Application detection system and method, electronic equipment and computer program product

Through a modular application detection system, utilizing task management, business background and detection modules, combined with a variety of detection configuration units, the problems of difficult operation, low applicability and inaccurate detection in existing technologies are solved, and efficient and accurate application detection is achieved, especially the security detection of hot update applications.

CN120654230APending Publication Date: 2025-09-16TENCENT TECH (BEIJING) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410302284.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-15
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing application detection technology requires intrusion into the application, which is difficult to operate, has low reusability, is not applicable to third-party applications, has a long training cycle when relying on manual detection, and cannot detect security risks during hot updates.

Method used

A modular application detection system is adopted, including a task management module, a business background module and a detection module. The detection tasks are orchestrated through a workflow engine, and multiple detection configuration units are used to perform security detection on the application, including basic detection, hot update detection, simulated manual operation detection, area and time period detection, deep random detection and page frame detection, etc., and the detection results are automatically output.

Benefits of technology

It achieves efficient and accurate detection of applications, improves the accuracy and real-time performance of detection results, has strong adaptability, is suitable for various applications, especially hot update applications, and reduces operational difficulty and training cycle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120654230A_ABST
    Figure CN120654230A_ABST
Patent Text Reader

Abstract

The invention provides an application detection system and method, electronic equipment and a computer program product. The application detection system comprises a task management module, a service background module and a detection module, wherein the task management module is used for performing task management on a to-be-detected application to obtain a detection task of the to-be-detected application; the business background module is used for performing business process arrangement on the detection task by calling a workflow engine to obtain a detection starting request of the detection task; and receiving a detection result list of the to-be-detected application, and performing detection result management on the detection result list to obtain a detection result, the detection module is used for responding to the detection starting request, and performing detection operation on each security detection item of the detection task through a plurality of detection configuration units to obtain a detection result list. Through the application, the to-be-detected application can be effectively detected, and the accuracy of the detection result is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet technology, and in particular to an application detection system, method, electronic device, and computer program product. Background Art

[0002] Application detection technology is mainly used to analyze and detect security flaws or vulnerabilities in applications in order to discover security risks in the applications. Among related technologies, some application detection technologies require intrusion into the application, which makes the operation difficult and has low reusability; some application detection technologies require obtaining the source files of the application, resulting in a very narrow scope of application and basically not applicable to third-party applications. If manual detection is relied upon, it is often closely related to the quality and experience of the operators, resulting in a long training cycle. In addition, some applications use hot updates, and unsafe content may appear during the use of the application. These unsafe contents are difficult to detect through conventional application detection technology. Therefore, the application detection methods in related technologies cannot obtain accurate application detection results. Summary of the Invention

[0003] The embodiments of the present application provide an application detection system, method, electronic device, and computer program product, which can effectively detect the application to be detected and improve the accuracy of the detection results.

[0004] The technical solution of the embodiment of the present application is implemented as follows:

[0005] An embodiment of the present application provides an application detection system, the system comprising: a task management module, a business background module, and a detection module; wherein: the task management module is used to perform task management on an application to be detected, obtain a detection task for the application to be detected, and send the detection task to the business background module; and receive a detection result of the application to be detected sent by the business background module, and display the detection result; the detection task includes at least one security detection item; the business background module is used to perform business process orchestration on the detection task by calling a workflow engine, obtain a detection start request for the detection task, and send the detection start request to the detection module; and receive a detection result list of the application to be detected sent by the detection module, perform detection result management on the detection result list, obtain the detection result, and then send the detection result to the task management module; the detection module includes multiple detection configuration units for executing different security detection items; the multiple detection configuration units are used to perform detection operations on each security detection item of the detection task in response to the detection start request, obtain the detection result list, and send the detection result list to the business background module.

[0006] In some embodiments, the task management module is also used to: obtain basic detection information of the application to be detected; determine the security detection items of the application to be detected based on the detection item list of the application detection system; obtain task execution information of the security detection items; and determine the detection task of the application to be detected based on the basic detection information, the security detection items and the task execution information.

[0007] In some embodiments, the task management module is also used to: update the task status of the detection task based on the detection result; when the detection result is safe, update the task status of the detection task from the to-be-detected state to the safe state; when the detection result is unsafe, update the task status of the detection task from the to-be-detected state to the unsafe state.

[0008] In some embodiments, the business background module is also used to: obtain multiple safety detection items in the detection task; determine the execution order of the multiple safety detection items based on the task execution information in the detection task; and generate a detection start request for the detection task based on the multiple safety detection items and the execution order.

[0009] In some embodiments, the detection module is used to: in response to the detection start request, obtain the data to be detected and the execution order corresponding to each security detection item; call the detection configuration unit in sequence according to the execution order, and input the data to be detected into the corresponding detection configuration unit; through the detection configuration unit, perform security detection on the data to be detected to obtain the detection result list.

[0010] In some embodiments, the security detection items include basic detection items, the data to be detected includes basic detection data, and the detection configuration unit includes a basic detection configuration unit; the detection module is also used to: obtain the basic detection data of the application to be detected in response to the detection start request; and perform verification and detection on the basic detection data through the basic detection configuration unit to obtain the verification and detection results corresponding to the basic detection items.

[0011] In some embodiments, the security detection item includes a hot update detection item, the data to be detected includes application execution data, and the detection configuration unit includes a hot update detection configuration unit; the detection module is also used to: obtain the application execution data of the application to be detected in response to the detection start request; and determine the hot update detection result corresponding to the hot update detection item based on a preset application execution threshold through the hot update detection configuration unit.

[0012] In some embodiments, the security detection item includes a simulated manual operation detection item, the data to be detected includes an application page, and the detection configuration unit includes a simulated manual detection configuration unit; the detection module is also used to: obtain the application page of the application to be detected in response to the detection start request; obtain the operable elements of the application page; through the simulated manual detection configuration unit, use a preset detection operation to perform content detection on the operable elements to obtain a content detection result corresponding to the simulated manual operation detection item.

[0013] In some embodiments, the security detection project also includes a region and time period detection project, and the detection configuration unit also includes a region and time period detection configuration unit; the detection module is also used to: in response to the detection start request, obtain the application page of the application to be detected; divide the application page into regions according to a preset number of region divisions to obtain multiple block areas of the application page; for each block area, determine the regional detection priority of the block area according to the application type of the application to be detected; through the region and time period detection configuration unit, according to the regional detection priority, perform regional detection on the block area within the preset detection time period to obtain the regional detection result corresponding to the region and time period detection project.

[0014] In some embodiments, the security detection item also includes a deep random detection item, the page level number of the application page is N, the detection configuration unit also includes a deep random detection configuration unit, and N is an integer greater than 1; the detection module is also used to: for the i-th level page in the application page, through the deep random detection configuration unit, perform the content detection and the area detection on the i-th level page in sequence to obtain the content detection result and the area detection result of the i-th level page, i is an integer greater than 0 and less than N; when the content detection result and the area detection result of the i-th level page indicate that the detection result of the application to be detected is safe, and the i+1-th level page is a new page, the content detection and the area detection are performed on the i+1-th level page in sequence through the deep random detection configuration unit to obtain the content detection result and the area detection result of the i+1-th level page; when any one of the content detection result and the area detection result of the i+1-th level page indicates that the detection result of the application to be detected is unsafe, or when the i+1-th level page is not a new page, end the detection task.

[0015] In some embodiments, the security detection project also includes a page frame detection project, the data to be detected also includes page frame data and a historical click path tree, and the detection configuration unit also includes a page frame detection configuration unit; the detection module is also used to: in response to the detection start request, obtain the page frame data of the application to be detected; based on the page frame data, determine the current tree feature corresponding to the hierarchical tree of each level of the page; for each current tree feature, perform similarity calculation on the current tree feature and the historical tree feature to obtain a similarity result; the historical tree feature is a tree feature before the current moment and the frame detection result corresponding to the page frame detection project indicates that the detection result of the application to be detected is safe; based on the similarity result and a preset similarity threshold, determine the similarity comparison result; when the similarity comparison result indicates that the detection result of the application to be detected is safe, obtain the historical click path tree of the application to be detected; through the page frame detection configuration unit, perform a click operation on the historical click path in the historical click path tree to obtain a click operation result; based on the click operation result, determine the frame detection result corresponding to the page frame detection project.

[0016] In some embodiments, the security detection item includes a specific page identification item, the data to be detected includes a specific page, and the detection configuration unit includes a specific page detection configuration unit; the detection module is also used to: obtain the specific page of the application to be detected in response to the detection start request; determine the identification method of the specific page according to the page type of the specific page; based on the identification method, identify and detect the specific page through the specific page detection configuration unit to obtain the identification detection result corresponding to the specific page identification item.

