Application Vulnerability Detection Method, Device, Electronic Device and Storage Medium
By performing SDK category clustering and API call analysis on the installation package of the target application, combined with the vulnerability identification model, the problem of SDK vulnerability detection and miss detection in the existing technology is solved, and efficient and accurate application vulnerability detection is achieved.
Patent Information
- Application Number
- CN202110076005.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-01-20
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-01-20
AI Technical Summary
现有的应用漏洞检测方法忽略了SDK的源代码,导致漏洞检测存在漏检的风险,无法有效检测因引入SDK导致的应用漏洞。
By obtaining the installation package of the target application, using the pre-built SDK category set to cluster the source code, combining API call analysis to determine the characteristics of the code fragment to be tested, and using the vulnerability identification model to detect whether there are specified vulnerabilities in the SDK.
It effectively solves the missed detection problem of application vulnerability detection, improves detection efficiency, can timely discover vulnerabilities introduced by the SDK, reduces the missed rate, and can detect unknown vulnerabilities or certain types of vulnerabilities, narrowing the scope of impact of vulnerabilities.
Smart Images

Figure CN113569249B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology. Specifically, this application relates to an application vulnerability detection method, apparatus, electronic device, and storage medium. Background Art
[0002] With the development of computer technology, the applications that can be installed on terminals are becoming increasingly rich, and the functions of each application program are gradually increasing to better provide rich entertainment experiences for end users.
[0003] Currently, in addition to integrating general functions, applications also use SDKs (Software Development Kits) provided by third parties to expand the functions of the applications. For example, face recognition functions, payment functions, location service functions, and so on. As the application installation package (APK, Android Packet) runs on the terminal, the source code of the application itself and the source code of the SDK are integrated together so that the application can provide extended functions to end users through the loading of the SDK when running on the terminal.
[0004] However, existing application vulnerability detections usually target the source code of the application itself, avoiding the source code of the SDK and ignoring the possibility that the application itself has vulnerabilities due to the introduction of the SDK. In this case, there is a risk of missed detections in application vulnerability detection. Summary of the Invention
[0005] Embodiments of this application provide an application vulnerability detection method, apparatus, electronic device, and storage medium, which can solve the problem of missed detections in application vulnerability detection in related technologies. The technical solutions are as follows:
[0006] According to one aspect of the embodiments of this application, an application vulnerability detection method includes: obtaining a detection object, where the detection object includes the installation package of a target application; clustering the source code of the detection object according to the SDK categories in a pre-constructed SDK category set of software development kits to obtain at least one SDK, where the SDK includes source code belonging to the same SDK category; determining the characteristics of the code segments to be tested in the SDK through application programming interface (API) call analysis; and performing application vulnerability detection on the characteristics of the code segments to be tested according to a vulnerability recognition model constructed for specified vulnerabilities to obtain a detection result on whether the code segments to be tested have the specified vulnerabilities.
[0007] According to one aspect of the embodiments of the present application, an application vulnerability detection method includes: initiating a vulnerability detection request to a server according to the installation package of a target application, so that the server, in response to the vulnerability detection request, performs application vulnerability detection on the SDK in the target application according to the above application vulnerability detection method; and receiving the detection result of the SDK in the target application returned by the server.
[0008] According to one aspect of the embodiments of the present application, an application vulnerability detection device includes: an application acquisition module for acquiring a detection object, where the detection object includes the installation package of a target application; a set acquisition module for clustering the source code of the detection object according to the SDK categories in a pre-constructed software development kit (SDK) category set to obtain at least one SDK, where the SDK includes the source code belonging to the same SDK category; a feature acquisition module for determining the features of the code segments to be detected in the SDK through application programming interface (API) call analysis; and a result acquisition module for performing application vulnerability detection on the features of the code segments to be detected according to a vulnerability recognition model constructed for a specified vulnerability to obtain the detection result of whether the code segments to be detected have the specified vulnerability.
[0009] In a possible implementation, the device further includes: a first target acquisition module for acquiring a first training object, where the first training object includes the installation package of a first training application; and a set construction module for constructing an SDK category set according to the source code of the first training object.
[0010] In a possible implementation, the first target acquisition module includes: a request download unit for sending a download request for an updated application to a third-party application platform if it is monitored that there is an application update on the third-party application platform, so that the third-party application platform pushes the installation package of the updated application in response to the download request; and an installation package receiving unit for receiving the installation package of the updated application and storing the received installation package of the updated application as the first training object.
[0011] In a possible implementation, the set construction module includes: a first decompilation unit for decompiling the first training object according to the application information of the first training application to obtain the source code of the first training object, where the source code of the first training object includes at least one training code segment; a first feature acquisition unit for determining the features of at least one training code segment through API call analysis; and a feature clustering unit for clustering at least one training code segment according to the features of at least one training code segment, and adding the features of the training code segments belonging to the same SDK category as the category features of the SDK category to the SDK category set.
[0012] In a possible implementation, the feature acquisition unit includes: a statistical subunit, configured to perform statistics on API calls executed by each training code snippet to obtain the features of the training code snippet.
[0013] In a possible implementation, the feature clustering unit includes: a traversal subunit, configured to traverse at least one training code snippet; a calculation subunit, configured to calculate a first similarity between the features of the currently traversed training code snippet and the features of the remaining training code snippets; and a clustering subunit, configured to classify the remaining training code snippets whose first similarity exceeds a first threshold into the SDK category to which the currently traversed training code snippet belongs.
[0014] In a possible implementation, the set acquisition module includes: a second decompilation unit, configured to perform decompilation processing on a detection object according to the application information of the target application to obtain the source code of the detection object, where the source code of the detection object includes at least one target code snippet; a second feature acquisition unit, configured to determine the features of each target code snippet through API call analysis; a first similarity calculation unit, configured to calculate a second similarity between the features of the target code snippet and the category features of each SDK category in the SDK category set; and a classification unit, configured to, if the second similarity exceeds a second threshold, determine that the target code snippet belongs to the SDK category, and form an SDK from the target code snippets belonging to the SDK category.
[0015] In a possible implementation, the result acquisition module includes: a third feature acquisition unit, configured to determine the features of a specified code snippet with a specified vulnerability based on a vulnerability identification model; a second similarity calculation unit, configured to calculate a third similarity between the features of the code snippet to be tested and the features of the specified code snippet; and a result generation unit, configured to, if the third similarity exceeds a third threshold, obtain a detection result that the code snippet to be tested has the specified vulnerability.
[0016] In a possible implementation, the device further includes: a second target acquisition module, configured to acquire a second training object, where the second training object includes a second training application with a specified vulnerability; and a model construction module, configured to construct a vulnerability identification model according to the specified vulnerability existing in the second training application.
[0017] In a possible implementation, the model construction module includes: a code determination unit, configured to determine at least one specified code snippet with a specified vulnerability in the second training application; a feature determination unit, configured to determine the features of the at least one specified code snippet through API call analysis; and a relationship construction unit, configured to construct a correspondence relationship between the features of the at least one specified code snippet and the specified vulnerability to obtain a vulnerability identification model.
[0018] According to one aspect of the embodiments of the present application, an application vulnerability detection device includes: a request initiation module, configured to initiate a vulnerability detection request to a server according to the installation package of a target application, so that the server, in response to the vulnerability detection request, performs application vulnerability detection on the SDKs in the target application according to the above application vulnerability detection method; and a result receiving module, configured to receive the detection result of the SDKs in the target application returned by the server.
[0019] According to one aspect of the embodiments of the present application, an electronic device includes: at least one processor, at least one memory, and at least one communication bus. Among them, computer-readable instructions are stored on the memory, and the processor reads the computer-readable instructions in the memory through the communication bus; when the computer-readable instructions are executed by the processor, the above-mentioned application vulnerability detection method is implemented.
[0020] According to one aspect of the embodiments of the present application, a storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned application vulnerability detection method is implemented.
[0021] According to one aspect of the embodiments of the present application, a computer program product includes computer-readable instructions. The computer-readable instructions are stored in a storage medium, and the processor of a computer device reads the computer-readable instructions from the storage medium, and the processor executes the computer-readable instructions, so that when the computer device executes, the above-mentioned application vulnerability detection method is implemented.
