Systems and methods for classifying applications on a computing device
By deploying the system protector on the computing device and obtaining and updating the classification results of applications, the heavy burden on computing resources and classification errors in the prior art are solved, and more efficient and accurate detection of malicious application is achieved, and computer security is improved.
Patent Information
- Application Number
- CN202010222091.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-10-16
- Filing Date
- 2020-03-26
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2040-03-26
AI Technical Summary
When existing anti-virus software detects malicious applications through remote infrastructure, it leads to a heavy burden on computing resources and an increase in classification errors.
By deploying the system protector on the computing device, obtain the classification results of the application from the security server and determine the category of the application based on the correlation rules. When the classification result does not satisfy the correlation rule, the classification is terminated and the applied attribute set is updated to obtain a new classification result.
Reduces the demand for computing resources, reduces errors in application classification, improves computer security, and ensures data information security.
Smart Images

Figure CN112149122B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of detecting malicious applications on a computing device using a remote server. Background Art
[0002] The widespread popularity of computing devices, including mobile computing devices, has opened up broad prospects for criminals to conduct cyberattacks, such as using malware. By obtaining illegal access to a user's computing device, criminals can gain access to the user's confidential data and the user's communications. Using the content of the illegal access, criminals can perform actions in the name of the user, including actions for conducting financial transactions. Therefore, dedicated software (e.g., antivirus software) is typically used to protect the user's device.
[0003] Modern antivirus software often works in cooperation with a remote infrastructure, and each possible service operates within this remote infrastructure. For example, the remote infrastructure can be used to provide services for data (such as data on whether an application belongs to certain categories). For example, according to the request of the antivirus software, the remote infrastructure can provide data indicating whether an application belongs to certain categories. Such services reduce the burden on the user's computing device by taking over labor-intensive computing tasks such as image recognition or classifying objects (files, applications, etc.) using multiple criteria.
[0004] However, this method has its drawbacks. The large number of antivirus applications connected to the remote server places a heavy burden on the services of the remote infrastructure. Incidentally, many requests from antivirus applications installed on various devices are the same. That is, a large number of requests are for obtaining information on the categories of exactly the same applications or files. To avoid running the same task on the remote infrastructure for each received request, a caching service can be used to memorize the results of previously executed tasks. Although this method reduces the computational burden to a certain extent, it increases the first type and second type of errors (false positives and false negatives). Therefore, the above method has drawbacks.
[0005] Therefore, there is a need for a better way to eliminate the need for increased computing resources and reduce errors in the classification of applications while detecting malicious applications. Summary of the Invention
[0006] Aspects of the present disclosure relate to the field of information security, and in particular to systems and methods for classifying applications.
[0007] In an exemplary aspect, a method for classifying an application on a computing device is implemented in a computer including a hardware processor. The method includes: obtaining a classification result of the application from a security server; when the classification result satisfies a relevance rule, designating the classification result as relevant, and determining the category of the application based on the result being designated as relevant; and when the classification result does not satisfy the relevance rule, performing at least one of the following: terminating the classification of the application, and updating the classification of the application based on a set of attributes of the application.
[0008] According to an aspect of the present disclosure, there is provided a system for classifying an application on a computing device. The system includes a hardware processor configured to: obtain a classification result of the application from a security server; when the classification result satisfies a relevance rule, designate the classification result as relevant, and determine the category of the application based on the result being designated as relevant; and when the classification result does not satisfy the relevance rule, perform at least one of the following: terminating the classification of the application, and updating the classification of the application based on a set of attributes of the application.
[0009] In an exemplary aspect, there is provided a non-transitory computer-readable medium having stored thereon a set of instructions for classifying an application on a computing device. The set of instructions includes instructions for: obtaining a classification result of the application from a security server; when the classification result satisfies a relevance rule, designating the classification result as relevant, and determining the category of the application based on the result being designated as relevant; and when the classification result does not satisfy the relevance rule, performing at least one of the following: terminating the classification of the application, and updating the classification of the application based on a set of attributes of the application.
[0010] In one aspect, the update of the classification includes receiving an updated classification from the security server in response to sending the set of attributes to the security server.
[0011] In one aspect, the set of attributes of the application includes at least one of the following: a plurality of files in the application package of the application, a plurality of executable files in the application package, a plurality of requested permissions and types of permissions, a plurality of classes in the executable files in the application package, and a plurality of methods in the executable files in the application package.
[0012] In one aspect, the classification result of the application is presented as one or more probabilities of the application belonging to one or more corresponding categories of the application.
[0013] In one aspect, one or more categories of the application include at least one of the following: a category of malicious applications, a category of unwanted applications, and a category of trusted applications.
[0014] In one aspect, a heuristic rule is used to determine the category of the application, and the heuristic rule is at least partially based on the result of the classification.
[0015] In one aspect, the method further includes: when an application is classified as malicious, removing or isolating the application from the computing device, and when an application is classified as unnecessary, performing at least one of the following: removing the application from the computing device, notifying a user of the computing device of the presence of the unnecessary application on the computing device, providing the user of the computing device with an option to select to retain or remove the unnecessary application, and revoking a permission previously granted to the application.
[0016] In one aspect, the method of the present disclosure classifies applications while eliminating the need to increase computing resources and while reducing errors in the classification of applications. The purpose of the method is to improve computer security. Thus, the method of the present disclosure helps to achieve the information security of data. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings incorporated in and constituting a part of this specification illustrate one or more exemplary aspects of the present disclosure and, together with the detailed description, are used to explain its principles and implementations.