[0017] An embodiment of the present application provides an application detection method, which includes: performing task management on an application to be detected to obtain a detection task for the application to be detected; calling a workflow engine to perform business process orchestration on the detection task to obtain a detection start request for the detection task; in response to the detection start request, performing detection operations on each security detection item of the detection task to obtain a corresponding detection result list for the detection task; performing detection result management on the detection result list to obtain a detection result of the application to be detected.

[0018] An embodiment of the present application provides an electronic device, comprising: a memory for storing computer-executable instructions; and a processor for implementing the application detection method provided in the embodiment of the present application when executing the computer-executable instructions stored in the memory.

[0019] An embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions for implementing the application detection method provided in the embodiment of the present application when executed by a processor.

[0020] An embodiment of the present application provides a computer program product, which includes computer-executable instructions, which are stored in a computer-readable storage medium; wherein, when a processor of an electronic device reads the computer-executable instructions from the computer-readable storage medium and executes the computer-executable instructions, the application detection method provided in the embodiment of the present application is implemented.

[0021] The embodiment of the present application has the following beneficial effects: first, a detection task of the application to be detected is generated through the task management module, and the detection task is sent to the business background module; then, a detection start request of the detection application is generated through the business background module, and the detection start request is sent to the detection module; finally, a plurality of detection configuration units in the detection module are used to perform security detection on the data to be detected, and a list of detection results is obtained, and the list of detection results is sent to the business background module, and the detection results of the application to be detected are obtained through the business background module, and the results are displayed in the task management module. In this way, the task management module, the business background module and the detection module together constitute a complete application detection system. In the application detection process of the application detection system, the various modules are interconnected and coordinated with each other to jointly realize the modular deployment of the application detection system, and through the application detection system, the detection configuration units are comprehensively used to perform batch detection on the detection tasks, so as to realize effective detection of the application to be detected, thereby obtaining accurate detection results. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 This is a schematic diagram of the application detection system architecture provided by an embodiment of the present application;

[0023] Figure 2 is a structural diagram of an application detection system provided in an embodiment of the present application;

[0024] Figure 3 Schematic diagram of the application detection method provided in the embodiment of the present application;

[0025] Figure 4 This is a flow chart of obtaining test results using an application detection system according to an embodiment of the present application;

[0026] Figure 5 This is a schematic diagram of the detection process after the system container deployment provided by the embodiment of the present application;

[0027] Figure 6 This is a flowchart of the task management module provided in the embodiment of the present application;

[0028] Figure 7 This is a flow chart of the business backend module provided in the embodiment of the present application;

[0029] Figure 8 This is a flow chart of the detection process by region and time period provided in the embodiment of the present application;

[0030] Figure 9 This is a flowchart of the deep random detection provided by the embodiment of the present application;

[0031] Figure 10 This is a flow chart of page frame detection provided in an embodiment of the present application. DETAILED DESCRIPTION

[0032] In order to make the purpose, technical solutions and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limiting this application. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0033] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0034] If similar descriptions of "first / second" appear in the application documents, the following explanation is added. In the following description, the terms "first\second\third" involved are merely used to distinguish similar objects and do not represent a specific order for the objects. It can be understood that "first\second\third" can be interchanged with a specific order or sequence where permitted, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0035] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program that has a predetermined function and works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as processing circuits or memories) or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the function of the module or unit.

[0036] Unless otherwise defined, all technical and scientific terms used in the embodiments of the present application have the same meanings as those commonly understood by those skilled in the art. The terms used in the embodiments of the present application are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.

[0037] The relevant data collection and processing in the embodiments of this application should be strictly in accordance with the requirements of relevant national laws and regulations when applied in examples, and the informed consent or separate consent of the personal information subject should be obtained. Subsequent data use and processing should be carried out within the scope of authorization of laws and regulations and the personal information subject.

[0038] In related technologies, application testing is generally performed through application detection techniques such as basic information detection, static detection, vulnerability scanning, penetration testing, and code auditing, or through experienced manual detection methods. However, some application detection techniques require intrusion into the application, making operation difficult and reusable. Some application detection techniques require access to the application's source files, resulting in a very narrow scope of application and being essentially unsuitable for third-party applications. Using experienced manual detection methods is often closely related to the operator's qualifications and experience, resulting in a long training cycle. Furthermore, some applications utilize hot updates, which may introduce unsafe content during application use. This unsafe content is difficult to detect using conventional application detection techniques, making accurate application detection results impossible.

[0039] Based on at least one of the above technical problems existing in the related art, the embodiments of the present application propose a systematic solution. This solution modularly deploys the application detection system and comprehensively applies application detection technologies to batch execute detection tasks and automatically output the detection results of the applications to be detected. In summary, the embodiments of the present application have obvious advantages in detection accuracy, real-time performance, and adaptability, providing developers with an efficient, accurate, and real-time application detection solution.

[0040] The following describes exemplary applications of the application detection device (i.e., electronic device) provided in the embodiments of the present application. The device provided in the embodiments of the present application can be implemented as various types of user terminals capable of data processing or application detection, such as laptops, tablet computers, desktop computers, set-top boxes, mobile devices (e.g., mobile phones, portable music players, personal digital assistants, dedicated messaging devices, portable gaming devices), smart phones, smart speakers, smart watches, smart TVs, and vehicle-mounted terminals, and can also be implemented as servers.

[0041] See also Figure 1 , Figure 1This is a schematic diagram of the architecture of an application detection system 455 provided in an embodiment of the present application. To support an application detection application, a task management module 4551 is used to manage tasks for the application to be detected, obtain detection tasks for the application to be detected, and send the detection tasks to a business backend module 4552. After receiving the detection tasks, the business backend module 4552 calls a workflow engine to orchestrate the detection tasks, obtain a detection start request for the detection tasks, and send the detection start request to a detection module 4553. The detection module 4553 includes multiple detection configuration units for executing different security detection items. The multiple detection configuration units are used to respond to the detection start request and perform detection operations on each security detection item of the detection task, obtain a detection result list, and send the detection result list to the business backend module 4552. After receiving the detection result list, the business backend module 4552 manages the detection result list, obtains the detection results, and then sends the detection results to the task management module 4551. After obtaining the detection results, the task management module 4551 displays the detection results.

[0042] See also Figure 2 , Figure 2 is a schematic structural diagram of an electronic device 40 provided in an embodiment of the present application, Figure 2 The electronic device 40 shown may be an application detection device, which includes: at least one processor 410, a memory 450, at least one network interface 420, and a user interface 430. The various components in the application detection device are coupled together via a bus system 440. It is understood that the bus system 440 is used to achieve connection and communication between these components. In addition to the data bus, the bus system 440 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, the bus system 440 is not shown in FIG. Figure 2 Various buses are labeled as bus system 440 .

[0043] The processor 410 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., where the general-purpose processor can be a microprocessor or any conventional processor, etc.

[0044] The user interface 430 includes one or more output devices 431 that enable presentation of media content, including one or more speakers and / or one or more visual display screens. The user interface 430 also includes one or more input devices 432, including user interface components that facilitate user input, such as a keyboard, mouse, microphone, touch screen display, camera, other input buttons and controls.

[0045] The memory 450 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard drives, optical drives, etc. The memory 450 may optionally include one or more storage devices that are physically remote from the processor 410.

[0046] The memory 450 includes volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be a read-only memory (ROM), and the volatile memory may be a random access memory (RAM). The memory 450 described in the embodiments of the present application is intended to include any suitable type of memory.

[0047] In some embodiments, the memory 450 can store data to support various operations, examples of which include programs, modules, and data structures, or a subset or superset thereof, as exemplified below.

[0048] Operating system 451, including system programs for processing various basic system services and performing hardware-related tasks, such as the framework layer, core library layer, and driver layer, which are used to implement various basic services and process hardware-based tasks;

[0049] A network communication module 452 is used to reach other electronic devices via one or more (wired or wireless) network interfaces 420. Exemplary network interfaces 420 include Bluetooth, Wi-Fi, and Universal Serial Bus (USB);

[0050] a presentation module 453 for enabling presentation of information via one or more output devices 431 (e.g., a display screen, a speaker, etc.) associated with the user interface 430 (e.g., a user interface for operating peripheral devices and displaying content and information);

[0051] The input processing module 454 is configured to detect one or more user inputs or interactions from one of the one or more input devices 432 and to translate the detected inputs or interactions.