[0022] The beneficial effects brought by the technical solution provided by the present application are:
[0023] In the above technical solution, the installation package of the target application is obtained as the detection object, and according to the SDK categories in the SDK category set, the source code of the detection object is clustered to obtain an SDK set including at least one SDK, and through API call analysis, the characteristics of the code segments to be tested in the SDK are determined. Furthermore, based on the vulnerability recognition model constructed according to the specified vulnerabilities, application vulnerability detection is performed on the characteristics of the code segments to be tested, and the detection result of whether the code segments to be tested have the specified vulnerabilities is obtained. Thus, an application vulnerability detection solution for SDKs is implemented based on the vulnerability recognition model, avoiding the possibility of vulnerabilities existing in the application itself due to the introduction of SDKs, and effectively solving the problem of missed detection in application vulnerability detection in the related art. Description of the Drawings
[0024] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description in the embodiments of the present application.
[0025] Figure 1 It is a schematic diagram of the implementation environment related to the present application.
[0026] Figure 2 is Figure 1 The timing diagram of the application vulnerability detection method involved in the corresponding embodiment.
[0027] Figure 3 It is a flowchart of an application vulnerability detection method shown according to an exemplary embodiment.
[0028] Figure 4 It is a flowchart of another application vulnerability detection method shown according to an exemplary embodiment.
[0029] Figure 5 is Figure 4 The flowchart of step 410 in the corresponding embodiment in one embodiment.
[0030] Figure 6 is Figure 4 The flowchart of step 430 in the corresponding embodiment in one embodiment.
[0031] Figure 7 is Figure 6 The flowchart of step 435 in the corresponding embodiment in one embodiment.
[0032] Figure 8 is Figure 3 The flowchart of step 330 in the corresponding embodiment in one embodiment.
[0033] Figure 9 is Figure 3 The flowchart of step 350 in the corresponding embodiment in one embodiment.
[0034] Figure 10 It is a flowchart of another application vulnerability detection method shown according to an exemplary embodiment.
[0035] Figure 11 is Figure 10 The flowchart of step 530 in the corresponding embodiment in one embodiment.
[0036] Figure 12 It is a flowchart of another application vulnerability detection method shown according to an exemplary embodiment.
[0037] Figure 13 It is a schematic diagram of the implementation of an application vulnerability detection method in an application scenario.
[0038] Figure 14 It is a structural block diagram of an application vulnerability detection device shown according to an exemplary embodiment.
[0039] Figure 15 It is a structural block diagram of another application vulnerability detection device shown according to an exemplary embodiment.
[0040] Figure 16 It is a hardware structure diagram of a server shown according to an exemplary embodiment.
[0041] Figure 17 It is a block diagram of the structure of an electronic device shown according to an exemplary embodiment. Detailed implementation manners
[0042] The embodiments of the present application will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary and are only used to explain the present application and should not be construed as a limitation of the present invention.
[0043] Those skilled in the art of the present technology can understand that unless specifically stated, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the term "including" used in the specification of the present application means the presence of the described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or their groups. It should be understood that when we say that an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The phrase "and / or" used herein includes all or any unit and all combinations of one or more related listed items.
[0044] The following is an introduction and explanation of several terms related to the present application:
[0045] SDK: The English abbreviation of Software Development Kit, which is interpreted as a software development kit in Chinese. Generally, it is a collection of development tools provided by a third party for a specific software package, software framework, hardware platform, operating system, etc.
[0046] APK: The English abbreviation of Android Packet, which is interpreted as an application installation package in Chinese. As the application installation package runs, the terminal is regarded as having installed the application or upgraded the application. When the application runs on the terminal, it can provide various functions that the application possesses for the terminal user. For example, an instant messaging application provides a session function for the terminal user.
[0047] Clustering: It is to divide the data objects in a dataset into different classes or clusters according to a specific criterion (such as the distance criterion), so that the similarity of the data objects within the same class or cluster is as large as possible, and at the same time, the difference of the data objects not in the same class or cluster is also as large as possible. It can also be understood that clustering makes the data objects of the same category gather together as much as possible, and the data objects of different categories are separated as much as possible.
[0048] As mentioned above, the existing application vulnerability detection ignores the possibility that the application itself has vulnerabilities due to the introduction of the SDK. In this case, there will be a risk of missed detection in application vulnerability detection.
[0049] It can be understood that the functions extended by the application can be implemented by SDKs provided by different third parties. For example, the payment function can be implemented by Payment SDK-1 provided by Party A and Payment SDK-2 provided by Party B. Suppose the payment function expected to be extended by the application can support payment SDKs provided by different third parties at the same time, then Payment SDK-1 and Payment SDK-2 will be introduced into the application simultaneously.
[0050] Then, in order to avoid false alarms in application vulnerability detection caused by the source code of SDKs with the same function interfering with the source code of the application, in an application vulnerability detection scheme, first collect the existing SDK set to extract the feature rules of the SDK from this SDK set and establish an SDK identification feature rule library; then, based on this SDK identification feature rule library, extract the source code of the SDK from the integrated source code of the SDK and the source code of the application itself, and execute special logic for the extracted source code of the SDK. For example, this special logic is not to perform application vulnerability detection on the source code of the SDK. Thus, the application vulnerability detection will only be performed on the source code of the application itself, thereby reducing the false alarm rate in this way.
[0051] In the above application vulnerability detection process, since the source code of the SDK is not detected for vulnerabilities, the possibility that the application itself has vulnerabilities due to the introduction of the SDK cannot be excluded, and there may still be a possibility of missed detection in application vulnerability detection.
[0052] In addition, in the above application vulnerability detection process, it is still limited to application vulnerability detection based on string rules or syntax analysis, and can only detect known vulnerabilities, and is still unable to effectively detect unknown vulnerabilities or a certain type of vulnerabilities, resulting in detection lag. In this case, there may also be a possibility of missed detection.
[0053] As can be seen from the above, there is still a risk of missed detection in application vulnerability detection in the related art.
[0054] Therefore, the application vulnerability detection method, device, electronic device and storage medium provided in this application are aimed at solving the above technical problems in the related art.
[0055] To make the objectives, technical solutions, and advantages of this application clearer, the following will further describe the embodiments of this application in detail with reference to the accompanying drawings.
[0056] Figure 1 It is a schematic diagram of the implementation environment involved in an application vulnerability detection method. This implementation environment includes a terminal 100 and a server 200.
[0057] Specifically, the terminal 100 can be used for the client to run and can be an electronic device such as a desktop computer, a laptop computer, a tablet computer, a server, etc., which is not limited herein.
[0058] Among them, the client is used to provide an application vulnerability detection entry for the end user. The client can be in the form of an application or a web page. Correspondingly, the user interface of the client can be in the form of a program window or a web page, which is not limited herein either.
[0059] The server 200 can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. For example, in this implementation environment, the server 200 provides an application vulnerability detection service for the terminal 100.
[0060] The server 200 and the terminal 100 are pre-established with a communication connection through wired or wireless means, etc., and data transmission between the terminal 100 and the server 200 is respectively realized through this communication connection. For example, the transmitted data includes but is not limited to: a vulnerability detection request initiated by the terminal 100 to the server 200, or a detection result returned by the server 200 to the terminal 100.
[0061] As the client runs on the terminal 100, the terminal 100 can upload the installation package of the target application through the application vulnerability detection entry provided by the client, as Figure 2 shown, so that the terminal 100 can initiate a vulnerability detection request to the server 200 according to the installation package of the target application, requesting the server 200 to perform application vulnerability detection on the SDK in the target application. Through the interaction between the terminal 100 and the server 200, for the server 200, it can receive this vulnerability detection request, and then respond to this vulnerability detection request to perform application vulnerability detection on the SDK in the target application, and return the detection result of the SDK in this target application to the terminal 100, as Figure 2 shown.
[0062] Please refer toFigure 3 , an embodiment of the present application provides an application vulnerability detection method, which is applicable to Figure 1 the server 200 in the implementation environment shown in the figure.
[0063] In the following method embodiments, for the sake of convenience of description, the execution subject of each step is described as the server, but this is not a limitation.
[0064] As Figure 3 shown in the figure, the method may include the following steps:
[0065] Step 310, obtain a detection object.
[0066] Among them, the detection object includes the installation package of the target application.
[0067] In the related art, application vulnerability detection mostly targets the application running stage, that is, through the running of the installation package of the application, the terminal is regarded as installing the application or upgrading the application, and then as the application runs on the terminal, the terminal will perform application vulnerability detection on the running application. At this time, the inventor found that even if the vulnerability is discovered in time, since the application has already run on the terminal, it will still inevitably have a certain impact on the system.
[0068] Therefore, in this embodiment, the installation package of the target application is used as the detection object. That is to say, the detection object is replaced from the target application to the installation package of the target application, so that the introduction of vulnerabilities is controlled at the stage of integrating the SDK into the application, so as to achieve the purpose of minimizing the scope of vulnerability impact.
