Malicious application identification method and device, computer device, and storage medium

By generating an installation relationship diagram of applications, target applications that meet preset conditions are identified as malicious applications, which solves the problems of low identification efficiency and accuracy in existing technologies and achieves efficient and accurate identification of malicious applications.

CN113642000BActive Publication Date: 2025-11-28GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110997582.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-27
Publication Date
2025-11-28
Estimated Expiration
2041-11-28

AI Technical Summary

Technical Problem

Existing technologies for identifying malicious applications are inefficient and inaccurate, especially in proactive identification methods which require large datasets and significant human and material resources, and the model training time is long.

Method used

By acquiring installation data from multiple applications, a connection graph corresponding to the installation relationships between applications is generated. The nodes and directed connections in the connection graph represent the installation relationships, and target applications that meet preset relationship conditions are identified as malicious applications.

Benefits of technology

It improves the efficiency and accuracy of malicious application identification, effectively identifying malicious applications that trick users into installing other applications, while reducing the consumption of manpower and resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113642000B_ABST
    Figure CN113642000B_ABST
Patent Text Reader

Abstract

The application discloses a malicious application identification method and device, computer equipment and a storage medium. The malicious application identification method comprises the following steps: obtaining installation data of a plurality of application programs; generating a connection graph corresponding to an installation relationship between the plurality of application programs based on the installation data, wherein the connection graph comprises nodes corresponding to each application program and edges formed by directed connection lines between the nodes, and the edges are used to represent the installation relationship; and obtaining a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs based on the connection graph, wherein an installation relationship between the target application program and other application programs in the plurality of application programs except the target application program satisfies a preset relationship condition. The method can accurately and effectively identify malicious applications, thereby reducing the risk of device attacks by malicious applications.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet, and more particularly, to a malicious application identification method and device, a computer device and a storage medium. BACKGROUND

[0002] With the development of Internet technology and the improvement of electronic device configuration level, the number of application programs that can be installed on electronic devices is also increasing, and the possibility of installing malicious applications on electronic devices is also increasing. Therefore, the demand for identifying malicious applications is also increasing. However, in the related art, the efficiency of identifying malicious applications needs to be improved. SUMMARY

[0003] In view of the above problems, the present application provides a malicious application identification method, device, computer device and storage medium.

[0004] In a first aspect, the present application provides a malicious application identification method, comprising: obtaining installation data of a plurality of application programs; generating a connection graph corresponding to an installation relationship between the plurality of application programs based on the installation data, the connection graph comprising nodes corresponding to each application program and edges between the nodes, the edges being used to represent the installation relationship; and obtaining a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs based on the connection graph, the installation relationship between the target application program and other application programs in the plurality of application programs except the target application program satisfying a preset relationship condition.

[0005] In a second aspect, the present application provides a malicious application identification device, comprising: a data obtaining module, a connection graph generating module and an application obtaining module, wherein the data obtaining module is configured to obtain installation data of a plurality of application programs; the connection graph generating module is configured to generate a connection graph corresponding to an installation relationship between the plurality of application programs based on the installation data, the connection graph comprising nodes corresponding to each application program and edges between the nodes, the edges being used to represent the installation relationship; and the application obtaining module is configured to obtain a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs based on the connection graph, the installation relationship between the target application program and other application programs in the plurality of application programs except the target application program satisfying a preset relationship condition.

[0006] Thirdly, embodiments of this application provide a computer device, including: one or more processors; a memory; and one or more application programs, wherein the one or more application programs are stored in the memory and configured to be executed by the one or more processors, and the one or more application programs are configured to perform the malicious application identification method provided in the first aspect above.

[0007] Fourthly, embodiments of this application provide a computer-readable storage medium storing program code, which can be invoked by a processor to execute the malicious application identification method provided in the first aspect above.

[0008] The solution provided in this application obtains installation data from multiple applications and generates a connection graph corresponding to the installation relationships between these applications. This connection graph includes edges formed by directed connections between nodes corresponding to each application, which characterize the installation relationships between applications. Then, based on this connection graph, a target application is identified as a malicious application among the multiple applications, and the installation relationships between the target application and other applications within the multiple applications satisfy preset relationship conditions. Therefore, a connection graph of installation relationships based on application installation data can be established. This connection graph can then be used to identify malicious applications that maliciously induce the installation of other applications, improving the efficiency and accuracy of malicious application identification. Attached Figure Description

[0009] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0010] Figure 1 A flowchart illustrating a method for identifying malicious applications according to an embodiment of this application is shown.

[0011] Figure 2 This is a schematic diagram of a connection diagram provided in an embodiment of this application.

[0012] Figure 3 A flowchart of a method for identifying malicious applications according to another embodiment of this application is shown.

[0013] Figure 4 A flowchart of a method for identifying malicious applications according to yet another embodiment of this application is shown.

[0014] Figure 5A flow chart of a method for identifying a malicious application according to yet another embodiment of the present application is shown.

[0015] Figure 6 A flow chart of a method for identifying a malicious application according to yet another embodiment of the present application is shown.

[0016] Figure 7 Another schematic diagram of a connection graph provided by an embodiment of the present application is shown.

[0017] Figure 8 Another schematic diagram of a connection graph provided by an embodiment of the present application is shown.

[0018] Figure 9 A flow chart of a method for identifying a malicious application according to yet another embodiment of the present application is shown.

[0019] Figure 10 A flow chart of a method for identifying a malicious application according to yet another embodiment of the present application is shown.

[0020] Figure 11 A block diagram of an apparatus for identifying a malicious application according to an embodiment of the present application is shown.

[0021] Figure 12 A block diagram of a computer device for executing a method for identifying a malicious application according to an embodiment of the present application is shown.

[0022] Figure 13 A storage unit for storing or carrying program code for implementing a method for identifying a malicious application according to an embodiment of the present application is shown. DETAILED DESCRIPTION

[0023] In order to enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the present application.

[0024] With the popularity of electronic devices and the rapid development of Internet services, the number of application software is rapidly increasing. Electronic devices that can install various application software have changed the way people work and live, and the security of application software is also facing a severe situation.

[0025] In particular, in mobile terminals, IOS (Apple operating system) and Android systems have occupied a large share of the smartphone market. While the smartphone system brings convenience to application developers, it also brings challenges to users and mobile phone manufacturers. The lack of APP (Application) review mechanism will lead to a large number of malicious software being easily released to the software application market. Therefore, the demand for detecting malicious software is very urgent.

[0026] Among the numerous malware, it can be divided into rogue promotion software, fee deduction software, password stealing virus software, and induced installation software according to its purpose, and the purpose of the malware is various. Whether it is rogue promotion or password stealing virus software, the performance is that the malware is disguised as normal software, and after the user installs it on the electronic device, it privately downloads other malicious software to achieve the illegal profit purpose of rogue promotion or password deduction. Therefore, how to find the application with malicious induced installation of other software from hundreds of millions of APPs is crucial.

[0027] In the related art, the identification method of the application with malicious induced installation of other software is divided into active identification and passive identification. Among them, the passive identification is that the manufacturer determines the effective fingerprint according to the pre-defined malicious behavior or user feedback, and the pre-defined fingerprint related to the behavior of malicious induced installation, such as pop-up window at sensitive time, background APP pull-up component, and large traffic occupation of background APP, when the APP has such malicious behavior, it is considered to be a malicious APP, and it is added to the list of malicious applications, or some manufacturers use user feedback to identify malicious induced installation software, and add these software to the list of operations; the active identification automatically extracts the most suitable features and combinations of features from the software through certain technical means (such as deep learning and machine learning algorithm) to determine whether an application is malicious software. Active identification mainly includes data collection, feature extraction, model design and effect detection.

[0028] In the currently used identification technology of malicious application, the passive identification method needs the experience of professionals, and determines the effective fingerprint according to the malicious application with malicious behavior, which needs to consume huge manpower and material resources, and the efficiency is relatively low; the active identification method needs a large amount of data set, and the construction of the data set also needs to consume huge manpower and material resources, and the training time of the model also needs to spend a long time, so the current active identification method is also relatively low in efficiency.