[0052] In some embodiments, the system provided by the embodiments of the present application can be implemented in software. Figure 2An application detection system 455 stored in memory 450 is shown. This system can be software in the form of a program or plug-in, and includes the following software modules: a task management module 4551, a business backend module 4552, and a detection module 4553. These modules are logical and can be arbitrarily combined or further separated according to the functions they implement. The functions of each module will be described below.

[0053] In other embodiments, the system provided in the embodiments of the present application can be implemented in hardware. As an example, the system provided in the embodiments of the present application can be a processor in the form of a hardware decoding processor, which is programmed to execute the application detection method provided in the embodiments of the present application. For example, the processor in the form of a hardware decoding processor can adopt one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs) or other electronic components.

[0054] In some embodiments, the terminal or server can implement the application detection method provided by the embodiment of the present application by running various computer executable instructions or computer programs. For example, computer executable instructions can be commands, machine instructions or software instructions at the microprogram level. The computer program can be a native program or software module in the operating system; it can be a local (Native) application (Application, APP), that is, a program that needs to be installed in the operating system to run, or it can be a small program that can be embedded in any APP, that is, a program that only needs to be downloaded to a browser environment to run. In short, the above-mentioned computer executable instructions can be instructions in any form, and the above-mentioned computer program can be an application, module or plug-in in any form.

[0055] The application detection method provided in each embodiment of the present application can be executed by an electronic device, wherein the electronic device can be a server or a terminal, that is, the application detection method provided in each embodiment of the present application can be executed by a server, or by a terminal, or by interaction between a server and a terminal.

[0056] See also Figure 3 , Figure 3: This is a flow chart of the application detection method provided in the embodiment of the present application. The application detection method can be implemented by an application detection system. The following will describe the application detection method in the embodiment of the present application in conjunction with the interaction between the task management module, the business background module, and the detection module in the application detection system. It should be noted that the application detection method here is an application detection method implemented by the interaction between the task management module, the business background module, and the detection module, and the method includes the following steps S201 to S209:

[0057] Step S201 : The task management module receives an application to be detected input by a user, performs task management on the application to be detected, and obtains a detection task for the application to be detected.

[0058] In an embodiment of the present application, a user can enter an application to be detected in the task management module of the application detection application. The application detection application may provide an application detection function. The user can enter the application to be detected on the application detection function page to trigger the task management module to perform task management on the application to be detected. The task management module is used to manage tasks in the application to be detected. Through task management operations, detection tasks for the application to be detected are generated. The application to be detected is an application that requires certain application detection technology to identify non-expected behavior.

[0059] In some embodiments, task management of the application to be detected can be achieved in the following ways: obtaining basic detection information of the application to be detected; determining the security detection items of the application to be detected based on the detection item list of the application detection system; obtaining task execution information of the security detection items; and determining the detection task of the application to be detected based on the basic detection information, security detection items and task execution information.

[0060] The basic detection information can include the application name, icon, package name, download address, etc. of the application to be detected, or it can be the task name of a preset detection task. The detection item list includes the detection items for all application detection functions that the application detection system can provide, that is, each detection item in the detection item list corresponds to a different application detection function. The task management module can automatically select the detection items required for the application to be detected based on the application type or application detection requirements of the application to be detected, that is, obtain the security detection items of the application to be detected. The number of security detection items can be multiple, for example, the security detection items can include hot update detection, random depth detection, page frame detection, etc. The task execution information of the security detection item includes the detection start time, detection end time, and detection frequency of the security detection item. Based on the basic detection information, security detection items, and task execution information, the detection task of the application to be detected can be determined, that is, the detection task includes the basic detection information, security detection items, and task execution information. After the detection task for the application to be detected is generated in the task management module, the task management module can submit the detection task to the business background module, and further generate a detection start request in the business background module.

[0061] In some embodiments, the task management module can also update the task status of the detection task based on the detection result; when the detection result is safe, the task status of the detection task is updated from the to-be-detected state to the safe state; when the detection result is unsafe, the task status of the detection task is updated from the to-be-detected state to the unsafe state.

[0062] That is to say, the task management module is also used to receive the detection results sent by the business background module. After the task management module receives the detection results, the task status of the detection task can be updated according to the detection results through the task status update function of the task management module. The detection results include safe and unsafe, which correspond to the two situations of application safety and application insecurity of the application to be detected. After the detection task is generated and before the detection result is obtained, the detection status of the detection task is the state to be detected. If the detection result of the application to be detected is safe, then in the task management module, the task status of the detection task is updated from the state to be detected to the safe state; if the detection result of the application to be detected is unsafe, then in the task management module, the task status of the detection task is updated from the state to be detected to the unsafe state. Through the task status update function in the task management module, the task status of the detection task can be updated in real time.

[0063] In other embodiments, the task management module can be a user interface module for human-computer interaction. Through the task management module, the user can submit, pause, delete, and other operations on the detection task. The user can also intuitively and in real time view the detection progress of the detection task, view the detection results of the application to be detected, etc.

[0064] Step S202: The task management module sends the detection task to the business background module.

[0065] In step S203, the business background module orchestrates the business process of the detection task by calling the workflow engine, and obtains a detection start request for the detection task.

[0066] In an embodiment of the present application, business process orchestration for a detection task can be achieved in the following manner: obtaining multiple security detection items in the detection task; then, determining the execution order of the multiple security detection items based on the task execution information in the detection task; and finally, generating a detection start request for the detection task based on the multiple security detection items and the execution order.

[0067] The business background module is used to arrange the business process of the detection task to ensure that the safety detection items in the detection task can be carried out smoothly according to the corresponding execution order. After the business background module receives the detection task sent by the task management module, it can obtain the multiple safety detection items in the detection task and the task execution information of the safety detection items, and generate the execution order of the multiple safety detection items according to the detection start time, detection end time, and detection frequency in the task execution information. The multiple safety detection items can be executed sequentially according to time or concurrently. The business background module can generate a detection start request for the detection task based on the multiple safety detection items and the execution order, that is, encapsulate the multiple safety detection items and the execution order together into the detection start request.

[0068] In addition, the application detection system also includes a storage module, which stores all data related to the detection task. After the business background module obtains multiple security detection items in the detection task, it can obtain the data to be detected corresponding to each security detection item from the storage module and encapsulate the data to be detected into the detection start request.

[0069] In other embodiments, the business backend module can also determine whether the current detection task is a detection task to be executed based on the task execution information. If the current detection task is an expired detection task or a detection task that has been completed, the detection task will be deleted from the detection task pool; if the current detection task is a detection task that does not need to be executed, the detection task will be placed back into the detection task pool and the business process orchestration operation will be performed when the detection task needs to be executed.

[0070] Here, when a detection start request is generated in the business background module, the business background module will also send the detection start request to the detection module, so that the subsequent detection module can respond to the detection start request and implement the detection operation of the detection task.

[0071] Step S204: The business background module sends a detection start request to the detection module.

[0072] In step S205 , the detection module responds to the detection start request and performs detection operations on each safety detection item of the detection task through multiple detection configuration units to obtain a detection result list.

[0073] In an embodiment of the present application, multiple detection configuration units are used to perform detection operations on each safety detection item of the detection task, which can be achieved in the following way: in response to a detection start request, the data to be detected and the execution order corresponding to each safety detection item are obtained; then, according to the execution order, the detection configuration units are called in sequence, and the data to be detected are input into the corresponding detection configuration units; finally, the detection configuration units are used to perform security detection on the data to be detected to obtain a list of detection results.

[0074] The detection module is a module for performing safety detection on the detection task of the application to be detected in the application detection system, and includes a plurality of detection configuration units for executing different safety detection items, that is, each different safety detection item corresponds to a different detection configuration unit. Each detection configuration unit in the plurality of detection configuration units is used to respond to a detection start request, and perform detection operations on each safety detection item of the detection task respectively, to obtain a list of detection results. If the detection start request encapsulates the data to be detected and the execution order corresponding to each safety detection item, the detection start request can be directly parsed to obtain the data to be detected and the execution order corresponding to each safety detection item. According to the execution order, multiple detection configuration units are called in sequence, and data is input to each detection configuration unit, that is, the data to be detected is subjected to safety detection, and the detection result data output by the plurality of detection configuration units is obtained, that is, a list of detection results is obtained.

[0075] Here, the detection module obtains the detection result list of the application to be detected, so that the subsequent detection module returns the detection result list to the business background module, and the business background module determines the final detection result of the application to be detected.

[0076] In some embodiments, the security detection project includes a basic detection project, the data to be detected includes basic detection data, and the detection configuration unit includes a basic detection configuration unit. The basic detection project is one of the detection projects in the security detection project, and is used to detect the basic detection data of the application to be detected. Therefore, for the basic detection project, the basic detection configuration unit in the detection module can be called to detect the basic detection data of the application to be detected. The detection process can be implemented in the following manner: the detection module obtains the basic detection data of the application to be detected in response to the detection start request; the basic detection data is verified and detected by the basic detection configuration unit to obtain the verification detection result corresponding to the basic detection project.