[0069] It should be added that in this embodiment, it is not limited to the number of target applications in the detection object and the number of installation packages of the target application. For example, the detection object may include at least one installation package of one target application, or may include multiple installation packages of multiple target applications, which is not limited here.
[0070] Regarding the acquisition of the detection object, it may be obtained from a vulnerability detection request initiated by the terminal in real time and extracting the detection object therefrom; it may also be obtained from the detection object stored historically in the server, and the detection object is obtained and stored from the vulnerability detection request initiated by the terminal in real time.
[0071] In other words, application vulnerability detection can be implemented for the detection object obtained by real-time extraction, so as to improve the real-time performance of application vulnerability detection; it can also be implemented for the detection object obtained by extracting in a historical time period, so as to improve the detection efficiency of application vulnerability detection. For example, when the memory occupancy of the server is relatively small, the detection object obtained by extracting in this historical time period is implemented.
[0072] Step 330: Cluster the source code of the detection object according to the SDK categories in the pre-constructed software development kit (SDK) category set to obtain at least one SDK.
[0073] Among them, the SDK includes the source code belonging to the same SDK category. This SDK category belongs to the pre-constructed SDK category set.
[0074] The inventor realized that the same code may exist in the same application or in different applications. In the related art, an application is generally regarded as a whole for application vulnerability detection. In this case, a large amount of duplicate code will be faced in each application vulnerability detection. For example, perform application vulnerability detection on the code x in application X and also perform application vulnerability detection on the code x in application Y, resulting in low detection efficiency of application vulnerability detection. Therefore, in this embodiment, after obtaining the detection object, the detection object is divided into SDKs, and the SDKs are used as the basic units for application vulnerability detection. For example, the code x in application X and the code x in application Y belong to the same SDK. At this time, only perform application vulnerability detection on the code x in the SDK once, avoiding a large amount of duplicate code in application vulnerability detection, and improving the detection efficiency of application vulnerability detection in this way.
[0075] Regarding the division of the detection object, it is implemented according to the category characteristics of the SDK categories in the SDK category set. The category characteristics of this SDK category are used to accurately describe the SDK category, and then uniquely identify the SDK category in the form of digital information. It can be understood that if the category characteristics are different, the SDK categories will also be different. In a possible implementation manner, the category characteristics of the SDK category are determined through API call analysis.
[0076] Thus, the source code of the detection object can be clustered based on the SDK categories in the SDK category set, so that the duplicate or similar source code is classified into the same SDK, providing a correctness guarantee for application vulnerability detection with the SDK as the basic unit.
[0077] It should be noted here that the source code of the detection object, that is, the source code of the target application, not only includes the source code of the target application itself, but also includes the source code of the SDK. That is to say, the source code of the detection object is actually the integration of the source code of the target application itself and the source code of the SDK. Then, the subsequent application vulnerability detection will not only be directed at the source code of the target application itself, but also at the source code of the SDK, excluding the possibility of application vulnerabilities caused by the introduction of the SDK in this way.
[0078] It should be noted that the source code of the target application itself provides the general functions of the target application, while the source code of the SDK is used to extend the functions of the target application. Therefore, the code of the SDK in the SDK collection can be the source code of the target application itself or the source code of the SDK used to extend the functions of the target application. This will not be repeated below.
[0079] Step 350, determine the characteristics of the code snippet to be tested in the SDK through application programming interface (API) call analysis.
[0080] Among them, the code snippet to be tested refers to the code snippet in the SDK that is planned to be subject to application vulnerability detection. It can be a class or a function, and there is no limitation here. The characteristics of the code snippet to be tested are used to accurately describe the code snippet to be tested, and then uniquely identify the code snippet to be tested in digital information. It can be understood that if the characteristics are different, the code snippets to be tested will also be different.
[0081] In this embodiment, the characteristics of the code snippet to be tested are determined through API call analysis. Specifically, for the code snippet to be tested in the SDK, the API calls executed by the code snippet to be tested are counted to obtain the characteristics of the code snippet to be tested.
[0082] The above statistics can count the types of API calls executed by the code snippet to be tested, and can also count the number of different types of API calls executed by the code snippet to be tested. Or, the types and the number of API calls executed by the code snippet to be tested are counted simultaneously.
[0083] For example, for the code snippet A to be tested in the SDK, the types of API calls executed by the code snippet A to be tested include a and b, and the number of a-type API calls executed by the code snippet A to be tested is 2 times, and the number of b-type API calls executed is 3 times. Then, the characteristics of the code snippet A to be tested can be uniquely represented as A = {a: 2, b: 3}.
[0084] It is worth mentioning that for each SDK, the code snippets to be tested it contains may still be repeated, and correspondingly, the characteristics of the code snippets to be tested may also be repeated. Therefore, in a possible embodiment, for the code snippets to be tested in the SDK, deduplication processing will be performed based on the characteristics of the code snippets to be tested.
[0085] For example, through clustering, the code snippet A to be tested and the code snippet A' to be tested are classified into the same SDK. Since the characteristics of the code snippet A to be tested and the characteristics of the code snippet A' to be tested are repeated, after deduplication processing, only the code snippet A to be tested or the code snippet A' to be tested will be subject to application vulnerability detection once. In this way, it can effectively avoid a large amount of repeated code in each application vulnerability detection.
[0086] Step 370: Apply vulnerability detection to the features of the code snippet to be tested using the vulnerability identification model built based on the specified vulnerability, and obtain the detection result of whether the specified vulnerability exists in the code snippet to be tested.
[0087] Among them, the vulnerability identification model is built based on the specified vulnerability, reflecting the association and mapping between the specified code snippet with the specified vulnerability and the specified vulnerability. For example, through the features of the specified code snippet, the association and mapping between the specified code snippet and the specified vulnerability it has can be realized. In other words, from the features of the specified code snippet, the specified vulnerability existing in the specified code snippet can be determined.
[0088] Based on this, after determining the features of the code snippet to be tested, through the vulnerability identification model, it is possible to detect whether the code snippet to be tested has an association and mapping with the specified vulnerability, and thus obtain the detection result of whether the specified vulnerability exists in the code snippet to be tested. Still taking the previous example for illustration, assume that based on the vulnerability identification model, the feature of the specified code snippet S is S = {a: 2, b: 3}, and the specified vulnerability S' existing in the specified code snippet S can be determined.
[0089] Then, for the feature of the code snippet A to be tested is A = {a: 2, b: 3}, it can be detected that the code snippet A to be tested has an association and mapping with the specified vulnerability S', and thus obtain the detection result that the code snippet A to be tested has the specified vulnerability S'.
[0090] Suppose there is another code snippet A' to be tested that is identical to the code snippet A to be tested, then their features are also the same, that is, the feature of this code snippet A' to be tested is A' = {a: 2, b: 3}. Since the code snippet A to be tested has been tested before, at this time, it is no longer necessary to repeat the application vulnerability detection for the code snippet A' to be tested, and it can also be considered that the code snippet A' to be tested has been completed with detection, and the detection result of the code snippet A' to be tested is the same as that of the code snippet A to be tested, that is, the code snippet A' to be tested also has the specified vulnerability S'.
[0091] In a possible implementation, the vulnerability identification model can be built based on a machine learning model. In a possible implementation, the vulnerability identification model can be built based on the correspondence between the features of the specified code snippet with the specified vulnerability and the specified vulnerability.
[0092] Through the above process, for the SDK in the application, an application vulnerability detection solution is implemented, avoiding the possibility that the application itself has vulnerabilities due to the introduction of the SDK, thereby effectively solving the problem of missed detection in application vulnerability detection in the related art.
[0093] In addition, the SDK is used as the basic unit for application vulnerability detection to avoid a large amount of duplicate code in each application vulnerability detection, thereby effectively improving the detection efficiency of application vulnerability detection.
[0094] Please refer to Figure 4 , a possible implementation manner is provided in the embodiments of the present application. After step 330, the method may further include the following steps:
[0095] Step 410, obtain a first training object.
[0096] The first training object is used to implement the construction of the SDK category set, and the first training object includes the installation package of the first training application.
[0097] In a possible implementation manner, as Figure 5 shown, step 410 may include the following steps:
[0098] Step 411, monitor whether there is an application update on the third-party application platform.
[0099] First, it should be noted that the third-party application platform is used to store the installation packages of applications and provide application download services to a large number of end users. For application publishers, after completing the application development, they can release the installation package of the application through the third-party application platform. For end users, they can download the installation package of the application released by the application publisher through the third-party application platform.
