood that in order to facilitate the acquisition of program behavior specification data corresponding to the application during security testing, an application identifier of the application is generated based on the mapping relationship between the program behavior specification data and the corresponding application, wherein the mapping relationship includes the corresponding relationship between the program behavior specification data and the application, and setting the application identifier facilitates the acquisition of the corresponding program behavior specification data according to the application identifier of the application during security testing.
[0119] Step S14: constructing a preset behavior data set according to the program behavior specification data and the application identifier.
[0120] It is easy to understand that a preset behavior data set is constructed according to the program behavior specification data and the application identifier. The preset behavior data set can be a data center. The program behavior specification data is saved in the data center. When security detection is required through the program behavior specification data, the corresponding program behavior specification data can be obtained from the preset behavior data set according to the application identifier to be detected. Among them, the establishment of the data center can be based on a company or a country, etc., which is not limited in this embodiment.
[0121] This embodiment obtains application development data, determines program behavior specification data according to the application development data; establishes a mapping relationship between the program behavior specification data and the corresponding application; generates an application identifier of the application according to the mapping relationship; and constructs a preset behavior data set according to the program behavior specification data and the application identifier. In this embodiment, the program behavior specification data and the current running data of the application are combined to detect whether there are security issues in the terminal application. The program behavior specification data comes from the program developer, provides the most comprehensive program behavior detection, significantly improves the accuracy of the application security detection results, and solves the technical problem of inaccurate application security detection results.
[0122] refer to Figure 4 , Figure 4 This is a flow chart of a third embodiment of an application security detection method of the present invention. Based on the above second embodiment, the application security detection method of this embodiment includes, in step S11:
[0123] Step S110: Acquire application development data.
[0124] It is easy to understand that the application development data may be normal behavior information of the application during the development phase, and may be provided by the program manufacturer or obtained in other ways, which is not limited in this embodiment.
[0125] Step S111: Process the application development data to obtain target application development data.
[0126] It should be noted that the application development data is processed to obtain target application development data, wherein the data processing process includes but is not limited to data cleaning, data obfuscation and other processing, and this embodiment does not limit this. This embodiment is illustrated with data cleaning and data obfuscation processing. For example: the application development data is cleaned according to a preset data cleaning algorithm to obtain the application development data to be processed; the performance indicator data sequence of the application development data is determined according to the performance indicator data characteristics; the application development data to be processed is subjected to data obfuscation processing according to the performance indicator data sequence to obtain the target application development data.
[0127] It should be understood that the connection rate time series of the application development data is obtained according to a preset data cleaning algorithm; the application development data is cleaned according to the connection rate time series to obtain the application development data to be processed. Specifically, the process of performing data cleaning on the application development data according to the connection rate time series to obtain the application development data to be processed can be: determining whether the connection rate time series is greater than a preset cleaning threshold; determining the application development data to be cleaned in the application development data whose connection rate time series is greater than the preset cleaning threshold; removing the application development data to be cleaned in the application development data to obtain the application development data to be processed.
[0128] It is easy to understand that the process of data fuzzification processing can be: obtaining developer behavior information based on the application development data to be processed; constructing a behavior frequency time series based on the developer behavior information; performing data fuzzification processing on the behavior frequency time series based on the performance indicator data series to obtain the target application development data. Specifically, the process of performing data fuzzification processing on the behavior frequency time series based on the performance indicator data series to obtain the target application development data can be: performing differential stabilization processing on the behavior frequency time series based on the performance indicator data series to obtain a stabilized behavior frequency time series; and constructing the target application development data based on the stabilized behavior frequency time series.
[0129] Step S112: determining program behavior specification data through a preset program behavior model according to the target application development data.
[0130] It should be noted that the preset program behavior model is a program behavior model based on machine learning. The preset program behavior model can be a machine learning model pre-set by the user according to actual needs. This embodiment does not limit the specific machine learning model. The target application development data is the normal behavior information of the application to be detected during the development stage. The program behavior specification data is determined by the preset program behavior model based on the target application development data.
[0131] Specifically, the program behavior specification data may include call interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information during the operation of the application to be detected. Among them, the call interface information may be Unix system call information or Mach system call information, the file system behavior information may include file system behavior information such as opening, reading, modifying, and creating, the network behavior information may include network behavior information such as TCP, HTTP, and DNS, the inter-process communication behavior information may include information such as the opened inter-process communication service and the called interface. Due to the differences in platforms, for example, the kernel on macOS also provides RPC services, and the driver behavior information may include opened drivers and called interfaces, etc. In addition, the program behavior specification data may also include other behavior information, which may be other than the above-mentioned call interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information, but other behaviors that are meaningful to security detection are not limited in this embodiment.
