Application security sharing method and device, equipment, storage medium and program product

By performing application risk detection, cybersecurity assessment, and source detection during sharing operations, the information security risks caused by employees installing unauthorized applications on their mobile devices were resolved, ensuring the secure sharing of sensitive information.

CN120834940APending Publication Date: 2025-10-24SHENZHEN COMTOP INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510807468.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-10-24

AI Technical Summary

Technical Problem

When employees install unauthorized applications on their mobile devices for work, it poses a risk to corporate information security, especially the leakage of sensitive information.

Method used

By performing application risk detection, network security assessment, and application source detection during the sharing operation, the detection results are integrated to determine the security of the sharing operation, and the sharing operation is completed when it corresponds to the target user after safety is confirmed.

Benefits of technology

It enhances the security of application sharing, blocks the leakage path of unauthorized applications, and ensures that sensitive information is not transmitted to unauthorized applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120834940A_ABST
    Figure CN120834940A_ABST
Patent Text Reader

Abstract

The invention relates to an application security sharing method and device, computer equipment, a computer readable storage medium and a computer program product. Comprising the steps of displaying an information determination page in response to a sharing operation on a target application; determining a page based on the information, and performing application risk detection, network security evaluation and application source detection; performing information integration on the multiple detection results, and determining whether the sharing operation is a safe sharing operation or not; under the condition that the sharing operation is the safe sharing operation, determining whether the sharing operation corresponds to the target user or not; and under the condition that the sharing operation corresponds to the target user, completing the sharing operation through the target application. Through the above mode, when the user executes the sharing operation, the terminal performs application risk detection, network security evaluation and application source detection, and further identifies the user, so that abnormal behaviors can be monitored, an unauthorized application leakage path can be blocked, and the application sharing security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, in particular to an application security sharing method and device, computer equipment, computer readable storage medium and computer program product. BACKGROUND

[0002] With the development of mobile informatization, mobile office has become a common solution to improve enterprise operation efficiency. However, while bringing convenience, this mode also introduces significant risks in mobile security and enterprise information security management. In particular, it is worth noting that when employees install and use non-company authorized or designated application programs on mobile devices for office work, it will cause serious security risks. Such behavior may lead employees to transmit sensitive information (such as key data, links, classified documents, etc.) in enterprise applications to non-authorized applications through the sharing function of mobile devices, thereby forming a data leakage path, endangering enterprise information security and causing potential losses. SUMMARY

[0003] Therefore, it is necessary to provide an application security sharing method, device, computer equipment, computer readable storage medium and computer program product to improve the security of application sharing.

[0004] In a first aspect, the present application provides an application security sharing method, comprising:

[0005] In response to a sharing operation on a target application, displaying an information determination page;

[0006] Based on the information determination page, performing application risk detection, network security assessment and application source detection;

[0007] Integrating the detection results of the application risk detection, the assessment results of the network security assessment, and the detection results of the application source detection to determine whether the sharing operation is a safe sharing operation;

[0008] In the case that the sharing operation is a safe sharing operation, determining whether the sharing operation corresponds to a target user;

[0009] In the case that the sharing operation corresponds to the target user, completing the sharing operation through the target application.

[0010] In one of the embodiments, the method further comprises:

[0011] In the case that the detection result of the application risk detection indicates that the target application has no risk, the assessment result of the network security assessment indicates that the network environment is normal, and the detection result of the application source detection indicates that the target application has a source, it is determined that the sharing operation is a safe sharing operation.

[0012] In one of the embodiments, the application risk detection comprises:

[0013] According to the application type of the target application, determine the corresponding vulnerability detection strategy, code detection strategy, data risk detection strategy and permission detection strategy;

[0014] According to the vulnerability detection strategy, detect whether there is a vulnerability in the configuration information of the target application;

[0015] According to the code detection strategy, detect whether there is malicious code in the code of the target application;

[0016] According to the data risk detection strategy, detect whether the target application has data risk;

[0017] According to the permission detection strategy, detect whether there is an exception in the permission information of the target application;

[0018] According to the vulnerability detection result, the code detection result, the data risk detection result and the permission detection result, determine the detection result of the application risk detection.