[0029] In view of the above problems, the inventors propose the identification method, device, computer equipment and storage medium of the malicious application provided in the embodiments of the application, which can realize the connection graph of the installation relationship established based on the installation data of the application program, and can identify the malicious application with malicious induced installation of other application programs according to the connection graph, thereby improving the identification efficiency and accuracy of the malicious application. The specific identification method of the malicious application is described in detail in the subsequent embodiments.

[0030] Please refer to Figure 1 , Figure 1 The figure shows the flowchart of the identification method of the malicious application provided in an embodiment of the application. In specific embodiments, the identification method of the malicious application is applied to, for example Figure 11The malicious application identification apparatus 400 and the computer device 100 configured with the malicious application identification apparatus 400 are shown. Figure 12 The specific flow of the present embodiment will be described below with the computer device as an example. It can be understood that the computer device applied in the present embodiment can be a physical server, a cloud server, a PC computer, a notebook computer, etc., which is not limited herein. The flow shown below will be described in detail, and the malicious application identification method can specifically include the following steps. Figure 1 The specific flow of the present embodiment will be described below with the computer device as an example. It can be understood that the computer device applied in the present embodiment can be a physical server, a cloud server, a PC computer, a notebook computer, etc., which is not limited herein. The flow shown below will be described in detail, and the malicious application identification method can specifically include the following steps.

[0031] Step S110: Obtain installation data of a plurality of application programs.

[0032] In the present embodiment, the computer device can obtain installation data of a plurality of application programs, so as to determine the malicious application existing in the plurality of application programs based on the installation data. The installation data of the plurality of application programs can be the installation data corresponding to the application programs installed in different electronic devices. The installation data can include an application name, a pack name, an installation channel, an installation date, a region, etc., which are not limited herein. The application name refers to the name of the application program; the pack name is the unique identifier of an application program in the operating system, and different application programs can have the same name, but their pack names cannot be the same; the installation channel is the installation source of the application program, for example, the installation of the application program can be from a system application mall, a third-party application mall, a browser, other third-party application programs, etc., which are not limited herein; the installation date refers to the date when the application program is installed; and the region refers to the region where the user terminal corresponding to the application program is located. It can be understood that since the installation data can reflect the induced installation behavior, the subsequent malicious application that induces the installation of other application programs can be identified based on the obtained installation data.

[0033] In some embodiments, the installation data of the application installed on the electronic device can be collected by pre-performing data burying on different electronic devices. The pre-performed burying is used to collect the above installation data of the application installed on the electronic device. Alternatively, the electronic device can actively report the installation data of the application installed on the electronic device after installing the application each time. Correspondingly, the computer device can obtain the installation data reported by the electronic device. Alternatively, the electronic device can report the installation data of the application installed on the electronic device once every preset time. Alternatively, the computer device can pull the installation data of the buried application from the electronic device. The specific manner in which the electronic device obtains the installation data can not be limited. The electronic device is a device for installing and running the application, for example, can be a mobile terminal, etc. The computer device is an execution device of the malicious application identification method provided in the embodiments of the present application, for example, can be a server, a PC computer, a notebook computer, a mobile terminal, etc. By performing data burying on a large number of electronic devices, the computer device executing the malicious application identification method can collect the installation data of the application on the electronic device, so as to determine the existing malicious application based on the installation data. It can be understood that the computer device executing the malicious application identification method can also be any one of the electronic devices performing data burying, that is, the electronic devices performing data burying can obtain the installation data of the application of other electronic devices and perform subsequent steps, so as to determine the malicious application.

[0034] In some embodiments, the installation data of the plurality of applications obtained by the computer device can be installation data of more than a specified number of applications, so as to be able to determine the application inducing the installation of other applications, that is, the malicious application inducing installation based on the installation data of the application. It can be understood that the malicious application inducing installation usually exists in the case of inducing the installation of a large number of applications, so more than a specified number of installation data of the application can be obtained to accurately determine the malicious application inducing installation.

[0035] Step S120: generating a connection graph corresponding to an installation relationship between the plurality of applications based on the installation data, the connection graph including nodes corresponding to each application and edges between the nodes, the edges being used to represent the installation relationship.

[0036] In this embodiment, after acquiring installation data for multiple applications, the computer device can determine the installation relationships between these applications based on the installation data, and generate a connection graph containing these installation relationships. The connection graph includes nodes and edges; the nodes correspond to applications, and the edges represent the installation relationships between applications. The connection graph can also be understood as a knowledge graph, that is, a graph built with each application as a node and the installation relationships between applications as edges.

[0037] The edges in the connection graph are directed, meaning they are formed by directed connections between nodes. For any given edge, the installation channel of the application corresponding to the node pointed to by that edge is the application corresponding to the other node along that edge. For an example, please refer to [link to example graph]. Figure 2 , Figure 2 The diagram shows a connection diagram provided in an embodiment of this application. For the edge formed by the connecting line from the node corresponding to application A to the node corresponding to application B, the installation channel of application B is application A.

[0038] In some implementations, when a computer device generates a connection graph based on the installation data of multiple applications, it can define the nodes of the connection graph as applications and the edges as the installation relationships between applications. Then, based on the defined nodes and applications, the connection graph is generated by identifying the installation data. Of course, in addition to nodes and edges, the connection graph may also include the distance of each node from the root node, the number of edges originating from that node, etc., which are not limited here. The root node refers to the node at the root of the tree in the connection graph, or it can be understood as the first node in a linked chain with connections.

[0039] In some embodiments, after the computer device establishes the connection graph based on the installation data of the plurality of application programs, the connection graph can include a plurality of sets, and each set can include nodes corresponding to a plurality of application program pairs having an installation relationship. The plurality of sets can also be regarded as a relationship tree, i.e., the connection graph can include a plurality of nodes constituting a relationship tree. It can be understood that the application programs in different sets can not have an installation relationship, and thus cannot be connected by an edge. Therefore, the established connection graph can include a plurality of separate connection graphs. For these sets of application programs, the computer device can determine the number of application programs in each set of application programs. If the number of application programs is less than a number threshold, it indicates that the set of application programs does not have reference significance for determining the malicious application that induces installation, and thus the connection graph corresponding to the set of application programs can be deleted from the connection graph. The number threshold can be set based on demand or experience, and the specific value can not be limited. For example, the number threshold can be 2. It can be understood that if there is a connection between the nodes of only two application programs, the possibility of normal installation of the two application programs is high, and thus the connection between the two application programs can be deleted from the connection graph to avoid unnecessary computational complexity when determining the malicious application based on the connection graph.

[0040] Step S130: Based on the connection graph, a target application program in the plurality of application programs is obtained as a malicious application existing in the plurality of application programs, and an installation relationship between the target application program and other application programs in the plurality of application programs except the target application program satisfies a preset relationship condition.

[0041] In the embodiments of the present application, after the above connection graph is generated, the installation relationship between the application programs in the plurality of application programs can be reflected in the connection graph. Therefore, the malicious application that induces the installation of other application programs can be determined based on the connection graph. The computer device can determine, based on the connection graph, whether an installation relationship between each application program and other application programs in the plurality of application programs except the application program satisfies a preset relationship condition. Thus, a target application program satisfying the preset relationship condition is obtained, and the determined target application program is taken as a malicious application existing in the plurality of application programs. The preset relationship condition is a judgment basis for the malicious application that induces the installation of other application programs. If an installation relationship between an application program and other application programs in the plurality of application programs except the application program satisfies the preset relationship condition, it indicates that the application program is a malicious application that induces the installation of other application programs. Otherwise, if an installation relationship between an application program and other application programs in the plurality of application programs except the application program does not satisfy the preset relationship condition, it indicates that the application program is not a malicious application that induces the installation of other application programs.

