Application program detection method, device and electronic device

By obtaining the path vector characteristics of the application and inputting the detection model, using the application behavior knowledge graph, the problem of lack of credibility in the detection of application maliciousness in the prior art is solved, and efficient and reliable detection results are achieved.

CN113849812BActive Publication Date: 2025-05-16GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111057508.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-09
Publication Date
2025-05-16
Estimated Expiration
2041-09-09

AI Technical Summary

Technical Problem

The prior art lacks credibility when detecting whether an application is a malicious application and requires a lot of manpower and material resources to verify, resulting in inefficiency.

Method used

By obtaining the path vector characteristics of the target application, using the pre-constructed application behavior knowledge graph, these characteristics are input into the detection model, obtaining detection results and basis, and improving the credibility of the detection results.

Benefits of technology

This increases the credibility of the test results, avoids the subsequent consumption of a large amount of manpower and material resources for verification, and improves the detection efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113849812B_ABST
    Figure CN113849812B_ABST
Patent Text Reader

Abstract

The embodiments of the present application disclose an application detection method, device, and electronic device. The method includes: obtaining a target application, the target application being the application to be detected; obtaining the path vector features of the target application through a pre-constructed application behavior knowledge graph; inputting the path vector features of the target application into a detection model, and obtaining the detection result of the target application output by the detection model and the basis of the detection result. Through the above-mentioned method, the path vector features of the target application can be obtained through a pre-constructed application behavior knowledge graph, and then the path vector features are input into the detection model to obtain the detection result of the target application and the basis of the detection result, which increases the credibility of the detection result and avoids the need to consume a large amount of manpower and material resources to verify the detection result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of program detection technology, and more specifically, to an application detection method, device and electronic device. Background Art

[0002] In recent years, with the emergence of adversarial detection technologies such as obfuscation and distortion, the number and quality of malicious applications have shown a rapid upward trend. If malware cannot be quickly associated with network security threat events, it may be impossible to make more comprehensive prevention or remediation decisions in a timely manner. In this context, detecting whether an application is malicious has become a research hotspot.

[0003] However, current methods for detecting whether an application is a malicious application usually only give a final conclusion, which lacks credibility. If the conclusion is to be verified, a lot of manpower and material resources will be wasted. Summary of the invention

[0004] In view of the above problems, the present application proposes an application detection method, device and electronic device to improve the above problems.

[0005] In a first aspect, the present application provides an application detection method, which is applied to an electronic device, and the method includes: obtaining a target application, which is an application to be detected; obtaining a path vector feature of the target application through a pre-built application behavior knowledge graph; inputting the path vector feature of the target application into a detection model, and obtaining the detection result of the target application output by the detection model and the basis of the detection result.

[0006] In the second aspect, the present application provides an application detection device that runs on an electronic device, the device comprising: a target acquisition unit, used to acquire a target application, the target application being an application to be detected; a feature acquisition unit, used to acquire the path vector features of the target application through a pre-built application behavior knowledge graph; a result output unit, inputting the path vector features of the target application into a detection model, and acquiring the detection result of the target application output by the detection model and the basis of the detection result.

[0007] In a third aspect, the present application provides an electronic device comprising one or more processors and a memory; one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the above-mentioned method.

[0008] In a fourth aspect, the present application provides a computer-readable storage medium, in which program code is stored, wherein the above method is executed when the program code is run.

[0009] The present application provides an application detection method, device, electronic device, and storage medium. After acquiring the target application, the path vector features of the target application are acquired through a pre-constructed application behavior knowledge graph, the path vector features of the target application are input into a detection model, and the detection result of the target application output by the detection model and the basis of the detection result are acquired. Through the above-mentioned method, the path vector features of the target application can be acquired through a pre-constructed application behavior knowledge graph, and then the path vector features are input into the detection model to acquire the detection result of the target application and the basis of the detection result, thereby increasing the credibility of the detection result and avoiding the need to consume a large amount of manpower and material resources to verify the detection results one by one. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0011] Figure 1 A flow chart of an application detection method proposed in an embodiment of the present application is shown;

[0012] Figure 2 Shows this application Figure 1 A flowchart of an embodiment of S120;

[0013] Figure 3 A flowchart of an application detection method proposed in another embodiment of the present application is shown;

[0014] Figure 4 A flowchart of an application detection method proposed in another embodiment of the present application is shown;

[0015] Figure 5 A schematic diagram of a path vector feature adjacency matrix proposed in this application is shown;

[0016] Figure 6 A flowchart of an application detection method proposed in another embodiment of the present application is shown;

[0017] Figure 7 Shows this application Figure 6A flowchart of an implementation method of S4070;

[0018] Figure 8 Shows this application Figure 7 A flowchart of an implementation method of S4072;

[0019] Fig. 9 A schematic diagram of obtaining path features of an entity pair proposed in the present application is shown;

[0020] Fig.10 A structural block diagram of an application detection device proposed in an embodiment of the present application is shown;

[0021] Fig.11 A structural block diagram of an electronic device proposed in this application is shown;

[0022] Fig.12 It is a storage unit of an embodiment of the present application for storing or carrying a program code for implementing a parameter acquisition method according to an embodiment of the present application. DETAILED DESCRIPTION

[0023] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0024] In recent years, with the emergence of adversarial detection technologies such as obfuscation and distortion, the number and quality of malicious applications have shown a rapid upward trend. If malware cannot be quickly associated with network security threat events, it may be impossible to make more comprehensive prevention or remediation decisions in a timely manner. In this context, detecting whether an application is malicious has become a research hotspot.