[0019] In one of the embodiments, the network security evaluation comprises:

[0020] According to the network speed and network delay, determine the network quality information;

[0021] According to the network type and network sharing situation, determine the network privacy degree;

[0022] According to the network quality information and the network privacy degree, determine the evaluation result of the network security evaluation.

[0023] In one of the embodiments, the application source detection comprises:

[0024] According to the version number, the developer information and the release date of the target application, determine the source of the target application, and obtain the detection result of the application source detection.

[0025] In one of the embodiments, determining whether the sharing operation corresponds to the target user comprises:

[0026] According to the face image or according to the user password, determine whether the sharing operation corresponds to the target user.

[0027] Secondly, the application also provides an application security sharing device, comprising:

[0028] The display module is configured to display an information determination page in response to a sharing operation on a target application;

[0029] The detection module is configured to perform application risk detection, network security evaluation and application source detection based on the information determination page;

[0030] The integration module is configured to integrate the detection result of the application risk detection, the evaluation result of the network security evaluation, and the detection result of the application source detection, and determine whether the sharing operation is a safe sharing operation.

[0031] The determination module is configured to determine whether the sharing operation corresponds to the target user when the sharing operation is a safe sharing operation.

[0032] The sharing module is configured to complete the sharing operation through the target application when the sharing operation corresponds to the target user.

[0033] In a third aspect, the present application also provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method in the first aspect when executing the computer program.

[0034] In a fourth aspect, the present application also provides a computer readable storage medium, which stores a computer program, and the computer program implements the steps of the method in the first aspect when executed by a processor.

[0035] In a fifth aspect, the present application also provides a computer program product, comprising a computer program, and the computer program implements the steps of the method in the first aspect when executed by a processor.

[0036] The application security sharing method, device, computer device, computer readable storage medium and computer program product described above display an information determination page in response to a sharing operation on a target application, perform application risk detection, network security evaluation and application source detection based on the information determination page, integrate the detection result of the application risk detection, the evaluation result of the network security evaluation, and the detection result of the application source detection, and determine whether the sharing operation is a safe sharing operation. When the sharing operation is a safe sharing operation, it is determined whether the sharing operation corresponds to the target user. When the sharing operation corresponds to the target user, the sharing operation is completed through the target application. In this way, when a user performs a sharing operation, the terminal performs application risk detection, network security evaluation and application source detection, and further identifies the user, which can monitor abnormal behavior, block unauthorized application leakage paths, and improve the security of application sharing. BRIEF DESCRIPTION OF DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the drawings needed to be used in the description of the embodiments of the present application or the related art will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other related drawings can also be obtained without creative labor.

[0038] Figure 1 A flowchart of an embodiment of a method for applying a secure sharing method;

[0039] Figure 2 A flowchart of an embodiment of a method for applying a secure sharing method;

[0040] Figure 3 A block diagram of an embodiment of a secure sharing device for applying a secure sharing method;

[0041] Figure 4 An internal structure diagram of a computer device in an embodiment. DETAILED DESCRIPTION

[0042] In order to make the purposes, technical solutions and advantages of the present application clearer, further detailed description will be made to the present application in combination with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and not to limit the present application.

[0043] It should be noted that the terms "first", "second", and the like used in the present application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "include" and "have" and any variations thereof used in the present application are intended to cover non-exclusive inclusion. The term "multiple" used in the present application refers to two or more. The term "and / or" used in the present application refers to one of the options or any combination of multiple options.

[0044] In an exemplary embodiment, as shown in Figure 1 A method for applying a secure sharing method is provided. This embodiment is exemplified by the method applied to a terminal. It should be understood that the method can also be applied to a system including a terminal and a server, and implemented through the interaction of the terminal and the server. The terminal 102 can be, but is not limited to, various personal computers, notebook computers, smart phones, tablet computers, unmanned aerial vehicles, low-altitude flying vehicles, Internet of Things devices, and portable wearable devices. The Internet of Things device can be a smart speaker, a smart television, a smart air conditioner, a smart vehicle device, a projection device, etc. The portable wearable device can be a smart watch, a smart bracelet, a head-mounted device, etc. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, smart glasses, etc.