[0100] Based on this, for the third-party application platform, an application update refers to the update of the application installation package. For example, the updated application can be the application first released by the application publisher or an application with an upgraded version.
[0101] In this embodiment, the first training object, that is, the updated application from the third-party application platform, is used to collect a large number of training objects for implementing the construction of the SDK category set in this way.
[0102] If it is monitored that there is an application update on the third-party application platform, then execute steps 413 to 415.
[0103] On the contrary, if it is not monitored that there is an application update on the third-party application platform, then return to execute step 411 to continue monitoring whether there is an application update on the third-party application platform.
[0104] Step 413, if it is monitored that there is an application update on the third-party application platform, send a download request for the updated application to the third-party application platform.
[0105] Among them, for the download request of the updated application, the application information that can be carried includes but is not limited to: the application identifier of the updated application, the package name of the installation package of the updated application, the MD5 of the updated application, the update time of the updated application, the version number of the updated application, etc., so as to uniquely indicate the installation package of the updated application requested to be downloaded in this way.
[0106] Correspondingly, the third-party application platform will receive the download request for the updated application and push the installation package of the updated application in response to the download request.
[0107] Step 415, receive the installation package of the updated application and store the received installation package of the updated application as the first training object.
[0108] In this way, a large number of training objects can be obtained, which are used as the basis for constructing the SDK category set, fully ensuring the integrity and accuracy of the SDK category set.
[0109] Step 430, construct the SDK category set according to the source code of the first training object.
[0110] Among them, the SDK category set includes the category features of at least one SDK category.
[0111] In a possible implementation manner, as Figure 6 shown, step 430 may include the following steps:
[0112] Step 431, according to the application information of the first training application, decompile the first training object to obtain the source code of the first training object.
[0113] Among them, the source code of the first training object includes at least one training code snippet. The at least one training code snippet refers to the code snippet in the source code of the first training object, which can be a class or a function, and is not limited here.
[0114] It should be noted here that the installation package of the first training application is actually formed by compiling and encapsulating all the source code of the first training application or part of the updated source code by the compiler. Therefore, decompilation, which is equivalent to the reverse process of compilation, can convert the installation package of the first training application back into the corresponding source code.
[0115] Step 433, through API call analysis, determine the features of at least one training code snippet.
[0116] Among them, the features of the training code snippet are used to accurately describe the training code snippet, and thus uniquely identify the training code snippet in digital information. It should be understood that if the features are different, the training code snippets will also be different.
[0117] In this embodiment, the features of the training code snippets are determined through API call analysis. Specifically, for each training code snippet, the API calls executed by the training code snippet are counted to obtain the features of the training code snippet.
[0118] Similarly to the code snippet to be tested, the above statistics can count the types of API calls executed by the training code snippet, and can also count the number of times of different types of API calls executed by the training code snippet, or, simultaneously count the types and the number of times of API calls executed by the training code snippet.
[0119] For example, for the training code snippet B, the types of API calls executed by the training code snippet B include b and c, and the number of times of the b-type API calls executed by the training code snippet B is 2 times, and the number of times of the c-type API calls executed by the training code snippet B is 3 times. Then, the features of the training code snippet B can be uniquely represented as: B = {b: 2, c: 3}.
[0120] Step 435: Cluster at least one training code snippet according to the features of at least one training code snippet, and use the features of the training code snippets belonging to the same SDK category as the category features of the SDK category and add them to the SDK category set.
[0121] After determining the features of the training code snippets, each training code snippet can be clustered based on the features of the training code snippet, so that the training code snippets with the same or similar features are classified into the same SDK category, and the same or similar features are used as the category features of the SDK category.
[0122] Illustrated in combination with the foregoing example, assume that the source code of the first training object includes at least the training code snippets B, C, and D. Among them, the feature of the training code snippet B is B = {b: 2, c: 3}, the feature of the training code snippet C is C = {a: 2, b: 3}, and the feature of the training code snippet D is D = {a: 2, b: 3}.
[0123] Then, since the features of the training code snippets C and D are the same, both being {a: 2, b: 3}, therefore, the training code snippets C and D are classified into the same SDK category K1, and {a: 2, b: 3} is used as the category feature of the same SDK category K1.
[0124] Thus, in the SDK category set, it includes at least the category feature K1 = {a: 2, b: 3} of the same SDK category K1.
[0125] Under the effect of the above embodiment, the construction of the SDK category set is realized based on the first training object, which is used as the basis for classifying the detection object into SDKs, and provides a correctness guarantee for application vulnerability detection with SDKs as the basic unit.
[0126] Please refer to Figure 7 , in an embodiment of the present application, a possible implementation manner is provided, and step 435 may include the following steps:
[0127] Step 4351, traverse at least one training code snippet.
[0128] Step 4353, calculate the first similarity between the features of the currently traversed training code snippet and the features of the remaining training code snippets.
[0129] Step 4355, classify the remaining training code snippets whose first similarity exceeds the first threshold into the SDK category to which the currently traversed training code snippet belongs.
[0130] Among them, the first threshold can be flexibly set according to the actual needs of the application scenario, and no limitation is made here. For example, in an application scenario with relatively low accuracy requirements, the second threshold is set to 85%.
[0131] In this embodiment, clustering is implemented based on similarity calculation, that is, calculating the similarity of the features of different training code snippets. Optionally, the similarity can be implemented by calculation methods such as Euclidean distance, Manhattan distance, Minkowski distance, cosine similarity, Jaccard similarity, Pearson correlation coefficient, etc., and no limitation is made here.
[0132] If the similarity exceeds the threshold, it means that the different training code snippets are the same or similar, then classify the different training code snippets into the same SDK category; conversely, if the similarity is less than the threshold, it means that the different training code snippets are different, then classify the different training code snippets into different SDK categories.
[0133] Still taking the foregoing example for illustration, assume that the source code of the first training object includes at least training code snippets B, C, D, and E. Among them, the feature of training code snippet B is B = {b: 2, c: 3}, the feature of training code snippet C is C = {a: 2, b: 3}, the feature of training code snippet D is D = {a: 2, b: 3}, and the feature of training code snippet E is E = {b: 2, c: 4}.
[0134] Now traverse the training code snippets B, C, D, and E. First, use the traversed training code snippet B as the current training code snippet B.
[0135] Calculate the similarity between the features of the current training code snippet B and the features of the remaining training code snippets C, D, and E respectively: Since the features B = {b: 2, c: 3} of the current training code snippet B are different from the features {a: 2, b: 3} of the remaining training code snippets C and D, and the similarity is considered to be less than the threshold, the remaining training code snippets C and D do not belong to the SDK category to which the current training code snippet B belongs. That is, the training code snippets C and D belong to different SDK categories from the training code snippet B; at the same time, since the features B = {b: 2, c: 3} of the current training code snippet B are very similar to the features E = {b: 2, c: 4} of the remaining training code snippet E, and the similarity is considered to exceed the threshold, the remaining training code snippet E can be classified into the SDK category to which the current training code snippet B belongs. That is, the training code snippets B and E belong to the same SDK category.
[0136] Secondly, take the traversed training code snippet C as the current training code snippet C.
[0137] Calculate the similarity between the features of the current training code snippet C and the features of the remaining training code snippets D and E respectively: Since the features C = {a: 2, b: 3} of the current training code snippet C are exactly the same as the features D = {a: 2, b: 3} of the remaining training code snippet D, and the similarity is considered to exceed the threshold, the remaining training code snippet D can be classified into the SDK category to which the current training code snippet C belongs. That is, the training code snippets C and D belong to the same SDK category; at the same time, since the features C = {a: 2, b: 3} of the current training code snippet C are different from the features E = {b: 2, c: 4} of the remaining training code snippet E, and the similarity is considered to be less than the threshold, the remaining training code snippet E does not belong to the SDK category to which the current training code snippet C belongs. That is, the training code snippets C and E do not belong to the same SDK category.
[0138] Through the above process, the similarity of different training code snippets is measured based on the feature similarity, enabling the clustering of the same or similar training code snippets, which is used as the basis for constructing the SDK category set, fully ensuring the accuracy of constructing the SDK category set.
[0139] Please refer to Figure 8 , a possible implementation manner is provided in the embodiment of the present application. Step 330 may include the following steps:
[0140] Step 331, according to the application information of the target application, perform decompilation processing on the detection object to obtain the source code of the detection object.
[0141] Among them, the source code of the detection object includes at least one target code snippet. The at least one target code snippet refers to the code snippet in the source code of the detection object, which can be a class or a function, and is not specifically limited here.