[0025] The inventor found in relevant research that the current methods for detecting whether an application is malicious usually only give a final conclusion, and the final conclusion often requires a lot of human intervention to verify and determine. And the manual verification of each suspected malicious application requires installing and running the application, taking screenshots after finding the problematic interface, in order to provide a certain convincing basis. This means that if thousands of malicious applications are to be manually verified one by one, it will consume a lot of manpower and material resources, and if they are not verified, they will lack credibility.

[0026] Therefore, the inventors proposed an application detection method, device, and electronic device in the present application. After obtaining the target application, the path vector features of the target application are obtained through a pre-constructed application behavior knowledge graph, the path vector features of the target application are input into the detection model, and the detection result of the target application output by the detection model and the basis of the detection result are obtained. Through the above method, the path vector features of the target application can be obtained through a pre-constructed application behavior knowledge graph, and then the path vector features are input into the detection model to obtain the detection result of the target application and the basis of the detection result, which increases the credibility of the detection result and avoids the need to consume a lot of manpower and material resources to verify the detection results one by one.

[0027] See also Figure 1 The present application provides an application detection method, which is applied to an electronic device, and the method includes:

[0028] S110: Acquire a target application, where the target application is an application to be detected.

[0029] As a method, the target application can be obtained through an electronic device. For example, when a user jumps from the display interface of application A to application B, if the electronic device detects that application B is not in the system whitelist of the device, the electronic device can use application B as the application target program.

[0030] As another way, the target application can be obtained through the user. For example, when a user wants to download an application that is not used by many people, in order to avoid downloading unsafe applications, the user can enter the program detection interface of the electronic device, select the program as the target application, and enter the name of the target application in the search box of the detection interface.

[0031] S120: Acquire the path vector features of the target application through a pre-built application behavior knowledge graph.

[0032] Among them, the knowledge graph (KG) is essentially a knowledge base (KB) called a semantic network, that is, a knowledge base with a directed graph structure, in which the nodes of the graph can represent entities or concepts, and the edges of the graph can be composed of attributes or relationships and can represent various semantic relationships between entities / concepts. Among them, semantic relationships can be divided into two types: one is property, and the other is relationship. The biggest difference between properties and relationships is that the triple of attributes usually corresponds to an entity, for example:<Justin Bieber,Type,Person> , and the triples in which the relationship is located usually correspond to two entities, for example:<Justin Bieber,PlaceOfBrith,London> .

[0033] The application behavior knowledge graph can describe the knowledge related to application behavior. The application behavior knowledge graph can describe: multiple applications, each application is an entity; the relationship between applications, such as wake-up, interception, etc.; the attributes of applications, such as malicious applications, normal applications, etc.

[0034] Among them, the path vector feature of the target application can reflect the reasoning path formed by the triples in the application behavior knowledge graph. For example, there is a triple in the application behavior knowledge graph: <application A, wake up, application B>, then the path of the triple in the knowledge graph is: application A->wake up->application B.

[0035] like Figure 2 As shown, as a way, the path vector features of the target application are obtained through a pre-built application behavior knowledge graph, including:

[0036] S121: Obtain a path vector feature adjacency matrix through a pre-constructed application behavior knowledge graph, wherein the path vector feature adjacency matrix includes path vector features of all applications in the application behavior knowledge graph.

[0037] S122: Acquire the path vector features of the target application through a pre-constructed path vector feature adjacency matrix.

[0038] S130: Inputting the path vector feature of the target application into a detection model, and obtaining the detection result of the target application output by the detection model and the basis of the detection result.

[0039] Among them, the detection result includes one item from a normal application and a malicious application, and the basis of the detection result includes each path in the path vector feature of the target application and the weight corresponding to each path, and the value of the weight indicates the contribution of the corresponding path to the detection result of the target application.

[0040] Among them, if the weight of the path is greater than 0, it means that the path has contributed to the target application being detected as a malicious application, and the path is used as the basis for detecting the target application as a malicious application; if the weight of the path is less than 0, it means that the path has contributed to the target application being detected as a normal application. It can be understood that if the weight of the path is greater than 0, it can also indicate that the path is a malicious path.

[0041] Through the above method, the possibility of each path of the target application being a malicious path can be intuitively understood through the size of the weight value corresponding to each path.

