Forensic method, system, storage medium and computer device thereof applied to user interaction
By acquiring resource usage and system log information from terminal devices, the application's running status is determined and evidence is generated, solving the problem of difficulty in automatic evidence collection in existing technologies and realizing automatic evidence collection of application-user interactions.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-30
- Publication Date
- 2026-04-14
AI Technical Summary
Existing technologies fail to provide automated evidence collection methods, making it difficult to prove the legality of user interactions with applications on terminal devices.
By obtaining resource usage information and system log information of the device being investigated, it is determined whether the application is running, system stack information and window event information are obtained, and interactive evidence information is generated.
It enables automatic evidence collection of terminal device applications and user interactions, proving the application's running status and interactive behavior during the evidence collection process.
Smart Images

Figure CN113868072B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of application forensics, and in particular to a method, system, storage medium, and computer device for forensics based on application and user interaction. Background Technology
[0002] With the development of society, existing lawsuits often require evidence collection targeting apps (applications) on terminal devices such as mobile phones and tablets. Therefore, it is necessary to prove that the evidence collection process refers to the interaction between the user and a specific application. However, existing technologies do not provide corresponding automatic evidence collection methods, making it difficult to prove the legitimate source.
[0003] In summary, the existing methods have many problems in practical use, so it is necessary to improve them. Summary of the Invention
[0004] To address the aforementioned deficiencies, the present invention aims to provide a method, system, storage medium, and computer device for forensic investigation of applications and user interactions, thereby enabling automatic forensic investigation of applications and user interactions within the device being investigated.
[0005] To achieve the above objectives, the present invention provides a method for obtaining evidence through application-user interaction, comprising:
[0006] The first step is to extract the resource usage information of the device being investigated and the system log information of the application to be verified.
[0007] The judgment step involves determining, based on the resource usage information and the system log information, whether the device being verified is running the application to be verified.
[0008] The second acquisition step involves acquiring the system stack information and window event information of the device being verified if the application to be verified is already running.
[0009] The information generation step involves generating evidence information about the interaction between the application to be verified and the user using the system stack information and / or the window event information.
[0010] Optionally, the first acquisition step includes:
[0011] The information extraction step involves extracting the resource occupancy information from the device being examined.
[0012] The process query step involves querying the process ID (Identity document) of the application to be verified in the resource usage information based on the application package name of the application to be verified.
[0013] The filtering step involves filtering the system log information corresponding to the device being investigated using the process ID.
[0014] The determination step further includes:
[0015] Based on the resource usage information and the system log information corresponding to the system running status of the application to be verified, it is determined whether the device being verified is running the application to be verified.
[0016] Optionally, the second obtaining step includes:
[0017] If the application to be verified is already running, then obtain all the system stack information currently running in the system and the window event information triggered by the current user interface of the system.
[0018] It also provides an evidence collection system for application and user interaction, including:
[0019] The first acquisition unit is used to extract resource usage information of the device being examined and system log information of the application to be verified.
[0020] The judgment unit is used to determine whether the device being verified is running the application to be verified based on the resource usage information and the system log information.
[0021] The second acquisition unit is used to acquire the system stack information and window event information of the device being verified if the application to be verified is already running.
[0022] An information generation unit is used to generate evidence information of the interaction between the application to be verified and the user by using the system stack information and / or the window event information.
[0023] Optionally, the first acquisition unit includes:
[0024] An information extraction subunit is used to extract the resource occupancy information from the device being examined.
[0025] The process query subunit is used to query the process ID of the application to be verified in the resource usage information based on the application package name of the application to be verified.
[0026] The filtering subunit is used to filter out the system log information corresponding to the device being investigated by using the process ID.
[0027] The determination unit is further used for:
[0028] Based on the resource usage information and the system log information corresponding to the system running status of the application to be verified, it is determined whether the device being verified is running the application to be verified.