[0142] Similarly to the source code of the first training object, here, the installation package of the target application is formed by compiling and encapsulating all the source code of the target application or part of the updated source code using a compiler. Therefore, decompilation can also convert the installation package of the target application back into the corresponding source code.
[0143] Step 333, for each target code snippet, determine the characteristics of the target code snippet through API call analysis.
[0144] Among them, the characteristics of the target code snippet are used to accurately describe the target code snippet, and then uniquely identify the target code snippet in the form of digital information. It should be understood that if the characteristics are different, the target code snippets will also be different.
[0145] In this embodiment, the characteristics of the target code snippet are determined through API call analysis. Specifically, for each target code snippet, the API calls executed by the target code snippet are counted to obtain the characteristics of the target code snippet.
[0146] Similarly to the code snippet to be tested, the above statistics can count the types of API calls executed by the target code snippet, or count the number of different types of API calls executed by the target code snippet, or simultaneously count the types and the number of API calls executed by the target code snippet.
[0147] For example, for the target code snippet F, the types of API calls executed by the target code snippet F include a and c, and the number of a-type API calls executed by the target code snippet B is 3 times, and the number of c-type API calls executed is 4 times. Then, the characteristics of the target code snippet F can be uniquely represented as: F = {a: 3, c: 4}.
[0148] Step 335, for each SDK category in the SDK category set, calculate the second similarity between the characteristics of the target code snippet and the category characteristics of the SDK category.
[0149] After determining the characteristics of the target code snippet, each target code snippet can be clustered based on the characteristics of the target code snippet, so that the same or similar target code snippets are classified into the same SDK.
[0150] Similarly to the clustering of training code snippets, in this embodiment, clustering is also implemented based on similarity calculation, that is, calculating the similarity between the features of the target code snippet and the category features of the SDK category. Optionally, the similarity can also be implemented by calculation methods such as Euclidean distance, Manhattan distance, Minkowski distance, cosine similarity, Jaccard similarity, Pearson correlation coefficient, etc., and specific limitations are not constituted here.
[0151] If the similarity exceeds the threshold, indicating that the features of the target code snippet are the same or similar to the category features of the SDK category, then the target code snippet is classified into this SDK category; conversely, if the similarity is less than the threshold, indicating that the features of the target code snippet are different from the category features of the SDK category, then the target code snippet is classified into the remaining SDK categories.
[0152] In step 337, if the second similarity exceeds the second threshold, then the target code snippet belongs to the SDK category, and the SDK is composed of the target code snippets belonging to the SDK category.
[0153] Among them, the second threshold can be flexibly set according to the actual needs of the application scenario, and no limitation is imposed here. For example, in an application scenario with high accuracy requirements, the second threshold is set to 97%.
[0154] Illustrated in combination with the foregoing example, assume that the source code of the detection object at least includes: target code snippets F and G, the features of the target code snippet F are F = {a: 3, c: 4}, the features of the target code snippet G are G = {a: 2, c: 4}, and the SDK category set at least includes: the category features K1 of the SDK category K1 = {a: 2, b: 3}, the category features K2 of the SDK category K2 = {a: 2, c: 4}.
[0155] Through similarity calculation, since the features F = {a: 3, c: 4} of the target code snippet F are different from the category features K1 = {a: 2, b: 3} of the SDK category K1, that is, the similarity is less than the threshold, it is considered that the target code snippet F does not belong to the SDK category K1. Similarly, since the features F = {a: 3, c: 4} of the target code snippet F are similar to the category features K2 = {a: 2, c: 4} of the SDK category K2, that is, the similarity exceeds the threshold, then the target code snippet F is classified into the SDK category K2 and is considered that the target code snippet F belongs to the SDK category K2.
[0156] Since the features of the target code snippet G, G = {a: 2, c: 4}, are different from the category features of the SDK category K1, K1 = {a: 2, b: 3}, that is, the similarity is less than the threshold, the target code snippet G is considered not to belong to the SDK category K1. Similarly, since the features of the target code snippet G, G = {a: 2, c: 4}, are exactly the same as the category features of the SDK category K2, K2 = {a: 2, c: 4}, that is, the similarity exceeds the threshold, the target code snippet G is classified into the SDK category K2, and the target code snippet G is considered to belong to the SDK category K2.
[0157] It can be seen that the same or similar target code snippets F and G belong to the same SDK category K2. It can also be understood that the target code snippets F and G are classified into the same SDK. Then, the application vulnerability detection will be carried out for the same SDK to avoid repeated detection of the same or similar target code snippets F or G. In the above process, the similarity between the target code snippet and the SDK category is measured based on the feature similarity, enabling the clustering of the same or similar target code snippets, providing correctness guarantee for the application vulnerability detection with the SDK as the basic unit.
[0158] Please refer to Figure 9 , a possible implementation manner is provided in the embodiment of the present application. Step 350 may include the following steps:
[0159] Step 351, based on the vulnerability identification model, determine the features of the specified code snippet with the specified vulnerability.
[0160] Among them, the specified code snippet refers to the code snippet with the specified vulnerability, which can be a class or a function, and is not limited here.
[0161] As mentioned above, the vulnerability identification model reflects the association and mapping between the specified code snippet with the specified vulnerability and the specified vulnerability. For example, in the vulnerability identification model, the association and mapping between the specified code snippet S with the specified vulnerability S' and the specified vulnerability S' can be expressed as {S = {a: 2, b: 3}, S'}.
[0162] Therefore, based on the vulnerability identification model, the features of the specified code snippet S with the specified vulnerability S' can be determined as S = {a: 2, b: 3}.
[0163] Step 353, calculate the third similarity between the features of the code snippet to be tested and the features of the specified code snippet.
[0164] In this embodiment, the application vulnerability detection is achieved through clustering, that is, clustering based on the features of the code snippet to be tested, so that the code snippets to be tested with the same or similar features as the features of the specified code snippet are classified into the specified vulnerability where the specified code snippet exists.
[0165] Specifically, similar to the clustering of target code snippets, clustering is also implemented based on similarity calculation, that is, calculating the similarity between the features of the code snippet to be tested and the features of the specified code snippet. Optionally, the similarity can also be implemented through calculation methods such as Euclidean distance, Manhattan distance, Minkowski distance, cosine similarity, Jaccard similarity, Pearson correlation coefficient, etc., which are not limited here.
[0166] If the similarity exceeds the threshold, indicating that the features of the code snippet to be tested are the same or similar to the features of the specified code snippet, then classify the code snippet to be tested into the specified vulnerability where the specified code snippet exists, and consider that the code snippet to be tested has the specified vulnerability; conversely, if the similarity is less than the threshold, indicating that the features of the code snippet to be tested are different from the features of the specified code snippet, then consider that the code snippet to be tested does not have the specified vulnerability.
[0167] Step 355, if the third similarity exceeds the third threshold, then obtain the detection result that the code snippet to be tested has the specified vulnerability.
[0168] Among them, the third threshold can be flexibly set according to the actual needs of the application scenario, which is not limited here. For example, in an application scenario with high accuracy requirements, the third threshold is set to 99%.
[0169] Illustrated with the foregoing example, assume that the SDK includes at least: the feature of the code snippet A to be tested is A = {a: 2, b: 3}, and the feature of the specified code snippet S with the specified vulnerability S' is S = {a: 2, b: 3}.
[0170] Through similarity calculation, since the feature A = {a: 2, b: 3} of the code snippet A to be tested is exactly the same as the feature S = {a: 2, b: 3} of the specified code snippet S, that is, the similarity exceeds the threshold, then classify the code snippet A to be tested into the specified vulnerability S' where the specified code snippet S exists, and consider that the code snippet A to be tested has the specified vulnerability S'.
[0171] It can be seen from this that the detection result is used to indicate that the code snippet A to be tested has the specified vulnerability S'.
[0172] Through the cooperation of the above embodiments, the similarity between the code snippet to be tested and the specified code snippet with the specified vulnerability is measured based on feature similarity, enabling the implementation of the application vulnerability detection scheme for SDKs based on clustering, avoiding the possibility of the application itself having vulnerabilities due to the introduction of the SDK, and thus effectively solving the problem of missed detection in application vulnerability detection in the related art.
[0173] Please refer to Figure 10, In an embodiment of the present application, a possible implementation is provided. Before step 370, the method may further include the following steps:
[0174] Step 510, obtain a second training object.
[0175] The second training object is used to build a vulnerability identification model, and the second training object includes a second training application with a specified vulnerability.