[0042] Exemplarily, as shown in Table 1, each path in the path vector feature corresponding to the target application A obtained by the detection model and the weight corresponding to each path are as follows:

[0043] Table 1

[0044]

[0045]

[0046] It can be seen from Table 1 that the target application A has multiple paths with weights greater than 0, among which the path corresponding to the weight of 0.956266859 is very likely to be a malicious path. In addition, the target application A can also be judged to be a malicious application by making the sum of the weights of all paths of the target application A greater than 0.

[0047] The present embodiment provides an application detection method, which, after acquiring the target application, acquires the path vector features of the target application through a pre-constructed application behavior knowledge graph, inputs the path vector features of the target application into a detection model, and acquires the detection result of the target application output by the detection model and the basis of the detection result. The above method enables the path vector features of the target application to be acquired through a pre-constructed application behavior knowledge graph, and then the path vector features are input into the detection model to acquire the detection result of the target application and the basis of the detection result, thereby increasing the credibility of the detection result and avoiding the need to consume a large amount of manpower and material resources to verify the detection results one by one.

[0048] See also Figure 3 The present application provides an application detection method, which is applied to an electronic device, and the method includes:

[0049] S210: Acquire multiple application programs and mutual call records between application programs.

[0050] Exemplarily, as shown in Table 2, the mutual call record between applications may include:

[0051] Table 2

[0052]

[0053]

[0054] In Table 2, "callerPkg" is the package name of the caller application, "calledPkg" is the package name of the callee application, "cpn" is the component of the caller that wakes up the callee, and "call_type_(popup_type)" is the nature of the call behavior, such as whether it is intercepted, whether it is an alarm wakeup, etc.

[0055] It should be noted that the mutual call records between applications not only include the four items of "callerPkg", "calledPkg", "cpn", and "call_type_(popup_type)", but can also include, for example: "topPkg": the application that is in the foreground of the electronic device when the call behavior occurs, "user_nums": the number of users who reported the call behavior, "call_nums": the number of times the call occurred on that day, etc.

[0056] S220: Divide the multiple applications into positive samples and negative samples, wherein the applications belonging to the negative samples are malicious applications and correspond to designated labels, and the applications belonging to the positive samples are applications with more users in the system whitelist.

[0057] As a method, the multiple applications can be divided into positive and negative samples by prior knowledge. For example, some applications that have access to malicious advertising SDKs (Software Development Kits) (such as Pangolin Ad Alliance components) can be divided into negative samples, and applications that appear in the system whitelist and have a large number of users can be divided into positive samples.

[0058] As another approach, it can be obtained through some malicious application discrimination models, which are usually representation-based classifiers. Exemplarily, a Graph Neural Network (GNN) can learn the comprehensive features of all nodes in the knowledge graph, including their attribute features and graph structure features, and map them onto a high-dimensional hyperplane, such that points that are more similar in behavior and attributes tend to be mapped to closer positions on the hyperplane.

[0059] It should be noted that after dividing the positive and negative samples, a specified label can be assigned to all negative samples, and this specified label also needs to be added to the application behavior knowledge graph to be constructed. Exemplarily, this specified label can be an "ad_ware" label.

[0060] S230: Generate relationship triples based on the mutual call records between the applications, where the relationship triples represent the mutual relationships between the applications.

[0061] Exemplarily, based on the mutual call records between applications in Table 2, the following relationships can be obtained:

[0062] (1) <Application 1, call_type_(popup_type)1, Application 2>;

[0063] (2) <cpn 1, belongTo, Application 2>.

[0064] S240: Generate attribute triples based on the negative samples and the specified label, where the attribute triples represent the attributes of the negative samples.

[0065] Exemplarily, the negative sample attribute triple can be: <Negative sample 1, is, ad_ware>.

[0066] S250: Construct the application behavior knowledge graph based on the relationship triples and attribute triples.

[0067] Among them, the entities in the application behavior knowledge graph can include multiple entities, and each entity corresponds to an application. For the convenience of using the knowledge graph, the entities can be encoded. Exemplarily, the encoding of the entities can be as shown in Table 3. It can be understood that there can also be multiple semantic relationships (relationships, attributes) in the application behavior knowledge graph. Exemplarily, as shown in Table 4, the semantic relationships can be encoded as follows:

[0068] Table 3

[0069] Entity Encoding entity 0 com.tencent.mm 1 com.tencent.mm.app.WeChatSplashActivity 2 com.android.contacts.activities.RequestPermissionsActivity 3 com.android.incallu 4 com.android.incallui.oppoInCallActivity 5 com.iflytek.speechsuite ... ...

[0070] Table 4

[0071] Semantic Relation Encoding Semantic Relationship 0 callType_R_CallerActivityStartorFinishRecently 1 belongedTo 2 callType_R_CaLlerALlowBackgroundActivityStarts 3 callType_R_CallerIsBoundByForegrounduid 4 callType_R_forbid_AOSP 5 is ... ...