[0018] Figure 1 A schematic diagram of a system for classifying applications on a computing device according to an aspect of the present disclosure is shown.
[0019] Figure 2 A method for classifying applications using a classification service according to an aspect of the present disclosure is shown.
[0020] Figure 3 A method for classifying applications on a computing device based on correlation rules according to an aspect of the present disclosure is shown.
[0021] Figure 4 An example of a general-purpose computer system on which aspects of the present disclosure can be implemented is presented. DETAILED DESCRIPTION
[0022] Exemplary aspects are described herein in the context of systems, methods, and computer programs for classifying applications on a computing device without increasing the need for computing resources and without increasing errors in the classification of applications. Those of ordinary skill in the art will recognize that the following description is merely illustrative and is not intended to be limiting in any way. Those skilled in the art who benefit from the present disclosure will readily think of other aspects. Embodiments of the example aspects as shown in the drawings will now be described in detail. Throughout the drawings and the following description, the same reference numerals will be used as much as possible to refer to the same or similar things.
[0023] To clearly present the teachings of the present disclosure, a number of terms and concepts used in describing various aspects of the present disclosure are defined herein.
[0024] A malicious application is an application that can cause damage to the data of a computing system or the users of a computing system (i.e., a computer, a group of computers, a personal computer, a server, a mobile phone, etc.), such as: Internet worms, keyloggers, computer viruses, etc. The damage caused can be illegal access to computer resources, including data stored on the computer for theft purposes, and illegal use of resources, including storage of data, execution of calculations, etc.
[0025] A trusted application is an application that does not cause damage to a computing system or the users of a computing system. Trusted applications can include applications developed by trusted software manufacturers, downloaded from trusted sources (such as sites listed in the database of a trusted site), or applications whose identifiers (or other data by which the application is uniquely identified, such as the hash value of the application's file) are stored in the database of trusted applications. Identifiers of the manufacturer, such as digital certificates, can also be stored in the database of trusted applications.
[0026] An unwanted application is neither a malicious nor a trusted application. In addition, such an application can perform illegal access to computer resources (including data stored on the computer), although the leakage of such data does not cause direct damage to the computer or the users of the computer. Examples of unwanted applications can be adware, which can collect data from the user's device and / or display advertising materials to the user via the device.
[0027] An untrusted application is neither a trusted nor an unwanted application, but an application that is not classified as harmful, for example, with the help of an antivirus application. In addition, for example, with the help of antivirus scanning, an untrusted application can subsequently be classified as malicious.
[0028] A malicious file is a file that is a component of a malicious application and contains program code (e.g., executable or interpreted code).
[0029] An untrusted file is a file that is a component of an untrusted application and contains program code (e.g., executable or interpreted code).
[0030] A trusted file is a file that is a component of a trusted application.
[0031] An unwanted file is a file that is a component of an unwanted application and contains program code (executable or interpretable code).
[0032] The category of an application is a characteristic of the application that defines its subordination to one of the following: the category of trusted applications (the application is trusted), the category of malicious applications (the application is malicious), or the category of unwanted applications (the application is unwanted).
[0033] A relevance rule is a rule that includes requirements for classification results, where meeting these requirements reduces the probability of type I and type II errors in the classification results (and thus also reduces the number of errors). The probability is calculated as a numerical value.
[0034] The applied classification result is the probability that the application belongs to a given class of applications.
[0035] In one aspect, the present disclosure describes a system for classifying applications on a computing device without increasing the need for computing resources and without increasing errors in the classification of applications implemented on a computing system (e.g., a server, a computer, etc.). The system includes real-world devices, systems, components, and groups of components implemented by means of hardware such as an integrated microcircuit (application-specific integrated circuit, ASIC) or a field-programmable gate array (FPGA), or implemented, for example, in a combination of software and hardware such as a microprocessor system and a program instruction set, and also implemented on a neuromorphic chip. The functions of such devices of the system can be implemented individually by hardware and also in a combined form, where some functions of the system devices are implemented by software and some by hardware. In some aspects, some or all of the components, systems, etc. can be executed on a processor of a general-purpose computer (such as the general-purpose computer shown in Figure 4 ). In addition, the system components can be implemented within a single computing device or distributed among several interconnected computing devices.
[0036] Figure 1 A schematic diagram of a system 100 for classifying applications on a computing device according to an aspect of the present disclosure is shown.
[0037] The system 100 for classifying applications includes a classification service 160 implemented on a system protector 120 and a security server 150. In one aspect, the system protector 120 is implemented on a user's computing device, for example, implemented on the user's mobile computing device 110. Without loss of generality, the term "mobile computing device" is used to describe the teachings of the present disclosure. In other words, the method can be deployed on any standard computing device, and the use of the term "mobile computing device" is not intended to limit the benefits of the present disclosure to only mobile devices. On the contrary, users of any computing device, mobile or otherwise, can benefit from the teachings of the present disclosure.
[0038] In one aspect, the security server 150 further includes a reputation service 170. Additionally, the reputation service 170 can be communicatively coupled to a verdict database 180, which can also be implemented on the security server 150. It should be noted that the security server 150 can be presented as a single computing device or as a number of interconnected computing devices linked, for example, by a data transmission network 190, and each computing device can be a physical or virtual computing device.