[0077] The basic detection data can be basic information related to the application to be detected, such as application name, package name, application version, application permissions, application code, etc. The verification detection result is used to characterize whether the detection result of the application to be detected is safe or unsafe, and the verification detection result can be a part of the above-mentioned detection result list. When the security detection item includes a basic detection item, the basic detection data corresponding to the basic detection item is encapsulated in the detection start request, and the basic detection data of the application to be detected can be directly parsed. Through the verification detection function of the basic detection configuration unit, the basic detection data is verified and detected to obtain the verification detection results corresponding to the basic detection item. For example, by scanning the URL related to the application to be detected in the basic detection data, analyzing the application code and resource files, it is determined whether the application to be detected has security risks.

[0078] In some embodiments, the security detection project includes a hot update detection project, the data to be detected includes application execution data, and the detection configuration unit includes a hot update detection configuration unit. The hot update detection project is one of the detection projects in the security detection project. The hot update detection project mainly targets the application execution data generated during the hot update process. During the detection process, the application execution data of the application to be detected can be detected. Therefore, for the hot update detection project, the hot update detection configuration unit in the detection module can be called to detect the application execution data of the application to be detected. The detection process can be implemented in the following way: the detection module obtains the application execution data of the application to be detected in response to the detection start request; through the hot update detection configuration unit, based on the preset application execution threshold, the hot update detection result corresponding to the hot update detection project is determined.

[0079] Hot updates are a common update method used by application developers. After downloading and installing an app, users can instantly update the app when they open it. To update, users only need to download and install the updated application code, then open the app again. Some application security vulnerabilities may be caused by modifying the application through hot updates after submitting a valid application code version. Therefore, a hot update detection configuration unit is required to perform security checks on the application execution data of the application to be tested, generating hot update detection results corresponding to the hot update detection items.

[0080] The hot update detection result is used to characterize whether the detection result of the application to be detected is safe or unsafe, and the hot update detection result can also be part of the above-mentioned detection result list. When the security detection item includes the hot update detection item, the application execution data corresponding to the hot update detection item is encapsulated in the detection startup request, and the application execution data of the application to be detected can be directly parsed. The application execution data can be the number of application startups, the number of files generated and the generation time corresponding to the application code, etc. The preset application execution threshold is used to determine whether the application execution data is related to abnormal operations outside the plan of the application to be detected. The hot update detection result is determined by comparing the application execution data with the preset application execution threshold. Here, through the detection process of the application execution data generated during the hot update process by the hot update detection configuration unit in the detection module, it can be determined whether the application execution data is related to abnormal operations outside the plan of the application to be detected, thereby effectively detecting unsafe content that may appear in the hot update of the application to be detected.

[0081] In some embodiments, the security detection project includes a simulated manual operation detection project, the data to be detected includes an application page, and the detection configuration unit includes a simulated manual detection configuration unit. The simulated manual operation detection project is one of the detection projects in the security detection project. The simulated manual operation detection project mainly targets the operable elements of the application page. During the detection process, the operable elements of the application page can be detected. Therefore, for the simulated manual operation detection project, the simulated manual detection configuration unit in the detection module can be called to detect the application page of the application to be detected. The detection process can be implemented in the following way: the detection module obtains the application page of the application to be detected in response to the detection start request; obtains the operable elements of the application page; through the simulated manual detection configuration unit, a preset detection operation is used to perform content detection on the operable elements, and a content detection result corresponding to the simulated manual operation detection project is obtained. When the security detection project includes the simulated manual operation detection project, the detection start request encapsulates the application page corresponding to the simulated manual operation detection project, and the application page of the application to be detected can be directly parsed. The operable elements of an application page may be clickable elements, slidable elements, inputtable elements, etc. The preset detection operation is the detection operation corresponding to the operable element, which is pre-set in the application detection system and can be updated based on actual detection conditions. For example, the preset detection operation may be multiple clicks on a clickable element on the application page, or it may be entering special text into an inputtable element on the application page. The special text may be a portion of text randomly selected from a special text table in the application detection system.

[0082] In the application pages of some applications to be tested, by simulating a manual detection configuration unit, a preset detection operation is used to perform content detection on the operable elements. For applications to be tested that have a safe detection result, no unsafe content will appear on the application page after the content detection; however, for applications to be tested that have a safe detection result, abnormal pages or abnormal content may pop up on the application page after the content detection. These are all unsafe content of the application to be tested, that is, the content detection result corresponding to the simulated manual operation detection item is obtained. The content detection result is used to characterize whether the detection result of the application to be tested is safe or unsafe, and the content detection result can also be part of the above-mentioned detection result list.

[0083] In some embodiments, the security detection project also includes a region-by-region and time-period detection project, the data to be detected includes an application page, and the detection configuration unit also includes a region-by-region and time-period detection configuration unit. The region-by-region and time-period detection project is one of the detection projects in the security detection project. The region-by-region and time-period detection project is mainly aimed at different areas and different time periods of the application page. During the detection process, a detection can be performed on a certain time period of a certain area of ​​the application page. Therefore, for the region-by-region and time-period detection project, the region-by-region and time-period detection configuration unit in the detection module can be called to detect the application page of the application to be detected. The detection process can be implemented in the following way: the detection module obtains the application page of the application to be detected in response to the detection start request; the application page is divided into regions according to a preset number of regional divisions to obtain a plurality of block regions of the application page; for each block region, the regional detection priority of the block region is determined according to the application type of the application to be detected; through the region-by-region and time-period detection configuration unit, the block region is regionally detected within the preset detection time period according to the regional detection priority, and the regional detection result corresponding to the region-by-region and time-period detection project is obtained.

[0084] When security testing includes regional and time-segment testing, the test initiation request encapsulates the corresponding application page for the regional and time-segment testing item. This allows direct parsing to obtain the application page for the application to be tested. Regional division is used to divide the application page evenly or irregularly. Regional testing results are used to indicate whether the application to be tested is secure or unsafe. Regional testing results can also be included in the aforementioned test result list.

[0085] The application page is divided into regions according to the preset number of regional divisions to obtain multiple block areas. For example, the application page is divided into 4 block areas, namely area 1, area 2, area 3 and area 4. When the application type of the application to be detected is different, the regional detection priority of each block area is different. Different regional detection results may be obtained due to different detection time periods of regional detection. For example, when the detection time period is at night or on weekends, the possibility of detecting unsafe content will be greater than that during the day or on normal working days. Therefore, the regional and time period detection configuration unit can be used to perform regional detection on the block areas according to the regional detection priority within the preset detection time period, and obtain the regional detection results corresponding to the regional and time period detection items. For example, at 10 o'clock on Saturday night, the page content in area 3 is preferentially detected.

[0086] Here, by setting the regional detection priority of the block area in the application page and presetting the detection time period, the detection efficiency of the regional detection can be greatly improved.

[0087] In some embodiments, the security detection project also includes a deep random detection project, the data to be detected includes application pages, the page level of the application page is N, and the detection configuration unit also includes a deep random detection configuration unit, where N is an integer greater than 1. The deep random detection project is one of the detection projects in the security detection project. The deep random detection project mainly detects application pages with multiple page levels and is not used for the detection of single-layer application pages. In addition, during the detection process, the application page of a certain page level can be randomly detected. Therefore, for deep random detection projects, the deep random detection configuration unit in the detection module can be called to detect the application page of the application to be detected, and the detection process can be implemented in the following way: the detection module targets the i-th level page in the application page, and performs content detection and area detection on the i-th level page in sequence through the deep random detection configuration unit to obtain the content detection result and area detection result of the i-th level page, where i is an integer greater than 0 and less than N; when the content detection result and area detection result of the i-th level page indicate that the detection result of the application to be detected is safe, and the i+1-th level page is a new page, the content detection and area detection are performed on the i+1-th level page in sequence through the deep random detection configuration unit to obtain the content detection result and area detection result of the i+1-th level page; when any one of the content detection result and area detection result of the i+1-th level page indicates that the detection result of the application to be detected is unsafe, or when the i+1-th level page is not a new page, the detection task is terminated.