[0042] In some embodiments, the preset relationship condition can be that the number of other applications installed via the application as an installation channel is greater than the preset application number. It can be understood that when the number of other applications installed via the application as an installation channel is greater, it indicates that the application installs more other applications, and thus the possibility of inducing installation of other applications is higher, and thus the application can be determined as a malicious application inducing installation of other applications. Alternatively, the computer device can obtain the number of edges starting from each application, the number of edges indicating the number of other applications installed via the application as an installation channel, and then compare the obtained number of edges with the preset application number to determine whether the preset relationship condition is met according to the comparison result.

[0043] In other embodiments, the preset relationship condition can also be that the length of a link starting from the application in the connection graph is greater than a target length. The length of the link is positively correlated with the number of applications contained in the link, for example, refer again to Figure 2 For example, an application A installs an application C and an application F in sequence via a link, and the number of applications contained in the link is 2, and thus the length of the link can be 2. It can be understood that when the length of the link starting from the application is greater than the target length, it indicates that the application installed via the application as an installation channel becomes an installation channel of other applications, and in sequence, the number of installed applications is greater, and thus the possibility of inducing installation of other applications is higher, and thus the application can be determined as a malicious application inducing installation of other applications. Alternatively, in this embodiment, since the length of the link starting from the application in the connection graph is longer, it can be considered that the application sequentially induces installation of applications, and thus in addition to the application corresponding to the starting point of the link being determined as a malicious application, all applications in the link can also be determined as malicious applications inducing installation of other applications, or in addition to the application corresponding to the starting point of the link being determined as a malicious application, the application in the link that is less than a distance threshold from the starting point can also be determined as a malicious application inducing installation of other applications. Of course, the specific preset relationship condition is not limited.

[0044] In some embodiments, the computer device can sequentially traverse all nodes in the connection graph to determine whether each node corresponding application satisfies the preset relationship condition, and when any application satisfies the preset relationship condition, it is determined as a malicious application inducing installation of other applications, so that it can be determined whether each application in the above plurality of applications is a malicious application inducing installation of other applications, and thus all malicious applications existing in the plurality of applications can be determined.

[0045] The method for identifying malicious application provided in the embodiments of the present application comprises the following steps: obtaining installation data of a plurality of application programs; generating a connection graph corresponding to installation relationships between the plurality of application programs based on the installation data, wherein the connection graph comprises edges formed by directed connection lines between nodes corresponding to each application program, and the edges are used to represent the installation relationships between the application programs; obtaining a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs based on the connection graph, and the installation relationship between the target application program and other application programs in the plurality of application programs except the target application program satisfies a preset relationship condition. Thus, the connection graph of the installation relationships established based on the installation data of the application programs can be obtained, and the malicious application which maliciously induces the installation of other application programs can be identified according to the connection graph, thereby improving the identification efficiency and accuracy of the malicious application.

[0046] Please refer to Figure 3 , Figure 3 A flowchart of a method for identifying malicious application provided in another embodiment of the present application is shown. The method for identifying malicious application is applied to the computer device described above, and the following will be described in detail with respect to the flowchart shown in Figure 3 The method for identifying malicious application can specifically comprise the following steps:

[0047] Step S210: Obtain installation data of a plurality of application programs.

[0048] Step S220: Generate a connection graph corresponding to installation relationships between the plurality of application programs based on the installation data, wherein the connection graph comprises edges formed by directed connection lines between nodes corresponding to each application program, and the edges are used to represent the installation relationships.

[0049] In the embodiments of the present application, steps S210 and S220 can refer to the content of other embodiments, which will not be described herein again.

[0050] Step S230: Obtain the number of out-edges of the node corresponding to each application program as the out-degree based on the connection graph.

[0051] In the embodiments of the present application, when the computer device determines the application programs whose installation relationship with other application programs meets the preset relationship condition based on the connection graph, the computer device can obtain the out-degree of the node corresponding to each application program based on the connection graph. The out-degree refers to the number of out-edges of the node, that is, the number of out-edges of the node corresponding to each application program is obtained as the out-degree. It can be understood that, since the edges in the connection graph are edges formed by directed connection lines, that is, the connection graph is a directed graph, the number of out-edges of each node can be obtained as the out-degree. Alternatively, the computer device can traverse the node corresponding to each application program to determine the number of out-edges of each node in the connection graph as the out-degree. It can be understood that the out-degree corresponding to each application program indicates the number of other application programs installed by the node as an installation channel, and the greater the out-degree corresponding to the application program, the greater the possibility that the application program is a malicious application that induces the installation of other application programs. Therefore, the out-degree of each application program can be obtained to determine whether it is a malicious application that induces the installation of other application programs.

[0052] In some embodiments, when the computer device determines the out-degree corresponding to each application program, in addition to referring to the number of out-edges, the computer device can also refer to the number of application programs that can be passed through on the path of each edge of the node corresponding to each application program. Alternatively, the number of application programs that can be passed through from each application program as a starting point can be obtained as a first number, and the number of application programs that can be passed through on the path of each edge of the node corresponding to each application program can be obtained as a second number; for each application program, the second number corresponding to each edge is normalized, wherein the ratio of the second number to the first number is obtained as the normalized value; then, for each application program, the sum of the normalized values corresponding to each edge is obtained, and the obtained sum value is taken as the out-degree. It can be understood that, in this embodiment, when the out-degree corresponding to each node is obtained, both the edges with each node as a starting point and the number of application programs that can be passed through on the path of each edge are referred to, which provides an accurate reference for subsequent determination of malicious applications. It can be understood that the greater the number of application programs that can be passed through on the path of each edge of the node corresponding to each application program, the higher the possibility that it induces the installation of other application programs, and therefore, when the out-degree is determined, the number is also referred to, which can provide a more accurate reference for the determination of malicious applications.

[0053] In some embodiments, in determining the out-degree corresponding to each application, the computer device can refer to the number of downloads of the application corresponding to the node pointed to by each edge of the node of each application when it serves as an installation channel, that is, the number of occurrences of the corresponding download situation of each edge can be referred to. Alternatively, the above number of downloads can be taken as a first number, and the above number of downloads corresponding to each edge of each application can be taken as a second number; for each application, the above number of downloads corresponding to each edge of the application is normalized, wherein the ratio of the first number to the second number can be taken as the normalized value; then, for each application, the sum of the normalized values corresponding to each edge is calculated, and the obtained sum value is taken as the out-degree. Therefore, in this embodiment, the actual number of occurrences is also referred to in determining the out-degree, and the reference basis for determining the malicious application is more accurate. Alternatively, the above number of downloads can be replaced by the number of users, that is, the number of users of the electronic device corresponding to the above download situation.

[0054] Step S240: based on the out-degree corresponding to each application, an application satisfying a preset out-degree condition is obtained to obtain a target application, and the target application is taken as a malicious application existing in the plurality of applications.

[0055] In the embodiments of the present application, after the computer device obtains the out-degree of the node corresponding to each application, based on the out-degree corresponding to each application, an application satisfying a preset out-degree condition is obtained to obtain a target application, and the obtained target application is taken as a malicious application existing in the plurality of applications. The preset out-degree condition is used as a judgment basis for judging whether an application is a malicious application inducing the installation of other applications. If the out-degree corresponding to an application satisfies the preset out-degree condition, it can be determined that the application is a malicious application inducing the installation of other applications; otherwise, if the out-degree corresponding to an application does not satisfy the preset out-degree condition, it can be determined that the application is not a malicious application inducing the installation of other applications.

[0056] In some embodiments, the computer device can compare the out-degree corresponding to each application with a preset out-degree; according to the comparison result, it is determined whether the out-degree corresponding to each application is greater than the preset out-degree; if the out-degree of an application is greater than the preset out-degree, it is determined that the out-degree of the application satisfies the preset out-degree condition, that is, it can be determined that the application is a malicious application inducing the installation of other applications; otherwise, if the out-degree of an application is less than or equal to the preset out-degree, it is determined that the out-degree of the application does not satisfy the preset out-degree condition, that is, it can be determined that the application is not a malicious application inducing the installation of other applications.