[0039] In one aspect, the mobile computing device 110 further includes a database 140 of anti-virus records. In one aspect, the system protector 120 is communicatively coupled to the database 140 of anti-virus records. Anti-virus records stored, for example, in the database 140 include a formalized data set used by anti-virus software (or a similar system such as the system protector 120) to determine the category of an application, such as for detecting malicious applications.
[0040] In one aspect, the mobile computing device 110 includes an application 130. In one aspect, the application 130 can be an application downloaded from the Internet via the data transmission network 190, such as an application downloaded from an app store (e.g., from the App Store, Google Play, etc.). In another aspect, the application 130 can be obtained in other ways, for example, via a removable storage medium or a Bluetooth connection. To ensure the security of the mobile computing device 110, the system protector 120 is deployed on the device 110.
[0041] In one aspect, the system protector 120 collects a set of attributes of the application 130. In one aspect, the set of attributes that can be collected by the system protector 120 on behalf of the application 130 includes:
[0042] · Multiple files in the application package of the application 130;
[0043] · Multiple executable files in the application package;
[0044] · Multiple requested permissions and types of permissions;
[0045] · Multiple classes in the executable file; and
[0046] · Multiple methods in the executable file.
[0047] In one aspect, the application package of the application 130 can include a container for the files of the application 130. For example, the application package can include an installation package (APK) archive file, a compressed (ZIP) archive file, or a container based on any other standard, where the APK archive file is designed to run an application on a mobile computing device under the control of the Android operating system.
[0048] In one aspect, the executable file includes a DEX file, which is designed for execution on a device under the control of the Android operating system.
[0049] In one aspect, the executable file includes additional files containing instructions for execution by a computing device (which may include the use of an interpreter).
[0050] In one aspect, a request for permission is an indication for an application 130 to perform certain actions on a mobile computing device 110, where explicit consent from the user of the mobile computing device 110 is required for the actions for which permission is being requested. Some examples of actions that require explicit permission include: accessing a data transmission network, accessing a digital camera, accessing a microphone, etc. The permissions requested by a given application 130 can be described in a file, which can be part of the application package of the application 130.
[0051] In one aspect, any method known in the field of data structures can be used to formalize information about classes and methods used by the executable code of an application 130 as attributes of the application 130. For example, the attributes of an application can be provided in the form of a tree-like structure (list) with multiple levels:
[0052] · Class 1
[0053] o Method 1
[0054] o Method 2
[0055] · Class 2
[0056] o Method 3
[0057] Then, the set of attributes of the collected application 130 can be sent by the system protector 120 to the security server 150, and specifically to the classification service 160 existing on the security server 150.
[0058] The classification service 160 is designed to classify applications, especially the application 130, based on the set of attributes of the application.
[0059] The classification result of the application 130 is presented as the probability that the application 130 belongs to certain classes of applications. For example, the classification result of the application 130 can be expressed as follows: 80% malicious application, 85% unwanted application, 60% trusted application.
[0060] To obtain the above classification results, the classification service 160 uses a previously trained expert classification system. In one aspect, the trained classification system can be built from: neural networks, decision trees or ladders, Bayesian classifiers, and / or any other classifier system known in the art.
[0061] For the training of the classification service 160, on the one hand, a labeled application set can be used, the subordination relationship of which to application categories is considered to be known. On the other hand, the training can also use an additional system protector running on the security server 150. It should be noted that the formation of the labeled application set can be performed by an expert in the field of information technology or by any expert system known in the art.
[0062] Once the classification is completed by the classification service 160, the classification result of the application 130 is sent by the security server 150 to the system protector 120 in the mobile computing device 110.
[0063] On the one hand, the system protector 120 uses the classification result of the application 130 received from the classification service 160 to determine the category of the application 130. On the one hand, heuristic rules are used to perform the determination of the category of the application, and the heuristic rules are stored in the database 140 of the antivirus records. On the one hand, the heuristic rules require determining the category of the application 130 based on the classification result of the application 130.
[0064] An example of the heuristic rules can be expressed as follows:
[0065] "If for the application, the probability of belonging to:
[0066] · The probability of belonging to the category of malicious applications is greater than 30%; and
[0067] · The probability of belonging to the category of trusted applications is less than 20%;
[0068] Then, the application is classified as malicious".
[0069] On yet another hand, the system protector 120 uses heuristic rules, for example, the rules stored in the database 140, which are applied not only to the classification result of the application 130, but also to an additional attribute set of the application 130, and these additional attributes can be collected by the system protector 120.
[0070] On the one hand, the additional attribute set of the application 130 (also simply referred to as "additional attributes") is exactly the same attributes as those used for the classification of the application 130. On the other hand, this additional attribute set is different from the attributes used by the classification service 160.
[0071] Examples of the additional attribute set can be:
[0072] · The size of the executable file from the application package;
[0073] · The instruction sequence of the executable file from the application package.
[0074] In one aspect, the system protector 120 determines the category of the application 130 using at least one of the following: heuristic rules obtained from the database 140, classification results, and a set of additional attributes.
[0075] An example of such a heuristic rule can be: "If the probability that an application belongs to the malicious application category is greater than 30%, while the application package has an executable file of size 100 kB, and the executable file includes code containing a sequence of three exclusive-or (XOR) operations, then the application is classified as malicious."
