Application user tracking detection method and device based on dynamic and static combination technology
By combining dynamic and static technologies to build an application user tracking detection method, integrating static and dynamic analysis results, identifying and pruning or completing path information, it solves the problems of narrow detection coverage and low accuracy, and achieves high-coverage and high-accuracy user data tracking.
Patent Information
- Application Number
- CN202411822974.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-10
- Publication Date
- 2025-10-03
AI Technical Summary
Existing technologies have problems with narrow detection coverage and low detection accuracy when detecting whether applications use device identifiers to track users, and are unable to effectively protect user privacy and information security.
A method based on the combination of dynamic and static technology is adopted to construct the first inter-process control flow graph and the second inter-process control flow graph through static analysis and dynamic analysis respectively, and the two are integrated to form the third inter-process control flow graph, identify and prune or complete the path information, and construct a complete and accurate data leakage path.
It achieves high coverage and high accuracy of user data tracking detection, solves the problems of static analysis path explosion and low dynamic analysis coverage, and improves the accuracy and scope of detection.
Smart Images

Figure CN120744964A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to an application user tracking detection method and device based on a dynamic and static combined technology. Background Art
[0002] In the current mobile app market, some app operators have engaged in a series of serious violations in pursuit of profit. These actions not only harm the rights and interests of users but also negatively impact the healthy development of the entire industry. These behaviors are primarily manifested in the following aspects: First, some apps (application programs) collect and use personal information without user consent and generate device identifiers for user tracking. Second, these operators use this collected information to construct detailed user profiles for targeted advertising. Furthermore, they share data with other manufacturers beyond commercial promotion, further exacerbating the risk of user privacy breaches. These actions have not only sparked strong dissatisfaction and concern among consumers but have also led to confusion and price discrimination in app advertising, exposing some users to unfair treatment when purchasing.
[0003] Among the technologies related to data leakage analysis, most are based on either static taint analysis or dynamic instrumentation. Static taint analysis is relatively easy to use in large-scale app testing and offers high code coverage. However, it suffers from the path explosion problem caused by over-analysis. The analyzed paths may not actually be called, and runtime information cannot be obtained. Dynamic instrumentation runs the app in a real or virtual environment, injecting instrumentation code during execution to monitor runtime status. This suffers from incomplete path coverage.
[0004] In summary, relevant technologies for addressing apps' use of device identifiers to track users suffer from limited detection coverage and low accuracy. These issues urgently need to be addressed to effectively protect users' personal privacy and information security and promote the healthy development of the mobile app market. Summary of the Invention
[0005] Based on this, it is necessary to provide an application user tracking detection method and device based on dynamic and static combined technology that can solve the problems of narrow detection coverage and low detection accuracy when APP uses device identifiers to track users in response to the above technical problems.
[0006] In a first aspect, this embodiment provides an application user tracking detection method based on a combination of dynamic and static technologies, the method comprising:
[0007] Obtaining, according to an application package of a target application and a configuration file containing a predefined device identifier, a first inter-procedural control flow graph associated with the device identifier;
[0008] determining, based on program behavior of the target application in a running state, functions associated with an application programming interface of the device identifier and an application programming interface of network data transmission, and obtaining a second inter-procedural control flow graph of data leakage based on the functions;
[0009] Integrating the first inter-procedural control flow graph and the second inter-procedural control flow graph to obtain a third inter-procedural control flow graph;
[0010] A leakage path of user data from the target application is obtained according to the third inter-process control flow graph.
[0011] In some embodiments, integrating the first inter-procedural control flow graph and the second inter-procedural control flow graph to obtain a third inter-procedural control flow graph includes:
[0012] determining first path information that exists in the first inter-procedural control flow graph but does not exist in the second inter-procedural control flow graph, and pruning the first path information in the first inter-procedural control flow graph; and / or,
[0013] Second path information that exists in the second inter-procedural control flow graph but does not exist in the first inter-procedural control flow graph is determined, and the first inter-procedural control flow graph is completed according to the second path information.
[0014] In some embodiments, the predefined device identifier includes one or more of the following: an identifier of the device that hosts the application, an identifier generated based on user information associated with the device, an identifier defined based on the application, and an identifier defined based on a third-party software package.
[0015] In some embodiments, obtaining a second inter-procedural control flow graph for data leakage according to the function includes:
[0016] Obtaining the calling relationship of the function;
[0017] If it is determined according to the calling relationship that the calling operation of the device identifier is associated with the network data transmission operation, matching the calling operation of the device identifier with the network data transmission operation;
[0018] The second inter-process control flow graph is constructed according to the calling operation of the matching device identifier and the network data transmission operation.
[0019] In some embodiments, when it is determined that the calling operation of the device identifier is associated with a network data transmission operation based on the calling relationship, matching the calling operation of the device identifier with the network data transmission operation includes:
[0020] When the calling operation of the device identifier and the network data transmission operation are in the same thread and there is a calling relationship between the calling operation of the device identifier and the network data transmission operation, or there is an association relationship between the thread in which the calling operation of the device identifier is located and the thread in which the network data transmission operation is located, the calling operation of the device identifier and the network data transmission operation are matched.