[0045] In this embodiment, the method includes the following steps:

[0046] Step 102, in response to a sharing operation on a target application, displaying an information determination page.

[0047] The terminal is provided with an input module, which can be a mouse, a keyboard, or a touch screen. Taking a mobile phone as an example, a user triggers an operation (e.g., clicking, sliding, etc.) on an interface element on the screen to perform a sharing operation on a target application.

[0048] For example, the terminal displays a chat page of a target application, and the chat page includes at least one sharing button. The sharing operation can be triggered by clicking any sharing button on the page. For example, a user clicks a sharing button in an application, and the terminal displays a sharing menu including at least one application option. The sharing operation can be triggered by clicking an application option corresponding to the target application.

[0049] The terminal is provided with a display module, and the display module displays an information determination page upon triggering of the sharing operation. Optionally, the information determination page can be a sharing loading page, which displays a loading progress bar or a buffering countdown.

[0050] At step 104, based on the information determination page, application risk detection, network security assessment, and application source detection are performed.

[0051] The terminal performs application risk detection, network security assessment, and application source detection by reading application information and state information. Optionally, the information determination page displays detection progress and detection results.

[0052] In an optional implementation, application risk detection is performed to determine whether the target application is a risk application, and a detection result is obtained. Optionally, application risk detection is performed to determine whether a risk application is installed on the terminal, and a detection result is obtained.

[0053] In an optional implementation, application source detection is performed to determine whether the target application has a source. Optionally, application source detection is performed to determine whether all applications installed on the terminal have a source.

[0054] It can be understood that the application source refers to an initial source channel or path through which a user obtains and installs an application. Optionally, a secure source channel or path is pre-set, and the application source detection is achieved by detecting whether the application source belongs to the secure source channel or path. If the application source belongs to the secure source channel or path, it is determined that the application has a source, otherwise, it is determined that the application is a sourceless application.

[0055] Step 106, information integration is performed on the detection result of the application risk detection, the evaluation result of the network security evaluation, and the detection result of the application source detection, and it is determined whether the sharing operation is a safe sharing operation.

[0056] In an optional implementation, if the detection result of the application risk detection, the evaluation result of the network security evaluation, and the detection result of the application source detection are all normal, it is determined that the sharing operation is a safe sharing operation. For example, if it is detected that the target application has no risk, the network environment is normal, and the target application has a source, it is determined that the sharing operation is a safe sharing operation. For another example, if it is detected that all the applications installed on the terminal have no risk, the network environment is normal, and all the applications installed on the terminal have a source, it is determined that the sharing operation is a safe sharing operation.

[0057] In an optional implementation, if at least one of the detection result of the application risk detection, the evaluation result of the network security evaluation, and the detection result of the application source detection is abnormal, it is determined that the sharing operation is a non-safe sharing operation, and the sharing operation is interrupted at this time. For example, if it is detected that the target application has a risk, the network environment is abnormal, or the target application is a sourceless application, it is determined that the sharing operation is a non-safe sharing operation. For another example, if it is detected that any one of the applications installed on the terminal has a risk, the network environment is abnormal, or any one of the applications installed on the terminal is a sourceless application, it is determined that the sharing operation is a non-safe sharing operation.

[0058] In an optional implementation, according to a preset scoring rule, a comprehensive score is obtained according to the detection result of the application risk detection, the evaluation result of the network security evaluation, and the detection result of the application source detection, a score result is obtained, and it is determined whether the sharing operation is a safe sharing operation according to the score result and a preset safe score range. If the score result belongs to the preset safe score range, it is determined that the sharing operation is a safe sharing operation. If the score result does not belong to the preset safe score range, it is determined that the sharing operation is not a safe sharing operation. For example, a comprehensive score is obtained according to 0 to 10 points, and if the score result is higher than 6 points, it is determined that the sharing operation is a safe sharing operation.

[0059] Step 108, in the case where the sharing operation is a safe sharing operation, it is determined whether the sharing operation corresponds to a target user.

[0060] The target user refers to a user with sharing permission, for example, the target user refers to the actual owner of the terminal. If the sharing operation corresponds to the target user, it is indicated that the permission authentication of the sharing operation is passed. If the sharing operation does not correspond to the target user, it is indicated that the permission authentication of the sharing operation fails, and the sharing operation is interrupted at this time.