[0132] This embodiment obtains application development data; processes the application development data to obtain target application development data; and determines program behavior specification data based on the target application development data through a preset program behavior model. In this embodiment, the program behavior specification data and the current running data of the application are combined to detect whether there are security issues in the terminal application. The program behavior specification data comes from the program developer, provides the most comprehensive program behavior detection, significantly improves the accuracy of application security detection results, and solves the technical problem of inaccurate application security detection results in the existing technology.
[0133] In addition, an embodiment of the present invention further provides a storage medium, on which an application security detection program is stored, and the application security detection program is executed by a processor to perform the steps of the application security detection method described above.
[0134] Since the storage medium adopts all the technical solutions of all the above embodiments, it has at least all the beneficial effects brought by the technical solutions of the above embodiments, which will not be described one by one here.
[0135] Reference Figure 5 , Figure 5 This is a structural block diagram of the first embodiment of the safety detection device applied in the present invention.
[0136] like Figure 5 As shown, the application safety detection device of the embodiment of the present invention includes:
[0137] The determination module 10 is used to determine the application to be detected and the corresponding identification of the application to be detected according to the application security detection instruction when receiving the application security detection instruction from the user.
[0138] It should be understood that when receiving the user's application security detection instruction, it means that the user wants to perform a security detection on the application to be detected. Therefore, the application to be detected can be directly determined according to the application security detection instruction. In order to obtain the program behavior specification data corresponding to the application to be detected for security detection, the application identification corresponding to the application to be detected stored in advance can also be obtained, and then the program behavior specification data can be obtained through the application identification.
[0139] The acquisition module 20 is used to acquire corresponding program behavior specification data from a preset behavior data set according to the application identifier to be detected.
[0140] It is easy to understand that the preset behavior data set can be a data center, and the program behavior specification data is saved in the data center. When security detection is required through the program behavior specification data, the corresponding program behavior specification data can be obtained from the preset behavior data set according to the application identifier to be detected. Among them, the establishment of the data center can be based on a company or a country, etc., and this embodiment does not limit this.
[0141] It should be noted that the program behavior specification data may include call interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information during the operation of the application to be detected. Among them, the call interface information may be Unix system call information or Mach system call information, the file system behavior information may be file system behavior information such as opening, reading, modifying, and creating, the network behavior information may be network behavior information such as TCP, HTTP, and DNS, the inter-process communication behavior information may be information such as the opened inter-process communication service and the called interface. Due to the differences in platforms, for example, the kernel on macOS will also provide RPC services, and the driver behavior information may be the opened driver and the called interface. In addition, the program behavior specification data may also include other behavior information, which may be other than the above-mentioned call interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information, but other behaviors that are meaningful to security detection are not limited in this embodiment.
[0142] Specifically, the process of constructing a preset behavior data set may be: obtaining application development data, determining program behavior specification data based on the application development data; establishing a mapping relationship between the program behavior specification data and the corresponding application; generating an application identifier of the application based on the mapping relationship; and constructing a preset behavior data set based on the program behavior specification data and the application identifier. The application development data may be normal behavior information of the application during the development stage, which may be provided by the program manufacturer or obtained in other ways, and this embodiment does not limit this.
[0143] The calling module 30 is used to call the application to be detected and obtain the current running data of the application to be detected.
[0144] It should be noted that, the application to be detected is called to obtain the current running data of the application to be detected. In a specific implementation, the current running data of the application to be detected may include the calling interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information during the running process of the application to be detected. Among them, the calling interface information may be Unix system call information or Mach system call information, the file system behavior information may be file system behavior information such as opening, reading, modifying, and creating, the network behavior information may be network behavior information such as TCP, HTTP, and DNS, the inter-process communication behavior information may be information such as the opened inter-process communication service and the called interface. Due to the differences in platforms, for example, the kernel on macOS also provides RPC services, and the driver behavior information may be the opened driver and the called interface. In addition, the current running data may also include other behavior information, which may not be the above-mentioned calling interface information, file system behavior information, network behavior information, inter-process communication behavior information, and driver behavior information, but other behaviors that are meaningful to security detection, and this embodiment does not limit this.