[0021] In some embodiments, obtaining a leakage path of user data by the target application according to the third inter-process control flow graph includes:
[0022] constructing a list of sources and sinks based on device identifiers in the configuration file;
[0023] The propagation path of the data in the third inter-procedural control flow graph is traced based on the list including the source points and the sink points to obtain the leakage path.
[0024] In some embodiments, after obtaining a leakage path of user data by the target application according to the third inter-process control flow graph, the method further includes:
[0025] Obtaining preset application behavior rules, where the application behavior rules include one or more of the following: an application behavior of writing the device identifier to a file, an application behavior of obtaining the device identifier and sending the device identifier to a network, and an application behavior of sending the device identifier to a network based on a network data transmission operation;
[0026] The leakage paths are classified and counted based on the application behavior rules to obtain statistical results.
[0027] In a second aspect, this embodiment provides an application user tracking and detection device based on a dynamic and static combined technology, the device comprising:
[0028] a static analysis module, configured to obtain, based on an application package of a target application and a configuration file containing a predefined device identifier, a first inter-procedural control flow graph associated with the device identifier;
[0029] a dynamic analysis module, configured to determine, based on program behavior of the target application in a running state, functions associated with an application programming interface of the device identifier and an application programming interface of network data transmission, and obtain, based on the functions, a second inter-procedural control flow graph of data leakage;
[0030] an integration module, configured to integrate the first inter-procedural control flow graph and the second inter-procedural control flow graph to obtain a third inter-procedural control flow graph;
[0031] A data leakage path construction module is used to obtain a leakage path of user data from the target application according to the third inter-process control flow graph.
[0032] On the third aspect, in this embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the application user tracking detection method and device based on the dynamic and static combined technology described in the first aspect.
[0033] In a fourth aspect, a computer-readable storage medium is provided in this embodiment, on which a computer program is stored. When the computer program is executed by a processor, the method and device for application user tracking detection based on the dynamic and static combined technology described in the first aspect are implemented.
[0034] The above-mentioned application user tracking detection method and device based on the dynamic and static combined technology first forms a first inter-process control flow graph and a second inter-process control flow graph by static analysis and dynamic analysis respectively. By combining the first inter-process control flow graph and the second inter-process control flow graph, the data leakage path is completely and accurately constructed, solving the problems of static analysis path explosion and low dynamic analysis coverage. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 This is a diagram of an application environment of an application user tracking and detection method based on a dynamic and static combined technology in one embodiment;
[0036] Figure 2 1 is a flow chart of an application user tracking and detection method based on a dynamic and static combined technology in one embodiment;
[0037] Figure 3 A flowchart of an Android application user tracking and detection method in one embodiment;
[0038] Figure 4 A schematic diagram of a method for tracking and detecting Android application users in one embodiment;
[0039] Figure 5 A structural block diagram of an application user tracking detection device based on a dynamic and static combined technology in one embodiment;
[0040] Figure 6 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0041] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0042] The user tracking detection method based on the dynamic and static combined technology provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store data that server 104 needs to process. The data storage system can be integrated with server 104 or placed in the cloud or other network servers. Terminal-based detection and analysis of target applications can be performed to achieve user data tracking. Terminal 102 can be, but is not limited to, various personal computers, laptops, tablet computers, etc. Server 104 can be implemented as a standalone server or a server cluster consisting of multiple servers.
[0043] In one embodiment, Figure 2 As shown, a method for tracking and detecting application users based on the dynamic and static combined technology is provided. Figure 1 The terminal 102 in the example is used as an example to illustrate, including the following steps:
[0044] Step S202 : obtaining a first inter-process control flow graph associated with the device identifier according to the application package of the target application and the configuration file containing the predefined device identifier.
[0045] The application package of the target application can be in the form of source code or binary. The predefined device identifier is used to identify the device on which the target application is set. The device identifier can be a string, a number, etc. The configuration file is used to guide the analysis direction of the target application. Based on the device identifier in the configuration file, it can provide key nodes for user tracking detection for the target application analysis; the configuration file can also include information such as taint propagation rules and environmental configuration defined according to application requirements. The first inter-process control flow graph is used to indicate the possible propagation paths of data associated with the device identifier during the operation of the target application.
[0046] Optionally, the application package of the target application is parsed; in combination with the configuration information indicated by the configuration file, a control flow analysis is performed on the parsed application package to construct a control flow graph and a function call graph corresponding to the application package; and in combination with the control flow graph and the function call graph, a first inter-process control flow graph is obtained.
[0047] Step S204 , determining functions associated with the application programming interface of the device identifier and the application programming interface of the network data transmission according to the program behavior of the target application in the running state, and obtaining a second inter-process control flow graph of the data leakage according to the functions.
[0048] Among them, the functions associated with the device identifier application programming interface and the network data transmission application programming interface include functions that have a direct or indirect calling relationship with the device identifier API (application programming interface) and functions that have a direct or indirect calling relationship with the network data transmission API.