[0057] In some embodiments, the computer device can calculate a malicious application score corresponding to each application program based on the out-degree corresponding to each application program, and determine whether a preset out-degree condition is met based on the malicious application score. If the malicious application score of an application program is greater than a first score value, it indicates that the out-degree corresponding to the application program meets the preset out-degree condition. If the malicious application score of an application program is not greater than the first score value, it indicates that the out-degree corresponding to the application program does not meet the preset out-degree condition. Optionally, the malicious application score corresponding to an application program can be positively correlated with the out-degree, that is, the higher the out-degree, the higher the malicious application score.

[0058] In a possible implementation, when calculating the malicious application score corresponding to each application program based on the out-degree corresponding to each application program, the computer device can also refer to the number of application programs that can be passed through with the application program as a starting point in the connection graph. Optionally, a first score value corresponding to the out-degree and a second score value corresponding to the number of application programs that can be passed through with the application program as a starting point can be calculated respectively. The first score value and the second score value are weighted calculated, for example, weighted summed, according to a first weight corresponding to the out-degree and a second weight corresponding to the number of application programs that can be passed through with the application program as a starting point, to obtain a total score value as the malicious application score of the application program. The first score value is positively correlated with the out-degree, and the second score value is positively correlated with the number of application programs that can be passed through with the application program as a starting point. The first weight and the second weight can be set in advance or set each time the malicious application is identified, and their specific values can not be limited. It can be understood that the larger the number of application programs that can be passed through with the application program as a starting point, the higher the possibility of inducing the installation of other application programs. Therefore, when determining the malicious application score, the number is also referred to, which can make the reference basis for determining the malicious application more accurate.

[0059] The malicious application identification method provided by the embodiments of the present application can establish a connection graph of installation relationships based on installation data of application programs, determine the out-degree of each node corresponding to each application program according to the connection graph, and then determine the application program that meets the preset out-degree condition as a malicious application based on the out-degree, thereby improving the identification efficiency of the malicious application and effectively ensuring the accuracy of the identification of the malicious application.

[0060] Please refer to Figure 4 , Figure 4 A flowchart of a malicious application identification method provided by another embodiment of the present application is shown. The malicious application identification method is applied to the computer device described above, and the following will be described in detail with reference to the flowchart shown in Figure 4 The malicious application identification method can specifically include the following steps:

[0061] Step S310: Obtain installation data of a plurality of application programs.

[0062] Step S320: generating a connection graph corresponding to the installation relationship between the plurality of application programs based on the installation data, the connection graph comprising nodes corresponding to each application program and edges between the nodes, the edges being used to represent the installation relationship.

[0063] Step S330: obtaining the number of out-edges of the node corresponding to each application program as the out-degree based on the connection graph.

[0064] In the embodiments of the present application, steps S310 to S330 can refer to the content of other embodiments, which will not be described here.

[0065] Step S340: sorting the plurality of application programs in descending order of the out-degree to obtain a target sorting result.

[0066] In the embodiments of the present application, when the computer device determines the application programs meeting the preset out-degree condition as malicious applications based on the out-degree corresponding to each application program, the computer device can also obtain the application programs with relatively large out-degree in the plurality of application programs as malicious applications. The computer device can sort the plurality of application programs in descending order of the out-degree to obtain a target sorting result, and then determine the application programs ranking at the front in the target sorting result as malicious applications.

[0067] In some embodiments, when sorting the plurality of application programs, the computer device can also refer to the shortest path from the starting node in the installation link where the node corresponding to the application program is located. The computer device can sort the plurality of application programs in descending order of the out-degree corresponding to each application program to obtain a first sorting result; if there are application programs with the same out-degree in the first sorting result, the computer device can obtain the shortest path from the starting node in the installation link where the node corresponding to the application program is located; and then sort the application programs with the same out-degree in the first sorting result again in ascending order of the shortest path to obtain a second sorting result, and take the second sorting result as the target sorting result.

[0068] In this embodiment, the shortest path from the starting node in the installation link where the node corresponding to the application program is located represents the shortest path from the node corresponding to the application program to the root node in the connection graph. The length of the shortest path can be positively correlated with the number of application programs away from the starting node, for example, please refer to Figure 2, the root node of the installation link where the application program G is located is the application program A, and there is also the application program C between the application program G and the application program A in the installation link, the number of application programs from the root node (application program A) of the application program G is 2, and therefore the shortest path can be determined as 2. Alternatively, the computer device can use the igraph.shortest_paths(self, source=None, target=None, weights=None, mode=None) method of the igraph library in python to calculate the shortest path between the given starting node and the target node, wherein the target node is the node corresponding to any application program. It can be understood that the closer the application program is to the root node in the installation link where it is located, the greater the possibility that it will induce the installation of other application programs as an installation channel. Therefore, when the out-degree of the node corresponding to the application program is the same, the above shortest path can also be obtained, and these application programs with the same out-degree are sorted again, thereby obtaining a second sorting result as a target sorting result for subsequent determination of malicious applications that induce the installation of other application programs.

[0069] In some embodiments, when sorting the plurality of application programs, the computer device can also refer to the number of nodes that can be passed through (reached) by the node corresponding to the application program in the connection graph. Wherein the computer device can sort the plurality of application programs in descending order of out-degree based on the out-degree corresponding to each application program, to obtain a first sorting result; if there are application programs with the same out-degree in the first sorting result, the number of nodes that can be passed through by the node corresponding to the application programs with the same out-degree can be obtained as the node number; the application programs with the same out-degree in the first sorting result are sorted again in descending order of node number, to obtain a third sorting result, and the third sorting result is taken as the target sorting result. It can be understood that the greater the number of application programs that the node of the application program can pass through, the higher the possibility that it will induce the installation of other application programs. Therefore, when the out-degree of the node corresponding to the application program is the same, the above node number can also be obtained, and these application programs with the same out-degree are sorted again, thereby obtaining a third sorting result as a target sorting result for subsequent determination of malicious applications that induce the installation of other application programs, to improve the recognition accuracy of malicious applications.

[0070] Step S350: obtaining the application programs in the top N positions in the sorting result to obtain target application programs, and taking the target application programs as malicious applications existing in the plurality of application programs, wherein N is a positive integer.

[0071] In the embodiments of the present application, after obtaining the above target ranking result, the computer device can determine the application program ranking at the top as the malicious application inducing the installation of other application programs based on the target ranking result. The application program ranking at the top in the target ranking result can be obtained as the malicious application existing in the plurality of application programs. The specific value of N can not be limited, for example, N can be 2, 3, 5, etc.

[0072] The malicious application identification method provided by the embodiments of the present application can establish a connection graph of the installation relationship based on the installation data of the application programs, determine the out-degree of the node corresponding to each application program according to the connection graph, and then determine the malicious application based on the out-degree of the node corresponding to each application program. When the plurality of application programs are sorted in descending order of the out-degree of the node corresponding to each application program, the application program ranking at the top in the sorting result is determined as the malicious application inducing the installation of other application programs. Therefore, the identification efficiency of the malicious application is improved, and the accuracy of the identification of the malicious application is effectively ensured.

[0073] Please refer to Figure 5 , Figure 5 The flowchart of the malicious application identification method provided by another embodiment of the present application is shown. The malicious application identification method is applied to the computer device described above. The following will be described in detail with reference to the flowchart shown in Figure 5 The malicious application identification method can include the following steps:

[0074] Step S410: Obtain the installation data of the plurality of application programs.

[0075] Step S420: Based on the installation data, generate the connection graph corresponding to the installation relationship between the plurality of application programs. The connection graph includes the node corresponding to each application program and the edge formed by the directed connection line between the nodes. The edge is used to represent the installation relationship.

[0076] In the embodiments of the present application, the contents of step S410 and step S420 can refer to the contents of other embodiments, which will not be described here.