[0088] When the security detection project includes a deep random detection project, the application page corresponding to the deep random detection project is encapsulated in the detection startup request, and the application page of the application to be detected can be directly parsed. When the page level of the application page is multi-level, for each level of page, first, through the deep random detection configuration unit, the current page is used as the page to be detected, and content detection and area detection are performed on the current page to obtain the content detection result and area detection result of the current page. When the content detection result and the area detection result both represent that the detection result of the application to be detected is safe, then determine whether the next level page of the current page is a new page (i.e., an undetected page). When the next level page is a new page, the next level page is used as the page to be detected, and content detection and area detection are performed on the next level page. Until there is no page to be detected (i.e., there is no new page in the application page), or any one of the content detection result and area detection result of any level page represents that the detection result of the application to be detected is unsafe, the detection task is terminated. For example, assuming that the page level of the application page is 5, for the level 3 page, when the content detection result and area detection result of the level 3 page indicate that the detection result of the application to be detected is safe, and the level 4 page is a new page, content detection and area detection are performed on the level 4 page in sequence to obtain the content detection result and area detection result of the level 4 page. However, if the content detection result of the level 4 page indicates that the detection result of the application to be detected is unsafe, content detection and area detection will no longer be performed on the level 5 page, and the detection task is ended.

[0089] In some embodiments, the security detection project further includes a page frame detection project, the data to be detected further includes page frame data and a historical click path tree, and the detection configuration unit further includes a page frame detection configuration unit. The page frame detection project is one type of detection project in the security detection project. The page frame detection project primarily targets the page frame of the application page. During the detection process, the page frame data and the historical click path tree of the page frame of the application page can be detected. Therefore, for the page frame detection project, the page frame detection configuration unit in the detection module can be called to detect the page frame data and historical click path tree of the application to be detected. The detection process can be implemented in the following way: the detection module obtains the page frame data of the application to be detected in response to the detection start request; based on the page frame data, the current tree feature corresponding to the hierarchical tree of each level of the page is determined; for each current tree feature, the similarity between the current tree feature and the historical tree feature is calculated to obtain a similarity result; based on the similarity result and a preset similarity threshold, the similarity comparison result is determined; when the similarity comparison result indicates that the detection result of the application to be detected is safe, the historical click path tree of the application to be detected is obtained; through the page frame detection configuration unit, a click operation is performed on the historical click path in the historical click path tree to obtain a click operation result; based on the click operation result, the frame detection result corresponding to the page frame detection project is determined.

[0090] When the security detection project includes a page frame detection project, the page frame data and the historical click path tree corresponding to the page frame detection project are encapsulated in the detection start request, and the page frame data and the historical click path tree of the application to be detected can be directly parsed. The frame detection result is used to characterize whether the detection result of the application to be detected is safe or unsafe, and the frame detection result can also be part of the above-mentioned detection result list. The historical tree feature is a tree feature before the current moment when the frame detection result corresponding to the page frame detection project characterizes that the detection result of the application to be detected is safe. The historical click path tree is a tree structure containing the historical click paths of the application page, which is used to save the historical click paths of the application page.

[0091] The page framework data contains key information such as the hierarchical information of the application page and the operable elements of the application page. Based on this key information, the hierarchical tree of the application page can be drawn, and the current tree features corresponding to the hierarchical tree of each level of the page can be recorded. And for each level of the page, the similarity calculation method is used to calculate the similarity between each current tree feature and the historical tree feature to obtain a similarity result. When the similarity result is greater than or equal to the preset similarity threshold, the similarity comparison result indicates that the detection result of the application to be detected is unsafe; when the similarity result is less than the preset similarity threshold, the similarity comparison result indicates that the detection result of the application to be detected is safe, and then a click operation is performed on the historical click path in the historical click path tree, that is, the saved historical click path is reproduced. When the historical click path cannot be reproduced, the click operation result is a failed operation, which indicates that the page frame of the application to be tested has changed, and the frame detection result indicates that the detection result of the application to be tested is unsafe; when the historical click path can be reproduced, the click operation result is a successful operation, which indicates that the page frame of the application to be tested has not changed, and the frame detection result indicates that the detection result of the application to be tested is safe.

[0092] In some embodiments, the security detection project includes a specific page identification project, the data to be detected includes a specific page, and the detection configuration unit includes a specific page detection configuration unit. The specific page identification project is one of the detection projects in the security detection project. The specific page identification project is mainly aimed at a specific page in the application page. During the detection process, the specific page in the application page can be detected. Therefore, for the specific page identification project, the specific page detection configuration unit in the detection module can be called to detect the specific page of the application to be detected. The detection process can be implemented in the following way: the detection module obtains the specific page of the application to be detected in response to the detection start request; determines the identification method of the specific page according to the page type of the specific page; based on the identification method, the specific page is identified and detected by the specific page detection configuration unit to obtain the identification detection result corresponding to the specific page identification project.

[0093] The specific page can be a login page, floating window page, advertising page, update page, etc. in the application to be detected, and the page type of the specific page includes a static page type and a dynamic page type. The identification method of the specific page can be determined according to different page types. For static page types, the identification method can be image recognition, optical character recognition, semantic recognition, etc.; for dynamic page types, for example, the specific page is a playing video stream, and the identification method can be video recognition, audio recognition, video and audio mixed recognition, etc. The identification detection result is used to characterize whether the detection result of the application to be detected is safe or unsafe, and the identification detection result can also be part of the above-mentioned detection result list. When the security detection item includes a specific page identification item, the specific page corresponding to the specific page identification item is encapsulated in the detection start request, and the specific page of the application to be detected can be directly parsed. For example, when the specific page is a dynamic page type, the specific page is cut frame by frame, the image features of each frame are extracted, and the image features are classified and judged by the image classification recognition algorithm to obtain the final identification detection result corresponding to the specific page identification item.

[0094] In some embodiments, in addition to the types mentioned above, the security detection items of the application to be detected, the data to be detected, and the detection configuration unit in the detection module can also be updated and configured according to the actual detection requirements of the application to be detected, which is not limited here.

[0095] Here, through multiple detection configuration units in the detection module, different security detection operations are performed on the application to be detected. There is no need to rely on the quality and experience of the operator during the manual detection process. The security of the application to be detected can be effectively detected, which facilitates the subsequent improvement of the accuracy of the detection results.

[0096] Step S206: The detection module sends the detection result list to the business background module.

[0097] Step S207: The business background module manages the test result list to obtain the test result.

[0098] In an embodiment of the present application, the test result management is to fuse the multiple test results in the test result list to obtain the fused test result. When the business background module receives the test result list sent by the detection module, the test result list contains the results corresponding to each security detection item, for example, content detection results, area detection results, identification detection results, etc. In the test result management process, the repeated result content in the test result list can be deduplicated and the non-duplicate results can be integrated, so that the test result after the test result management is a complete test result of the application to be detected, thereby realizing effective application detection of the application to be detected.

[0099] Step S208: The business background module sends the detection result to the task management module.

[0100] In step S209, the task management module displays the detection results.

[0101] In an embodiment of the present application, first, a detection task of the application to be detected is generated by the task management module, and the detection task is sent to the business background module; then, a detection start request of the detection application is generated by the business background module, and the detection start request is sent to the detection module; finally, a security detection is performed on the data to be detected through multiple detection configuration units in the detection module, and a detection result list is obtained, and the detection result list is sent to the business background module. The detection result of the application to be detected is obtained by the business background module, and the result is displayed in the task management module. In this way, the task management module, the business background module and the detection module together constitute a complete application detection system, and the application detection method is implemented through the application detection system, eliminating the factor of manual intervention and breaking away from the limitation of traditional application detection technology that needs to be detected through three-party applications. In the detection process, only the data to be detected of the application to be detected needs to be obtained for security detection, without intruding into the application to be detected. Through the application detection system, application detection technology can be comprehensively used to effectively detect the application to be detected, thereby obtaining accurate detection results.

[0102] The following describes an exemplary application of the embodiments of the present application in a practical application scenario.

[0103] This application embodiment provides a general-purpose application detection system that utilizes server virtualization, elastic scheduling, randomized deep learning, simulated artificial intelligence, human-machine interaction, optical character recognition (OCR), video analysis, and machine learning to achieve configurable, debuggable, and fully automated application security detection. The system includes multiple submodules: a task management module, a business backend module, a detection module, a container service module, and a storage module. Generally speaking, the detection task is submitted in the task management module and marked as pending; the business background module is installed and started in the container service module; the business background module continues to run in the container service module and continuously detects the detection tasks to be executed in the task management module; after pulling the detection tasks to be executed, the detection business process begins to execute; the detection task is submitted to the detection module, the detection engine is started, and various security items of concern to the business are detected to determine whether the application is safe; the detection module returns the detection results to the business background module, the business background module records the detection results, and the production detection report is saved to the storage module, that is, the detection result storage is realized, and the execution results are returned to the task management module for display; the task management module updates the task status, and the task status is updated from pending to safe or unsafe, and provides a detailed viewing entrance. The flow diagram of using the application detection system to obtain the detection results is as follows Figure 4 As shown, the process is as follows: S1. Submit the detection task; S2. Execute the detection business process; S3. Start the detection engine; S4. Return the detection results; S5. Store the detection results. If the business backend module or the detection module has functional updates, an upgraded service image is created and the container service is updated to achieve the goal of updating the security detection system.