[0049] Optionally, the program behavior of the target application in the running state is obtained through a pre-written script, the functions in the target application behavior that directly or indirectly call the device identifier API and the network data transmission API and the function call relationship corresponding to these functions are determined, and based on the function call relationship, a data leakage chain associated with the acquisition and dissemination of user information data in the target application is constructed to obtain a second inter-process control flow graph constructed based on one or more data leakage chains.
[0050] Step S206 , integrating the first inter-procedural control flow graph and the second inter-procedural control flow graph to obtain a third inter-procedural control flow graph.
[0051] Since the first inter-process control flow graph is a graph obtained by static analysis of the target application, there is a possibility of path explosion, and the second inter-process control flow graph is a graph obtained by dynamic analysis of the target application, there is a possibility of path coverage and completion. Therefore, by integrating the first inter-process control flow graph and the second inter-process control flow graph, the advantages of the first inter-process control flow graph and the second inter-process control flow graph can be combined to obtain a third inter-process control flow graph that accurately analyzes the data leakage path. Optionally, when integrating the first inter-process control flow graph and the second inter-process control flow graph, after determining the common entry point and exit point of the two ICFGs, the duplicate nodes and redundant edges between the two inter-process control flow graphs can be removed, and the first inter-process control flow graph and the second inter-process control flow graph can be merged to obtain the third inter-process control flow graph.
[0052] Step S208 : obtaining a leakage path of user data by the target application according to the third inter-process control flow graph.
[0053] Optionally, after determining the starting node of the third inter-process control flow graph, the data propagation path is tracked by traversing the third inter-process control flow graph until the path starting from the starting node is explored. The obtained data flow path is the leakage path of user data by the target application.
[0054] In the above-mentioned application user tracking detection method based on the combination of dynamic and static technologies, a first inter-process control flow graph associated with data leakage is obtained by static analysis of the target application program, and a second inter-process control flow graph is obtained by dynamic analysis of the target application in the running state. By integrating the first inter-process control flow graph and the second inter-process control flow graph, the problem of low detection accuracy caused by the path explosion defect that may exist in the first inter-process control flow graph is overcome, and at the same time, the problem of narrow detection coverage caused by the incomplete path coverage defect that may exist in the second inter-process control flow graph is overcome, thereby achieving the effect of taking into account both high detection coverage and detection accuracy.
[0055] In one embodiment, integrating the first inter-procedural control flow graph and the second inter-procedural control flow graph to obtain a third inter-procedural control flow graph includes: determining first path information that exists in the first inter-procedural control flow graph but does not exist in the second inter-procedural control flow graph, and pruning the first path information in the first inter-procedural control flow graph; and / or determining second path information that exists in the second inter-procedural control flow graph but does not exist in the first inter-procedural control flow graph, and completing the first inter-procedural control flow graph based on the second path information.
[0056] Among them, the first path information and the second path information include information such as boundary conditions and intermediate nodes in the data leakage path. Optionally, based on all the first path information that exists in the first inter-process control flow graph and does not exist in the second inter-process control flow graph, the paths that exist in the first process control flow graph but are not touched during the actual execution process are determined, and the paths that are not touched during the actual execution process are pruned based on the first inter-process control flow graph. At the same time, the information that exists in the second inter-process control flow graph but does not exist in the first inter-process control flow graph is used as the second path information, and the edges and nodes in the second path information are supplemented to the first inter-process control flow graph. It is understandable that, according to needs, it is also possible to perform pruning only based on the first path information or to complete only based on the second path information.
[0057] Among them, the first inter-process control flow graph may be over-analyzed to obtain paths that are not related to data leakage, while the second process control flow graph is the data leakage path involved in the actual execution process. Therefore, this embodiment uses the first path information to identify paths that are not touched in the actual execution process, thereby removing these redundant parts in the first inter-process control flow graph generated by static analysis, making the graph structure more streamlined and accurate; the second path information in the second inter-process control flow graph analyzed by dynamic instrumentation is used to complete the paths that were not identified in the first control flow graph.
[0058] In one embodiment, the predefined device identifier includes one or more of the following: an identifier of the device hosting the application, an identifier generated based on user information associated with the device, an identifier defined based on the application, and an identifier defined based on a third-party software package.
[0059] User information refers to information that can identify a user, including but not limited to user fingerprints and facial features stored on the device. Third-party software packages are additional software components provided by providers other than the native system provider of the device or the primary developer of the target application.
[0060] Optionally, the predefined device identifiers include one or more of the following: an officially defined device ID, an ID generated using fingerprint information associated with the device, or an ID customized by an app and / or a third-party software development kit (SDK). Furthermore, after obtaining the predefined device identifiers, a device identifier library can be constructed.
[0061] The basis for detecting user tracking behavior of Android applications is the identification of device identifiers. In related technologies, the identification of device identifiers mainly focuses on officially defined device identifiers. This embodiment combines the device identifier associated with the device, as well as the device identifiers generated by the APP and third-party software packages, to improve the detection coverage, and solves the problem that the detection coverage has certain limitations and cannot fundamentally solve the problem of the proliferation of APP cross-application tracking and targeted push.