[0077] Step S430: Based on the connection graph, take the node corresponding to each application program as the root node, obtain the installation link group corresponding to the root node, and obtain a plurality of installation link groups. The installation link group includes the installation link between the application program corresponding to the root node and the application program corresponding to other nodes.

[0078] In the embodiments of the present application, since there are third-party software stores, application markets and the like, the user can also download and install the application program through such software stores, and part of the normal application programs will also have the phenomenon of downloading the application program. Therefore, when determining the existing malicious application based on the connection graph, the computer device can first determine the group of abnormal application programs that are suspected to be induced to install. First, the computer device can obtain the installation link group corresponding to the root node based on the connection graph, taking each application program corresponding node as the root node, to obtain a plurality of installation link groups. Each installation link group includes the installation link between the application program corresponding to the root node and the application program corresponding to other nodes, that is, each installation link group includes the link in which each edge of the root node is located.

[0079] Step S440: Obtain the installation link group in the plurality of installation link groups that meets the preset link condition as the target link group.

[0080] In the embodiments of the present application, after the computer device obtains the above plurality of installation link groups, it can obtain the installation link group in the plurality of installation link groups that meets the preset link condition as the target installation link group, so as to subsequently determine the malicious application from the target installation link group, and avoid regarding the normal software store or the application program that normally downloads other applications as a malicious application. The preset link condition is used as the basis for determining the target link group, that is, the basis for determining the group of abnormal application programs that are suspected to be induced to install. If the installation link group meets the preset link condition, it can be determined that the installation link group is the target link group. Otherwise, if the installation link group does not meet the preset link condition, it can be determined that the installation link group is not the target link group.

[0081] In some embodiments, the preset link condition can include that the number of application programs included in the installation link group meets a preset number condition. It can be understood that the more application programs in the installation link group, the greater the possibility that there is a malicious application in the group that induces the installation of other application programs. Therefore, the number of application programs included in each installation link group can be obtained, and it is determined whether the number of application programs included in each installation link group meets the preset number condition. If it meets the preset number condition, it can be determined as the target link group. If it does not meet the preset number condition, it is determined not to be the target link group. The preset number condition can be that, after sorting the plurality of installation link groups in descending order of the number of included application programs, the installation link groups in the top M positions in the sorting result, where M is a positive integer, or the number is greater than the preset number. Of course, the specific preset number condition can not be limited.

[0082] In some embodiments, the preset link condition can include that the link length of the installation link existing in the installation link group meets a preset length condition. It can be understood that the longer the length of the installation link existing in the installation link group, the greater the possibility of the existence of malicious applications in the group, and therefore the length of each installation link existing in the installation link group can be obtained, and the maximum length of the installation link of each installation link group is determined; if the length of the installation link meets the preset length condition, it can be determined that it is a target link group, and if it does not meet the preset length condition, it is determined that it is not a target link group. The length of the installation link can be positively correlated with the number of application programs contained in the link; the preset length condition can be that, according to the order from large to small of the maximum length of the installation link in the installation link group, the plurality of installation link groups are sorted, and the installation link groups in the top K positions in the sorting result, wherein K is a positive integer, or the maximum length of the installation link is greater than a preset length. Of course, the specific preset length condition can not be limited.

[0083] Of course, the above two embodiments can also be combined for implementation, for example, the computer device can sort the plurality of installation link groups according to the order from large to small of the number of contained application programs, to obtain a fourth sorting result; if there are installation link groups with the same number of contained application programs in the fourth sorting result, the fourth sorting result can be sorted again according to the order from large to small of the maximum length of the above installation link group for these installation link groups with the same number of contained application programs, to obtain a fifth sorting result; then, the top M installation link groups in the fifth sorting result are determined, wherein M is a positive integer.

[0084] In some embodiments, when the computer device obtains the installation link group that meets the preset link condition in the plurality of installation link groups, the number of nodes other than the root node in each installation link group of the plurality of installation link groups can be obtained as the number of reachable nodes; from the plurality of installation link groups, the installation link group with a number of reachable nodes greater than a preset number of nodes is screened out; from the screened plurality of installation link groups, the installation link group that meets the preset link condition is obtained as the target link group. The specific value of the preset number of nodes can not be limited, for example, it can be 20, 30, 40, etc. In this way, the installation link group with a number of reachable nodes meeting a preset number condition can be screened out from the plurality of installation link groups, and then the installation link group with the possibility of containing malicious applications induced by installation is determined, so as to reduce the calculation amount when determining whether the preset link condition is met.

[0085] In some embodiments, since part of the application program corresponding installation link group may exist in the installation link group corresponding to other application programs, after obtaining the plurality of installation link groups, the installation link group contained by other installation link groups can be filtered out to avoid subsequent repeated analysis and identification. For example, referring again to Figure 2 In the determination of the installation link group, the installation link group corresponding to the application program A has been determined, the installation link group corresponding to the application program A includes all application programs in Figure 2 , then the installation link group of the application program other than the application program A can be filtered out, and only the installation link group corresponding to the application program A is reserved. Then, based on the filtered installation link group, the installation link group satisfying the preset link condition is determined as the target link group.

[0086] In a possible implementation, the connection graph can be regarded as containing a plurality of tree structures, and different tree structures are separate tree structures since there is no installation relationship between the application programs, for example, Figure 2 The content shown in the figure can be regarded as a tree structure. The computer device can take the group corresponding to each tree structure as the plurality of installation link groups filtered above, thereby reducing the subsequent calculation amount.

[0087] Step S450: based on the target link group, obtaining a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs, and the installation relationship between the target application program and other application programs in the plurality of application programs other than the target application program satisfies the preset relationship condition.

[0088] In the embodiments of the present application, after the computer device obtains the target link group, the target application program in the plurality of application programs can be obtained from the target link group as a malicious application existing in the plurality of application programs, and the installation relationship between the target application program and other application programs in the plurality of application programs other than the target application program satisfies the preset relationship condition.

[0089] It should be noted that in the embodiments of the present application, the way of determining the target link group when determining the malicious application based on the connection graph can also be combined with other embodiments. For example, when combined with the first two embodiments, the target link group can be determined, and then the out-degree of each application program in the target link group is determined, and then the application program whose out-degree satisfies the preset out-degree condition is determined as the existing malicious application.

[0090] The malicious application identification method provided in the embodiments of the present application can realize a connection graph of installation relationships established based on installation data of application programs, then determine a target link group meeting preset link conditions based on the connection graph, and determine an application program meeting preset relationship conditions as a malicious application based on the target link group, thereby avoiding identifying an application program normally installing other application programs as a malicious application, so as to improve the identification efficiency of malicious applications and effectively ensure the accuracy of malicious application identification.

[0091] Please refer to Figure 6 , Figure 6 The flowchart of the malicious application identification method provided in another embodiment of the present application is shown. The malicious application identification method is applied to the computer device described above, and the following will be described in detail with respect to the flowchart shown in Figure 6 The malicious application identification method can specifically include the following steps:

[0092] Step S510: Obtain installation data of a plurality of application programs.

[0093] Step S520: Generate a connection graph corresponding to installation relationships between the plurality of application programs based on the installation data, the connection graph including nodes corresponding to each application program and edges formed by directed connection lines between nodes, and the edges being used to represent the installation relationships.

[0094] In the embodiments of the present application, steps S510 and S520 can refer to the content of the foregoing embodiments, which will not be described herein again.

[0095] Step S530: Identify a strongly connected component in the connection graph.

[0096] In the embodiments of the present application, the computer device can also identify a strongly connected component (SCC) in the connection graph after obtaining the connection graph. The strongly connected component represents a group of nodes in the connection graph that can reach each other (i.e., a plurality of nodes can reach each other). For example, please refer to Figure 7 In the connection graph shown in Figure 7 Node 3 and node 6 are strongly connected, so there is a strongly connected component, i.e., [3, 6], in the connection graph. In some embodiments, the computer device can use tarjan's algorithm based on depth-first search to obtain the strongly connected component, the necessary node and the necessary edge in the directed connection graph, so as to process the strongly connected component subsequently. The tarjan's algorithm is an algorithm for solving the strongly connected component in the directed graph proposed by Robert Tarjan.