[0072] Through the above encoding, the triples in the application behavior knowledge graph can be represented as: 0 0 0, 1 0 1, 22 0, 3 2 1, 4 4 2, 5 4 1, etc.

[0073] It should be noted that before constructing the application behavior knowledge graph, it is necessary to deduplicate the acquired relationship triples and attribute triples.

[0074] S260: Acquire a target application, where the target application is an application to be detected.

[0075] S270: Acquire the path vector features of the target application through a pre-built application behavior knowledge graph.

[0076] S280: Inputting the path vector feature of the target application into the detection model, and obtaining the detection result of the target application output by the detection model and the basis of the detection result.

[0077] The application detection method provided in this embodiment can obtain the path vector features of the target application through the pre-constructed application behavior knowledge graph through the above method, and then input the path vector features into the detection model to obtain the detection result of the target application and the basis of the detection result, thereby increasing the credibility of the detection result and avoiding the need to consume a lot of manpower and material resources to verify the detection results one by one. In addition, by constructing the application behavior knowledge graph, more potential malicious paths can be mined using the constructed application behavior knowledge graph, thereby improving the ability to detect whether an application is a malicious application.

[0078] See also Figure 4 The present application provides an application detection method, which is applied to an electronic device, and the method comprises:

[0079] S310: Divide the multiple applications into a training set and a test set.

[0080] As one approach, the multiple applications may be randomly divided into training sets and test sets in proportion.

[0081] As another approach, the applications belonging to the positive samples can be divided into a training set and a test set of positive samples in proportion; then the applications belonging to the negative samples can be divided into a training set and a test set of negative samples in the same proportion as the positive samples; finally, the training sets of positive and negative samples are combined into a final training set, and the test sets of positive and negative samples are combined into a final test set.

[0082] It should be noted that the ratio can be determined according to the number of applications obtained. For example, if the number of applications obtained is small, in order to obtain more training data to obtain a more accurate detection model, the ratio can be training set: validation set is 9:1; if the number of applications obtained is large, the ratio can be training set: validation set is 8:2.

[0083] S320: Establish entity pairs corresponding to the multiple applications respectively to obtain multiple entity pairs, wherein the head entity in the entity pair is the corresponding application, and the tail entity is the specified tag.

[0084] S330: Obtain all path features in the application behavior knowledge graph corresponding to each of the multiple entity pairs to obtain multiple path features, wherein each path feature represents a path corresponding to the path feature.

[0085] S340: De-duplicate the multiple path features to obtain de-duplicate path features, and construct a path vector feature adjacency matrix based on the de-duplicate path features, wherein each column of the path vector feature adjacency matrix represents a path feature, and each row of the path vector feature adjacency matrix represents a path vector feature of a pair of entity pairs.

[0086] like Figure 5 As shown, the value of each element in the path vector feature adjacency matrix is ​​0 or 1. For example, in this row of the path vector feature representing the entity pair (head entity 1, tail entity), the element value corresponding to path 1 is 1, indicating that there is such a path feature for the entity pair, and the element value corresponding to path 2 of the entity is 0, indicating that there is no such path feature for the entity pair.

[0087] S350: Obtain a target path vector feature from a path vector feature adjacency matrix, wherein the target path vector feature is a path vector feature corresponding to the training set.

[0088] S360: Input the target path vector feature into the model to be trained to train the model to be trained and obtain a detection model.

[0089] The detection model may be a machine learning classification model. For example, a stochastic gradient descent classifier (SGD Classifier) ​​may be used as the detection model, and a grid search may be used to obtain the best hyperparameters of the detection model.

[0090] S370: Obtain a target application, where the target application is an application to be detected.

[0091] S380: Obtain the path vector features of the target application through a pre-built application behavior knowledge graph.

[0092] S390: Input the path vector feature of the target application into the detection model, and obtain the detection result of the target application output by the detection model and the basis of the detection result.

[0093] The application detection method provided in this embodiment can obtain the path vector features of the target application through the pre-built application behavior knowledge graph through the above method, and then input the path vector features into the detection model to obtain the detection results of the target application and the basis of the detection results, thereby increasing the credibility of the detection results and avoiding the need to consume a lot of manpower and material resources to verify the detection results one by one. In addition, by dividing multiple applications into training sets and test sets, and inputting the path vector features in the training set into the detection model for training, the accuracy of the detection results of the target application can be improved, and further, a more reliable basis for the detection results can be obtained.

[0094] See also Figure 6 The present application provides an application detection method, which is applied to an electronic device, and the method includes:

[0095] S4010: Obtain the call records of multiple applications and between applications.

[0096] S4020: Divide the multiple applications into positive samples and negative samples, wherein the applications belonging to the negative samples are malicious applications and correspond to designated labels, and the applications belonging to the positive samples are applications with more users in the system whitelist.

[0097] S4030: Generate a relationship triplet according to the mutual call records between the applications, wherein the relationship triplet represents the mutual relationship between the applications.

[0098] S4040: Generate an attribute triplet according to the negative sample and the designated label, wherein the attribute triplet represents an attribute of the negative sample.