[0062] In one embodiment, a second inter-process control flow graph for data leakage is obtained based on a function, including: obtaining a calling relationship of the function; matching the calling operation of the device identifier with the network data transmission operation when determining that the calling operation of the device identifier is associated with the network data transmission operation based on the calling relationship; and constructing a second inter-process control flow graph based on the matching calling operation of the device identifier and the network data transmission operation.
[0063] The acquired function calling relationships include calling relationships obtained by sorting out functions that directly and indirectly call device identifiers, and / or calling relationships obtained by sorting out functions that are directly and indirectly related to network data transmission operations.
[0064] The association of a device identifier call operation with a network data transmission operation refers to the target application's data transmission process involving operations such as obtaining and reading data from the device identifier, as well as network data transmission, i.e., transmitting data to an external network. Optionally, determining that the device identifier call operation is associated with the network data transmission operation includes: determining that the device identifier call operation matches the network data transmission operation when a data leakage chain can be derived by combining the device identifier call operation and the network data transmission operation.
[0065] Optionally, code injected into the target process can be used to capture function call behavior within the target application's program behavior, identifying function calls related to network data transmission operations. Customized detection code can then be used to determine the data propagation process of the device identifier and identify function calls related to the device identifier. Function call stacks can be traced to gather information across multiple processes within the application, identifying function call relationships. Based on these function call relationships, the data leakage path can be identified by identifying the device identifier call operations and network data transmission operations. This data leakage path can then be represented as a second inter-process control flow graph.
[0066] In this embodiment, by obtaining the calling relationship of the function and determining that the data transmission process involves the data of the device identifier and the network data transmission, the actual data leakage path can be screened based on the matching device identifier calling operation and network data transmission operation, thereby constructing an accurate second inter-process control flow graph.
[0067] Furthermore, in one embodiment, when it is determined based on the calling relationship that the calling operation of the device identifier is associated with the network data transmission operation, the calling operation of the device identifier and the network data transmission operation are matched, including: when the calling operation of the device identifier and the network data transmission operation are in the same thread and there is a calling relationship between the calling operation of the device identifier and the network data transmission operation, or when there is an association relationship between the thread in which the calling operation of the device identifier is located and the thread in which the network data transmission operation is located, the calling operation of the device identifier and the network data transmission operation are matched.
[0068] Optionally, when the thread in which the device identifier's calling operation is located and the thread in which the network data transmission operation is located are the same thread, if there is a direct or indirect calling relationship between the device identifier's calling operation and the network data transmission operation, it can be determined that the device identifier's calling operation matches the network data transmission operation; when the thread in which the device identifier's calling operation is located and the thread in which the network data transmission operation is located are not the same thread, or there is no direct or indirect calling relationship between the device identifier's calling operation and the network data transmission operation, when it is detected that the thread in which the device identifier's calling operation is located has thread operations such as creating a new thread, notifying other threads, and running other threads, and the thread operation is related to network data transmission, it is determined that the device identifier's calling operation matches the network data transmission operation; similarly, when it is detected that the thread in which the network data transmission operation is located has thread operations such as creating a new thread, notifying other threads, and running other threads, and the thread operation is associated with the device identifier or network data transmission, it can also be determined that the device identifier's calling operation matches the network data transmission operation.
[0069] In this embodiment, the calling operation of the device identifier and the network data transmission operation are matched by the thread information corresponding to the calling operation of the device identifier, and various data leakage paths are obtained. The fine-grained division of the associated matching of the device identifier acquisition behavior and the network Socket operation is realized, thereby improving the detection coverage corresponding to the control flow graph between the second process.
[0070] In one embodiment, a leakage path of user data of a target application is obtained according to a third inter-process control flow graph, including: constructing a list including source points and sink points according to a device identifier in a configuration file; and tracing a propagation path of data in the third inter-process control flow graph based on the list including source points and sink points to obtain a leakage path.
[0071] Sources are the points where sensitive data is acquired, such as reading device information, location information, or device IDs. Sinks are where data may be leaked or used, such as network transmission, logging, or file writing. Predefined lists of sources and sinks are used to identify key locations during the target application's execution that could lead to user data leakage. Alternatively, a list of sources and sinks can be constructed using device identifiers obtained through predefined methods.
[0072] Optionally, control flow analysis is performed based on the application package and configuration file to obtain a first inter-process control flow graph of the target application; after integrating the first inter-process control flow graph and the second inter-process control flow graph to obtain a third inter-process control flow graph, the solver obtains data flow path information from the source point to the sink point for the third inter-process control flow graph to obtain the data flow path.
[0073] In this embodiment, a first inter-process control flow graph is constructed based on the flow path obtained by solving the device identifier, so that the first inter-process control flow graph can provide a data leakage path related to user information using the device.