[0061] Step 110, in the case where the sharing operation corresponds to the target user, the sharing operation is completed through the target application.

[0062] In a case where the sharing operation is a safe sharing operation and the permission authentication is passed, the sharing operation is continued on the target application, and the content to be shared is shared through the target application.

[0063] In the application safe sharing method, in response to the sharing operation on the target application, an information determination page is displayed; based on the information determination page, application risk detection, network security assessment and application source detection are performed; the detection result of the application risk detection, the assessment result of the network security assessment and the detection result of the application source detection are integrated to determine whether the sharing operation is a safe sharing operation; in a case where the sharing operation is a safe sharing operation, it is determined whether the sharing operation corresponds to the target user; in a case where the sharing operation corresponds to the target user, the sharing operation is completed through the target application. Through the above-mentioned manner, when the user performs the sharing operation, the terminal performs application risk detection, network security assessment and application source detection, and further identifies the user, which can monitor abnormal behavior, block unauthorized application leakage path, and improve the security of application sharing.

[0064] In one exemplary embodiment, the method further comprises: in a case where the detection result of the application risk detection indicates that the target application does not exist risk, the assessment result of the network security assessment indicates that the network environment is normal, and the detection result of the application source detection indicates that the target application exists source, determining that the sharing operation is a safe sharing operation.

[0065] In a case where the sharing operation is a safe sharing operation and the permission authentication is passed, the sharing operation is continued on the target application, and the content to be shared is shared through the target application. Figure 2 application safe sharing method comprises: a user performs a sharing operation on a terminal. The terminal obtains application information of a target application. Based on the application information, the terminal respectively performs application risk detection, network security assessment and application source detection. If the target application exists risk, or the network environment is abnormal, or the target application is a sourceless application, the detection fails, and the sharing operation is interrupted. If the target application does not exist risk, the network environment is normal, and the target application exists source, user detection is performed. After the user detection is passed, the sharing operation is performed.

[0066] In one exemplary embodiment, the application risk detection comprises: determining corresponding vulnerability detection strategy, code detection strategy, data risk detection strategy and permission detection strategy according to the application type of the target application; detecting whether there is a vulnerability in the configuration information of the target application according to the vulnerability detection strategy; detecting whether there is malicious code in the code of the target application according to the code detection strategy; detecting whether the target application exists data risk according to the data risk detection strategy; detecting whether there is an exception in the permission information of the target application according to the permission detection strategy; and determining the detection result of the application risk detection according to the vulnerability detection result, the code detection result, the data risk detection result and the permission detection result.

[0067] Among them, in order to realize fine application risk detection, different application types correspond to vulnerability detection strategies, code detection strategies, data risk detection strategies and permission detection strategies are set in advance, and according to the application type of the target application, the corresponding vulnerability detection strategy, code detection strategy, data risk detection strategy and permission detection strategy are queried. It can be understood that under different application types, the detection items corresponding to each vulnerability detection strategy are different; similarly, under different application types, the detection items corresponding to each code detection strategy are different, the detection items corresponding to each data risk detection strategy are different, and the detection items corresponding to each permission detection strategy are different.

[0068] The specific detection process is: whether there is a vulnerability in the configuration information, for example, detecting the error of the open debugging interface, the database is not encrypted, etc. Detect whether there is malicious code in the code of the target application, such as signature tampering, code obfuscation, etc. Detect whether the target application has data risk, such as storing passwords in plaintext in logs, plaintext communication, etc. Detect whether there is an exception in the permission information of the target application, such as excessive application permissions, etc.

[0069] The detection result of the application risk detection includes that the target application does not exist risk or the target application exists risk. In an optional implementation manner, if the configuration information of the target application has a vulnerability, or the code of the target application has malicious code, or the target application has data risk, or the permission information of the target application has an exception, it is determined that the detection result of the application risk detection is that the target application exists risk. Correspondingly, if the configuration information of the target application does not have a vulnerability, the code of the target application does not have malicious code, the target application does not have data risk, and the permission information of the target application does not have an exception, it is determined that the detection result of the application risk detection is that the target application does not exist risk.