[0029] Optionally, the second acquisition unit is used for:
[0030] If the application to be verified is already running, then obtain all the system stack information currently running in the system and the window event information triggered by the current user interface of the system.
[0031] Additionally, a storage medium and a computer device are provided, the storage medium being used to store a computer program for performing the above-described forensic methods of application and user interaction.
[0032] The computer device includes a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor. When the processor executes the computer program, it implements the aforementioned evidence collection method for application and user interaction.
[0033] The present invention describes an application-based evidence collection method and system for user interaction. This method extracts resource usage information from the device being examined and system log information from the application to be verified to determine whether the device is running the application. If the application is running, system stack information and window event information from the device are obtained. Evidence of user interaction between the application and the user is generated using the system stack information and / or window event information. During the evidence collection process, system resource usage information, system log information, system stack information, and window event information are saved. Resource usage information and system log information prove that the application is running during the evidence collection process; system stack information and window event information confirm that the application interacts with the user and that the window event information corroborates the evidence. Attached Figure Description
[0034] Figure 1 This is a flowchart illustrating the steps of the evidence collection method for application and user interaction according to a preferred embodiment of the present invention.
[0035] Figure 2 This is a flowchart illustrating the optional steps of the first acquisition step in the application-user interaction evidence collection method according to a preferred embodiment of the present invention.
[0036] Figure 3 This is a flowchart illustrating the optional steps of the information generation step in the application-user interaction evidence collection method according to a preferred embodiment of the present invention.
[0037] Figure 4 This is a schematic block diagram of the structure of the evidence collection system for application and user interaction according to a preferred embodiment of the present invention;
[0038] Figure 5 This is a schematic block diagram of the structure of the first acquisition unit, which is an optional component of the evidence collection system for application and user interaction according to a preferred embodiment of the present invention.
[0039] Figure 6 This is a schematic block diagram of the structure of the information generation unit, which is an optional component of the evidence collection system for application and user interaction according to a preferred embodiment of the present invention. Detailed Implementation
[0040] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0041] It should be noted that references to "an embodiment," "embodiment," "example embodiment," etc., in this specification refer to the described embodiment including specific features, structures, or characteristics, but not every embodiment must include these specific features, structures, or characteristics. Furthermore, such expressions do not refer to the same embodiment. Moreover, when describing specific features, structures, or characteristics in conjunction with embodiments, whether or not explicitly described, it is indicated that incorporating such features, structures, or characteristics into other embodiments is within the knowledge of those skilled in the art.
[0042] Furthermore, certain terms are used in the specification and subsequent claims to refer to specific components or parts. Those skilled in the art will understand that manufacturers may use different names or terms to refer to the same component or part. This specification and subsequent claims do not distinguish components or parts by differences in name, but rather by differences in function. The terms "comprising" and "including" used throughout the specification and subsequent claims are open-ended and should be interpreted as "including but not limited to." Additionally, the term "connection" here includes any direct and indirect electrical connection means. Indirect electrical connection means include connections made through other means.
[0043] Figure 4 The preferred embodiment of the present invention illustrates an application and user interaction-based evidence collection system 100, comprising a first acquisition unit 10, a judgment unit 20, a second acquisition unit 30, and an information generation unit 40, wherein:
[0044] The first acquisition unit 10 is used to extract resource usage information of the device under investigation and system log information of the application to be verified; the judgment unit 20 is used to determine whether the device under investigation is running the application to be verified based on the resource usage information and system log information; the second acquisition unit 30 is used to acquire system stack information and window event information of the device under investigation if the application to be verified is running; the information generation unit 40 is used to generate evidence information of the application to be verified interacting with the user through the system stack information and / or window event information. In this embodiment, the device under investigation is an Android system terminal, which uses system log information and resource usage information to prove that the app under investigation is running during the investigation process; then, evidence information of the corresponding application to be verified is generated through system stack information, or window event information, or system stack information and window event information, and this evidence information is used to prove that the application under investigation is running normally and interacting with the user during the investigation process. In other words, during the evidence collection process, system resource usage information, system log information, system stack information, and window event information are saved. The resource usage information and system log information prove that the application being investigated has been running during the evidence collection process; the system stack information and window event information confirm that the application being investigated interacts with the user and that the window event information can corroborate the evidence collection content.