[0074] In one embodiment, after obtaining the leakage path of user data of the target application according to the third inter-process control flow graph, the method also includes: obtaining preset application behavior rules, the application behavior rules including one or more of the following: application behavior of writing a device identifier to a file, application behavior of obtaining a device identifier and sending the device identifier to a network, and application behavior of sending a device identifier to a network based on a network data transmission operation; classifying and counting the leakage paths based on the application behavior rules to obtain statistical results.
[0075] Optionally, after detecting that the data leakage path includes obtaining a device identifier from any file, and when determining that the path also includes an application behavior of sending the device identifier to the network through a Socket, the path is judged to be consistent with the application behavior of obtaining the device identifier from the written file and sending the device identifier to the network.
[0076] Optionally, when it is detected that the data leakage path includes an application behavior of sending the device identifier to the network through the Socket, it is determined that the path meets the application behavior of sending the device identifier to the network based on the network data transmission operation.
[0077] Optionally, when it is detected that the data leakage path includes an action of writing a device identifier into any file, it is determined that the path complies with the application action of writing a device identifier into a file.
[0078] In this embodiment, by classifying and counting the leakage paths, it is possible to facilitate subsequent analysis of the user tracking detection results.
[0079] In one embodiment, the related art solves the problem of narrow detection coverage and low detection accuracy due to a single analysis method in user tracking detection methods for Android applications. Figure 3 A flowchart of a user tracking detection method for Android applications is proposed. This method can analyze Android applications through a combination of dynamic and static methods. The combination of the two analyses can more accurately detect the user tracking behavior of Android applications.
[0080] like Figure 3 As shown, including:
[0081] Step S301: Obtain the APK file of the target application.
[0082] Wherein, the APK file is the application package in the above embodiment. Optionally, the APK file of the target application can be obtained through a mainstream application distribution platform, or the APK file of the required application version can be obtained on a third-party download platform.
[0083] Step S302 , sort out and collect three different types of device identifiers: officially defined device ID, ID generated using device fingerprint information, and ID customized by APP and / or SDK, and build a device identifier library.
[0084] Collecting officially defined device IDs includes: obtaining standard definitions and usage of device IDs by consulting official technical documents provided by device manufacturers or platforms, and collecting officially defined device identifiers from official documents.
[0085] Collecting device fingerprint information to generate IDs includes: collecting device identifiers generated by device fingerprint information from public code libraries and academic papers, and collecting content related to device fingerprint information by searching and analyzing public libraries and related academic papers, including methods and implementations for generating device identifiers.
[0086] Collecting IDs customized by APPs and / or SDKs includes: analyzing the device identifiers used in some mobile applications and software development kits, and collecting some device identifiers customized by mobile applications and / or SDKs; and further obtaining the device identifiers customized by developers in the code and the ID information actually used on the device by performing reverse engineering analysis on the target application.
[0087] Step S303 : Perform static taint analysis and dynamic instrumentation analysis on the target application to obtain a first inter-procedural control flow graph and a second inter-procedural control flow graph of data leakage, respectively.
[0088] Static taint analysis involves parsing the APK file, constructing a program dependency graph based on the parsed APK file, performing control flow analysis, and obtaining a first inter-procedural control flow graph for the target application. Furthermore, taints are identified based on a predefined configuration file, and the paths within the target application's inter-procedural control flow graph are tracked using the taints identified in the configuration file to analyze and obtain data flow paths. During step S303, the propagation path of the taint within the target application is not tracked, and the first inter-procedural control flow graph is directly obtained.
[0089] Dynamic instrumentation analysis includes: tracking the target APP (target application) in running state, the program call stack of the target APP, and obtaining the data transmission path of the target APP during runtime based on the program call stack.
[0090] Step S304 : constructing a data leakage path diagram by merging the first inter-process control flow graph and the second inter-process control flow graph.
[0091] The merging includes pruning and completion. Pruning refers to pruning the third inter-procedural control flow graph obtained by static taint analysis, and completion refers to completing the second inter-procedural control flow graph obtained by dynamic instrumentation analysis. Optionally, the inter-procedural control flow graphs obtained by static taint analysis and dynamic instrumentation analysis are integrated, and the inter-procedural control flow graph obtained by static taint analysis is pruned using the inter-procedural control flow graph of dynamic instrumentation analysis. The information in the inter-procedural control flow graph of dynamic instrumentation analysis is then used to complete the completion, and a complete and accurate data leakage path diagram is generated based on the merged third inter-procedural control flow graph.
[0092] Furthermore, after executing step S304, all key nodes involving device identifiers and network data transmission in the application program can be monitored while the APP is running, and the data leakage mode in the data leakage path diagram can be matched with the application behavior rules. The data leakage behavior can be analyzed and classified according to the matching results to facilitate the identification and statistics of various data leakage behaviors. Optionally, the application behavior rule matching includes statistical leakage behaviors that meet the following rules: obtaining a device identifier from an API and ultimately writing it to a file, obtaining a device identifier from an API and ultimately sending it to the network via a Socket, software generating a custom device identifier and ultimately writing it to a file, software generating a custom device identifier and ultimately sending it to the network via a Socket, obtaining a device identifier from a file and ultimately sending it to the network via a Socket.