[0076] In one aspect, in addition to the above method, the system protector 120 is also capable of sending a request to the security server 150 to obtain the classification result of the application 130 without sending the set of attributes of the application 130 to the server 150. In this case, the request is addressed to the server 150 and specifically to the reputation service 170 operating (running) within the security server 150, where the request itself can include an identifier of the application 130, such as its name, the checksum of the application package, or any other identifier that uniquely characterizes the application 130, etc.
[0077] When the request is sent to the reputation service 170, in order to provide the classification result of the application 130 to the system protector 120 without providing the set of attributes of the application 130, the reputation service 170 uses the classification results of previously classified applications stored. The classification results of the previously classified applications are obtained by the classification service 160 performing classification using the set of attributes of the previously classified applications previously collected by the system protector 120.
[0078] In one aspect, the reputation service 170 utilizes the verdict database 180 to store this data. In addition, the classification results of various applications can be stored in the verdict database 180 in combination with their respective circumstances for obtaining the classification results. For example, the circumstances can include:
[0079] · The timestamp of the classification;
[0080] · The identifier of the application being classified;
[0081] · The type of the expert classification system used;
[0082] · The error estimate of the expert classification system used;
[0083] · The version (1.0, 1.1, 2.0, 3.0, etc.) of the mechanism for collecting the attributes used by the system protector; and
[0084] · The version (1.0, 1.1, 2.0, 3.0, etc.) of the mechanism of the expert classification system.
[0085] Previously obtained application classification results include classification results executed by classification service 160 in response to requests from system protector 120 running on mobile computing device 110, as well as classification results executed in response to requests from similar protection systems that may be located on computing devices of one or more users or on security server 150. Such previously classified applications can be applications for which system protectors (present on device 110 and server 150) have collected a set of attributes and sent the collected attributes to classification service 160 to obtain classification results.
[0086] In one aspect, such applications are applications from the above-mentioned marked application set.
[0087] Whenever classification service 160 generates classification results for certain applications (including application 130), service 160 can send the classification results to reputation service 170. In one aspect, the circumstances for obtaining the classification results are also sent to reputation service 170. Subsequently, reputation service 170 can store the received information in decision database 180.
[0088] The classification results of application 130 provided by reputation service 170, including the circumstances of the obtained classification results, are sent to system protector 120 to determine the relevance of the classification results (as the relevance of the attributes of the information).
[0089] In one aspect, the relevance of the classification results is determined by system protector 120 present on mobile computing device 110. In another aspect, the relevance of the classification results is determined by another system protector present on security server 150. Thus, the determination of the relevance of the classification results of application 130 can be performed on mobile computing device 110 or on security server 150.
[0090] To determine the relevance of the classification of application 130, system protector 120 (like any other protection system) uses rules for determining relevance (relevance rules). These relevance rules can be stored in database 140 of antivirus records, which can contain requirements to be applied to the classification results of application 130.
[0091] If the classification results of application 130 meet the requirements of the relevance rules, the classification results are classified as relevant by system protector 120.
[0092] Examples of the requirements of the relevance rules can be as follows:
[0093] · The difference between the classification timestamp and the current timestamp is within the specified range of allowed values;
[0094] · The error estimate of the expert classification system used is not greater than 0.5%;
[0095] · The mechanism version of the expert classification system used to obtain the classification result is not lower than the mechanism version of the expert classification system used in the classification service; and
[0096] · The version of the mechanism for collecting attributes used by the system protector to obtain the classification result is not lower than the version of the mechanism for collecting attributes used in the classification service.
[0097] On the one hand, in order to designate the classification result of application 130 as relevant, the classification result must satisfy at least one relevance rule.
[0098] On the other hand, in order to designate the classification result of application 130 as relevant, the classification result must satisfy all the relevance rules stored in the database 140 of antivirus records.
[0099] If the system protector 120 does not classify (or designate) the classification result of application 130 as relevant, on the one hand, the system protector 120 collects the set of attributes of application 130 for sending to the classification service 160 according to the above possibilities, and then obtains the classification result of application 130 (for example, in synchronous mode). The classification result obtained in this way is considered relevant by the system protector 120 (that is, without further relevance verification by means of relevance rules).
[0100] Then, on the one hand, the system protector 120 can use the relevance result of the classification of application 130 to determine the category of application 130.
[0101] On the one hand, the above solution is used together with heuristic rules such as the rules stored in the database 140 of antivirus records.
[0102] On yet another hand, a simplified method can be used to determine the category of application 130. For example, the category of application 130 can be defined as the category with the highest probability that application 130 belongs to based on the classification result.
[0103] On the one hand, the application classified as malicious by the system protector 120 can be removed by the system protector 120, or can be placed in an isolation area. On the one hand, the application classified as unnecessary can also be removed by the system protector 120. On the other hand, when the application is classified as unnecessary, the system protector 120 can simply notify the user of the mobile computing device 110 of the existence of the unnecessary application on the device 110, and / or suggest one or more options to the user, such as the option of whether to remove the unnecessary application.
[0104] On the other hand, the system protector 120 can revoke the permission granted to application 130 in order to protect the mobile computing device 110 from the actions that can be performed by application 130.
[0105] It should be noted that the contents of the anti-virus record database 140 and the decision database 180 can be modified by experts in the field of information technology. In addition, the content of the database 140 can also be remotely modified by commands received from the security server 150.