[0070] In an exemplary embodiment, network security evaluation includes: determining network quality information according to network speed and network delay; determining network privacy degree according to network type and network sharing situation; determining the evaluation result of network security evaluation according to network quality information and network privacy degree.

[0071] Among them, the network speed, network delay, network type and network sharing situation of the current network environment are obtained, the network quality is evaluated according to the network speed and network delay to determine the network quality information, and the network privacy is evaluated according to the network type and network sharing situation to determine the network privacy degree.

[0072] The network sharing condition refers to a configuration state in which network resources (such as bandwidth, data, connection permission, etc.) are used by multiple users, devices or applications in a specific network environment, and the network sharing condition can be obtained by communicating with the network device. The network type includes a public network, a private network, and the like.

[0073] Optionally, the network quality information and the network privacy degree are both scores, and in a specific implementation, the network quality information is scored based on a pre-set scoring rule according to network speed and network delay, and the network privacy degree is scored based on the network type and the network sharing condition.

[0074] The evaluation result of the network security evaluation includes a normal network environment and an abnormal network environment. The network quality information and the network privacy degree are integrated (for example, the scores are added) to determine the evaluation result of the network security evaluation. In an optional implementation, if the comprehensive score of the network security evaluation is greater than a pre-set score, it is determined that the network environment is normal; if the comprehensive score of the network security evaluation is less than or equal to the pre-set score, it is determined that the network environment is abnormal.

[0075] In an exemplary embodiment, the application source detection includes: determining the source of the target application according to the version number, the developer information and the release date of the target application, and obtaining the detection result of the application source detection.

[0076] The detection result of the application source detection includes that the target application has a source or the target application is a sourceless application. The corresponding application resource is queried in a safe source channel or path (for example, an application store) according to the version number, the developer information and the release date of the target application, and if the corresponding application resource is queried, it is indicated that the target application has a source (that is, the source of the target application is reasonable). Correspondingly, if no matching application resource is queried, it is indicated that the target application is a sourceless application (that is, the source of the target application is unreasonable).

[0077] In an exemplary embodiment, determining whether the sharing operation corresponds to the target user includes: determining whether the sharing operation corresponds to the target user according to the face image or according to the user password.

[0078] The face image is obtained, and the face image is compared with a pre-stored face image of the target user. If they are consistent, it is determined that the sharing operation corresponds to the target user; if they are inconsistent, it is determined that the sharing operation does not correspond to the target user. The user password is received through the information determination page, and the user password is compared with a pre-stored password of the target user. If they are consistent, it is determined that the sharing operation corresponds to the target user; if they are inconsistent, it is determined that the sharing operation does not correspond to the target user.

[0079] It should be understood that although each step in the flowchart involved in the above-described embodiments is shown in sequence according to the arrow, the steps are not necessarily executed in the order indicated by the arrow. Unless otherwise specified herein, the execution of the steps is not strictly limited in sequence, and the steps can be executed in other orders. Moreover, at least some of the steps in the flowchart involved in the above-described embodiments can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of the steps or stages is not necessarily sequential, but can be alternately or alternately executed with at least part of other steps or steps or stages in other steps. It can be understood that the steps in different embodiments can be freely combined as needed, and various non-contradictory schemes formed by the combination are within the scope of protection of the present application.

[0080] Based on the same inventive concept, the embodiments of the present application also provide an application security sharing device for implementing the above-mentioned application security sharing method. The problem-solving implementation scheme provided by the device is similar to the implementation scheme described in the above method, so the specific limitations in one or more application security sharing device embodiments provided below can refer to the limitations of the application security sharing method described above, which will not be repeated here.

[0081] In one exemplary embodiment, as shown in Figure 3 An application security sharing device is provided, comprising:

[0082] The display module 302 is configured to display an information determination page in response to a sharing operation on a target application.

[0083] The detection module 304 is configured to perform application risk detection, network security assessment, and application source detection based on the information determination page.

[0084] The integration module 306 is configured to integrate the detection results of the application risk detection, the assessment results of the network security assessment, and the detection results of the application source detection to determine whether the sharing operation is a secure sharing operation.