[0099] S4050: Construct the application behavior knowledge graph according to the relationship triples and attribute triples.

[0100] S4060: Divide multiple applications into training sets and test sets.

[0101] S4070: Obtain path vector features of each of the multiple applications through a pre-constructed application behavior knowledge graph, and construct a path vector feature adjacency matrix based on the path vector features of each of the multiple applications.

[0102] like Figure 7 As shown, as a way, through the application behavior knowledge graph, the path vector features of each of the multiple applications are obtained, and the path vector feature adjacency matrix is ​​constructed based on the path vector features of each of the multiple applications, including:

[0103] S4071: Establish entity pairs corresponding to a plurality of applications respectively to obtain a plurality of entity pairs, wherein the head entity in the entity pair is the corresponding application, and the tail entity is the specified tag.

[0104] S4072: Obtain all path features in the application behavior knowledge graph corresponding to each of the multiple entity pairs to obtain multiple path features, wherein each path feature represents a path corresponding to the path feature.

[0105] Among them, Figure 8 As shown, the specific process of obtaining all path features in the application behavior knowledge graph corresponding to each of the multiple entity pairs and obtaining multiple path features is as follows: S410: Obtain the first subgraph and the second subgraph corresponding to each of the multiple entity pairs through the application behavior knowledge graph, the first subgraph includes all paths in the application behavior knowledge graph with the head entity in the corresponding entity pair as the central node and the path length being the specified path length, the second subgraph includes all paths in the application behavior knowledge graph with the tail entity in the corresponding entity pair as the central node and the path length being the specified path length.

[0106] Among them, the specified path length is the number of hops, and one hop represents a triple. For example, if you want to answer the question "Who are the directors of the movies starring Zhang San?", you can get the answer through a two-hop reasoning path formed by two triples: <Zhang San, starring, movie name 1>, <movie name 1, director, Li Si>.

[0107] As a method, all paths in the first subgraph and the second subgraph that start from the central node and have a path length of a specified path length can be obtained by a random walk.

[0108] As another way, all paths in the first subgraph and the second subgraph that start from the central node and have a path length of a specified path length can be obtained by a breadth first search (BFS).

[0109] Among them, because random walks are unconstrained, it may not be possible to find all path features even after multiple random walks, while using breadth-first search can obtain more path features than random walks.

[0110] It should be noted that the designated path length can be determined based on the data processing capability of the electronic device, wherein the stronger the data processing capability, the longer the corresponding designated path length. Exemplarily, the designated path length of electronic device A is X, and the designated path length of electronic device B is Y. If the data processing capability of electronic device A is stronger than that of electronic device B, the value of X is greater than the value of Y; if the data processing capability of electronic device B is stronger than that of electronic device A, the value of Y is greater than the value of X.

[0111] Furthermore, it should be noted that the designated path length can also be determined based on actual application conditions. For example, when the designated path length is 2 hops, most of the paths that need to be obtained have been covered; when the designated path length is 3 hops, all the paths that need to be obtained have been covered and there are still many paths that are not related to the paths that need to be obtained; when the designated path length is 4 hops, the entire knowledge graph has been covered. In this case, out of comprehensive consideration of the data processing capabilities of the electronic device and obtaining as many paths as possible that need to be obtained, 2 hops can be selected as the designated path length.

[0112] Through the above-mentioned method, the designated path length can be determined based on the data processing capability of the electronic device, thereby improving the applicability and portability of the application detection method proposed in the present application.

[0113] S420: If there are a first path and a second path in the path corresponding to the entity pair, flip the second path to obtain a flipped second path, wherein the first path is a path with the head entity as the center node, the second path is a path with the tail entity as the center node, and the first path and the second path have the same intermediate nodes.

[0114] S430: Connect the flipped second path with the first path to obtain a reference path, wherein the starting point of the reference path is the head entity corresponding to the first path, and the terminal of the reference path is the tail entity corresponding to the second path.

[0115] S440: Remove the starting point and the end point of the reference path to obtain a path feature of the entity pair corresponding to the application behavior knowledge graph.

[0116] For example, Fig. 9 As shown, the head entity 1 is the child of the central node Figure 1 There is a path 1: head entity 1->node A->...->node M->node N, with the tail entity as the child of the central node Figure 2There is a path 2 in the file: tail entity->node B->...->node M->node P. Among them, there is a common intermediate node M between path 1 and path 2, so path 2 needs to be flipped into path 3: node P->node M->...->node B->tail entity, and then path 1 and path 3 are spliced ​​to get path 4: head entity 1->node A->...->node M->...->node B->tail entity. Among them, after removing the starting point and end point of path 4, a path feature of the entity pair (head entity 1, tail entity) can be obtained. Figure 1 Kazuko Figure 2 By traversing all the paths in the , we can get the entity pair (head entity 1, tail entity) in the child Figure 1 Kazuko Figure 2 All path features within range.