[0106] Figure 2 A method 200 for classifying an application using a classification service according to the teachings of the present disclosure is shown. The method 200 can be implemented on a computing system including any number of devices, for example, a computing system 100 including a mobile computing device 110 and a security server 150.
[0107] Step 201, the method 200 collects a set of attributes of the application 130 present on the device 110 through the system protector 120 running on the user's mobile computing device 110.
[0108] Step 202, the method 200 sends the collected set of attributes to the security server 150 through the system protector 120, more precisely, to the classification service 160 present on the security server 150.
[0109] Step 203, the method 200 classifies the application 130 based on the set of attributes received from the system protector 120 through the classification service 160 present on the security server 150. In one aspect, the result of the classification includes: one or more probabilities that the application 130 belongs to one or more corresponding classes of applications. In one aspect, the classes of applications include: trusted, malicious, and unwanted. The classification result is sent by the classification service 160 to the system protector 120 present on the device 110.
[0110] Step 204, the method 200 determines the class of the application based on the classification result received from the classification service 160 through the system protector 120.
[0111] In one aspect, the class of the application is further determined based on the attributes of the application 130. In one aspect, the attributes of the application used to determine the class of the application include at least one of the following: the set of attributes collected from the application, and an additional set of attributes, where the additional attributes are attributes not used for the classification of the application 130.
[0112] When the method 200 as described above is used to determine the class of the application 130, the attributes of the application (for example, using heuristic rules locally stored on the mobile computing device 110) are used to refine the classification result of the application 130. Therefore, the method 200 helps to describe type I and type II errors (false positives and omissions) in classifying the application 130.
[0113] In addition, if an error occurs, the heuristics stored locally are updated to enable quick correction of the error. Thus, unlike an expert classification system that requires complex retraining of the classification algorithm, errors in the locally stored heuristics can be corrected in a short time and without a complex system. In other words, when an error is detected, the update of the heuristics can be performed locally, thereby improving the classification of the application in a more sensitive manner.
[0114] It should be noted that to achieve the above improvements, the system protector 120 can send any given information about the application 130 and the category assigned to the application by the system protector 120 to the security server 150, which is necessary for detecting the first and second type errors by any method generally known in the art. After detecting the first or second type error, the security server 150 (e.g., by means of the system protector 120 running on the server 150) can provide the system protector 120 with changes to the heuristics. The changes to the heuristics can include changes to specific rules or changes to the instructions for issuing deletion rules. The heuristics are changed to prevent incorrect determination of the category of the application 130 when using the modified local heuristics from the database 140. In addition, when an expert classification system is used to determine the category of an application after the correction of the heuristics, the method of the present disclosure achieves faster correction of the first and second type errors.
[0115] Figure 3 A method 300 for classifying applications on a computing device based on relevance rules in accordance with the teachings of the present disclosure is shown. The method 300 can be implemented on a computing system including any number of devices, e.g., the computing system 100 including the mobile computing device 110 and the security server 150.
[0116] In step 301, the method 300 sends a request by the system protector 120 to obtain the classification result of the application 130. In one aspect, the request is sent to the security server 150, particularly to the reputation service 170 existing on the security server 150. The reputation service 170 stores the classification results of classified applications, i.e., the results of the previous classification of any number of applications performed by the classification service 160. The previous classification is based on the set of previously classified applications collected by the system protector 120.
[0117] In step 302, the method 300 obtains the classification result of the application 130 by the system protector 120. For example, the system protector 120 receives the classification result from the reputation service 170.
[0118] Step 303, the method 300 determines whether the classification result of the obtained application 130 is relevant by the system protector 120 based on the relevance rule. When the system protector 120 deems the classification result of the application to be relevant, the method 300 proceeds to step 320. On the one hand, when the system protector 120 does not deem the classification result of the application 130 to be relevant, the system protector 120 proceeds to step 310. On the other hand, the system protector 120 simply terminates the method 300.
[0119] Step 310, the method 300 executes the steps described in connection with method 200. Figure 2 Accordingly, the system protector 120 collects and sends the set of attributes of the application 130 to the security server 150. Then, the system protector 120 obtains from the security server 150 the updated result of the classification from the application 130.
[0120] Step 320, on the one hand, through the system protector 130, the method 300 can specify the updated result of the classification of the application 130 as relevant based on the relevance rule. The classification result of the application 130 that meets the relevance rule is deemed relevant by the system protector 120.
[0121] Step 330, through the system protector 120, the method 300 determines the category of the application 130 based on the classification result designated as associated.
[0122] On the one hand, the update of the classification includes receiving the updated classification from the security server in response to sending the set of attributes to the security server.
[0123] On the one hand, the set of attributes of the application includes at least one of the following: multiple files in the application package of the application, multiple executable files in the application package, multiple requested permissions and the types of permissions, multiple classes in the executable files in the application package, and multiple methods in the executable files in the application package.
[0124] On the one hand, the result of the classification of the application is presented as one or more probabilities that the application belongs to one or more classes of the corresponding application.
[0125] On the one hand, one or more classes of the application include at least one of the following: the class of malicious applications, the class of unwanted applications, and the class of trusted applications.
[0126] On the one hand, heuristic rules at least partially based on the classification result are used to determine the category of the application.
