Front-end process killing method, device, equipment and storage medium

By obtaining and analyzing the activity information of front-end processes in the Android system, judging and closing the malicious keep-alive process, the problem of inability to effectively detect front-end processes in the existing technology is solved, and the protection of user rights and improvement of equipment performance is achieved.

CN113918933BActive Publication Date: 2025-06-24DOUYIN VISION CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111130175.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-26
Publication Date
2025-06-24
Estimated Expiration
2041-09-26

AI Technical Summary

Technical Problem

The existing technology cannot effectively detect and kill malicious maintenance behaviors of front-end processes in Android systems, resulting in users facing problems such as damage to tariffs, privacy leakage, rapid battery consumption and mobile phone lag.

Method used

By obtaining the activity information of the front-end process of the second operating system, the pixel size of the active view is calculated, and whether it is a keep-alive process is determined based on the preset pixel threshold. If so, the process is closed.

Benefits of technology

It has realized the investigation and killing of malicious maintenance behaviors of front-end processes, protecting users' rights and interests, and preventing waste of tariffs, privacy leakage and equipment performance degradation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113918933B_ABST
    Figure CN113918933B_ABST
Patent Text Reader

Abstract

The present invention provides a method, apparatus, device, and storage medium for killing front-end processes, which are applied to an electronic device. The electronic device includes a first operating system and a second operating system that shares a kernel with the first operating system and is deployed in the first operating system. The method includes: obtaining activity information sent by the activity of the front-end process of the second operating system; obtaining the pixel size of the view of the activity according to the activity information; determining whether the front-end process is a keep-alive process according to the pixel size and a preset pixel threshold; and closing the front-end process when the front-end process is a keep-alive process. The technical solution of the present invention can kill the malicious keep-alive of the front-end process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular, to a method, device, equipment, and storage medium for killing front-end processes. Background Art

[0002] In the related art, various normal interfaces provided by Android for applications to keep application processes resident are becoming a new "umbrella" for malicious application developers. Developers have created a large number of rogue applications by maliciously using Android process keep-alive, which not only brings serious consequences such as damaged user fees and privacy leakage to users, but also causes phenomena such as rapid battery consumption of mobile devices and mobile phone lags, destroying the user experience of using Android devices.

[0003] In some Android applications, some applications will start a front-end activity with a view size of 1 px (pixel) for process keep-alive, and Android will not actively kill the front-end activity. Summary of the Invention

[0004] The present invention provides a method, device, electronic device, and non-transitory computer-readable storage medium for killing front-end processes, which are used to solve the problem in the prior art that front-end processes cannot be killed, and to realize the killing of malicious keep-alive of front-end processes.

[0005] In a first aspect, the present invention provides a method for killing front-end processes, which is applied to an electronic device. The electronic device includes a first operating system and a second operating system that shares a kernel with the first operating system and is deployed in the first operating system. The method includes: obtaining activity information sent by an activity of a front-end process of the second operating system; obtaining the pixel size of a view of the activity according to the activity information; judging whether the front-end process is a keep-alive process according to the pixel size and a preset pixel threshold; and closing the front-end process when the front-end process is a keep-alive process.

[0006] According to the method for killing front-end processes provided by the present invention, the step of judging whether the front-end process is a keep-alive process according to the pixel size and a preset pixel threshold includes: determining that the front-end process is a keep-alive process when the pixel size is less than or equal to the pixel threshold.

[0007] According to the method for killing front-end processes provided by the present invention, the pixel threshold is 1 pixel.

[0008] According to the method for killing front-end processes provided by the present invention, the front-end process is created by the first operating system, and the activity is created by the second operating system.

[0009] According to the present invention, a method for killing front-end processes is provided, where the first operating system and the second operating system share the Linux kernel.

[0010] According to the present invention, a method for killing front-end processes is provided. Closing the front-end process includes: obtaining the process ID of the front-end process; and closing the front-end process according to the process ID.