[0176] Regarding the acquisition of the second training object, it can be sourced from the active reporting of the terminal. For example, when the terminal performs application vulnerability detection and detects an application with a specified vulnerability, it reports the application with the specified vulnerability to the server. It can also be sourced from the active collection of the server. For example, the server issues a vulnerability collection request irregularly / regularly, and the terminal will feedback the applications with the specified vulnerability detected during the historical time period to the server.
[0177] Correspondingly, the server can build a vulnerability identification model based on the applications with the specified vulnerability reported by the terminal in real time, so as to improve the real-time performance of model building and further fully ensure the timely update of the vulnerability identification model. It can also build a vulnerability identification model based on the applications with the specified vulnerability detected during the historical time period feedback by the terminal, so as to fully ensure the integrity of the vulnerability identification model.
[0178] Step 530, build a vulnerability identification model according to the specified vulnerability existing in the second training application.
[0179] In this embodiment, the vulnerability identification model is built based on the correspondence between the characteristics of the specified code snippet with the specified vulnerability and the specified vulnerability.
[0180] Specifically, in a possible implementation, as Figure 11 shown, step 530 may include the following steps:
[0181] Step 531, determine at least one specified code snippet with the specified vulnerability in the second training application.
[0182] The specified code snippet refers to the code snippet with the specified vulnerability in the source code of the second training application, which can be a class or a function, and is not limited here.
[0183] In a possible implementation manner, the specified code snippet is determined by manual screening. Specifically, the code snippet with the specified vulnerability is selected from the source code of the second training application manually as the specified code snippet with the specified vulnerability.
[0184] In a possible implementation, a specified code snippet is determined in response to API call analysis. Specifically, API calls executed by each code snippet in the source code of the second training application are analyzed to use the code snippet that executes a specified type of API call as the specified code snippet with a specified vulnerability. For example, the specified types of such API calls include, but are not limited to: externally accessible input types, internally executable types.
[0185] Step 533: Determine the characteristics of at least one specified code snippet through API call analysis.
[0186] Among them, the characteristics of the specified code snippet are used to accurately describe the specified code snippet, and thus uniquely identify the specified code snippet in digital information. It should be understood that if the characteristics are different, the specified code snippets will also be different.
[0187] In this embodiment, the characteristics of the specified code snippet are determined through API call analysis. Specifically, for each specified code snippet, the API calls executed by the specified code snippet are counted to obtain the characteristics of the specified code snippet.
[0188] Similarly to the code snippet to be tested, the above counting can count the types of API calls executed by the specified code snippet, and can also count the number of times of different types of API calls executed by the specified code snippet, or count both the types and the number of times of API calls executed by the specified code snippet at the same time.
[0189] For example, for the specified code snippet S with the specified vulnerability S', the types of API calls executed by the specified code snippet S include a and b, and the number of times of a-type API calls executed by the specified code snippet S is 2 times, and the number of times of b-type API calls executed is 3 times. Then, the characteristics of the specified code snippet S can be uniquely represented as: S = {a: 2, b: 3}.
[0190] Step 535: Build the correspondence between the characteristics of at least one specified code snippet and the specified vulnerability to obtain a vulnerability identification model.
[0191] Still taking the previous example for illustration, after determining that the characteristics of the specified code snippet S with the specified vulnerability S' are S = {a: 2, b: 3}, the correspondence between the characteristics of the specified code snippet S and the specified vulnerability S' in the vulnerability identification model can be built.
[0192] Specifically, in the vulnerability identification model, it at least includes the correspondence: {S = {a: 2, b: 3}, S'}.
[0193] It can be seen that the vulnerability identification model reflects the association and mapping between the specified code snippet S with the specified vulnerability S' and the specified vulnerability S'.
[0194] Under the action of the above embodiments, the construction of the vulnerability identification model is realized based on the second training object, which is used as the basis for detecting application vulnerabilities for the SDK, and further enables the realization of the application vulnerability detection solution for the SDK.
[0195] Please refer to Figure 12 , the embodiment of the present application provides an application vulnerability detection method, which is applicable to Figure 1 the terminal 100 in the implementation environment shown.
[0196] In the following method embodiments, for the sake of description, the execution subject of each step is described as the terminal, but this is not a limitation thereto.
[0197] As Figure 12 shown, the method may include the following steps:
[0198] Step 610, initiate a vulnerability detection request to the server according to the installation package of the target application, so that the server responds to the vulnerability detection request and performs application vulnerability detection on the SDK in the target application according to the application vulnerability detection method in the above embodiments.
[0199] Step 630, receive the detection result of the SDK in the target application returned by the server.
[0200] Through the above process, after the application publisher compiles the installation package of the target application, on the one hand, the client running on the terminal deploys an application vulnerability detection entry. Based on this application vulnerability detection entry, the application publisher can initiate a vulnerability detection request to the server to submit the installation package of the target application to the server for application vulnerability detection; on the other hand, the code compilation environment running on the terminal deploys a web service interface. Taking this web service interface as the application vulnerability detection entry, then, based on this web service interface, the application publisher can also initiate a vulnerability detection request to the server to submit the installation package of the target application to the server for application vulnerability detection, thus greatly facilitating the terminal user to implement the application vulnerability detection of the SDK in the target application and effectively improving the user experience.
[0201] Figure 13 is a schematic diagram of the implementation of an application vulnerability detection method in an application scenario.
[0202] In this application scenario, as Figure 13 shown in a, it exemplarily shows an architecture diagram of a system for an application vulnerability detection method. In Figure 13 a, the system for application vulnerability detection includes four subsystems: a mobile application store monitoring subsystem 801, an application SDK identification subsystem 802, a vulnerability model identification subsystem 803, and a mobile application vulnerability detection subsystem 804.
[0203] The functions implemented by each of the above subsystems in the application vulnerability detection method are introduced below:
[0204] Mobile application store monitoring subsystem 801:
[0205] This subsystem 801 is used to monitor whether there is an application update on the third-party application platform. When an application update is detected on the third-party application platform, the installation package of the updated application is obtained as the data source input of the subsystem 801, so as to realize the construction of the SDK category set.
[0206] Among them, the third-party application platform includes but is not limited to: App Annie, Baidu Mobile Assistant, Xiaomi Application Store, Huawei Application Store, VIVO Application Store, OPPO Application Store, Google Play Store, etc.
[0207] As Figure 13 shown in b, it exemplarily shows the implementation block diagram of the mobile application store monitoring subsystem. In Figure 13 b, this subsystem 801 includes a monitoring center 8011, a download center 8013, and a storage center 8015. Among them, the monitoring center 8011 is used to monitor whether there is an application update on the third-party application platform; the download center 8013 is used to send a download request for the updated application to the third-party application platform when the monitoring center 8011 detects an application update on the third-party application platform; the storage center 8015 is used to receive and store the installation package of the updated application returned by the third-party application platform in response to the download request.
[0208] Thus, a large number of updated applications can be obtained as the first training applications, and the installation package of the first training application is used as the first training object to realize the subsequent construction of the SDK category set.
[0209] Application SDK identification subsystem 802:
[0210] This subsystem 802 is used to divide the installation package of the input application into SDKs. As Figure 13 shown in c, it exemplarily shows the implementation block diagram of the application SDK identification subsystem. In Figure 13 c, this subsystem 802 includes a scheduling center 8021, a training center 8022, an identification center 8023, and an SDK data set 8024.
[0211] Among them, the scheduling center 8021 is used to identify the source of the input application. The input application can be the first training application from the mobile application store detection subsystem 801, or it can be the target application sent from the terminal. If the input application is identified as the first training application, the installation package of the first training application will be passed to the training center 8022. Conversely, if the input application is identified as the target application, the target application will be passed to the recognition center 8023. It should be noted here that the identification of the input application depends on the input tag, which is used to uniquely identify the source of the input application. For example, the input tag is 1, indicating that the input application is the first training application; the input tag is 0, indicating that the input application is the target application. This input tag can be encapsulated into the application information of the input application when the input application is obtained. For example, when the first training application is stored in the storage center 8015, the input tag 1 is encapsulated into the application information of the first training application; when the target application is uploaded to the system, the input tag 0 is encapsulated into the application information of the target application.
[0212] The training center 8022 is used to construct a set of SDK categories. Specifically: decompile and analyze the API calls of the installation package of the first training application to obtain the features of at least one training code snippet, and cluster the at least one training code snippet based on the features of the at least one training code snippet to form a set of SDK categories containing the category features of at least one SDK category.