[0127] In one aspect, the method further includes: when an application is classified as malicious, removing the application from the computing device or isolating the application, and when the application is classified as unwanted, performing at least one of the following: removing the application from the computing device, notifying a user of the computing device of the presence of the unwanted application on the computing device, providing the user of the computing device with an option to select to retain or remove the unwanted application, and revoking a permission previously granted to the application.
[0128] The above method is advantageous in terms of reducing the burden on the classification service 160, and thus also reducing the burden on the security server 150, thereby presenting an improvement in the classification result. Additionally, determining the relevance of the results of previously performed classifications provided by the reputation service 170 advantageously reduces the first and second type errors during the classification of the application 130, and thus also when determining the category of the application 130, due to "obsolescence", incorrect and irrelevant classifications will not be used to determine the category of the application 130.
[0129] Figure 4 A block diagram of a computer system 20 showing aspects of a system and method for classifying applications on a computing device that can be implemented in accordance with an exemplary aspect is shown. It should be noted that the computer system 20 can correspond to, for example, the virtual security device 102 as described previously. The computer system 20 can be in the form of multiple computing devices, or in the form of a single computing device, such as, for example, a desktop computer, a laptop computer, a portable computer, a mobile computing device, a smart phone, a tablet computer, a server, a mainframe, an embedded device, and other forms of computing devices.
[0130] As shown, the computer system 20 includes a central processing unit (CPU) 21, a system memory 22, and a system bus 23 connecting various system components, including the memory associated with the central processing unit 21. The system bus 23 can include a bus memory or a bus storage controller, a peripheral bus, and a local bus capable of interacting with any other bus architecture. Examples of buses can include an external controller interface (PCI), an industry standard architecture bus (ISA), a high-speed serial computer bus (PCI-Express), an HT bus (HyperTransport TM )), InfiniBand TM ), Serial ATA (SerialATA), I2C (I 2(C) and other suitable connector products. The central processing unit 21 (also referred to as a processor) includes one or more processor groups having a single or multiple cores. The processor 21 may execute one or more computer-executable codes implementing the techniques of the present disclosure. The system memory 22 may be any memory for storing data used herein and / or computer programs executable by the processor 21. The system memory 22 may include volatile memory such as random access memory (RAM) 25 and non-volatile memory such as read-only memory (ROM) 24, flash memory, or any combination thereof. The basic input / output system (BIOS) 26 may store basic programs for transferring information between elements of the computer system 20, such as those when loading an operating system using the ROM 24.
[0131] The computer system 20 may include one or more storage devices such as one or more removable storage devices 27, one or more fixed storage devices 28, or a combination thereof. The one or more removable storage devices 27 and fixed storage devices 28 are connected to the system bus 23 via a storage interface 32. In one aspect, the storage devices and the corresponding computer-readable storage media are power-independent modules for storing computer instructions, data structures, program modules, and other data of the computer system 20. The system memory 22, the removable storage devices 27, and the fixed storage devices 28 may use various computer-readable storage media. Examples of computer-readable storage media include mechanical memories such as cache, static random access memory (SRAM), dynamic random access memory (DRAM), zero-capacitor RAM, dual-transistor RAM, enhanced dynamic random access memory (eDRAM), extended data output RAM (EDO RAM), double data rate memory (DDR RAM), electrically erasable read-only memory (EEPROM), nanotube random access memory (NRAM), resistive random access memory (RRAM), semiconductor-oxide-nitride-oxide-silicon (SONOS), phase change memory (PRAM); flash memory or other memory technologies such as in a solid state drive (SSD) or a flash drive; magnetic cartridges, tapes, and disk storage such as in a hard disk drive or a floppy disk; optical memory such as in a compact disc read-only memory (CD-ROM) or a digital versatile disc (DVD); and any other medium that can be used to store the required data and can be accessed by the computer system 20.
[0132] The system memory 22, removable storage device 27, and fixed storage device 28 of the computer system 20 can be used to store an operating system 35, additional program applications 37, other program modules 38, and program data 39. The computer system 20 can include a peripheral interface 46 that is used to transfer data from input devices 40 (such as a keyboard, mouse, stylus, game controller, voice input device, touch input device, or other peripheral devices such as a printer or scanner) via one or more I / O ports (such as a serial port, parallel port, Universal Serial Bus (USB), or other peripheral interface). A display device 47 such as one or more monitors, projectors, or integrated displays can also be connected to the system bus 23 through an output interface 48 such as a video adapter. In addition to the display device 47, the computer system 20 can be equipped with other peripheral output devices (not shown), such as speakers and other audio-visual devices.
[0133] The computer system 20 can operate in a network environment using a network connection to one or more remote computers 49. One remote computer (or multiple remote computers) 49 can be a local computer workstation or server that includes most or all of the above-described elements in the nature of the computer system 20. There can also be other devices in the computer network, such as, but not limited to, routers, network stations, peer devices, or other network nodes. The computer system 20 can include one or more network interfaces 51 or network adapters that are used to communicate with the remote computer 49 via one or more networks, such as a local area computer network (LAN) 50, a wide area computer network (WAN), an intranet, and the Internet. Examples of the network interface 51 can include an Ethernet interface, a Frame Relay interface, a Synchronous Optical Network interface (SONET interface), and a wireless interface.
[0134] Aspects of the present disclosure can be a system, a method, and / or a computer program product. The computer program product can include a computer-readable storage medium (or medium) having computer-readable program instructions for causing a processor to execute aspects of the present disclosure.