[0011] In a second aspect, the present invention provides a front-end process killing device applied to an electronic device. The electronic device includes a first operating system and a second operating system that shares a kernel with the first operating system and is deployed in the first operating system. The device includes: a first obtaining unit for obtaining activity information sent by the activity of the front-end process of the second operating system; a second obtaining unit for obtaining the pixel size of the view of the activity according to the activity information; a judging unit for judging whether the front-end process is a keep-alive process according to the pixel size and a preset pixel threshold; and a closing unit for closing the front-end process when the front-end process is a keep-alive process.

[0012] According to the present invention, in the front-end process killing device, the judging unit is further configured to determine that the front-end process is a keep-alive process when the pixel size is less than or equal to the pixel threshold.

[0013] According to the present invention, in the front-end process killing device, the pixel threshold is 1 pixel.

[0014] According to the present invention, in the front-end process killing device, the front-end process is created by the first operating system, and the activity is created by the second operating system.

[0015] According to the present invention, in the front-end process killing device, the first operating system and the second operating system share the Linux kernel.

[0016] According to the present invention, in the front-end process killing device, the closing unit is further configured to obtain the process ID of the front-end process; and close the front-end process according to the process ID.

[0017] In a third aspect, the present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the front-end process killing method as described in any one of the above are implemented.

[0018] In a fourth aspect, the present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the front-end process killing method as described in any one of the above are implemented.

[0019] The front-end process killing method, device, electronic device and non-transitory computer-readable storage medium provided by the present invention can determine whether there is a process for keeping alive according to the active view pixels of the front-end process and the pixel threshold, and kill the process for keeping alive, so as to realize the monitoring of malicious processes for keeping alive of application programs and achieve the purpose of protecting the rights and interests of users. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0021] Figure 1 is one of the flow diagrams of the front-end process killing method provided by the present invention;

[0022] Figure 2 is the second flow diagram of the front-end process killing method provided by the present invention;

[0023] Figure 3 is the structural diagram of the front-end process killing device provided by the present invention;

[0024] Figure 4 is the structural diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] In order to make the purpose, technical solutions and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions of the present invention in combination with the specific embodiments of the present invention and the corresponding drawings. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present invention.

[0026] In the related art, an Android application can start an activity with a view size of 1 pixel at the front end of the operating system to keep alive the front-end process of the application. Due to the system design reasons of Android, the front-end activity is generally not actively killed, which leaves room for malicious process keeping alive of application programs. A large number of applications have realized process keeping alive under Android by starting an activity with a view size of 1 pixel at the front end.

[0027] To solve this problem, the embodiments of the present invention provide a front-end process killing method, device, electronic device and non-transitory computer-readable storage medium.

[0028] The following will, in conjunction with the accompanying drawings, elaborate in detail on the technical solutions provided by various embodiments of the present invention.

[0029] As Figure 1 shown is a flowchart of the front-end process killing method according to an embodiment of the present invention. The method provided by the embodiment of the present invention can be executed by any electronic device with computer processing capabilities, such as various electronic devices like tablet computers and mobile phones.

[0030] In an embodiment of the present invention, a first operating system runs on the electronic device, and a second operating system that shares the kernel with it runs in the first operating system.

[0031] For example, the first operating system as the host and the second operating system deployed in the first operating system share the Linux kernel and are implemented through technologies such as LXC and containerization.

[0032] For example, the first operating system can be various GNU / Linux distributions, such as Ubuntu, Debian, RedHat, etc. It should be noted that the first operating system is not limited to running on a physical machine and can also be an operating system hosted on other operating systems, such as WSL in the Windows system.

[0033] For example, the second operating system can be the Android operating system, covering AndroidOS issued by Google, AOSP, and various derivative systems based on AOSP, such as MIUI, EMUI, One UI, etc.

[0034] As is known to those skilled in the art, there are also various other mobile operating systems based on the Linux Kernel, such as Tizen, HarmonyOS, Meego, etc. as examples of the second operating system, which are equally applicable to the technical solutions of the embodiments of the present invention.

[0035] Although not explicitly described, those skilled in the art can understand that the first operating system and the second operating system can also be the same operating system. For example, in the Android system, another Android operating system is run through container technology.

[0036] As Figure 1 shown, an embodiment of the present invention provides a front-end process killing method, including:

[0037] Step 102, obtaining the activity information sent by the activities of the front-end processes of the second operating system.