[0097] Step S540: merging the strongly connected components in the connection graph into the same node.

[0098] In the embodiment of the present application, after the computer device determines the strongly connected components existing in the connection graph, the computer device can merge the strongly connected components in the connection graph into the same node, so as to obtain the connection graph after the merging of the strongly connected components, thereby effectively avoiding the situation that wireless loops appear when the malicious application is determined subsequently, and the malicious application cannot be normally identified, for example, avoiding the situation that the depth-first search cannot be performed when the shortest path in the above embodiment is determined. Exemplarily, please refer to Figure 8 , compared with the connection graph shown in Figure 7 , the node 3 and the node 6 before the condensation can be regarded as the same node after the condensation.

[0099] In some embodiments, the computer device can use the condensation algorithm to regard the strongly connected components as a node, and retain the nodes and edges that are not in the strongly connected components (i.e., the above necessary nodes and necessary edges), and the obtained graph is the graph after the condensation. For example, please refer to Figure 7 and Figure 8 , Figure 8 , the connection graph after the condensation of the connection graph shown in Figure 7 , Figure 7 , the node 3 and the node 6 are regarded as a node, the condensation is performed, and the connection graph shown in Figure 8 is obtained. Therefore, the graph after the condensation is a directed acyclic graph (DAG), and the situation that wireless loops appear when the malicious application is determined subsequently, and the malicious application cannot be normally identified, is avoided.

[0100] Step S550: based on the connection graph after the merging of the strongly connected components, obtaining a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs, and an installation relationship between the target application program and other application programs in the plurality of application programs except the target application program satisfies a preset relationship condition.

[0101] In the embodiment of the present application, after the computer device obtains the connection graph after the merging of the strongly connected components, the computer device can determine a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs based on the merged connection graph.

[0102] It should be noted that in the embodiment of the present application, when the malicious application is determined based on the connection graph, the manner of first determining the target link group can also be combined with other embodiments. For example, when combined with the above embodiment, the strong connected components can be merged in the embodiment of the present application first, then the target link group is determined, the out-degree of each application program in the target link group is determined, and then the application program whose out-degree satisfies the preset out-degree condition is determined as the existing malicious application.

[0103] The malicious application identification method provided by the embodiments of the present application can realize a connection graph of installation relationships established based on installation data of application programs, then merge strong connected components existing in the connection graph, and then determine application programs satisfying preset relationship conditions as malicious application based on the merged connection graph, thereby more effectively improving the identification efficiency of malicious application.

[0104] Referring to Figure 9 , Figure 9 A flowchart of a malicious application identification method provided by another embodiment of the present application is shown. The malicious application identification method is applied to the computer device described above, and the following will be described in detail with reference to the flowchart shown in Figure 9 The malicious application identification method can specifically include the following steps:

[0105] Step S610: Obtain installation data of a plurality of application programs.

[0106] In the embodiments of the present application, step S610 can refer to the content of other embodiments.

[0107] Step S620: Obtain an installation channel corresponding to each application program in the plurality of application programs based on the installation data.

[0108] Step S630: Generate a connection graph corresponding to installation relationships between the plurality of application programs based on the installation channel, the connection graph including nodes corresponding to each application program and edges formed by directed connection lines between the nodes, the edges being used to represent the installation relationships.

[0109] In the embodiments of the present application, when generating the connection graph based on the installation data, the computer device can identify the installation channel corresponding to each application program based on the installation data, so as to determine the installation relationships between the application programs according to the installation channel. Optionally, there is data of type app_install_channel (installation channel) in the installation data, and the computer device can extract the data of this type from the installation data of the application program, thereby obtaining the installation channel of the application program. For example, the installation channel of the application program B is the application program A, and the computer device can obtain the installation relationship between the application program A and the application program B, based on which the installation relationship between each application program and other application programs can be obtained, so that the connection graph corresponding to the installation relationships between the plurality of application programs can be generated.

[0110] In some embodiments, after obtaining the installation data of the plurality of application programs, the computer device can also pre-process the installation data, and then generate the connection graph corresponding to the installation relationships between the above plurality of application programs based on the pre-processed installation data, so as to improve the accuracy of the subsequent identification result.

[0111] In a possible implementation, the computer device can filter data satisfying preset filtering conditions from the installation data. The preset filtering conditions can include: installation data of self-installed and self-updated application programs; data of regions being foreign countries; installation data of application programs downloaded from official channels; and installation data of application programs corresponding to download channels ranked in top T positions, where T is a positive integer. The self-installed and self-upgraded application programs are useless for the analysis of the application programs maliciously induced to be installed this time, and thus are directly filtered out, that is, the installation data of the application programs with package name = download channel are filtered out. It can be understood that, in the process of using the application program, the application program is automatically upgraded, and thus in the installation data, the package name = the name of the application program, the download channel = the name of the application program, that is, the package name and the installation channel are the application program, and thus such data can be filtered out. Generally, the malicious application is identified for domestic application, and thus the installation data of foreign countries can be filtered out. The processing method can be to screen out installation data with region = 'CN'. Since the official application store has a certain audit mechanism for the listing of application programs, and more malicious applications are directly from the download of non-official channel software stores, the data directly downloaded from the official channel can be filtered out. Alternatively, the filtering method can be that app_install_channel not in official channel. Similarly, the download channels ranked in the top T positions are usually official channels, and thus the data of the download channels can also be filtered out. In this way, the installation data affecting the identification result can be filtered out, so as to improve the accuracy of the identification result of the subsequent identification of the malicious application.

[0112] Step S640: based on the connection graph, obtaining a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs, an installation relationship between the target application program and other application programs in the plurality of application programs except the target application program satisfying a preset relationship condition.

[0113] In the embodiments of the present application, step S640 can refer to the content of other embodiments, which will not be described here.

[0114] It should be noted that the generation method of the connection graph provided in the embodiments of the present application can also be combined into other embodiments.

[0115] The malicious application identification method provided in the embodiments of the present application provides a generation method of a connection graph. After determining the installation channels of each application program based on the installation data, the connection graph is generated based on the installation channel of each application program. Then, based on the generated connection graph, the application programs satisfying the preset relationship condition are determined as malicious applications, and the identification efficiency of the malicious applications is effectively improved.

[0116] Referring to Figure 10 , Figure 10 A flowchart of a method for identifying a malicious application according to another embodiment of the present application is shown. The method for identifying a malicious application is applied to the computer device described above, and will be described in detail below with reference to the flowchart shown in Figure 10 The method for identifying a malicious application can specifically include the following steps:

[0117] Step S710: Obtain installation data of a plurality of application programs.

[0118] Step S720: Based on the installation data, generate a connection graph corresponding to an installation relationship between the plurality of application programs, the connection graph including nodes corresponding to each application program and edges between the nodes, the edges being used to represent the installation relationship.

[0119] Step S730: Based on the connection graph, obtain a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs, the installation relationship between the target application program and other application programs in the plurality of application programs except the target application program satisfying a preset relationship condition.

[0120] In the embodiments of the present application, steps S710 to S730 can refer to the content of the foregoing embodiments, which will not be described here again.

[0121] Step S740: Generate a blacklist including the malicious application.

[0122] In the embodiments of the present application, after the computer device determines the malicious application existing in the plurality of application programs, the computer device can generate a blacklist including the malicious application based on the identified malicious application, so as to be pushed to a user terminal. Alternatively, the computer device can be a server, which can be a server of a manufacturer of the user terminal, or a server of a third-party software store, etc., which is not limited here. Thus, the server can generate a blacklist including the identified malicious application, so as to be pushed to each user terminal.