[0117] S4073: De-duplicate the multiple path features to obtain de-duplicate path features, and construct a path vector feature adjacency matrix based on the de-duplicate path features, wherein each column of the path vector feature adjacency matrix represents a path feature, and each row of the path vector feature adjacency matrix represents a path vector feature of a pair of entity pairs.

[0118] S4080: Obtain a target path vector feature from a path vector feature adjacency matrix, wherein the target path vector feature is a path vector feature corresponding to the training set.

[0119] S4090: Input the target path vector feature into the model to be trained to train the model to be trained and obtain a detection model.

[0120] S4100: Obtain a target application, where the target application is an application to be detected.

[0121] S4200: Acquire the path vector features of the target application through a pre-built application behavior knowledge graph.

[0122] S4300: Inputting the path vector feature of the target application into a detection model, and obtaining the detection result of the target application output by the detection model and the basis of the detection result.

[0123] The application detection method provided in this embodiment can obtain the path vector features of the target application through the pre-built application behavior knowledge graph through the above method, and then input the path vector features into the detection model to obtain the detection results of the target application and the basis of the detection results, thereby increasing the credibility of the detection results and avoiding the need to consume a lot of manpower and material resources to verify the detection results one by one. In addition, by constructing a path vector feature adjacency matrix, when the path vector features corresponding to each application are needed later, the features can be obtained by simply searching the adjacency matrix, which is very convenient and fast.

[0124] See also Fig.10 , the present application provides an application detection device 600, which runs on an electronic device, and the device 600 includes;

[0125] A target acquisition unit 610 is used to acquire a target application, where the target application is an application to be detected;

[0126] Feature acquisition unit 620: used to acquire the path vector feature of the target application through a pre-built application behavior knowledge graph;

[0127] The result output unit 630 is used to input the path vector feature of the target application into the detection model, and obtain the detection result of the target application output by the detection model and the basis of the detection result;

[0128] Wherein, optionally, the detection result includes one item of a normal application and a malicious application, and the basis of the detection result includes each path in the path vector feature of the target application and the weight corresponding to each path, and the value of the weight indicates the contribution degree of the corresponding path to the detection result of the target application. If the weight of the path is greater than 0, it means that the path has contributed to the detection of the target application as a malicious application, and the path is used as the basis for detecting that the target application is a malicious application; if the weight of the path is less than 0, it means that the path has contributed to the detection of the target application as a normal application.

[0129] Optionally, the feature acquisition unit 620 is specifically used to obtain a path vector feature adjacency matrix through a pre-constructed application behavior knowledge graph, wherein the path vector feature adjacency matrix includes the path vector features of all applications in the application behavior knowledge graph; and obtain the path vector features of the target application through the pre-constructed path vector feature adjacency matrix.

[0130] Wherein, the device 600 further includes:

[0131] The application behavior knowledge graph construction unit 640 is used to obtain multiple applications and mutual call records between applications; divide the multiple applications into positive and negative samples, wherein the applications belonging to the negative samples are malicious applications and correspond to designated labels, and the applications belonging to the positive samples are applications with more users in the system whitelist; generate relationship triples based on the mutual call records between the applications, and the relationship triples represent the relationship between the applications; generate attribute triples based on the negative samples and the designated labels, and the attribute triples represent the attributes of the negative samples; and construct the application behavior knowledge graph based on the relationship triples and attribute triples.

[0132] The detection model training unit 650 is used to divide multiple applications into a training set and a test set; obtain the path vector features of each of the multiple applications through a pre-constructed application behavior knowledge graph, and construct a path vector feature adjacency matrix based on the path vector features of each of the multiple applications; obtain the target path vector features from the path vector feature adjacency matrix, and the target path vector features are the path vector features corresponding to the training set; input the target path vector features into the model to be trained to train the model to be trained and obtain the detection model.

[0133] As a method, the detection model training unit 650 is specifically used to establish entity pairs corresponding to multiple applications to obtain multiple entity pairs, wherein the head entity in the entity pair is the corresponding application, and the tail entity is the specified label; obtain all path features in the application behavior knowledge graph corresponding to each of the multiple entity pairs to obtain multiple path features, wherein each path feature represents a path corresponding to the path feature; deduplicate the multiple path features to obtain deduplicated path features, and construct a path vector feature adjacency matrix based on the deduplicated path features, wherein each column of the path vector feature adjacency matrix represents a path feature, and each row of the path vector feature adjacency matrix represents a path vector feature of a pair of entity pairs.

[0134] As another method, the detection model training unit 650 is specifically used to obtain the first subgraph and the second subgraph corresponding to each of the multiple entity pairs through the application behavior knowledge graph, wherein the first subgraph includes all paths in the application behavior knowledge graph with the head entity in the corresponding entity pair as the central node and the path length being the specified path length, and the second subgraph includes all paths in the application behavior knowledge graph with the tail entity in the corresponding entity pair as the central node and the path length being the specified path length; if there are a first path and a second path in the path corresponding to the entity pair, then flip the second path to obtain a flipped second path, wherein the first path is a path with the head entity as the central node, the second path is a path with the tail entity as the central node, and the first path and the second path have the same intermediate nodes; connect the flipped second path with the first path to obtain a reference path, wherein the starting point of the reference path is the head entity corresponding to the first path, and the terminal of the reference path is the tail entity corresponding to the second path; remove the starting point and the end point of the reference path to obtain a path feature corresponding to the entity pair in the application behavior knowledge graph.