[0145] Furthermore, considering that in actual applications, if the application to be detected is directly called to obtain the current running data of the application to be detected, it is bound to result in too few objects involved in behavior detection and low accuracy. To overcome this defect, when calling the application to be detected, the current installation information of the application to be detected is obtained, and it is determined whether the application to be detected is in the state to be detected based on the current installation information. When the application to be detected is in the state to be detected, behavior detection is performed according to the calling instruction to obtain the current running data.
[0146] The detection module 40 is used to perform application security detection on the application to be detected according to the program behavior specification data and the current running data.
[0147] It should be understood that the program behavior specification data is matched with the current running data to obtain a behavior matching result; the current running data is screened according to the behavior matching result to obtain abnormal behavior information; and application security detection is performed on the application to be detected based on the abnormal behavior information.
[0148] Specifically, the current running data can be matched with the program behavior specification data, and the obtained behavior matching result can be to determine the information similarity based on the current running data and the program behavior specification data, screen the current running data based on the information similarity, obtain abnormal behavior information, and determine whether the information similarity is greater than a preset threshold. When the information similarity is greater than the preset threshold, it is determined that the behavior information corresponding to the information similarity should not be screened out; when the information similarity is less than or equal to the preset threshold, it is determined that the behavior information corresponding to the information similarity should be screened out and is abnormal behavior information, and application security detection is performed on the application to be detected based on the abnormal behavior information, wherein the preset threshold can be a value preset by the user. The current running data and the program behavior specification data can be matched for: calling interface information, file system behavior information, network behavior information, inter-process communication behavior information, driver behavior information, and other behavior information.
[0149] It should be noted that, in order to further improve the accuracy of application security detection results, it can be achieved by combining the matching results of program behavior specification data with the detection results of blacklist detection, for example: matching the program behavior specification data with the current running data to obtain the running behavior matching results; matching the current running data with the attack behavior information in the preset blacklist to obtain the attack behavior matching results; screening the current running data according to the attack behavior matching results and the running behavior matching results to obtain abnormal behavior information; performing application security detection on the application to be detected according to the abnormal behavior information. Among them, the preset blacklist can be a traditional way of detecting attacks, and this embodiment does not limit this.
[0150] The present embodiment provides an application security detection device, which includes: a determination module 10, which is used to determine the application to be detected and the corresponding application identifier to be detected according to the application security detection instruction when receiving the application security detection instruction from the user; an acquisition module 20, which is used to obtain the corresponding program behavior specification data from the preset behavior data set according to the application identifier to be detected; a calling module 30, which is used to call the application to be detected and obtain the current running data of the application to be detected; and a detection module 40, which is used to perform application security detection on the application to be detected according to the program behavior specification data and the current running data. In the present embodiment, the program behavior specification data and the current running data of the application are combined to detect whether there are security issues in the terminal application. The program behavior specification data comes from the program developer, provides the most comprehensive program behavior detection, significantly improves the accuracy of the application security detection results, and solves the technical problem of inaccurate application security detection results in the existing.
[0151] In one embodiment, the application security detection device further includes: a generation module;
[0152] The generating module is used to obtain application development data and determine program behavior specification data according to the application development data;
[0153] Establishing a mapping relationship between the program behavior specification data and the corresponding application;
[0154] generating an application identifier of the application according to the mapping relationship;
[0155] A preset behavior data set is constructed according to the program behavior specification data and the application identifier.
[0156] In one embodiment, the generating module is further used to obtain application development data;
[0157] Processing the application development data to obtain target application development data;
[0158] The program behavior specification data is determined according to the target application development data through a preset program behavior model.
[0159] In one embodiment, the generating module is further used to clean the application development data according to a preset data cleaning algorithm to obtain the application development data to be processed;
[0160] Determining a performance indicator data sequence of the application development data according to the performance indicator data characteristics;
[0161] The application development data to be processed is subjected to data fuzzification processing according to the performance indicator data sequence to obtain target application development data.
[0162] In one embodiment, the generating module is further used to obtain a connection rate time series of the application development data according to a preset data cleaning algorithm;
[0163] The application development data is cleaned according to the connection rate time series to obtain the application development data to be processed.
[0164] In one embodiment, the generating module is further used to determine whether the connection rate time series is greater than a preset cleaning threshold;
[0165] Determine the application development data to be cleaned whose connection rate time series is greater than the preset cleaning threshold in the application development data;
[0166] The application development data to be cleaned is removed from the application development data to obtain the application development data to be processed.