[0123] Step S750: Push the blacklist to a user terminal, the user terminal being used to output prompt information for prompting that a malicious application is being installed when installing an application program in the blacklist.

[0124] In the embodiments of the present application, after the computer device generates the blacklist, the computer device can push the blacklist to the user terminal. Correspondingly, the user terminal can receive the above blacklist, so that the user terminal can output prompt information for prompting that a malicious application is being installed when installing an application program in the blacklist, so as to avoid the user from installing the malicious application, which affects the use safety.

[0125] The method for identifying malicious applications provided by the embodiments of the present application can quickly and effectively determine malicious applications installed by malicious inducement, has a short response time and high efficiency. Moreover, the behavior characteristics of the malicious inducement behavior are fully mined, thereby ensuring the accuracy of the generated blacklist of malicious applications. Moreover, only simple data burying is required to obtain the above installation data, and the malicious applications can be determined by generating a connection graph based on the installation data, thereby having a very low cost and being able to be deployed online to automatically help developers find malicious applications installed by malicious inducement.

[0126] Referring to FIG. 4, Figure 11 FIG. 4 shows a structural block diagram of a device 400 for identifying malicious applications according to an embodiment of the present application. The device 400 for identifying malicious applications comprises a computer device as described above, and comprises a data acquisition module 410, a connection graph generation module 420, and an application acquisition module 430. The data acquisition module 410 is configured to acquire installation data of a plurality of application programs. The connection graph generation module 420 is configured to generate a connection graph corresponding to an installation relationship between the plurality of application programs based on the installation data. The connection graph comprises nodes corresponding to each application program and edges formed by directed connection lines between the nodes, and the edges are used to represent the installation relationship. The application acquisition module 430 is configured to acquire a target application program from the plurality of application programs as a malicious application existing in the plurality of application programs based on the connection graph, and the installation relationship between the target application program and other application programs in the plurality of application programs except the target application program satisfies a preset relationship condition.

[0127] In some embodiments, the application acquisition module 430 can be configured to acquire, based on the connection graph, an out-degree of each node corresponding to each application program as an out-degree of each application program, acquire an application program satisfying a preset out-degree condition based on the out-degree of each application program, obtain a target application program, and take the target application program as a malicious application existing in the plurality of application programs.

[0128] In a possible implementation, the application acquisition module 430 can acquire, based on the out-degree of each application program, an application program satisfying a preset out-degree condition, obtain a target application program, and take the target application program as a malicious application existing in the plurality of application programs, which can include: sorting the plurality of application programs in a descending order of out-degree based on the out-degree of each application program, obtaining a target sorting result; acquiring an application program in a top N position in the sorting result, obtaining a target application program, and taking the target application program as a malicious application existing in the plurality of application programs, where N is a positive integer.

[0129] Optionally, the application obtaining module 430 sorts the plurality of application programs in descending order of out-degree based on the out-degree corresponding to each application program, to obtain a target sorting result, which can include: sorting the plurality of application programs in descending order of out-degree based on the out-degree corresponding to each application program, to obtain a first sorting result; if there are application programs with the same out-degree in the first sorting result, obtaining the shortest path from the starting node to the node corresponding to the application programs with the same out-degree in the installation link; re-sorting the application programs with the same out-degree in the first sorting result in ascending order of the shortest path, to obtain a second sorting result, and taking the second sorting result as the target sorting result.

[0130] In some embodiments, the application obtaining module 430 can be configured to: based on the connection graph, taking each application program corresponding node as a root node, obtaining the installation link group corresponding to the root node, to obtain a plurality of installation link groups, the installation link group including the installation link between the application program corresponding to the root node and the application program corresponding to other nodes; obtaining the installation link group that meets the preset link condition in the plurality of installation link groups as a target link group; based on the target link group, obtaining a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs, the installation relationship between the target application program and other application programs in the plurality of application programs except the target application program meeting the preset relationship condition.

[0131] In a possible implementation, the preset link condition includes at least one of the following conditions: the number of application programs included in the installation link group meets a preset number condition; the link length of the installation link existing in the installation link group meets a preset length condition.

[0132] In a possible implementation, the application obtaining module 430 obtains the installation link group that meets the preset link condition in the plurality of installation link groups as a target link group, which can include: obtaining the number of nodes other than the root node in each installation link group of the plurality of installation link groups as the number of reachable nodes; from the plurality of installation link groups, screening out the installation link group with the number of reachable nodes greater than a preset node number; from the screened plurality of installation link groups, obtaining the installation link group that meets the preset link condition as the target link group.

[0133] In some embodiments, the application acquisition module 430 can be configured to: identify a strongly connected component in the connection graph; merge the strongly connected component in the connection graph into one node; and acquire, based on the connection graph after merging the strongly connected component, a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs, the target application program satisfying a preset relationship condition with respect to an installation relationship between the target application program and other application programs in the plurality of application programs except the target application program.

[0134] In some embodiments, the connection graph generation module 410 can be configured to: acquire, based on the installation data, an installation channel corresponding to each application program in the plurality of application programs; and generate, based on the installation channel, a connection graph corresponding to an installation relationship between the plurality of application programs.

[0135] In some embodiments, the connection graph generation module 410 can be configured to: pre-process the installation data; and generate, based on the pre-processed installation data, a connection graph corresponding to an installation relationship between the plurality of application programs.

[0136] In some embodiments, the connection graph generation module 410 pre-processes the installation data, including: filtering, from the installation data, data satisfying a preset filtering condition.

[0137] In some embodiments, the malicious application identification apparatus 400 can further include a list generation module and a list pushing module. The list generation module is configured to generate a black list including the malicious application after acquiring, based on the connection graph, the target application program in the plurality of application programs as the malicious application existing in the plurality of application programs. The list pushing module is configured to push the black list to a user terminal, the user terminal being configured to output prompt information for prompting that a malicious application is being installed when installing an application program in the black list.

[0138] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-described apparatuses and modules can refer to the corresponding process in the foregoing method embodiments, which will not be described herein.

[0139] In several embodiments provided in the present application, the coupling between the modules can be electrical, mechanical or other forms of coupling.

[0140] In addition, each functional module in each embodiment of the present application can be integrated in one processing module, or each module can exist physically independently, or two or more modules can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of a software functional module.

[0141] In summary, the scheme provided in the present application, by obtaining installation data of a plurality of application programs, generating a connection graph corresponding to an installation relationship between the plurality of application programs based on the installation data, the connection graph including edges formed by directed connection lines between nodes corresponding to each application program, the edges being used to represent the installation relationship between the application programs, then based on the connection graph, obtaining a target application program in the plurality of application programs as a malicious application existing in the plurality of application programs, and the installation relationship between the target application program and other application programs in the plurality of application programs except the target application program satisfying a preset relationship condition. Thus, the connection graph of the installation relationship established based on the installation data of the application programs can be realized, and according to the connection graph, the malicious application that maliciously induces the installation of other application programs can be identified, and the identification efficiency and accuracy of the malicious application are improved

[0142] For reference Figure 12 which shows a structural block diagram of a computer device provided in an embodiment of the present application. The computer device 100 can be a physical server, a cloud server, a PC computer, a notebook computer, etc. capable of running an application program. The computer device 100 in the present application can include one or more of the following components: a processor 110, a memory 120, and one or more application programs, wherein the one or more application programs can be stored in the memory 120 and configured to be executed by the one or more processors 110, and the one or more programs are configured to perform the method as described in the foregoing method embodiment.

[0143] The processor 110 can include one or more processing cores. The processor 110 connects various parts within the entire computer device 100 by various interfaces and lines, performs various functions of the computer device 100 and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory 120, and calling data stored in the memory 120. Optionally, the processor 110 can be implemented in at least one of a hardware form of a digital signal processing (DSP), a field-programmable gate array (FPGA), and a programmable logic array (PLA). The processor 110 can be integrated with a combination of one or more of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. Among them, the CPU mainly processes operating systems, user interfaces, and application programs; the GPU is responsible for rendering and drawing display content; and the modem is used for processing wireless communication. It can be understood that the above-mentioned modem can also not be integrated into the processor 110, but be implemented separately through a communication chip.