[0104] The system adopts containerized deployment, breaking away from the traditional application security testing method that requires terminals to install, operate, and uninstall applications. The detection process diagram after the system container deployment is as follows: Figure 5 As shown, first, the task management module generates a detection task and submits it to the business backend module. Then, the workflow engine in the business backend module generates a detection initiation request and sends it to the detection module, which can be a detection module under any system, such as iOS or Android. Finally, the detection module responds to the detection initiation request, performs a test on each detection item in the detection task, and returns the test results. All of this is performed within a large server, and through batch simulation of terminal systems, dozens or even thousands of tasks can be tested simultaneously. Maintenance is simple and automated, with no dirty data interfering between tasks. High reliability and trustworthiness improve the flexibility of business deployment and reduce maintenance costs.

[0105] The task management module is a user interface module for human interaction. It allows operations such as submitting, pausing, and deleting tasks, viewing task progress, and querying task result documents. This module provides task detection model configuration and, based on application type, allows for full testing, regional testing, time-specified testing, continuous click testing in special areas, and configuration of detection frequency.

[0106] like Figure 6 As shown, the process of the task management module is as follows: S01, configure the task name, add basic information, that is, the application name, icon, package name, download address, etc. of the application (that is, the above-mentioned application to be detected); S02, pull the list of security detection items from the background and check them, that is, check the detection items that need to be performed for the task, for example, the detection items can be static security detection, file list detection, hot update detection, framework update detection and content security detection, etc.; S03, configure the detection start time, end time, and detection frequency; S04, form a detection task; S05, submit the detection task.

[0107] The business backend module uses the workflow engine to perform business automation management and business process orchestration to ensure the smooth progress of the application detection process. Figure 7As shown, the process of the business background module is as follows: when a detection task is pulled, S10, determine whether the detection task needs to be detected, that is, determine whether the detection task needs to be executed based on the configuration such as the detection start time, end time, detection frequency (that is, the number of times the task is executed); S11, if the detection task does not need to be detected, determine whether it needs to be deleted from the pool to be detected; S12, if it is an expired detection task, or a detection task that has been completed, then the task status is transferred to completed, and the detection task is deleted from the pool of tasks to be detected; if it is a detection task that has not expired, or a detection task that has not been completed, put the detection task back into the pool to be detected and wait for the next task to be pulled; S13, if it is a detection task that needs to be executed this time, that is, the detection task needs to be detected, then perform safety checks one by one according to the detection items, that is, read the detection item configuration, and perform concurrent or sequential execution according to the order of the detection items; S13, record the detection results; and the task detection is completed.

[0108] The detection module can integrate multiple detection modules based on different detection priorities. For example, there are dedicated detection modules focused on content security, code security, and application behavior. This module actually performs application detection, and can check application privacy compliance, whether the application requests excessive user permissions, record unauthorized application behavior, determine application code security, application content security, and Software Development Kit (SDK) compliance. Finally, a detailed list of results is returned to the business backend module.

[0109] The detection module includes a variety of detection methods, such as regional and time-segment detection configuration to improve detection efficiency, special page identification configuration, page framework change configuration, and page depth detection methods. These detection methods can be orchestrated and configured according to business needs. Basic detection is one of the detection methods in the detection module. It verifies the application name, version, package name, size, file hash value, permission requests, certificates, etc., and scans the involved Uniform Resource Locator (URL) for security risks. Without running the application, it detects potential security risks by analyzing the application code and resource files.

[0110] In addition, detection methods can also include dynamic detection to detect whether the application has been tampered with, secondary packaging behavior, whether it contains illegal information, malicious code, virus code, whether it is mixed with harmful resources, etc.

[0111] Detection methods can also include hot update detection, which is used to determine whether the application has performed additional operations outside the plan by recording the number of times the application is started and detecting the number and time of files generated by the application; it can also scan the system background process and compare it with the currently scheduled applications to find unplanned processes, thereby finding applications with abnormal operations.

[0112] Detection methods can also include simulating manual operations. The detection method involves opening the app page; obtaining clickable, swipeable, and inputtable elements; randomly selecting an element and performing a corresponding operation; and determining whether there is unsafe content. Based on this simulated manual operation method, various detection modes can be configured to combat anomalies and identify unsafe applications.

[0113] Detection methods can also include frequent clicks and swipes in specific locations. Some apps operate normally, but multiple clicks in specific areas can cause specific pages or content to be exposed, bypassing the initial content check. After the task management module configures the detection mode for a task, it can perform multiple checks on certain areas of certain pages within the app, such as special swipe gestures, multiple clicks, and continuous taps, hoping to trigger potentially unsafe content.

[0114] These special inspection operations are stored in the special operation database and are set up in advance by the detection system. During operation, they are continuously summarized and updated from industry reports and daily inspection accumulation.

[0115] Detection methods can also include special input detection of input boxes. As mentioned above, after detecting that there is a configuration that can be input, you can randomly extract some or all special texts from the system's preset special text input table, enter them, and then check the application's feedback to catch possible unsafe applications.

[0116] Detection methods can also include detection by region and time period. Application security detection can be set to trigger at different time periods, such as late at night, weekends, etc. The probability of detecting unsafe content during these time periods is relatively high. The ability to batch configure the start time of detection tasks, and automatically execute tasks when they expire. In order to improve the efficiency of application detection, application pages can be divided into blocks by region for detection. For example, Figure 8 As shown, a page is divided into 4 blocks, and the area detection priority is set according to different application types. During the set detection period, high-priority areas are detected first. For example, the content in area 4 is detected first at 11 pm, which improves the detection speed and detection quantity of the application.

[0117] Detection methods can also include deep random detection. In addition to content security detection of the application's page elements, all pages in the application must be traversed to ensure that the detection is not repeated or missed. The random deep detection algorithm realizes the function of automatically simulating manual clicks. By obtaining the page frame data, the page configuration information and clickable and swiping metadata are cleaned out. Based on this information, deep detection can be achieved. The detection process is as follows: Figure 9 As shown, the process is as follows:

[0118] A1. Open the main page; A2. Check the security of the page content; A3. Determine whether the page content is safe. If not, record and end the detection; A4. If safe, obtain the configuration information and other metadata of the page, i.e. the coordinates of the elements in the page, clickable elements, slidable elements, etc.; A5. Select a clickable element to click based on the priority of the time + area configuration; A6. Determine whether there is a new clickable element; A7. If there is no new clickable element, determine whether there is a previous page; A8. If there is a new clickable element, the page level +1; A9. Determine whether the page level reaches the set level threshold; A10. If the set level threshold is not reached, enter the next level page; if the set level threshold is reached, return to step A7; A11. Determine whether the next level page is a new page; if the next level page is a new page, return to step A2; if the next level page is not a new page, return to step A7; A12. If there is a previous level page, return to the previous level page and continue with step A5; if there is no previous level page, end.

[0119] Detection methods can also include page frame detection. Generally speaking, the page frame of an application is relatively stable and will not change the main frame at will. However, some unsafe applications will update their content through various means. Identifying the page frame structure of these applications and comparing whether there are major changes in the page frame is an effective way to determine whether the application has major content changes. The page frame detection process is as follows: Figure 10 shown.

[0120] First, obtain the page framework data, typically in XML or JSON format. This framework data contains layout hierarchy information, as well as other key information such as clickability, swipeability, and activation. Based on this data, a page hierarchy tree is drawn, and tree features are recorded. Through multiple application tests, tree features of the same page are compared and similarity is calculated. If a set threshold is reached (for example, below 70%), the page is considered to have undergone a major framework change, and a warning is issued for subsequent high-quality verification.

[0121] In addition, there are many clickable elements on the page. Free clicking forms a historical click path tree, which is recorded. The application is tested multiple times, and the operations are reproduced using the saved historical click path tree. If the path tree changes, it can be determined that the page frame content has changed, and a conclusion is given that the frame has changed for high-quality verification in subsequent processes.

[0122] The page frame detection process is as follows: A01. Start the Android application package (Android Application Package, APK); A02. Determine whether the application needs to perform page frame comparison; A03. If page frame comparison is required, determine whether to read the historical click path tree; A04. If the historical click path tree is read, perform the click operation according to the historical click path tree; A05. Determine whether to reproduce the click operation; A06. If the click operation is reproduced, perform image content security detection and end the detection; A07. If the click operation is not reproduced, record the result; A08. If page frame comparison is not required, or the historical click path tree is not read, enter the subsequent process.