[0045] See Figure 5 Optionally, the first acquisition unit 10 includes an information extraction subunit 11, a process query subunit 12, and a filtering subunit 13, wherein:
[0046] The information extraction subunit 11 is used to extract resource usage information from the device being verified; the process query subunit 12 is used to query the process ID of the application to be verified in the resource usage information based on the application package name of the application to be verified; the filtering subunit 13 is used to filter out the system log information corresponding to the device being verified by the process ID. Specifically, in this embodiment, the resource usage information of the device being verified (i.e., the Android system terminal, which can be a mobile phone or tablet computer, etc.) can be obtained through the Android system top command (an instruction), and the process ID of the running program can be found in the resource usage information; the corresponding process ID and user ID can be found in the top output information of the Android system by the package name of the application to be verified; and then the system log information can be filtered out from the resource usage information by the process ID. Specifically, the process ID of the application is queried by the top command, and the system log information filtered by the process ID is all the system logs output during the current operation of the application. The system log information can output all the activity information of the application to be verified so as to know the running status of the application to be verified.
[0047] Preferably, the judgment unit 20 is further configured to: determine whether the device under test is running the application to be verified based on the system running status of the application to be verified corresponding to the resource usage information and system log information. By outputting the system running status of the application to be verified based on all activity information of the system log information and resource usage information, it can be proven that the application to be verified is running on the device under test.
[0048] Optionally, the second acquisition unit 30 is used to: if the application to be verified is already running, acquire all the system stack information currently running in the system and the window event information triggered by the current user interface. That is, if the judgment unit 20 proves that the application to be verified is already running, then the second acquisition unit 30 acquires all the system stack information and the window event information triggered by the current user interface. When the system refreshes the screen information, it will call the event method of the interface and return the specific event information through the event object entity.
[0049] See Figure 6 Optionally, the information generation unit 40 includes a parsing subunit 41, a data statistics subunit 42, and a combination generation subunit 43, wherein:
[0050] The parsing subunit 41 is used to parse the system stack information to obtain the page information of the application to be verified currently interacting with the user; the data statistics subunit 42 is used to count the event data triggered by the application to be verified during its operation in the window event information; the combination and generation subunit 43 is used to combine the page information and event data to generate evidence information. By obtaining all the system stack information currently running in the system, the content corresponding to the page information can be parsed to view the page information currently interacting with the user; by counting the events triggered during the application's operation in the system window event statistics, the type of the currently triggered window event, the current system clock time, which application triggered the event, the text information corresponding to the current event, and the window control corresponding to the current event can be obtained.
[0051] Optionally in this embodiment, the information generation unit 40 is further configured to: capture the system stack information and / or the window event information to generate the evidence information in image format. By capturing screenshots of the interface images used to prove the interaction between the application and the user using the system stack information and / or window event information, and saving them as evidence information in image format, evidence information of one or more images can be captured and further packaged and stored.
[0052] Optionally, the information generation unit 40 is further configured to: record the process of acquiring the system stack information and / or the window event information to generate the evidence information. The process of acquiring the system stack information and / or the window event information, such as how the system stack information and / or the window event information are obtained, can be recorded as video. The recorded video data can be stored as evidence information to prove that the application being investigated interacted with the user and that the application being investigated has been running.
[0053] Even better, in other embodiments, a storage unit is also included for storing evidence information in a pre-built database. The pre-built database can be used to store evidence information from at least one application; that is, the database can store evidence information from multiple specified applications and can be distinguished by the user IDs of different applications.