[0167] In one embodiment, the generating module is further used to obtain developer behavior information according to the application development data to be processed;
[0168] Constructing a behavior frequency time series according to the developer behavior information;
[0169] The behavior frequency time series is subjected to data fuzzification processing according to the performance indicator data series to obtain target application development data.
[0170] In one embodiment, the generating module is further used to perform differential stabilization processing on the behavior frequency time series according to the performance indicator data series to obtain a stabilized behavior frequency time series;
[0171] Target application development data is constructed based on the stable behavior frequency time series.
[0172] In one embodiment, the generating module is further used to obtain the code development task of the application to be detected;
[0173] Obtaining code development activity information corresponding to the code development task;
[0174] Acquire code submission behavior data of the code development activity according to the development flow corresponding to the code development activity information;
[0175] The code submission behavior data is used as application development data.
[0176] In one embodiment, the generating module is further used to determine the current program development stage according to the code development task;
[0177] Matching the current program development stage with a preset program development stage;
[0178] When the current program development stage successfully matches the preset program development stage, a step of acquiring code development activity information corresponding to the code development task is performed.
[0179] In one embodiment, the detection module 40 is further used to match the program behavior specification data with the current running data to obtain a behavior matching result;
[0180] Filter the current operation data according to the behavior matching result to obtain abnormal behavior information;
[0181] An application security detection is performed on the application to be detected according to the abnormal behavior information.
[0182] In one embodiment, the detection module 40 is further used to
[0183] Matching the program behavior specification data with the current operation data to obtain an operation behavior matching result;
[0184] Matching the current running data with the attack behavior information in a preset blacklist to obtain an attack behavior matching result;
[0185] The current operation data is screened according to the attack behavior matching result and the operation behavior matching result to obtain abnormal behavior information;
[0186] An application security detection is performed on the application to be detected according to the abnormal behavior information.
[0187] Other embodiments or specific implementations of the application security detection device of the present invention may refer to the above-mentioned application security detection method embodiments, which will not be described in detail here.
[0188] It should be understood that the above is only an example and does not constitute any limitation on the technical solution of the present invention. In specific applications, technicians in this field can make settings as needed, and the present invention does not limit this.
[0189] It should be noted that the workflow described above is merely illustrative and does not limit the scope of protection of the present invention. In practical applications, technicians in this field can select part or all of them according to actual needs to achieve the purpose of the present embodiment, and no limitation is made here.
[0190] In addition, for technical details not fully described in this embodiment, reference can be made to the application security detection method provided in any embodiment of the present invention, and will not be repeated here.
[0191] In addition, it should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or system. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or system including the element.
[0192] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0193] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as a read-only memory (ROM) / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present invention.
[0194] The above are only preferred embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. An application security detection method, characterized in that: The application security detection method comprises: Get application development data; Clean the application development data according to a preset data cleaning algorithm to obtain the application development data to be processed; Determining a performance indicator data sequence of the application development data according to the performance indicator data characteristics; Performing data fuzzification processing on the application development data to be processed according to the performance indicator data sequence to obtain target application development data; Determining program behavior specification data through a preset program behavior model according to the target application development data; Establishing a mapping relationship between the program behavior specification data and the corresponding application; generating an application identifier of the application according to the mapping relationship; Constructing a preset behavior data set according to the program behavior specification data and the application identifier; Upon receiving an application security detection instruction from a user, determining an application to be detected and a corresponding application identifier to be detected according to the application security detection instruction; Acquire corresponding program behavior specification data from a preset behavior data set according to the application identifier to be detected; Calling the application to be detected to obtain current running data of the application to be detected; An application security check is performed on the application to be checked according to the program behavior specification data and the current running data.
2. The application security detection method according to claim 1, characterized in that: The step of performing data cleaning on the application development data according to a preset data cleaning algorithm to obtain the application development data to be processed includes: Obtaining a connection rate time series of the application development data according to a preset data cleaning algorithm; The application development data is cleaned according to the connection rate time series to obtain the application development data to be processed.
3. The application security detection method according to claim 2, characterized in that: The step of performing data cleaning on the application development data according to the connection rate time series to obtain the application development data to be processed comprises: Determine whether the connection rate time series is greater than a preset cleaning threshold; Determine the application development data to be cleaned whose connection rate time series is greater than the preset cleaning threshold in the application development data; The application development data to be cleaned is removed from the application development data to obtain the application development data to be processed.