[0123] Detection methods can also include special page identification. There are many special pages in the application, such as privacy pages, login pages, update pages, advertising pages, pop-up pages, etc. These pages can be identified through optical character recognition (OCR), that is, keyword recognition, semantic recognition and other methods, or through framework structure recognition and other means.

[0124] For the application content identification part, image recognition can be used. During the application inspection process, the application content can be saved by taking screenshots, and then the content security detection can be performed using image recognition to identify unsafe content. Video recognition can also be used to perform audio and video content security detection on the video stream played in the application. Single audio review, single video content review, mixed review, etc. can be performed according to the configuration. Scene review can be performed, and the types that need to be reviewed in detail can be configured, for example, types containing illegal information. The video is cut frame by frame, the image element features are extracted, and the elements are classified and judged through the image classification and recognition algorithm, and compared with the sample library. Hybrid review uses the means of artificial intelligence autonomous learning to generate a large model for identifying content security through training with a large sample size of labeled text, voice, pictures, videos, etc. The model makes autonomous decisions and outputs the detection results. In general, the technical solutions in the embodiments of this application are only general explanatory texts, the purpose of which is to clearly and clearly explain the operation process of the entire system. In actual use, the detection technology can be targeted, expanded, or recombined according to the actual needs of the application detection business.

[0125] The system provided in the embodiments of this application is a comprehensive application security testing system with advantages such as easy deployment, simple maintenance, and convenient operation. It proposes the concept of multi-engine integration and automated workflow configuration, eliminating the factor of manual intervention and making large-scale testing tasks possible. In production and daily life, it can effectively detect application security, timely filter and intercept harmful applications, ensure the compliance and stability of business systems, reduce the spread of harmful information, and maintain a clean network.

[0126] It is understandable that in the embodiments of the present application, the content involving user information, such as security detection items of the application to be detected, detection configuration units, detection results and other information, if it involves data related to user information or enterprise information, when the embodiments of the present application are applied to specific products or technologies, it is necessary to obtain user permission or consent, or to blur this information to eliminate the correspondence between this information and the user; and the relevant data collection and processing should be strictly in accordance with the requirements of relevant national laws and regulations when applied in examples, and the informed consent or separate consent of the personal information subject should be obtained, and subsequent data use and processing should be carried out within the scope of authorization of laws and regulations and the personal information subject.

[0127] The following continues to describe the exemplary structure of the application detection system 455 provided in the embodiment of the present application as a software module. In some embodiments, such as Figure 2 As shown, the software modules in the application detection system 455 stored in the memory 450 may include: a task management module 4551, which is used to perform task management on the application to be detected, obtain the detection task of the application to be detected, and send the detection task to the business background module 4552; and receive the detection result of the application to be detected sent by the business background module 4552, and display the detection result; the detection task includes at least one security detection item; the business background module 4552 is used to perform business process orchestration on the detection task by calling the workflow engine, obtain the detection start request of the detection task, and send the detection result to the business background module 4552. The detection start request is sent to the detection module 4553; and, the detection result list of the application to be detected sent by the detection module 4553 is received, and the detection result list is managed to obtain the detection result, and then the detection result is sent to the task management module 4551; the detection module 4553 includes multiple detection configuration units for executing different security detection items; the multiple detection configuration units are used to respond to the detection start request, perform detection operations on each security detection item of the detection task respectively, obtain the detection result list, and send the detection result list to the business background module 4552.

[0128] In some embodiments, the task management module 4551 is also used to: obtain basic detection information of the application to be detected; determine the security detection items of the application to be detected based on the detection item list of the application detection system; obtain task execution information of the security detection items; determine the detection task of the application to be detected based on the basic detection information, the security detection items and the task execution information.

[0129] In some embodiments, the task management module 4551 is also used to: update the task status of the detection task according to the detection result; when the detection result is safe, update the task status of the detection task from the to-be-detected state to the safe state; when the detection result is unsafe, update the task status of the detection task from the to-be-detected state to the unsafe state.

[0130] In some embodiments, the business background module 4552 is also used to: obtain multiple safety detection items in the detection task; determine the execution order of the multiple safety detection items based on the task execution information in the detection task; and generate a detection start request for the detection task based on the multiple safety detection items and the execution order.

[0131] In some embodiments, the detection module 4553 is used to: in response to the detection start request, obtain the data to be detected and the execution order corresponding to each security detection item; call the detection configuration unit in sequence according to the execution order, and input the data to be detected into the corresponding detection configuration unit; through the detection configuration unit, perform security detection on the data to be detected to obtain the detection result list.

[0132] In some embodiments, the security detection items include basic detection items, the data to be detected includes basic detection data, and the detection configuration unit includes a basic detection configuration unit; the detection module 4553 is also used to: respond to the detection start request, obtain the basic detection data of the application to be detected; through the basic detection configuration unit, verify and detect the basic detection data to obtain the verification detection results corresponding to the basic detection items.

[0133] In some embodiments, the security detection item includes a hot update detection item, the data to be detected includes application execution data, and the detection configuration unit includes a hot update detection configuration unit; the detection module 4553 is also used to: obtain the application execution data of the application to be detected in response to the detection start request; determine the hot update detection result corresponding to the hot update detection item based on a preset application execution threshold through the hot update detection configuration unit.

[0134] In some embodiments, the security detection item includes a simulated manual operation detection item, the data to be detected includes an application page, and the detection configuration unit includes a simulated manual detection configuration unit; the detection module 4553 is also used to: respond to the detection start request, obtain the application page of the application to be detected; obtain the operable elements of the application page; through the simulated manual detection configuration unit, use a preset detection operation to perform content detection on the operable elements to obtain the content detection result corresponding to the simulated manual operation detection item.

[0135] In some embodiments, the security detection project also includes a region and time period detection project, and the detection configuration unit also includes a region and time period detection configuration unit; the detection module 4553 is also used to: in response to the detection start request, obtain the application page of the application to be detected; divide the application page into regions according to a preset number of regional divisions to obtain multiple block areas of the application page; for each block area, determine the regional detection priority of the block area according to the application type of the application to be detected; through the region and time period detection configuration unit, according to the regional detection priority, perform regional detection on the block area within the preset detection time period to obtain the regional detection result corresponding to the region and time period detection project.

[0136] In some embodiments, the security detection project also includes a deep random detection project, the page level of the application page is N, and the detection configuration unit also includes a deep random detection configuration unit, where N is an integer greater than 1; the detection module 4553 is also used to: for the i-th level page in the application page, perform the content detection and the area detection on the i-th level page in sequence through the deep random detection configuration unit to obtain the content detection result and the area detection result of the i-th level page, where i is an integer greater than 0 and less than N; when the content detection result and the area detection result of the i-th level page indicate that the detection result of the application to be detected is safe, and the i+1-th level page is a new page, perform the content detection and the area detection on the i+1-th level page in sequence through the deep random detection configuration unit to obtain the content detection result and the area detection result of the i+1-th level page; when any one of the content detection result and the area detection result of the i+1-th level page indicates that the detection result of the application to be detected is unsafe, or when the i+1-th level page is not a new page, end the detection task.

[0137] In some embodiments, the security detection project also includes a page frame detection project, the data to be detected also includes page frame data and a historical click path tree, and the detection configuration unit also includes a page frame detection configuration unit; the detection module 4553 is also used to: in response to the detection start request, obtain the page frame data of the application to be detected; based on the page frame data, determine the current tree feature corresponding to the hierarchical tree of each level of the page; for each current tree feature, calculate the similarity between the current tree feature and the historical tree feature to obtain a similarity result; the historical tree feature is a tree feature before the current moment and the frame detection result corresponding to the page frame detection project indicates that the detection result of the application to be detected is safe; based on the similarity result and a preset similarity threshold, determine the similarity comparison result; when the similarity comparison result indicates that the detection result of the application to be detected is safe, obtain the historical click path tree of the application to be detected; through the page frame detection configuration unit, perform a click operation on the historical click path in the historical click path tree to obtain a click operation result; based on the click operation result, determine the frame detection result corresponding to the page frame detection project.

[0138] In some embodiments, the security detection item includes a specific page identification item, the data to be detected includes a specific page, and the detection configuration unit includes a specific page detection configuration unit; the detection module 4553 is also used to: respond to the detection start request, obtain the specific page of the application to be detected; determine the identification method of the specific page according to the page type of the specific page; based on the identification method, identify and detect the specific page through the specific page detection configuration unit to obtain the identification detection result corresponding to the specific page identification item.