[0085] The determination module 308 is configured to determine whether the sharing operation corresponds to a target user if the sharing operation is a secure sharing operation.

[0086] The sharing module 310 is configured to complete the sharing operation through the target application if the sharing operation corresponds to the target user.

[0087] The application security sharing device can monitor abnormal behaviors, block unauthorized application leakage paths, and improve the security of application sharing when a user performs a sharing operation.

[0088] In an exemplary embodiment, the integration module 306 is further configured to determine that the sharing operation is a safe sharing operation when the detection result of the application risk detection indicates that the target application has no risk, the evaluation result of the network security evaluation indicates that the network environment is normal, and the detection result of the application source detection indicates that the target application has a source.

[0089] In an exemplary embodiment, the detection module 304 is further configured to determine a corresponding vulnerability detection strategy, a code detection strategy, a data risk detection strategy, and a permission detection strategy according to the application type of the target application; detect whether there is a vulnerability in the configuration information of the target application according to the vulnerability detection strategy; detect whether there is malicious code in the code of the target application according to the code detection strategy; detect whether the target application has data risk according to the data risk detection strategy; detect whether there is an exception in the permission information of the target application according to the permission detection strategy; and determine the detection result of the application risk detection according to the vulnerability detection result, the code detection result, the data risk detection result, and the permission detection result.

[0090] In an exemplary embodiment, the detection module 304 is further configured to determine network quality information according to the network speed and the network delay; determine the network privacy degree according to the network type and the network sharing situation; and determine the evaluation result of the network security evaluation according to the network quality information and the network privacy degree.

[0091] In an exemplary embodiment, the detection module 304 is further configured to determine the source of the target application according to the version number, the developer information, and the release date of the target application, and obtain the detection result of the application source detection.

[0092] In an exemplary embodiment, the determination module 308 is further configured to determine whether the sharing operation corresponds to the target user according to the face image or according to the user password.

[0093] The various modules in the application security sharing device can be all or part of software, hardware, and combinations thereof. The various modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory in the computer device in software form, so as to be called and executed by the processor to perform the operations corresponding to the various modules.

[0094] In an exemplary embodiment, a computer device is provided, which can be a terminal, and the internal structure diagram of the computer device can be as shown in Figure 4The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for running the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is configured to exchange information between the processor and external devices. The communication interface of the computer device is configured to perform wired or wireless communication with external terminals. The wireless communication can be achieved through WIFI, mobile cellular network, Near Field Communication (NFC) or other technologies. The computer program is executed by the processor to implement an application security sharing method. The display unit of the computer device is configured to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device, or an external keyboard, touchpad or mouse, etc.

[0095] Those skilled in the art can understand that, Figure 4 The skilled in the art can understand that,

[0096] In one exemplary embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the following steps: in response to a sharing operation on a target application, displaying an information determination page; based on the information determination page, performing application risk detection, network security assessment and application source detection; integrating the detection result of the application risk detection, the assessment result of the network security assessment and the detection result of the application source detection to determine whether the sharing operation is a safe sharing operation; in the case that the sharing operation is a safe sharing operation, determining whether the sharing operation corresponds to a target user; in the case that the sharing operation corresponds to the target user, completing the sharing operation through the target application.

[0097] In an embodiment, the processor, when executing the computer program, further implements the following steps: in a case that the detection result of the application risk detection represents that the target application does not exist risk, the evaluation result of the network security evaluation represents that the network environment is normal, and the detection result of the application source detection represents that the target application exists source, determining that the sharing operation is a safe sharing operation.

[0098] In an embodiment, the processor, when executing the computer program, further implements the following steps: according to the application type of the target application, determining a corresponding vulnerability detection strategy, a code detection strategy, a data risk detection strategy and a permission detection strategy; according to the vulnerability detection strategy, detecting whether there is a vulnerability in the configuration information of the target application; according to the code detection strategy, detecting whether there is malicious code in the code of the target application; according to the data risk detection strategy, detecting whether the target application exists data risk; according to the permission detection strategy, detecting whether there is an exception in the permission information of the target application; and according to the vulnerability detection result, the code detection result, the data risk detection result and the permission detection result, determining the detection result of the application risk detection.