[0093] Optionally, static taint analysis can be performed on the target app based on the Flowdroid framework; dynamic instrumentation analysis can be performed on the target app based on the dynamic instrumentation technology framework Frida. Figure 4 A schematic diagram of another Android application user tracking detection method is provided. Figure 4 As shown, after obtaining a list of device identifiers, three different types of device identifiers are obtained: officially defined device ID, device fingerprint information generated ID, and APP and / or SDK customized ID. Then, static analysis and dynamic analysis are performed on the device identifier list.
[0094] Static taint analysis of a target app involves parsing and preprocessing the mobile app's code, including reading the APK file, extracting its DEX file, and converting it into an intermediate representation suitable for static analysis. The converted code is then read and the target app's first interprocedural control flow graph (ICFG) is constructed. This ICFG analyzes the call relationships between methods within the program, thereby inferring the data flow path within the application and generating data flow analysis results. The ICFG describes the execution order of statements and instructions within the application, as well as the function call relationships, helping to determine the application's execution path. The data flow analysis results are primarily obtained by analyzing the static method call graph within the ICFG to determine the data call sequence and possible execution paths. Context-sensitive and object-sensitive analysis methods are used to minimize false positives and false negatives. A predefined list of sources and sinks is generated based on device identifier categories. This list of sources and sinks identifies key locations that could potentially leak sensitive information. The forward solver constructs a worklist starting from the source. The worklist includes the statement types of each item in the data flow analysis list and the data flow path obtained by expanding the IFDS (Inter-procedural, Finite, Distributive, Subset Problem) algorithm. The worklist constructed by the forward solver is used to provide and maintain contextual information and path information for the backward solver. Based on the worklist constructed by the forward solver, the backward solver starts from the sink and traces back to the source point in reverse. It confirms the rationality of the data flow path from the sink to the source point, removes redundant data flow paths, and combines the path information generated by the forward solver to determine whether potential data leakage actually exists, implement data flow analysis, and construct a data leakage graph. In this embodiment, after constructing the first inter-process control flow graph, the forward solver and the backward solver do not temporarily obtain a data leakage graph based on the analysis of the first inter-process control flow graph. Instead, on the basis of the first inter-process control flow graph, a second inter-process control flow graph generated by dynamic instrumentation analysis is combined to obtain a third inter-process control flow graph. Based on the third inter-process control flow graph, data flow analysis is performed to construct a data leakage graph containing a data leakage path.
[0095] Dynamic analysis of the target APP includes: using the Java reflection mechanism to dynamically load and manipulate Java classes and methods, and executing the written scripts through the JavaScript engine, so that the code injected into the target process can dynamically control the application behavior through JavaScript, monitor and intercept sensitive API calls related to user privacy data processing, and obtain the network traffic during the operation of the target APP, where sensitive API refers to API related to device identifier calls; the purpose of obtaining the network traffic during the operation of the target APP is to obtain the network Socket operation when the network information transmission is realized. Insert custom detection code, the detection code tracks the function call stack through the dynamic insertion method, and HOOKs the key nodes involved in the acquisition of device identifiers when the target APP is running based on sensitive API calls to achieve device identifier tracking, thereby obtaining device identifier acquisition behavior; by tracking the function call stack, the detection code can also HOOK all key nodes involved in network data transmission when the target APP is running, and obtain the function call relationship corresponding to the network Socket operation. According to the function call relationship between the device identifier acquisition behavior and the network Socket operation, the threads corresponding to the two behaviors are determined, and association matching is implemented based on the threads corresponding to the two behaviors: when the device identifier acquisition behavior and the network Socket operation are in the same thread and have a direct or indirect calling relationship, the device identifier acquisition behavior and the network Socket operation are matched; when the device identifier acquisition behavior and the network Socket operation are in different threads or do not have a calling relationship, the thread where the device identifier acquisition behavior is located may directly create a new thread, notify the handler to run the thread, or run the thread managed by the thread pool. According to the association relationship between the thread associated with the device identifier and the thread corresponding to the network Socket operation, the device identifier acquisition behavior and the network Socket operation are matched, and an inter-process control flow graph containing a data leakage path is obtained to obtain the data leakage path.
[0096] When dynamically analyzing the target APP, information is collected between multiple processes of the application by adopting the dynamic instrumentation method; the dynamic instrumentation method is used to accurately track the data leakage path, and the fine-grained division of the associated matching of device identifier acquisition behavior and network Socket operations can be achieved to maximize the capture and analysis of device identifier acquisition behavior and its subsequent network Socket operations, thereby filtering out the actual data leakage path from the data leakage graph.
[0097] Finally, the data leakage chain obtained by dynamic analysis and the data flow analysis of the ICFG (Interprocedural Control Flow Graph) performed by static analysis are combined to obtain a data leakage path diagram, and the behavior of the application tracking users is identified based on the data leakage path diagram.