[0144] The memory 120 can include a random access memory (RAM) and can also include a read-only memory (ROM). The memory 120 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 120 can include a program storage area and a data storage area, wherein the program storage area can store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playing function, an image playing function, etc.), instructions for implementing each of the method embodiments described below, etc. The data storage area can also store data created by the computer device 100 in use (such as a phone book, audio and video data, chat record data, etc.).

[0145] Please refer to Figure 13 which shows a structural block diagram of a computer readable storage medium provided by an embodiment of the present application. The computer readable medium 800 stores program codes therein, and the program codes can be called and executed by a processor to perform the methods described in the above method embodiments.

[0146] The computer-readable storage medium 800 can be an electronic storage memory such as a flash memory, an EEPROM (Electrically Erasable Programmable Read-Only Memory), an EPROM, a hard disk or a ROM. Optionally, the computer-readable storage medium 800 comprises a non-transitory computer-readable medium. The computer-readable storage medium 800 has a storage space for program codes 810 to execute any of the method steps described above. These program codes can be read from or written to one or more computer program products. The program codes 810 can be compressed, for example, in an appropriate form.

[0147] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art will understand that they can still modify the technical solutions described in the foregoing embodiments, or make equivalent replacements for some of the technical features, without departing from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for identifying malicious applications, characterized in that, The method includes: Retrieve installation data for multiple applications; Based on the installation data, a connection graph corresponding to the installation relationship between the multiple applications is generated. The connection graph includes nodes corresponding to each application and edges formed by directed connecting lines between nodes. The edges are used to represent the installation relationship. Based on the connection graph, a target application is obtained from the plurality of applications as a malicious application existing in the plurality of applications. The installation relationship between the target application and other applications in the plurality of applications satisfies a preset relationship condition. The preset relationship condition includes: the number of other applications installed by the application as an installation channel is greater than a preset number of applications; the length of the link from which the application is the starting point in the connection graph is greater than the target length; or the out-degree of the application satisfies a preset out-degree condition, where the out-degree is the number of out-edges of the node corresponding to the application.

2. The method according to claim 1, characterized in that, The step of obtaining the target application from the plurality of applications based on the connection graph, as a malicious application existing in the plurality of applications, includes: Based on the connection graph, the number of outgoing edges of each node corresponding to each application is obtained as the outgoing degree; Based on the out-degree of each application, applications that meet the preset out-degree conditions are obtained to obtain the target application, and the target application is identified as a malicious application among the multiple applications.

3. The method according to claim 2, characterized in that, The step of obtaining applications that meet preset out-degree conditions based on the out-degree of each application, obtaining target applications, and identifying the target applications as malicious applications among the multiple applications includes: Based on the out-degree of each application, the applications are sorted in descending order of out-degree to obtain the target sorting result; The application that ranks in the top N positions of the sorting results is obtained as the target application, and the target application is identified as a malicious application among the multiple applications, where N is a positive integer.

4. The method according to claim 3, characterized in that, The process of sorting the multiple applications based on their out-degrees, from largest to smallest, to obtain the target sorting result includes: Based on the out-degree of each application, the applications are sorted in descending order of out-degree to obtain a first sorting result; If there are applications with the same out-degree in the first sorting result, obtain the shortest path from the starting node in the installation link of the node corresponding to the application with the same out-degree; According to the shortest path in ascending order, the applications with the same out-degree in the first sorting result are sorted again to obtain the second sorting result, and the second sorting result is used as the target sorting result.

5. The method according to claim 1, characterized in that, The step of obtaining the target application from the plurality of applications based on the connection graph, as a malicious application existing in the plurality of applications, includes: Based on the connection graph, taking the node corresponding to each application as the root node, the installation link group corresponding to the root node is obtained, resulting in multiple installation link groups. The installation link group includes the installation links between the application corresponding to the root node and the applications corresponding to other nodes. Obtain the installation link group that meets the preset link conditions from the multiple installation link groups, and use it as the target link group; Based on the target link group, the target application in the multiple applications is obtained as a malicious application existing in the multiple applications. The installation relationship between the target application and other applications in the multiple applications, excluding the target application, meets the preset relationship conditions.

6. The method according to claim 5, characterized in that, The preset link conditions include at least one of the following conditions: The number of applications included in the installation link group meets the preset quantity condition. The length of the installation links in the installation link group meets the preset length condition.

7. The method according to claim 5, characterized in that, The step of obtaining the installation link group that meets the preset link conditions from the plurality of installation link groups as the target link group includes: The number of nodes other than the root node in each of the multiple installation link groups is obtained as the number of reachable nodes; From the multiple installation link groups, select the installation link groups with a number of reachable nodes greater than a preset number of nodes; From the selected multiple installation link groups, the installation link groups that meet the preset link conditions are selected as the target link groups.

8. The method according to claim 1, characterized in that, The step of obtaining the target application from the plurality of applications based on the connection graph, as a malicious application existing in the plurality of applications, includes: Identify the strongly connected components in the connection graph; Merge the strongly connected components in the connection graph into a single node; Based on the connection graph after merging the strongly connected components, the target application in the plurality of applications is obtained as a malicious application existing in the plurality of applications. The installation relationship between the target application and other applications in the plurality of applications satisfies a preset relationship condition.

9. The method according to any one of claims 1-8, characterized in that, The step of generating a connection diagram corresponding to the installation relationships among the multiple applications based on the installation data includes: Based on the installation data, obtain the installation channel corresponding to each of the multiple applications; Based on the installation channels, a connection diagram corresponding to the installation relationships between the multiple applications is generated.

10. The method according to any one of claims 1-8, characterized in that, The step of generating a connection diagram corresponding to the installation relationships among the multiple applications based on the installation data includes: The installation data is preprocessed; Based on the preprocessed installation data, a connection diagram corresponding to the installation relationships between the multiple applications is generated.

11. The method according to claim 10, characterized in that, The preprocessing of the installation data includes: Filter the installation data to find data that meets the preset filtering conditions.

12. The method according to any one of claims 1-8, characterized in that, After obtaining the target application from the plurality of applications based on the connection graph, which is identified as a malicious application existing within the plurality of applications, the method further includes: Generate a blacklist that includes the malicious application; The blacklist is pushed to the user terminal, which is used to output a prompt message indicating that a malicious application is being installed when an application in the blacklist is being installed.

13. A malicious application identification device, characterized in that, The device includes: a data acquisition module, a connection graph generation module, and an application acquisition module, wherein... The data acquisition module is used to acquire installation data for multiple applications; The connection graph generation module is used to generate a connection graph corresponding to the installation relationship between the multiple applications based on the installation data. The connection graph includes nodes corresponding to each application and edges formed by directed connecting lines between nodes. The edges are used to represent the installation relationship. The application acquisition module is used to acquire a target application from the plurality of applications based on the connection graph. The target application is considered a malicious application among the plurality of applications. The installation relationship between the target application and other applications in the plurality of applications satisfies a preset relationship condition. The preset relationship condition includes: the number of other applications installed by the application as an installation channel is greater than a preset number of applications; the length of the link from which the application is the starting point in the connection graph is greater than the target length; or the out-degree of the application satisfies a preset out-degree condition. The out-degree is the number of outgoing edges of the node corresponding to the application.

14. A computer device, characterized in that, include: One or more processors; Memory; One or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the one or more processors, the one or more applications being configured to perform the method as described in any one of claims 1-12.

15. A computer-readable storage medium, characterized in that, The computer-readable storage medium contains program code that can be invoked by a processor to execute the method as described in any one of claims 1-12.

Citation Information

Patent Citations

  • Data mining method and device, computer equipment and storage medium

    CN112948469A

  • Identifying device, identifying method and identifying program

    US20170223040A1