[0099] In an embodiment, the processor, when executing the computer program, further implements the following steps: according to the network speed and the network delay, determining the network quality information; according to the network type and the network sharing situation, determining the network privacy degree; and according to the network quality information and the network privacy degree, determining the evaluation result of the network security evaluation.

[0100] In an embodiment, the processor, when executing the computer program, further implements the following steps: according to the version number, the developer information and the release date of the target application, determining the source of the target application, and obtaining the detection result of the application source detection.

[0101] In an embodiment, the processor, when executing the computer program, further implements the following steps: according to the face image or according to the user password, determining whether the sharing operation corresponds to the target user.

[0102] In an embodiment, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the following steps: in response to a sharing operation on a target application, displaying an information determination page; based on the information determination page, performing application risk detection, network security evaluation and application source detection; integrating the detection result of the application risk detection, the evaluation result of the network security evaluation and the detection result of the application source detection to determine whether the sharing operation is a safe sharing operation; in a case that the sharing operation is a safe sharing operation, determining whether the sharing operation corresponds to a target user; and in a case that the sharing operation corresponds to the target user, completing the sharing operation through the target application.

[0103] In an embodiment, the computer program, when executed by the processor, further implements the following steps: in a case that the detection result of the application risk detection represents that the target application does not exist risk, the evaluation result of the network security evaluation represents that the network environment is normal, and the detection result of the application source detection represents that the target application exists source, determining that the sharing operation is a safe sharing operation.

[0104] In an embodiment, the computer program, when executed by the processor, further implements the following steps: according to the application type of the target application, determining a corresponding vulnerability detection strategy, a code detection strategy, a data risk detection strategy and a permission detection strategy; according to the vulnerability detection strategy, detecting whether there is a vulnerability in the configuration information of the target application; according to the code detection strategy, detecting whether there is malicious code in the code of the target application; according to the data risk detection strategy, detecting whether the target application exists data risk; according to the permission detection strategy, detecting whether there is an exception in the permission information of the target application; and according to the vulnerability detection result, the code detection result, the data risk detection result and the permission detection result, determining the detection result of the application risk detection.

[0105] In an embodiment, the computer program, when executed by the processor, further implements the following steps: according to the network speed and the network delay, determining network quality information; according to the network type and the network sharing situation, determining a network privacy degree; and according to the network quality information and the network privacy degree, determining the evaluation result of the network security evaluation.

[0106] In an embodiment, the computer program, when executed by the processor, further implements the following steps: according to the version number, the developer information and the release date of the target application, determining the source of the target application, and obtaining the detection result of the application source detection.

[0107] In an embodiment, the computer program, when executed by the processor, further implements the following steps: according to the face image or according to the user password, determining whether the sharing operation corresponds to the target user.

[0108] In an embodiment, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the following steps: in response to a sharing operation on a target application, displaying an information determination page; based on the information determination page, performing application risk detection, network security evaluation and application source detection; integrating the detection result of the application risk detection, the evaluation result of the network security evaluation and the detection result of the application source detection to determine whether the sharing operation is a safe sharing operation; in a case that the sharing operation is a safe sharing operation, determining whether the sharing operation corresponds to the target user; and in a case that the sharing operation corresponds to the target user, completing the sharing operation through the target application.

[0109] In an embodiment, the computer program, when executed by the processor, further implements the following steps: in a case that the detection result of the application risk detection represents that the target application does not exist risk, the evaluation result of the network security evaluation represents that the network environment is normal, and the detection result of the application source detection represents that the target application exists a source, determining that the sharing operation is a safe sharing operation.

[0110] In an embodiment, the computer program, when executed by the processor, further implements the following steps: according to the application type of the target application, determining a corresponding vulnerability detection strategy, a code detection strategy, a data risk detection strategy and a permission detection strategy; according to the vulnerability detection strategy, detecting whether there is a vulnerability in the configuration information of the target application; according to the code detection strategy, detecting whether there is malicious code in the code of the target application; according to the data risk detection strategy, detecting whether the target application exists data risk; according to the permission detection strategy, detecting whether there is an exception in the permission information of the target application; and according to the vulnerability detection result, the code detection result, the data risk detection result and the permission detection result, determining the detection result of the application risk detection.