[0098] Most of the related technologies in data leakage analysis are based on a single static taint analysis technology or a single dynamic instrumentation analysis technology. Among them, static taint analysis technology is to scan the APP code without running the target APP, find all the execution flows of the APP to detect the taint source leakage path within the APP. It can be used relatively easily in the detection of large quantities of APPs, and its code coverage is also high, but it has shortcomings that are difficult to overcome. Static taint analysis technology has the problem of path explosion caused by over-analysis, and the analyzed path may not be actually called. Dynamic instrumentation analysis technology is to run the APP in a real or virtual environment, and inject instrumentation code during the operation to monitor the runtime status. Compared with static analysis, it is more realistic, but dynamic instrumentation analysis technology also has the defect of incomplete path coverage.
[0099] Compared to related technologies, this embodiment identifies and explores the definition of device identifiers, sorting and collecting three different types of device identifiers. This creates a device identifier library that is far richer than existing commonly used identifiers, thus improving detection coverage. Furthermore, after static and dynamic analysis each generate inter-procedural control flow graphs, the statically generated graphs are pruned and complemented with dynamically generated graphs. By combining static taint analysis with dynamic instrumentation, the generation and propagation of device identifiers is tracked, constructing a data leakage path map. This approach effectively addresses the issues of path explosion in static analysis and low coverage in dynamic analysis. Furthermore, to accurately track data leakage paths and construct a complete leakage chain within an app, from data acquisition to data transmission, dynamic instrumentation is employed to correlate and match device identifier acquisition behavior with network socket operations in various scenarios, enabling accurate detection of leakage behavior. Therefore, the method in this embodiment boasts a wide detection range and high accuracy, providing technical support for detecting illegal apps and preventing the leakage of user privacy information.
[0100] Based on the same inventive concept, the embodiments of the present application also provide an application user tracking and detection device based on a dynamic and static combination technology for implementing the aforementioned application user tracking and detection method based on a dynamic and static combination technology. The implementation solution provided by this device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations of one or more embodiments of the application user tracking and detection device based on a dynamic and static combination technology provided below can be found in the above limitations of the application user tracking and detection method based on a dynamic and static combination technology, and will not be repeated here.
[0101] In one embodiment, Figure 5 As shown, an application user tracking detection device based on a dynamic and static combined technology is provided, comprising: a static analysis module, a dynamic analysis module, an integration module and a data leakage path construction module; wherein,
[0102] a static analysis module, configured to obtain a first inter-procedural control flow graph associated with the device identifier based on an application package of a target application and a configuration file containing a predefined device identifier;
[0103] a dynamic analysis module, configured to determine, based on program behavior of a target application in a running state, functions associated with an application programming interface of a device identifier and an application programming interface of network data transmission, and obtain a second inter-procedural control flow graph of data leakage based on the functions;
[0104] An integration module, configured to integrate the first inter-procedural control flow graph and the second inter-procedural control flow graph to obtain a third inter-procedural control flow graph;
[0105] The data leakage path construction module is used to obtain the leakage path of the target application to the user data according to the third inter-process control flow graph.
[0106] Optionally, the predefined device identifier includes one or more of the following: an identifier of the device that hosts the application, an identifier generated based on user information associated with the device, an identifier defined based on the application, and an identifier defined based on a third-party software package.
[0107] In some embodiments, the integration module integrates the first inter-process control flow graph and the second inter-process control flow graph to obtain a third inter-process control flow graph, including: determining first path information that exists in the first inter-process control flow graph but does not exist in the second inter-process control flow graph, and pruning the first path information in the first inter-process control flow graph; and / or, determining second path information that exists in the second inter-process control flow graph but does not exist in the first inter-process control flow graph, and completing the first inter-process control flow graph based on the second path information.
[0108] In some embodiments, the dynamic analysis module obtains a second inter-process control flow graph of data leakage based on the function, including: obtaining the calling relationship of the function; matching the calling operation of the device identifier with the network data transmission operation when it is determined based on the calling relationship that the calling operation of the device identifier is associated with the network data transmission operation; and constructing a second inter-process control flow graph based on the matching calling operation of the device identifier and the network data transmission operation. Optionally, matching the calling operation of the device identifier with the network data transmission operation when it is determined based on the calling relationship that the calling operation of the device identifier is associated with the network data transmission operation includes: matching the calling operation of the device identifier with the network data transmission operation when the calling operation of the device identifier and the network data transmission operation are in the same thread and there is a calling relationship between the calling operation of the device identifier and the network data transmission operation, or when there is an association relationship between the thread where the calling operation of the device identifier is located and the thread where the network data transmission operation is located.
[0109] In some embodiments, the data leakage path construction module obtains the leakage path of the target application to the user data based on the third inter-process control flow graph, including: constructing a list containing source points and sink points based on the device identifier in the configuration file; tracking the propagation path of the data in the third inter-process control flow graph based on the list containing source points and sink points to obtain the leakage path.