[0135] Among them, optionally, the detection model training unit 650 is specifically used to determine the designated path length based on the data processing capability of the electronic device, wherein the stronger the data processing capability, the longer the corresponding designated path length.

[0136] The present application provides an application detection device, which runs on an electronic device. After acquiring a target application, the path vector features of the target application are acquired through a pre-constructed application behavior knowledge graph, the path vector features of the target application are input into a detection model, and the detection result of the target application output by the detection model and the basis of the detection result are acquired. Through the above-mentioned method, the path vector features of the target application can be acquired through a pre-constructed application behavior knowledge graph, and then the path vector features are input into the detection model to acquire the detection result of the target application and the basis of the detection result, thereby increasing the credibility of the detection result and avoiding the need to consume a large amount of manpower and material resources to verify the detection results one by one.

[0137] See also Fig.11 Based on the above-mentioned application detection method and device, the embodiment of the present application also provides another electronic device 100 that can execute the above-mentioned terminal control method. The electronic device 100 includes one or more (only one is shown in the figure) processors 102 and a memory 104 coupled to each other. The memory 104 stores a program that can execute the content of the above-mentioned embodiment, and the processor 102 can execute the program stored in the memory 104.

[0138] Among them, the processor 102 may include one or more processing cores. The processor 102 uses various interfaces and lines to connect various parts of the entire electronic device 100, and executes various functions and processes data of the electronic device 100 by running or executing instructions, programs, code sets or instruction sets stored in the memory 104, and calling data stored in the memory 104. Optionally, the processor 102 can be implemented in at least one hardware form of digital signal processing (Digital Signal Processing, DSP), field programmable gate array (Field-Programmable Gate Array, FPGA), and programmable logic array (Programmable Logic Array, PLA). The processor 102 can integrate one or a combination of a central processing unit (Central Processing Unit, CPU), a graphics processing unit (Graphics Processing Unit, GPU) and a modem. Among them, the CPU mainly processes the operating system, user interface and application programs; the GPU is responsible for rendering and drawing display content; and the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 102, but may be implemented separately through a communication chip.

[0139] The memory 104 may include a random access memory (RAM) or a read-only memory (ROM). The memory 104 may be used to store instructions, programs, codes, code sets or instruction sets. The memory 104 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the following various method embodiments, etc. The data storage area may also store data (such as a phone book, audio and video data, chat record data) created by the terminal 100 during use.

[0140] Please refer to Fig.12 , which shows a structural block diagram of a computer-readable storage medium provided in an embodiment of the present application. The computer-readable storage medium 800 stores program codes, which can be called by a processor to execute the method described in the above method embodiment.

[0141] The computer readable storage medium 800 may be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM, a hard disk, or a ROM. Optionally, the computer readable storage medium 800 includes a non-transitory computer-readable storage medium. The computer readable storage medium 800 has storage space for program code 810 that performs any method step in the above method. These program codes can be read from or written to one or more computer program products. The program code 810 can be compressed, for example, in an appropriate form.

[0142] In summary, the present application provides a method, device, and electronic device for generating network access configuration information. After acquiring the target application, the path vector features of the target application are acquired through a pre-constructed application behavior knowledge graph, the path vector features of the target application are input into a detection model, and the detection result of the target application output by the detection model and the basis of the detection result are acquired. Through the above-mentioned method, the path vector features of the target application can be acquired through a pre-constructed application behavior knowledge graph, and then the path vector features are input into the detection model to acquire the detection result of the target application and the basis of the detection result, thereby increasing the credibility of the detection result and avoiding the need to consume a large amount of manpower and material resources to verify the detection results one by one.

[0143] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. An application detection method, characterized in that: Applied to electronic equipment, the method comprises: Obtaining a target application, where the target application is an application to be detected; Acquire the path vector features of the target application through a pre-built application behavior knowledge graph; Inputting the path vector feature of the target application into the detection model, and obtaining the detection result of the target application output by the detection model and the basis of the detection result, The detection model is obtained by training the model to be trained through the target path vector feature, wherein the step of obtaining the target path vector feature includes: dividing multiple applications into a training set and a test set; establishing entity pairs corresponding to each of the multiple applications to obtain multiple entity pairs, wherein the head entity in the entity pair is the corresponding application, and the tail entity is the specified label; obtaining all path features corresponding to the multiple entity pairs in the application behavior knowledge graph to obtain multiple path features, wherein each path feature represents a path corresponding to the path feature; deduplicating the multiple path features to obtain deduplicated path features, and constructing a path vector feature adjacency matrix based on the deduplicated path features, wherein each column of the path vector feature adjacency matrix represents a path feature, and each row of the path vector feature adjacency matrix represents a path vector feature of a pair of entity pairs; obtaining the target path vector feature from the path vector feature adjacency matrix, wherein the target path vector feature is the path vector feature corresponding to the training set.