[0111] In an embodiment, the computer program, when executed by the processor, further implements the following steps: according to the network speed and the network delay, determining network quality information; according to the network type and the network sharing situation, determining a network privacy degree; and according to the network quality information and the network privacy degree, determining the evaluation result of the network security evaluation.

[0112] In an embodiment, the computer program, when executed by the processor, further implements the following steps: according to the version number, the developer information and the release date of the target application, determining the source of the target application, and obtaining the detection result of the application source detection.

[0113] In an embodiment, the computer program, when executed by the processor, further implements the following steps: according to the face image or according to the user password, determining whether the sharing operation corresponds to the target user.

[0114] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant regulations.

[0115] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. The non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. The volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, the RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.

[0116] The technical features of the above embodiments can be combined in any manner. To make the description concise, all possible combinations of the technical features in the above embodiments are not described, but as long as the combinations of the technical features do not exist, they should be considered as the scope of the present application.

[0117] The above-described embodiments are merely illustrative of several embodiments of the present application, and the description is relatively specific and detailed, but should not be understood as a limitation on the scope of the patent. It should be noted that for those skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are all within the scope of the present application. Therefore, the scope of protection of the present application should be subject to the appended claims.

Claims

1. An application security sharing method, characterized by, The method comprises: in response to a sharing operation on a target application, displaying an information determination page; based on the information determination page, performing application risk detection, network security assessment and application source detection; information integration is performed on the detection result of the application risk detection, the assessment result of the network security assessment and the detection result of the application source detection to determine whether the sharing operation is a safe sharing operation; in the case that the sharing operation is a safe sharing operation, it is determined whether the sharing operation corresponds to a target user; in the case that the sharing operation corresponds to the target user, the sharing operation is completed through the target application.

2. The method of claim 1, wherein, The method further comprises: in the case that the detection result of the application risk detection represents that there is no risk in the target application, the assessment result of the network security assessment represents that the network environment is normal, and the detection result of the application source detection represents that the target application has a source, it is determined that the sharing operation is a safe sharing operation.

3. The method of claim 1, wherein, The application risk detection comprises: according to the application type of the target application, determining corresponding vulnerability detection strategy, code detection strategy, data risk detection strategy and permission detection strategy; according to the vulnerability detection strategy, detecting whether there is a vulnerability in the configuration information of the target application; according to the code detection strategy, detecting whether there is malicious code in the code of the target application; according to the data risk detection strategy, detecting whether there is data risk in the target application; according to the permission detection strategy, detecting whether there is an exception in the permission information of the target application; according to the vulnerability detection result, the code detection result, the data risk detection result and the permission detection result, the detection result of the application risk detection is determined.

4. The method of claim 1, wherein, The network security assessment comprises: according to the network speed and the network delay, determining the network quality information; according to the network type and the network sharing situation, determining the network privacy degree; according to the network quality information and the network privacy degree, determining the assessment result of the network security assessment.

5. The method of claim 1, wherein, The application source detection comprises: according to the version number, the developer information and the release date of the target application, determining the source of the target application to obtain the detection result of the application source detection.

6. The method according to any one of claims 1 to 5, characterized in that, The determination of whether the sharing operation corresponds to the target user comprises: according to the face image or according to the user password, it is determined whether the sharing operation corresponds to the target user.

7. An application security sharing apparatus characterized by comprising: The device comprises: a display module, configured to display an information determination page in response to a sharing operation on a target application; a detection module, configured to perform application risk detection, network security assessment and application source detection based on the information determination page; an integration module, configured to perform information integration on the detection result of the application risk detection, the assessment result of the network security assessment and the detection result of the application source detection to determine whether the sharing operation is a safe sharing operation; a determination module, configured to determine whether the sharing operation corresponds to a target user in the case that the sharing operation is a safe sharing operation; a sharing module, configured to complete the sharing operation through the target application in the case that the sharing operation corresponds to the target user.

8. A computer device comprising a memory and a processor, the memory storing a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6.

9. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6.

10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6.