[0139] It should be noted that the description of the system embodiment of the present application is similar to the description of the above-mentioned method embodiment and has similar beneficial effects as the method embodiment, so it will not be repeated. For technical details not disclosed in the system embodiment, please refer to the description of the method embodiment of the present application for understanding.

[0140] The embodiment of the present application provides a computer-readable storage medium in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, the processor will execute the application detection method provided by the embodiment of the present application, for example, Figure 3 The application detection method is shown.

[0141] An embodiment of the present application provides a computer program product including computer-executable instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer-executable instructions from the computer-readable storage medium and executes the computer-executable instructions, causing the electronic device to perform the application detection method described above in the embodiment of the present application.

[0142] In some embodiments, the computer-readable storage medium may be a memory such as RAM, ROM, flash memory, magnetic surface memory, optical disk, or CD-ROM; or may be various devices including one or any combination of the above memories.

[0143] In some embodiments, computer-executable instructions may be in the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0144] As an example, computer-executable instructions may, but need not, correspond to a file in a file system, may be stored as part of a file that stores other programs or data, such as in one or more scripts in a HyperText Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple coordinating files (e.g., files storing one or more modules, subroutines, or code portions).

[0145] By way of example, computer-executable instructions may be deployed to be executed on one electronic device, or on multiple electronic devices located at one site, or on multiple electronic devices distributed across multiple sites and interconnected by a communication network.

[0146] The above description is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. Any modifications, equivalent replacements, and improvements made within the spirit and scope of the present application are included in the scope of protection of the present application.

Claims

1. An application detection system, characterized in that: The system includes a task management module, a business background module and a detection module; wherein: The task management module is used to manage tasks for the application to be detected, obtain detection tasks for the application to be detected, and send the detection tasks to the business background module; and receive the detection results of the application to be detected sent by the business background module and display the detection results; the detection tasks include at least one security detection item; The business backend module is configured to perform business process orchestration on the detection task by calling a workflow engine, obtain a detection start request for the detection task, and send the detection start request to the detection module; and receive a detection result list of the application to be detected sent by the detection module, perform detection result management on the detection result list, obtain the detection result, and then send the detection result to the task management module; The detection module includes multiple detection configuration units for executing different security detection items; the multiple detection configuration units are used to respond to the detection start request, perform detection operations on each security detection item of the detection task respectively, obtain the detection result list, and send the detection result list to the business background module.

2. The system according to claim 1, wherein: The task management module is also used to: Obtaining basic detection information of the application to be detected; Determining security detection items of the application to be detected based on the detection item list of the application detection system; Obtaining task execution information of the safety detection project; Based on the basic detection information, the security detection items and the task execution information, a detection task of the application to be detected is determined.

3. The system according to claim 2, characterized in that The task management module is also used to: According to the detection result, the task status of the detection task is updated; When the detection result is safe, the task status of the detection task is updated from the pending detection state to the safe state; When the detection result is unsafe, the task state of the detection task is updated from the to-be-detected state to the unsafe state.

4. The system according to claim 2, wherein: The business backend module is also used to: Acquire multiple safety detection items in the detection task; determine the execution order of the multiple safety detection items according to the task execution information in the detection task; A detection start request for the detection task is generated based on the multiple safety detection items and the execution order.

5. The system according to claim 4, characterized in that The detection module is also used for: In response to the detection start request, the data to be detected and the execution order corresponding to each security detection item are obtained; according to the execution order, the detection configuration units are called in sequence, and the data to be detected are input into the corresponding detection configuration units; through the detection configuration units, the data to be detected are security detected to obtain the detection result list.

6. The system according to claim 5, characterized in that The safety detection items include basic detection items, the data to be detected include basic detection data, and the detection configuration unit includes a basic detection configuration unit; The detection module is further configured to: obtain the basic detection data of the application to be detected in response to the detection start request; and perform verification and detection on the basic detection data through the basic detection configuration unit to obtain verification and detection results corresponding to the basic detection items.

7. The system according to claim 5, characterized in that The security detection item includes a hot update detection item, the data to be detected includes application execution data, and the detection configuration unit includes a hot update detection configuration unit; The detection module is further configured to: obtain the application execution data of the application to be detected in response to the detection start request; and determine, through the hot update detection configuration unit, a hot update detection result corresponding to the hot update detection item based on a preset application execution threshold.

8. The system according to claim 5, wherein: The security detection item includes a simulated manual operation detection item, the data to be detected includes an application page, and the detection configuration unit includes a simulated manual detection configuration unit; The detection module is further configured to: in response to the detection start request, obtain the application page of the application to be detected; and obtain operable elements of the application page; The simulated manual detection configuration unit uses a preset detection operation to perform content detection on the operable element to obtain a content detection result corresponding to the simulated manual operation detection item.

9. The system according to claim 8, characterized in that The safety detection items also include area and time period detection items, and the detection configuration unit also includes area and time period detection configuration units; The detection module is further configured to: in response to the detection start request, obtain the application page of the application to be detected; divide the application page into regions according to a preset number of region divisions to obtain a plurality of block regions of the application page; For each block area, the regional detection priority of the block area is determined according to the application type of the application to be detected; through the regional and time period detection configuration unit, the block area is subjected to regional detection according to the regional detection priority within the preset detection time period to obtain the regional detection result corresponding to the regional and time period detection item.

10. The system according to claim 9, characterized in that The security detection project further includes a deep random detection project, the page level number of the application page is N, the detection configuration unit further includes a deep random detection configuration unit, and N is an integer greater than 1; The detection module is further configured to: for an i-th level page in the application page, sequentially perform the content detection and the area detection on the i-th level page through the deep random detection configuration unit, to obtain a content detection result and an area detection result for the i-th level page, where i is an integer greater than 0 and less than N; When the content detection result and the area detection result of the i-th level page indicate that the detection result of the application to be detected is safe, and the i+1-th level page is a new page, the deep random detection configuration unit sequentially performs the content detection and the area detection on the i+1-th level page to obtain the content detection result and the area detection result of the i+1-th level page; If any one of the content detection result and the area detection result of the i+1th level page indicates that the detection result of the application to be detected is unsafe, or if the i+1th level page is not a new page, the detection task is terminated.

11. The system according to claim 10, wherein: The security detection project further includes a page frame detection project, the data to be detected further includes page frame data and a historical click path tree, and the detection configuration unit further includes a page frame detection configuration unit; The detection module is further configured to: obtain the page frame data of the application to be detected in response to the detection start request; and determine the current tree feature corresponding to the hierarchical tree of each level of the page based on the page frame data; For each current tree feature, a similarity calculation is performed between the current tree feature and a historical tree feature to obtain a similarity result; the historical tree feature is a tree feature before the current moment and when the frame detection result corresponding to the page frame detection item indicates that the detection result of the application to be detected is safe; Determining a similarity comparison result based on the similarity result and a preset similarity threshold; When the similarity comparison result indicates that the detection result of the application to be detected is safe, obtaining the historical click path tree of the application to be detected; Performing a click operation on the historical click paths in the historical click path tree through the page frame detection configuration unit to obtain a click operation result; Based on the click operation result, a frame detection result corresponding to the page frame detection item is determined.

12. The system according to claim 5, wherein: The security detection item includes a specific page identification item, the data to be detected includes a specific page, and the detection configuration unit includes a specific page detection configuration unit; The detection module is also used to: obtain the specific page of the application to be detected in response to the detection start request; determine the identification method of the specific page according to the page type of the specific page; based on the identification method, identify and detect the specific page through the specific page detection configuration unit to obtain the identification detection result corresponding to the specific page identification item.

13. An application detection method, characterized in that: The method is applied to the application detection system according to any one of claims 1 to 12, and the method comprises: Performing task management on the application to be detected to obtain the detection task of the application to be detected; Invoke a workflow engine to perform business process orchestration on the detection task, and obtain a detection start request for the detection task; In response to the detection start request, performing detection operations on each safety detection item of the detection task respectively, and obtaining a corresponding detection result list of the detection task; The test result list is managed to obtain the test result of the application to be tested.

14. An electronic device, characterized in that: include: a memory for storing computer-executable instructions; The processor is configured to implement the application detection method according to claim 13 when executing the computer executable instructions stored in the memory.

15. A computer program product, characterized in that The computer program product includes computer-executable instructions stored in a computer-readable storage medium; Wherein, when the processor of the electronic device reads the computer-executable instructions from the computer-readable storage medium and executes the computer-executable instructions, the application detection method described in claim 13 is implemented.

Citation Information

Cited By

  • Automatic detection scoring method and device for advertisement website and related medium

    CN121073556A