4. The application security detection method according to claim 1, characterized in that: The step of performing data fuzzification processing on the application development data to be processed according to the performance indicator data sequence to obtain target application development data comprises: Acquiring developer behavior information according to the application development data to be processed; Constructing a behavior frequency time series according to the developer behavior information; The behavior frequency time series is subjected to data fuzzification processing according to the performance indicator data series to obtain target application development data.
5. The application security detection method according to claim 4, characterized in that: The step of performing data fuzzification processing on the behavior frequency time series according to the performance indicator data series to obtain target application development data includes: Performing differential stabilization processing on the behavior frequency time series according to the performance indicator data series to obtain a stabilized behavior frequency time series; Target application development data is constructed based on the stable behavior frequency time series.
6. The application security detection method according to claim 1, characterized in that: Before the step of obtaining the application development data and determining the program behavior specification data according to the application development data, the method further includes: Obtaining a code development task for the application to be detected; Obtaining code development activity information corresponding to the code development task; Acquire code submission behavior data of the code development activity according to the development flow corresponding to the code development activity information; The code submission behavior data is used as application development data.
7. The application security detection method according to claim 6, characterized in that: After the step of obtaining the code development task of the application to be detected, the method further includes: Determining the current program development stage according to the code development task; Matching the current program development stage with a preset program development stage; When the current program development stage successfully matches the preset program development stage, a step of acquiring code development activity information corresponding to the code development task is performed.
8. The application security detection method according to any one of claims 1 to 7, characterized in that: The step of performing application security detection on the application to be detected according to the program behavior specification data and the current running data includes: Matching the program behavior specification data with the current running data to obtain a behavior matching result; Filter the current operation data according to the behavior matching result to obtain abnormal behavior information; An application security detection is performed on the application to be detected according to the abnormal behavior information.
9. The application security detection method according to any one of claims 1 to 7, characterized in that: The step of performing application security detection on the application to be detected according to the program behavior specification data and the current running data includes: Matching the program behavior specification data with the current operation data to obtain an operation behavior matching result; Matching the current running data with the attack behavior information in a preset blacklist to obtain an attack behavior matching result; The current operation data is screened according to the attack behavior matching result and the operation behavior matching result to obtain abnormal behavior information; An application security detection is performed on the application to be detected according to the abnormal behavior information.
10. An application security detection device, characterized in that: The application security detection device comprises: A generation module is used to obtain application development data; clean the application development data according to a preset data cleaning algorithm to obtain the application development data to be processed; determine the performance indicator data sequence of the application development data according to the performance indicator data characteristics; perform data fuzzification processing on the application development data to be processed according to the performance indicator data sequence to obtain target application development data; determine program behavior specification data through a preset program behavior model according to the target application development data; establish a mapping relationship between the program behavior specification data and the corresponding application; generate an application identifier of the application according to the mapping relationship; and construct a preset behavior data set according to the program behavior specification data and the application identifier; The determination module is further configured to determine the application to be detected and the corresponding identification of the application to be detected according to the application security detection instruction when receiving the application security detection instruction from the user; An acquisition module, configured to acquire corresponding program behavior specification data from a preset behavior data set according to the application identifier to be detected; A calling module, used for calling the application to be detected and obtaining the current running data of the application to be detected; The detection module is used to perform application security detection on the application to be detected according to the program behavior specification data and the current running data.
11. The application security detection device according to claim 10, characterized in that: The generating module is further used to obtain the connection rate time series of the application development data according to a preset data cleaning algorithm; The application development data is cleaned according to the connection rate time series to obtain the application development data to be processed.
12. The application security detection device according to claim 11, characterized in that: The generating module is further used to determine whether the connection rate time series is greater than a preset cleaning threshold; Determine the application development data to be cleaned whose connection rate time series is greater than the preset cleaning threshold in the application development data; The application development data to be cleaned is removed from the application development data to obtain the application development data to be processed.
13. An application security detection device, characterized in that: The application security detection device comprises: a memory, a processor, and an application security detection program stored in the memory and executable on the processor, wherein the application security detection program is configured with steps for implementing the application security detection method according to any one of claims 1 to 9.
14. A storage medium, characterized in that: The storage medium stores an application security detection program, which, when executed by a processor, implements the steps of the application security detection method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Mobile terminal application abnormity detection method, storage device and mobile terminal
CN107517308A
Hardened event counters for anomaly detection
CN108027860A