[0054] Figure 1 This invention illustrates a preferred embodiment of an application-based forensic method for user interaction, comprising the following steps:
[0055] S101: Extract resource usage information of the device being tested and system log information of the application to be verified;
[0056] S102: Based on the resource usage information and the system log information, determine whether the device being verified is running the application to be verified;
[0057] S103: If the application to be verified is already running, then obtain the system stack information and window event information of the device being verified;
[0058] S104: Generate evidence information of the interaction between the application to be verified and the user using the system stack information and / or the window event information.
[0059] The device being investigated is an Android system terminal. System log information and resource usage information corroborate that the app being investigated was running during the investigation process. Then, system stack information, window event information, or both are used to generate evidence information for the application to be verified. This evidence information proves that the application was running normally and interacting with the user during the investigation process. Specifically, the system resource usage information, system log information, system stack information, and window event information for each investigation session are saved. Resource usage information and system log information prove that the application was running during the investigation; system stack information and window event information confirm that the application interacted with the user and that the window event information corroborates the evidence.
[0060] See Figure 2 Optionally, step S101 further includes:
[0061] S1011: Extract the resource usage information from the device being examined;
[0062] S1012: Query the process ID of the application to be verified in the resource usage information based on the application package name of the application to be verified;
[0063] S1013: Filter the system log information corresponding to the device under investigation using the process ID. Specifically, the resource usage information of the device under investigation (i.e., the Android system terminal, which can be a mobile phone or tablet, etc.) can be obtained using the Android system's `top` command. The process ID of the running program can be found in the resource usage information. The corresponding process ID and user ID can be found in the `top` output information of the application to be verified using the package name of the application. Then, the system log information can be filtered from the resource usage information using the process ID. Specifically, the process ID of the application can be found using the `top` command. The system log information filtered by the process ID is all the system logs output during the application's current operation. This system log information can output all activity information of the application to be verified to understand its running status.
[0064] Optionally, step S102 further includes: determining whether the device under test is running the application to be verified based on the system running status of the application to be verified corresponding to the resource usage information and system log information. By outputting the system running status of the application to be verified based on all activity information of the system log information and resource usage information, it can be proven that the application to be verified is running on the device under test.
[0065] Optionally, step S103 further includes: if the application to be verified is already running, then obtaining all the system stack information currently running in the system and the window event information triggered by the current user interface of the system. When the system refreshes the screen information, it will call the event method of the interface and return the specific event information through the event object entity.
[0066] See Figure 3 Step S104 includes:
[0067] S1041: Parse the system stack information to obtain the page information of the application to be verified currently interacting with the user;
[0068] S1042: Collect event data triggered by the application to be verified during runtime in the event information of the form;
[0069] S1043: Combine the page information and the event data to generate the evidence information.
[0070] By obtaining all system stack information currently running, the corresponding content of page information can be parsed to view the page information currently interacting with the user; by statistically analyzing the events triggered during application runtime through system window events, it is possible to obtain the type of window event currently triggered, the current system clock time, which application triggered the event, the text information corresponding to the current event, and the window control corresponding to the current event.
[0071] Optionally, step S104 further includes: capturing the system stack information and / or window event information to generate evidence information in image format. By capturing screenshots of interface images used to prove the interaction between the application and the user using the system stack information and / or window event information, and saving them as evidence information in image format, one or more images of evidence information can be captured and further packaged and stored.
[0072] Optionally, step S104 further includes: recording the process of acquiring the system stack information and / or window event information to generate evidence information. The process of acquiring the system stack information and / or window event information, such as how the system stack information and / or window event information are obtained, can be recorded as video. The recorded video data can be stored as evidence information to prove that the application being investigated interacted with the user and that the application being investigated was running.
[0073] In other embodiments, optionally, step S104 may be followed by:
[0074] The storage step involves storing the evidence information in a pre-built data repository. This pre-built data repository can be used to store evidence information from at least one application; that is, it can store evidence information from multiple specified applications and can be distinguished by the user IDs of different applications.