[0135] A computer-readable storage medium is a tangible device that can hold and store program code in the form of instructions or data structures that are accessible by a processor of a computing device such as computing system 20. The computer-readable storage medium can be an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. By way of example, such computer-readable storage media include random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), portable compact disc read-only memory (CD-ROM), digital versatile discs (DVDs), flash memory, hard disks, portable computer disks, memory sticks, floppy disks, or even mechanical encoding devices such as punch cards or raised structures in grooves having instructions recorded thereon. As used herein, a computer-readable storage medium should not be construed to be a transient signal per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or transmission medium, or electrical signals transmitted through a wire.
[0136] The computer-readable program instructions described herein are downloaded from a computer-readable storage medium to a respective computing device, or are downloaded to an external computer or external storage device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network). The network can include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. The network interface in each computing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the respective computing device.
[0137] The computer-readable program instructions for carrying out operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages and conventional procedural programming languages. The computer-readable program instructions may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network (including a LAN or a WAN), or may be connected to an external computer (e.g., through the Internet). In some aspects, an electronic circuit including, for example, a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA) can execute the computer-readable program instructions by utilizing state information of the computer-readable program instructions to personalize the electronic circuit, in order to carry out aspects of the present disclosure.
[0138] In various aspects, the systems and methods of the present disclosure can be addressed in terms of modules. As used herein, the term "module" refers to a real-world device, component, or arrangement of components implemented using hardware such as, for example, by an application specific integrated circuit (ASIC) or a field programmable gate array (FPGA), or as a combination of hardware and software, such as by a microprocessor system and instruction set to implement the functions of the module, which (when executed) transforms the microprocessor system into a dedicated device. A module can also be implemented as a combination of both, where some functions are implemented solely by hardware and other functions are implemented by a combination of hardware and software. In some embodiments, at least a portion of a module, and in some cases, all of a module, can be executed on a processor of a computer system (such as the computer system described in more detail above in Figure 4 ). Thus, each module can be implemented in a variety of suitable configurations and should not be limited to any particular exemplary implementation herein.
[0139] For clarity, not all conventional features of the various aspects are disclosed herein. It should be understood that in the development of any actual implementation of the present disclosure, numerous implementation-specific decisions must be made to achieve the developer's specific goals, and such specific goals will vary from one implementation to another and from one developer to another. It should be understood that such development efforts may be complex and time-consuming, but for those of ordinary skill in the art who benefit from the present disclosure, this is merely a routine engineering task.
[0140] Furthermore, it should be understood that the language or terminology used herein is for the purpose of description and not limitation, such that the terminology or language of this specification is to be understood by those of ordinary skill in the art in light of the teachings and guidance presented herein, in conjunction with the knowledge of one or more relevant fields of technology. Additionally, unless explicitly stated otherwise, no term in the specification or claims is intended to be construed as having an uncommon or special meaning.
[0141] The various aspects disclosed herein include current and future known equivalents of known modules mentioned herein by way of example. Additionally, while aspects and applications have been shown and described, it will be apparent to those skilled in the art who benefit from the present disclosure that many more modifications are possible without departing from the inventive concepts disclosed herein than those described above.
Claims
1. A method for classifying applications on a computing device, the method comprises: Obtaining the classification result of an application from a security server, wherein the classification result of the application is presented as one or more probabilities that the application belongs to one or more corresponding categories of applications, and the one or more categories of the application include: the category of malicious applications, the category of unwanted applications that are neither malicious nor trusted, and the category of trusted applications; Applying one or more correlation rules to the classification result, wherein the one or more correlation rules contain requirements for the classification result, and the requirements reduce the probability of false positive errors in the classification of the application. One or more correlation rules related to the classification result are based on at least one of the following conditions: the difference between the classification timestamp and the current timestamp is within a specified range of allowable values, and the error estimate of the expert classification system is not greater than a preset threshold; When the classification result satisfies one or more correlation rules, designating the classification result as relevant, and determining the category of the application based on the result being designated as relevant; and When the classification result does not satisfy the correlation rules, perform at least one of the following: terminate the classification of the application, and update the classification of the application based on the attribute set of the application, wherein the update of the classification includes: receiving the updated classification from the security server in response to sending the attribute set to the security server.
2. The method according to claim 1, wherein, The preset threshold is 0.5%.
3. The method according to claim 1, wherein, The attribute set of the application includes at least one of the following: Multiple files in the application package of the application; Multiple executable files in the application package; Multiple requested permissions and types of permissions; Multiple classes in the executable files in the application package; And Multiple methods in the executable files in the application package.
4. The method according to claim 1, wherein, Use heuristic rules that are at least partially based on the classification result to determine the category of the application.
5. The method according to claim 1, further comprises: When the application is classified as malicious, removing the application from the computing device or isolating the application; And When the application is classified as unwanted, perform at least one of the following: remove the application from the computing device, notify the user of the computing device of the existence of the unwanted application on the computing device, provide the user of the computing device with an option to select to retain or remove the unwanted application, and revoke the permissions previously granted to the application.
6. The method according to claim 1, wherein, If the classification result satisfies at least one correlation rule, the classification result of the application is designated as satisfying the correlation rule.
7. The method according to claim 1, wherein, If the classification result satisfies all correlation rules, the classification result of the application is designated as satisfying the correlation rule.