[0213] The SDK dataset 8024 is used to store the set of SDK categories formed by the training center 8022.
[0214] It is worth mentioning that in order to avoid repeated clustering, when there is still an input of the first training application in the training center 8022, the clustering is paused. When the input of the first training application stops, the clustering of the training code snippets can be carried out, thereby improving the construction efficiency of the set of SDK categories.
[0215] The recognition center 8023 is used to generate SDKs. Specifically: according to the category features of the SDK categories in the set of SDK categories stored in the SDK dataset 8024, and combining the features of the target code snippets obtained by decompiling and analyzing the API calls of the installation package of the target application, cluster the target code snippets to generate at least one SDK.
[0216] Thus, subsequent application vulnerability detection can be implemented with the SDK as the basic unit.
[0217] Vulnerability model recognition subsystem 803:
[0218] The subsystem 803 is used to build a vulnerability identification model. Specifically: obtain a second training application with a specified vulnerability, and through decompilation and API call analysis, obtain the features of at least one specified code snippet with the specified vulnerability in the second training application, and build the correspondence between the features of the at least one specified code snippet and the specified vulnerability.
[0219] Thus, the vulnerability identification model can reflect the association and mapping between the specified code snippet with the specified vulnerability and the specified vulnerability, so as to realize subsequent application vulnerability detection.
[0220] Mobile application vulnerability detection subsystem 804:
[0221] The subsystem 804 is used to perform application vulnerability detection on each SDK provided by the application SDK identification subsystem 802 until all SDKs complete the application vulnerability detection. Specifically: for each SDK, obtain the features of the code snippets to be tested in the SDK through decompilation and API call analysis, and cluster the code snippets to be tested in combination with the vulnerability model identification subsystem 803 to obtain the detection result of whether the code snippets to be tested have the specified vulnerability.
[0222] In this application scenario, on the one hand, taking the SDK as the basic unit for application vulnerability detection can avoid a large amount of repetitive code in application vulnerability detection and effectively improve the detection efficiency of application vulnerability detection; on the other hand, introducing clustering analysis into application vulnerability detection upgrades the detection limited to specific vulnerability rules (such as string rules or syntax analysis) to the detection based on abstract vulnerability rules (such as the correspondence between the specified code snippet with the specified vulnerability and the specified vulnerability), so that there is no detection lag in application vulnerability detection, and it can not only detect known vulnerabilities, but also effectively detect unknown vulnerabilities or a certain type of vulnerability (such as the specified vulnerability), thus effectively reducing the false negative rate.
[0223] In addition, replacing the detection object from the application with the installation package of the application enables the application vulnerability detection to timely introduce the SDK integration into the application stage, which can effectively narrow the scope affected by the SDK vulnerability.
[0224] The following is an embodiment of the device of the present application, which can be used to execute the application vulnerability detection method involved in the present application. For the details not disclosed in the embodiment of the device of the present application, please refer to the method embodiment of the application vulnerability detection method involved in the present application.
[0225] Please refer to Figure 14 , an application vulnerability detection device 900 is provided in the embodiment of the present application, including but not limited to: an application acquisition module 910, a set acquisition module 930, a feature acquisition module 950, and a result acquisition module 970.
[0226] Among them, the application acquisition module 910 is used to acquire a detection object, and the detection object includes the installation package of the target application.
[0227] The set acquisition module 930 is used to cluster the source code of the detection object according to the SDK categories in the pre-constructed software development kit (SDK) category set, to obtain at least one SDK, and the SDK includes the source code belonging to the same SDK category.
[0228] The feature acquisition module 950 is used to determine the features of the code snippet to be tested in the SDK through application programming interface (API) call analysis.
[0229] The result acquisition module 970 is used to perform application vulnerability detection on the features of the code snippet to be tested according to the vulnerability identification model constructed for the specified vulnerability, to obtain the detection result of whether the code snippet to be tested has the specified vulnerability.
[0230] Please refer to Figure 15 , in the embodiment of the present application, an application vulnerability detection device 1000 is provided, including but not limited to: a request initiation module 1010 and a result receiving module 1030.
[0231] Among them, the request initiation module 1010 is used to initiate a vulnerability detection request to the server according to the installation package of the target application, so that the server responds to the vulnerability detection request and performs application vulnerability detection on the SDK in the target application according to the application vulnerability detection method in the above embodiments.
[0232] The result receiving module 1030 is used to receive the detection result of the SDK in the target application returned by the server.
[0233] It should be noted that when the above-mentioned application vulnerability detection device performs application vulnerability detection, only the above-mentioned division of each functional module is used for illustration. In actual application, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the application vulnerability detection device will be divided into different functional modules to complete all or part of the functions described above.
[0234] In addition, the above-mentioned application vulnerability detection device and the embodiment of the application vulnerability detection method belong to the same concept. The specific ways in which each module performs operations have been described in detail in the method embodiment, and will not be repeated here.
[0235] Thus, for the SDK in the application, an application vulnerability detection solution is implemented, avoiding the possibility that the application itself has vulnerabilities due to the introduction of the SDK, thereby effectively solving the problem of missed detection in application vulnerability detection in the related art.
[0236] In addition, taking the SDK as the basic unit for application vulnerability detection can avoid a large amount of duplicate code in each application vulnerability detection, thereby effectively improving the detection efficiency of application vulnerability detection.
[0237] Figure 16 A schematic structural diagram of a server shown according to an exemplary embodiment. This server is applicable to Figure 1 the server 200 in the shown implementation environment.
[0238] It should be noted that this server is only an example adapted to this application and cannot be considered as providing any limitation to the scope of use of this application. This server cannot be interpreted as needing to rely on or necessarily having Figure 16 one or more components in the shown exemplary server 2000.
[0239] The hardware structure of the server 2000 may vary greatly due to different configurations or performances. For example, Figure 16 as shown, the server 2000 includes: a power supply 210, an interface 230, at least one memory 250, and at least one central processing unit (CPU) 270.
[0240] Specifically, the power supply 210 is used to provide working voltage for each hardware device on the server 2000.
[0241] The interface 230 includes at least one wired or wireless network interface for interacting with external devices. For example, for Figure 1 the interaction between the terminal 100 and the server 200 in the shown implementation environment.
[0242] Of course, in other examples adapted to this application, the interface 230 may further include at least one serial-parallel conversion interface 233, at least one input / output interface 235, and at least one USB interface 237, etc. Figure 16 as shown, and this is not a specific limitation here.
[0243] The memory 250, as a carrier for resource storage, can be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc. The resources stored thereon include an operating system 251, application programs 253, and data 255, etc., and the storage method can be temporary storage or permanent storage.
[0244] Among them, the operating system 251 is used to manage and control each hardware device and application program 253 on the server 200 to enable the central processing unit 270 to perform operations and processing on the massive data 255 in the memory 250. It can be Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSD TM, etc.
[0245] The application program 253 is a computer program that completes at least one specific task based on the operating system 251, and it may include at least one module ( Figure 16 not shown), and each module may separately contain a series of computer-readable instructions for the server 2000. For example, the data monitoring device can be regarded as the application program 253 deployed on the server 2000.
[0246] The data 255 can be photos, pictures, etc. stored in the disk, or source code, etc., and is stored in the memory 250.
[0247] The central processing unit 270 may include one or more than one processors, and is configured to communicate with the memory 250 through at least one communication bus, so as to read the computer-readable instructions stored in the memory 250, and then implement the operation and processing of the massive data 255 in the memory 250. For example, the application vulnerability detection method is completed in the form of reading a series of computer-readable instructions stored in the memory 250 by the central processing unit 270.
[0248] In addition, the present application can also be implemented by a hardware circuit or a combination of a hardware circuit and software. Therefore, the implementation of the present application is not limited to any specific hardware circuit, software, and the combination of the two.
[0249] Please refer to Figure 17 , in the embodiment of the present application, an electronic device 4000 is provided, which includes at least one processor 4001, at least one communication bus 4002, and at least one memory 4003.
[0250] Among them, the processor 4001 and the memory 4003 are connected, such as through the communication bus 4002. Optionally, the electronic device 4000 may further include a transceiver 4004, and the transceiver 4004 can be used for data interaction between the electronic device and other electronic devices, such as data sending and / or data receiving, etc. It should be noted that in practical applications, the transceiver 4004 is not limited to one, and the structure of the electronic device 4000 does not constitute a limitation to the embodiment of the present application.
[0251] The processor 4001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logical blocks, modules, and circuits described in connection with the disclosure of this application. The processor 4001 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0252] The communication bus 4002 may include a path for transmitting information between the above components. The communication bus 4002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The communication bus 4002 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 17 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.