[0075] The present invention also provides a storage medium for storing, for example, Figures 1 to 3 The computer program is a method for obtaining evidence through user interaction. For example, computer program instructions, when executed by a computer, can invoke or provide the methods and / or technical solutions according to this application through the operation of the computer. The program instructions invoking the methods of this application may be stored in a fixed or removable storage medium, and / or transmitted via data streams in broadcast or other signal carrying media, and / or stored in the storage medium of a computer device operating according to the program instructions. Here, one embodiment according to this application includes, as... Figure 4 The computer device of the evidence collection system shown in the application interacts with the user, preferably includes a storage medium for storing computer programs and a processor for executing computer programs, wherein when the computer program is executed by the processor, the computer device is triggered to execute the methods and / or technical solutions based on the foregoing embodiments.
[0076] It should be noted that this application can be implemented in software and / or a combination of software and hardware, for example, using an application-specific integrated circuit (ASIC), a general-purpose computer, or any other similar hardware device. In one embodiment, the software program of this application can be executed by a processor to implement the steps or functions described above. Similarly, the software program of this application (including related data structures) can be stored in a computer-readable recording medium, such as RAM memory, magnetic or optical drives, floppy disks, and similar devices. Furthermore, some steps or functions of this application can be implemented in hardware, for example, as circuitry that works with a processor to perform the various steps or functions.
[0077] The method according to the invention can be implemented on a computer as a computer-implemented method, or in dedicated hardware, or a combination of both. Executable code or portions thereof for the method according to the invention can be stored on a computer program product. Examples of computer program products include memory devices, optical storage devices, integrated circuits, servers, online software, etc. Preferably, the computer program product includes non-transitory program code components stored on a computer-readable medium so as to execute the method according to the invention when the program product is executed on a computer.
[0078] In a preferred embodiment, the computer program includes computer program code components adapted to perform all the steps of the method according to the invention when the computer program is run on a computer. Preferably, the computer program is embodied on a computer-readable medium.
[0079] In summary, the application-user interaction forensics method and system described in this invention extracts resource usage information of the device under investigation and system log information of the application to be verified to determine whether the device under investigation is running the application to be verified. If the application to be verified is running, the system stack information and window event information of the device under investigation are obtained. Evidence information of the interaction between the application to be verified and the user is generated using the system stack information and / or window event information. During the forensics process, system resource usage information, system log information, system stack information, and window event information are saved. Resource usage information and system log information prove that the application under investigation is running during the forensics process; system stack information and window event information confirm that the application under investigation interacts with the user and that the forensics content can be corroborated by window event information.
[0080] Of course, the present invention may have other various embodiments. Without departing from the spirit and essence of the present invention, those skilled in the art can make various corresponding changes and modifications according to the present invention, but these corresponding changes and modifications should all fall within the protection scope of the appended claims.
Claims
1. A method for obtaining evidence through application-user interaction, characterized in that, Including: The first step is to extract the resource usage information of the device being investigated and the system log information of the application to be verified. The judgment step involves determining, based on the resource usage information and the system log information, whether the device being verified is running the application to be verified. The second acquisition step involves acquiring the system stack information and window event information of the device being verified if the application to be verified is already running. The information generation step involves generating evidence information about the interaction between the application to be verified and the user using the system stack information and / or the window event information. The information generation steps include: The parsing step involves parsing the system stack information to obtain the page information of the application to be verified that is currently interacting with the user. The data statistics step involves collecting event data triggered by the application to be verified during runtime from the event information of the form. In conjunction with the generation step, the page information and the event data are combined to generate the evidence information.
2. The method for obtaining evidence of application and user interaction according to claim 1, characterized in that, The first acquisition step includes: The information extraction step involves extracting the resource occupancy information from the device being examined. The process query step involves querying the process ID of the application to be verified in the resource usage information based on the application package name of the application to be verified. The filtering step involves filtering the system log information corresponding to the device being investigated using the process ID.