[0110] In some embodiments, after the data leakage path construction module obtains the leakage path of user data of the target application according to the third inter-process control flow graph, the execution method also includes: obtaining preset application behavior rules, the application behavior rules including one or more of the following: application behavior of writing a device identifier to a file, application behavior of obtaining a device identifier and sending the device identifier to a network, and application behavior of sending a device identifier to a network based on a network data transmission operation; and classifying and counting the leakage paths based on the application behavior rules to obtain statistical results.
[0111] Each module in the aforementioned device for tracking and detecting an application user based on a combination of dynamic and static technologies can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor within a computer device in the form of hardware, or can be stored in a computer device memory in the form of software, so that the processor can call and execute the corresponding operations of each module.
[0112] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 6As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected via a system bus, and the communication interface, the display unit and the input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a method for tracking and detecting an application user based on a combination of dynamic and static technologies is implemented. The display unit of the computer device is used to form a visually visible picture, which can be a display screen or a projection device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse.
[0113] Those skilled in the art will understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0114] In one embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.
[0115] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0116] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0117] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.
[0118] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0119] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A method for tracking and detecting application users based on a combination of dynamic and static technologies, characterized in that: The method comprises: Obtaining, according to an application package of a target application and a configuration file containing a predefined device identifier, a first inter-procedural control flow graph associated with the device identifier; determining, based on program behavior of the target application in a running state, functions associated with an application programming interface of the device identifier and an application programming interface of network data transmission, and obtaining a second inter-procedural control flow graph of data leakage based on the functions; Integrating the first inter-procedural control flow graph and the second inter-procedural control flow graph to obtain a third inter-procedural control flow graph; A leakage path of user data from the target application is obtained according to the third inter-process control flow graph.
2. The method according to claim 1, characterized in that The integrating the first inter-procedural control flow graph and the second inter-procedural control flow graph to obtain a third inter-procedural control flow graph includes: determining first path information that exists in the first inter-procedural control flow graph but does not exist in the second inter-procedural control flow graph, and pruning the first path information in the first inter-procedural control flow graph; and / or, Second path information that exists in the second inter-procedural control flow graph but does not exist in the first inter-procedural control flow graph is determined, and the first inter-procedural control flow graph is completed according to the second path information.
3. The method according to claim 1, characterized in that The predefined device identifier includes one or more of the following: an identifier of the device hosting the application, an identifier generated based on user information associated with the device, an identifier defined based on the application, and an identifier defined based on a third-party software package.
4. The method according to claim 1, wherein The step of obtaining a second inter-procedural control flow graph for data leakage according to the function includes: Obtaining the calling relationship of the function; If it is determined according to the calling relationship that the calling operation of the device identifier is associated with the network data transmission operation, matching the calling operation of the device identifier with the network data transmission operation; The second inter-process control flow graph is constructed according to the calling operation of the matching device identifier and the network data transmission operation.
5. The method according to claim 4, characterized in that When it is determined according to the calling relationship that the calling operation of the device identifier is associated with the network data transmission operation, matching the calling operation of the device identifier with the network data transmission operation includes: When the calling operation of the device identifier and the network data transmission operation are in the same thread and there is a calling relationship between the calling operation of the device identifier and the network data transmission operation, or there is an association relationship between the thread in which the calling operation of the device identifier is located and the thread in which the network data transmission operation is located, the calling operation of the device identifier and the network data transmission operation are matched.
6. The method according to claim 1, characterized in that Obtaining a leakage path of user data by the target application according to the third inter-process control flow graph includes: constructing a list of sources and sinks based on device identifiers in the configuration file; The propagation path of the data in the third inter-procedural control flow graph is traced based on the list including the source points and the sink points to obtain the leakage path.
7. The method according to claim 1, characterized in that After obtaining a leakage path of user data by the target application according to the third inter-process control flow graph, the method further includes: Obtaining preset application behavior rules, where the application behavior rules include one or more of the following: an application behavior of writing the device identifier to a file, an application behavior of obtaining the device identifier and sending the device identifier to a network, and an application behavior of sending the device identifier to a network based on a network data transmission operation; The leakage paths are classified and counted based on the application behavior rules to obtain statistical results.
8. An application user tracking and detection device based on a dynamic and static combined technology, characterized in that: The device comprises: a static analysis module, configured to obtain, based on an application package of a target application and a configuration file containing a predefined device identifier, a first inter-procedural control flow graph associated with the device identifier; a dynamic analysis module, configured to determine, based on program behavior of the target application in a running state, functions associated with an application programming interface of the device identifier and an application programming interface of network data transmission, and obtain, based on the functions, a second inter-procedural control flow graph of data leakage; an integration module, configured to integrate the first inter-procedural control flow graph and the second inter-procedural control flow graph to obtain a third inter-procedural control flow graph; A data leakage path construction module is used to obtain a leakage path of user data from the target application according to the third inter-process control flow graph.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Mobile application privacy leakage detection method and device based on bidirectional path tracing
CN121327828A
Method and device for detecting privacy leakage of mobile application based on bidirectional path tracing
CN121327828B