[0038] The foreground process is the process that is currently displayed on the screen and interacts with the user. There are very few foreground processes in the system, and this type of process has the greatest impact on the user experience. The foreground process will only be destroyed when the system's memory is so scarce that it is insufficient to maintain the basic interaction with the user. Therefore, the importance of this type of process is the highest. An Activity is a component that can contain a user interface. It can be simply understood that one page corresponds to one Activity, which is mainly used to interact with the user. Activity information refers to the running information of the Activity, which can be passed through the ActivityInfo class.

[0039] Taking the Android system as an example, in an application, an Activity is usually a single screen. An Activity represents a screen that a user can see, and is mainly used to handle the overall work of the application, such as listening for system events, displaying a specified View (view) for the user, starting other Activities, etc. All Activities of an application inherit from the android.app.Activity class, which is a basic class provided by Android. After other Activities inherit this parent class, they implement various functions through the methods of the parent class.

[0040] The ActivityInfo class is an abstract base class used to create a composite activity from a pre-existing Activity object and can be used to pass activity information. The ActivityInfo class contains information about the tracked activity. Its definition is as follows:

[0041] public ref class ActivityInfo sealed

[0042] [System.Runtime.Serialization.DataContract]

[0043] public sealed class ActivityInfo

[0044] [<System.Runtime.Serialization.DataContract>]

[0045] type ActivityInfo=class

[0046] Public NotInheritable Class ActivityInfo

[0047] The inheritance of the ActivityInfo class is: Object -> ActivityInfo, and the attribute is: DataContractAttribute.

[0048] The constructor of the ActivityInfo class is:

[0049] ActivityInfo(String, String, String, String), which represents initializing a new instance of the ActivityInfo class with the specified name, ID, instance ID, and type name.

[0050] The properties of the ActivityInfo class are as follows:

[0051] Id: Gets the ID of the activity.

[0052] InstanceId: Gets the runtime ID of the activity instance.

[0053] Name: Gets the name associated with the activity.

[0054] TypeName: Gets the type name of the activity.

[0055] The methods of the ActivityInfo class include:

[0056] Equals(Object): Determines whether the specified object is equal to the current object (inherited from Object).

[0057] GetHashCode(): Serves as the default hash function (inherited from Object).

[0058] GetType(): Gets the Type of the current instance (inherited from Object).

[0059] MemberwiseClone(): Creates a shallow copy of the current Object (inherited from Object).

[0060] ToString(): Gets the string representation of the ActivityInfo object.

[0061] Step 104, obtain the pixel size of the view of the activity according to the activity information.

[0062] The pixel size of the view of the activity is the pixel size of the display window of the activity. When designing the keep-alive process, generally design the display window of the activity to be transparent. At this time, the display window of the activity is not visible to the naked eye, but can be detected by the operating system.

[0063] Step 106: Determine whether the front-end process is a keep-alive process according to the pixel size and a preset pixel threshold.

[0064] Specifically, in a keep-alive process, generally, the activity size is designed to be 1 pixel, and there is no transparent switching animation. During normal program operation, it is impossible to have an activity with a size of 1 pixel. By setting the pixel threshold to 1 pixel and comparing the size of the current activity with 1 pixel, it is possible to determine whether the current process is a keep-alive process.

[0065] Step 108: If so, close the front-end process.

[0066] Specifically, if the pixel size of the view of the current activity is less than or equal to 1 pixel, the process where the current activity is located is a keep-alive process, and thus this process can be destroyed, that is, closed. If the size of the current activity is greater than 1 pixel, there is no need to process the process where the current activity is located.

[0067] In the technical solution of the embodiment of the present invention, by comparing the pixel size of the activity with the set pixel threshold, and when the pixel size is less than the pixel threshold, it is determined that there is a front-end keep-alive process, and then the front-end keep-alive process can be detected and killed.

[0068] In step 106, if the pixel size is less than or equal to the pixel threshold, it is determined that the front-end process is a keep-alive process.

[0069] In the embodiment of the present invention, the pixel threshold can be 1 pixel, but it is not limited thereto. For example, the pixel threshold can also be 2 pixels.

[0070] In the embodiment of the present invention, taking the first operating system as Linux and the second operating system as Android as an example, the activity is created by Android, and its front-end process is created and managed by Linux.