8. The method according to claim 1, wherein, the categories of the trusted applications include applications developed by trusted software manufacturers, applications downloaded from trusted sources, or applications whose identifiers are stored in the database of trusted applications.
9. A system for classifying applications on a computing device, comprising: at least one processor configured to: obtain the classification result of an application from a security server, wherein the classification result of the application is presented as one or more probabilities that the application belongs to one or more corresponding categories of applications, and the one or more categories of the application include: the category of malicious applications, the category of unwanted applications that are neither malicious nor trusted, and the category of trusted applications; apply one or more correlation rules to the classification result, wherein the one or more correlation rules contain requirements for the classification result, and the requirements reduce the probability of false positive errors in the classification of the application, and one or more correlation rules related to the classification result are based on at least one of the following conditions: the difference between the classification timestamp and the current timestamp is within a specified range of allowable values, and the error estimate of the expert classification system is not greater than a preset threshold; when the classification result satisfies one or more correlation rules, designate the classification result as relevant, and determine the category of the application based on the result being designated as relevant; and when the classification result does not satisfy the correlation rules, perform at least one of the following: terminate the classification of the application, and update the classification of the application based on the set of attributes of the application, wherein the update of the classification includes: receiving the updated classification from the security server in response to sending the set of attributes to the security server.
10. The system according to claim 9, wherein, the preset threshold is 0.5%.
11. The system according to claim 9, wherein, the set of attributes of the application includes at least one of the following: multiple files in the application package of the application; multiple executable files in the application package; multiple requested permissions and types of permissions; multiple classes in the executable files in the application package; and multiple methods in the executable files in the application package.
12. The system according to claim 9, wherein, heuristic rules at least partially based on the classification result are used to determine the category of the application.
13. The system according to claim 9, the processor is further configured to: when the application is classified as malicious, remove the application from the computing device or isolate the application; and when the application is classified as unwanted, perform at least one of the following: remove the application from the computing device, notify the user of the computing device of the existence of the unwanted application on the computing device, provide the user of the computing device with an option to select to retain or remove the unwanted application, and revoke the permissions previously granted to the application.
14. The system according to claim 9, wherein, If the result of the classification satisfies at least one relevance rule, the result of the classification of the application is designated as satisfying the relevance rule.
15. The system according to claim 9, wherein, If the result of the classification satisfies all relevance rules, the result of the classification of the application is designated as satisfying the relevance rule.
16. The system according to claim 9, wherein, The categories of the trusted applications include applications developed by trusted software manufacturers, applications downloaded from trusted sources, or applications whose identifiers are stored in a database of trusted applications.
17. A non-transitory computer-readable medium storing computer-executable instructions for classifying applications on a computing device, the instructions including instructions for: Obtaining the result of the classification of the application from a security server, wherein, The result of the classification of the application is presented as one or more probabilities that the application belongs to one or more corresponding categories of applications, and the one or more categories of applications include: the category of malicious applications, the category of unwanted applications that are neither malicious nor trusted, and the category of trusted applications; Applying one or more relevance rules to the result of the classification, wherein the one or more relevance rules include requirements for the result of the classification, and the requirements reduce the probability of false positive errors in the classification of the application. Wherein, the one or more relevance rules related to the result of the classification are based on at least one of the following conditions: the difference between the timestamp of the classification and the current timestamp is within a specified range of allowable values, and the error estimate of the expert classification system is not greater than a preset threshold; When the result of the classification satisfies one or more relevance rules, designating the result of the classification as relevant, and determining the category of the application based on the result being designated as relevant; and When the result of the classification does not satisfy the relevance rule, perform at least one of the following: terminating the classification of the application, and updating the classification of the application based on the set of attributes of the application. Wherein, the update of the classification includes: receiving the updated classification from the security server in response to sending the set of attributes to the security server.
18. The non-transitory computer-readable medium according to claim 17, wherein, The preset threshold is 0.5%.
19. The non-transitory computer-readable medium according to claim 17, wherein, The set of attributes of the application includes at least one of the following: Multiple files in the application package of the application; Multiple executable files in the application package; Multiple requested permissions and types of permissions; Multiple classes in the executable files in the application package; and Multiple methods in the executable files in the application package.
20. The non-transitory computer-readable medium according to claim 17, wherein the category of the application is determined using heuristic rules that are at least partially based on the result of the classification.
21. The non-transitory computer-readable medium according to claim 17, the instructions further including instructions for: When the application is classified as malicious, remove the application from the computing device or isolate the application; and When the application is classified as unnecessary, perform at least one of the following: remove the application from the computing device, notify the user of the computing device of the presence of the unnecessary application on the computing device, provide the user of the computing device with an option to select to retain or remove the unnecessary application, and revoke the permissions previously granted to the application.
22. The non-transitory computer-readable medium according to claim 17, wherein, If the result of the classification satisfies at least one relevance rule, the result of the classification of the application is designated as satisfying the relevance rule.
23. The non-transitory computer-readable medium according to claim 17, wherein, If the result of the classification satisfies all relevance rules, the result of the classification of the application is designated as satisfying the relevance rule.
24. The non-transitory computer-readable medium according to claim 17, wherein, The categories of the trusted applications include applications developed by trusted software manufacturers, applications downloaded from trusted sources, or applications whose identifiers are stored in a database of trusted applications.
Citation Information
Patent Citations
USB firewall apparatus and method
US20120240234A1