[0253] The memory 4003 may be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory) or other type of dynamic storage device that can store information and instructions, or it may also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0254] Computer-readable instructions are stored in the memory 4003, and the processor 4001 reads the computer-readable instructions stored in the memory 4003 through the communication bus 4002.
[0255] When the computer-readable instructions are executed by the processor 4001, the application vulnerability detection method in the above embodiments is implemented.
[0256] In addition, an embodiment of the present application provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the application vulnerability detection method in the above embodiments is implemented.
[0257] An embodiment of the present application provides a computer program product, which includes computer-readable instructions stored in a storage medium. The processor of the computer device reads the computer-readable instructions from the storage medium, and the processor executes the computer-readable instructions, so that the computer device executes the application vulnerability detection method in the above embodiments.
[0258] Compared with the related art, on the one hand, taking the SDK as the basic unit for application vulnerability detection can avoid a large amount of duplicate code in application vulnerability detection, and can effectively improve the detection efficiency of application vulnerability detection; on the other hand, introducing clustering analysis into application vulnerability detection can improve the detection from being limited to specific vulnerability rules (such as string rules or syntax analysis) to detection based on abstract vulnerability rules (such as the correspondence between a specified code segment with a specified vulnerability and the specified vulnerability), thereby making the application vulnerability detection free from detection lag. It can not only detect known vulnerabilities, but also effectively detect unknown vulnerabilities or a certain type of vulnerabilities (such as specified vulnerabilities), thus effectively reducing the false negative rate.
[0259] In addition, the detection object is replaced from the application to the installation package of the application, so that the application vulnerability detection can timely introduce the SDK integration into the application stage, and can effectively narrow the scope affected by the SDK vulnerability.
[0260] It should be understood that although the steps in the flowchart of the accompanying drawings are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.
[0261] The above are only some embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A method for detecting application vulnerabilities, characterized in that, Including: Obtain a detection object, where the detection object includes an installation package of a target application; Cluster the source code of the detection object according to the SDK categories in a pre-constructed SDK category set, to obtain at least one SDK, where the SDK includes source code belonging to the same SDK category, and the source code in the same SDK is repetitive or similar; Determine the characteristics of the code snippets to be tested in the SDK through application programming interface (API) call analysis, where the characteristics represent at least one of the type and number of API calls executed by the corresponding code snippets; Deduplicate the code snippets to be tested in the SDK according to the characteristics of the code snippets to be tested in the SDK; Perform application vulnerability detection on the characteristics of the code snippets to be tested according to a vulnerability recognition model built based on a specified vulnerability, to obtain a detection result on whether the specified vulnerability exists in the code snippets to be tested.
2. The method according to claim 1, characterized in that, Before the step of clustering the source code of the detection object according to the SDK categories in a pre-constructed SDK category set to obtain at least one SDK, the method further includes: Obtain a first training object, where the first training object includes an installation package of a first training application; Construct the SDK category set according to the source code of the first training object.
3. The method according to claim 2, wherein The obtaining of the first training object includes: If it is monitored that there is an application update on a third-party application platform, send a download request for the updated application to the third-party application platform, so that the third-party application platform pushes the installation package of the updated application in response to the download request; Receive the installation package of the updated application, and store the received installation package of the updated application as the first training object.
4. The method according to claim 2, wherein The constructing of the SDK category set according to the source code of the first training object includes: Perform decompilation processing on the first training object according to the application information of the first training application, to obtain the source code of the first training object, where the source code of the first training object includes at least one training code snippet; Determine the characteristics of the at least one training code snippet through API call analysis; Cluster the at least one training code snippet according to the characteristics of the at least one training code snippet, and use the characteristics of the training code snippets belonging to the same SDK category as the category characteristics of the SDK category, and add them to the SDK category set.
5. The method according to claim 4, wherein The determining of the characteristics of the at least one training code snippet through API call analysis includes: For each of the training code snippets, count the API calls executed by the training code snippet, to obtain the characteristics of the training code snippet.
6. The method according to claim 4, wherein The clustering of the at least one training code snippet according to the characteristics of the at least one training code snippet includes: Traverse the at least one training code snippet; Calculate the first similarity between the characteristics of the currently traversed training code snippet and the characteristics of the remaining training code snippets; Classify the remaining training code snippets whose first similarity exceeds a first threshold into the SDK category to which the currently traversed training code snippet belongs.
7. The method according to claim 1, characterized in that, The step of clustering the source code of the detection object according to the SDK category in the pre-built software development kit SDK category set to obtain at least one SDK includes: Decompiling the detection object according to the application information of the target application to obtain the source code of the detection object, wherein the source code of the detection object includes at least one target code fragment; For each target code snippet, determine the characteristics of the target code snippet through API call analysis; For each SDK category in the SDK category set, calculating a second similarity between a feature of the target code snippet and a category feature of the SDK category; If the second similarity exceeds a second threshold, the target code snippet belongs to the SDK category, and the SDK is composed of the target code snippets belonging to the SDK category.
8. The method according to claim 1, wherein The vulnerability identification model constructed according to the specified vulnerability performs application vulnerability detection on the features of the code snippet to be tested, and obtains a detection result of whether the code snippet to be tested has the specified vulnerability, including: Based on the vulnerability identification model, determining features of a specified code snippet having the specified vulnerability; Calculating a third similarity between the feature of the code snippet to be tested and the feature of the specified code snippet; If the third similarity exceeds a third threshold, a detection result is obtained that the code snippet to be tested has the specified vulnerability.
9. The method according to claim 1, wherein Before the vulnerability identification model constructed according to the specified vulnerability performs vulnerability detection on the features of the code snippet to be tested and obtains a detection result of whether the code snippet to be tested belongs to the specified vulnerability, the method further includes: Acquire a second training object, where the second training object includes a second training application having the specified vulnerability; The vulnerability identification model is constructed according to the specified vulnerability existing in the second training application.
10. The method according to claim 9, characterized in that, The step of constructing the vulnerability identification model according to the specified vulnerability existing in the second training application includes: Determine in the second training application at least one specified code snippet having the specified vulnerability; Determining, through API call analysis, characteristics of the at least one specified code snippet; A corresponding relationship between the feature of the at least one specified code fragment and the specified vulnerability is constructed to obtain the vulnerability identification model.
11. A method for detecting application vulnerabilities, characterized in that, include: Initiating a vulnerability detection request to a server according to an installation package of a target application, so that the server responds to the vulnerability detection request and performs application vulnerability detection on the SDK in the target application according to the application vulnerability detection method according to any one of claims 1 to 10; Receive the detection result of the SDK in the target application returned by the server.
12. An application vulnerability detection device, characterized in that, include: An application acquisition module, used to acquire a detection object, wherein the detection object includes an installation package of a target application; A set acquisition module, used for clustering the source code of the detection object according to the SDK category in the pre-built software development kit SDK category set to obtain at least one SDK, wherein the SDK includes source code belonging to the same SDK category, and the source code in the same SDK is repeated or similar; A feature acquisition module, configured to determine features of a code snippet to be tested in the SDK by analyzing through an application programming interface (API). The features represent at least one of the type and the number of API calls executed by the corresponding code snippet. Duplicate removal is performed on the code snippet to be tested in the SDK according to the features of the code snippet to be tested in the SDK; A result acquisition module, configured to perform application vulnerability detection on the features of the code snippet to be tested by using a vulnerability identification model built based on a specified vulnerability, so as to obtain a detection result on whether the code snippet to be tested has the specified vulnerability.
13. An application vulnerability detection device, characterized in that, including: A request initiation module, configured to initiate a vulnerability detection request to a server according to an installation package of a target application, so that the server, in response to the vulnerability detection request, performs application vulnerability detection on the SDK in the target application according to the application vulnerability detection method according to any one of claims 1 to 10; A result receiving module, configured to receive a detection result of the SDK in the target application returned by the server.
14. An electronic device, characterized in that, including: At least one processor, at least one memory, and at least one communication bus, wherein Computer-readable instructions are stored on the memory, and the processor reads the computer-readable instructions in the memory through the communication bus; When the computer-readable instructions are executed by the processor, the application vulnerability detection method according to any one of claims 1 to 11 is implemented.
15. A storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by the processor, the application vulnerability detection method according to any one of claims 1 to 11 is implemented.
Citation Information
Patent Citations
SDK security detection method and related equipment
CN110990833A
Application detection method and device, computer equipment and readable storage medium
CN112148305A