3. The method for obtaining evidence of application and user interaction according to claim 2, characterized in that, The determination step further includes: Based on the resource usage information and the system log information corresponding to the system running status of the application to be verified, it is determined whether the device being verified is running the application to be verified.
4. The method for obtaining evidence of application and user interaction according to claim 1, characterized in that, The second acquisition step includes: If the application to be verified is already running, then obtain all the system stack information currently running in the system and the window event information triggered by the current user interface of the system.
5. The method for obtaining evidence of application and user interaction according to claim 1, characterized in that, The information generation step further includes: The system stack information and / or the window event information are extracted to generate the evidence information in image format.
6. The method for obtaining evidence of application and user interaction according to claim 1, characterized in that, The information generation step further includes: The process of acquiring the system stack information and / or the form event information is used to generate the evidence information.
7. The method for obtaining evidence of application and user interaction according to claim 1, characterized in that, The information generation step is followed by: The storage step involves storing the evidence information in a pre-built data database.
8. The method for obtaining evidence of application and user interaction according to claim 1, characterized in that, The device being used for evidence collection is an Android system terminal.
9. An evidence collection system that integrates application and user interaction, characterized in that, Including: The first acquisition unit is used to extract resource usage information of the device being examined and system log information of the application to be verified. The judgment unit is used to determine whether the device being verified is running the application to be verified based on the resource usage information and the system log information. The second acquisition unit is used to acquire the system stack information and window event information of the device being verified if the application to be verified is already running. An information generation unit is used to generate evidence information of the interaction between the application to be verified and the user by using the system stack information and / or the window event information; The information generation unit includes: The parsing subunit is used to parse the system stack information to obtain the page information of the application to be verified currently interacting with the user; The data statistics subunit is used to collect event data triggered by the application to be verified during runtime in the event information of the form; The combined generation subunit is used to combine the page information and the event data to generate the evidence information.
10. The evidence collection system for application and user interaction according to claim 9, characterized in that, The first acquisition unit includes: An information extraction subunit is used to extract the resource occupancy information from the device being examined. The process query subunit is used to query the process ID of the application to be verified in the resource usage information based on the application package name of the application to be verified. The filtering subunit is used to filter out the system log information corresponding to the device being investigated by using the process ID.
11. The evidence collection system for application and user interaction according to claim 10, characterized in that, The determination unit is further used for: Based on the resource usage information and the system log information corresponding to the system running status of the application to be verified, it is determined whether the device being verified is running the application to be verified.
12. The evidence collection system for application and user interaction according to claim 9, characterized in that, The second acquisition unit is used for: If the application to be verified is already running, then obtain all the system stack information currently running in the system and the window event information triggered by the current user interface of the system.
13. The evidence collection system for application and user interaction according to claim 9, characterized in that, The information generation unit is further used for: The system stack information and / or the window event information are extracted to generate the evidence information in image format.
14. The evidence collection system for application and user interaction according to claim 9, characterized in that, The information generation unit is further used for: The process of acquiring the system stack information and / or the form event information is used to generate the evidence information.
15. The evidence collection system for application and user interaction according to claim 9, characterized in that, return include: The storage unit stores the evidence information in a pre-built database.
16. The evidence collection system for application and user interaction according to claim 9, characterized in that, The device being used for evidence collection is an Android system terminal.
17. A storage medium, characterized in that, A computer program for storing an evidence-gathering method for performing any one of the application and user interaction methods described in claims 1 to 8.
18. A computer device, characterized in that, The method includes a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor executes the computer program to implement the application and user interaction evidence collection method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Method and device for monitoring quality of application
CN106095660A
Electronic evidence fixing and network evidence obtaining method and system based on memory evidence obtaining and block chain
CN110232645A