2. The method according to claim 1, characterized in that The step of obtaining the path vector features of the target application program through the pre-built application program behavior knowledge graph includes: Obtaining a path vector feature adjacency matrix through a pre-built application behavior knowledge graph, wherein the path vector feature adjacency matrix includes path vector features of all applications in the application behavior knowledge graph; The path vector features of the target application are obtained through a pre-constructed path vector feature adjacency matrix.

3. The method according to claim 1, characterized in that Before obtaining the target application, the method further includes: Obtain the call records of multiple applications and between applications; Divide the multiple applications into positive samples and negative samples, wherein the applications belonging to the negative samples are malicious applications and have corresponding designated labels, and the applications belonging to the positive samples are applications with a large number of users in the system whitelist; Generate a relation triple according to the mutual call records between the applications, wherein the relation triple represents the mutual relationship between the applications; Generate an attribute triplet according to the negative sample and the specified label, wherein the attribute triplet represents the attribute of the negative sample; The application behavior knowledge graph is constructed according to the relationship triples and attribute triples.

4. The method according to claim 1, characterized in that: The acquiring of all path features in the application behavior knowledge graph corresponding to each of the plurality of entity pairs, to obtain a plurality of path features, includes: Obtaining a first subgraph and a second subgraph corresponding to each of the plurality of entity pairs through the application behavior knowledge graph, wherein the first subgraph includes all paths in the application behavior knowledge graph that have a head entity in the corresponding entity pair as a central node and a path length of a specified path length, and the second subgraph includes all paths in the application behavior knowledge graph that have a tail entity in the corresponding entity pair as a central node and a path length of a specified path length; If there is a first path and a second path in the path corresponding to the entity pair, flip the second path to obtain a flipped second path, wherein the first path is a path with the head entity as the central node, the second path is a path with the tail entity as the central node, and the first path and the second path have the same intermediate node; Connecting the flipped second path with the first path to obtain a reference path, wherein the starting point of the reference path is the head entity corresponding to the first path, and the terminal of the reference path is the tail entity corresponding to the second path; The starting point and the end point of the reference path are removed to obtain a path feature of the entity pair corresponding to the application behavior knowledge graph.

5. The method according to claim 4, characterized in that The method further comprises: The designated path length is determined based on the data processing capability of the electronic device, wherein the stronger the data processing capability, the longer the corresponding designated path length.

6. The method according to any one of claims 1 to 5, characterized in that: The detection result includes one item of a normal application and a malicious application, the basis of the detection result includes each path in the path vector feature of the target application and the weight corresponding to each path, the value of the weight indicates the contribution degree of the corresponding path to the detection result of the target application, and after inputting the path vector feature of the target application into the detection model and obtaining the detection result of the target application output by the detection model and the basis of the detection result, it also includes: If the weight of the path is greater than 0, it means that the path contributes to the target application being detected as a malicious application, and the path is used as a basis for detecting that the target application is a malicious application; If the weight of a path is less than 0, it means that the path contributes to the target application being detected as a normal application.

7. An application detection device, characterized in that: Running on an electronic device, the device comprises: A target acquisition unit, used to acquire a target application, wherein the target application is an application to be detected; A feature acquisition unit, used to acquire the path vector feature of the target application through a pre-built application behavior knowledge graph; A result output unit, inputting the path vector feature of the target application into a detection model, and obtaining a detection result of the target application output by the detection model and a basis for the detection result; A detection model training unit is used to divide multiple applications into training sets and test sets; establish entity pairs corresponding to each of the multiple applications to obtain multiple entity pairs, wherein the head entity in the entity pair is the corresponding application, and the tail entity is the specified label; obtain all path features in the application behavior knowledge graph corresponding to each of the multiple entity pairs to obtain multiple path features, wherein each path feature represents a path corresponding to the path feature; deduplicate the multiple path features to obtain deduplicated path features, and construct a path vector feature adjacency matrix based on the deduplicated path features, wherein each column of the path vector feature adjacency matrix represents a path feature, and each row of the path vector feature adjacency matrix represents a path vector feature of a pair of entity pairs; obtain a target path vector feature from the path vector feature adjacency matrix, wherein the target path vector feature is the path vector feature corresponding to the training set; input the target path vector feature into the model to be trained to train the model to be trained and obtain a detection model.

8. An electronic device, characterized in that: comprising one or more processors and memory; One or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program code, wherein when the program code is run, the method according to any one of claims 1 to 6 is executed.

Citation Information

Patent Citations

  • API object calling relation graph based method for detecting malicious behavior of application program in Android mobile phone platform

    CN105184160A