[0071] In step 108, closing the keep-alive process includes: obtaining the process number of the front-end process; and closing the front-end process according to the process number.

[0072] In the technical solution of the embodiment of the present invention, by monitoring the view size of the front-end activity of the application in the second operating system through the first operating system, if it is found that the pixel of the view is too small, the front-end activity and the process where the activity is located can be killed, thus solving the problem that systems such as Android do not actively kill the front-end activity, and realizing the detection and killing of the front-end malicious keep-alive process.

[0073] Taking Linux and Android as examples, during the running of an Android App, the activities of the front-end process will send their own information to Linux. Linux obtains the activity information of the activity, directly obtains pixel information such as width and height from the info (information) of the activity, and judges the size of the activity based on this pixel information. If the activity is too small, for example, the view size of the activity is 1 pixel, Linux calls the kill method to kill the process where the activity is located.

[0074] Among them, kill is the kill method built in Linux, and its usage can be kill + process ID.

[0075] In the embodiment of the present invention, the first operating system (for example, the Linux system) is responsible for managing the application processes in the second operating system (for example, Android), including creating and destroying processes. The second operating system is responsible for creating and displaying the activities of the application, and sending the activity information to the first operating system. The first operating system can obtain information such as the size of the front-end activity of the application in the second operating system. When the obtained activity information is used to determine that the size of the view of the activity is less than or equal to the set pixel threshold, the kill method can be called to kill the process of the corresponding application.

[0076] When the first operating system is the Linux system and the second operating system is the Android system, as Figure 2 shown, the front-end process killing method of the embodiment of the present invention includes the following steps:

[0077] Step 201, an application in the Android system creates a first activity.

[0078] Step 202, the Android system sends the activity information of the first activity to the Linux system.

[0079] Step 203, the Linux system obtains the pixel size of the view of the first activity according to the received activity information.

[0080] Step 204, the Linux system judges whether there is a process to be kept alive according to the pixel size and the set pixel threshold.

[0081] Step 205, when the Linux system determines that there is a process to be kept alive, it kills the process of the application where the first activity is located.

[0082] Specifically, the Task Manager (ActivityManager) in the Android system can obtain information such as the content of running programs. The role of ActivityManager is to provide an interface for interaction for all running Activities in the system. The main interfaces revolve around information such as running process information, task information, and service information. ActivityManager calls the getRunningServices() function, but it does not implement this function itself. Instead, it calls the getServices() function of the ActivityManagerProxy proxy class. This class is a proxy class of ActivityManagerNative. Both of these classes implement the ActivityManager interface, which is the structure of the proxy pattern. When calling the getServices() function of the ActivityManagerProxy proxy class, it will call the corresponding function in ActivityManagerNative. However, this class also does not truly implement the specific function. Instead, it uses the Binder inter-process communication mechanism to call the getServices() function in ActivityManagerService, where the specific function is implemented.

[0083] All currently running tasks, all processes, and all services can be obtained using ActivityManager. The currently displayed activity can be obtained through ActivityManager.

[0084] All "running" tasks in the system, and the "running" state includes tasks that have been frozen by the system. Moreover, the returned list is sorted in order, which means that the first one must have been run later than the second one. getRunningTasks has an integer parameter indicating the maximum number of elements in the returned list. Then, if we pass 1 as the parameter, the task returned is the currently running task. Then, the top-level activity is obtained from the task, and this activity is the one currently displayed to the user. The process of obtaining the currently displayed activity is shown in the following code:

[0085] ActivityManager am

[0086] =(ActivityManager)getSystemService(ACTIVITY_SERVICE);

[0087] ComponentName cn = am.getRunningTasks(1).get(0).topActivity;

[0088] Log.d("", "pkg:" + cn.getPackageName());

[0089] Log.d("", "cls:" + cn.getClassName());

[0090] Among them, the Android system obtains the package information PackageInfo of the application program, and then can obtain the list of all ActivityInfo in the Manifest.xml. The AndroidManifest.xml file describes the basic characteristics of the application program and each of its components, and it can be used as an interface between the Android system and the application program.

[0091] In step 202, the Android system sends the activity information of the first activity to the Linux system. Specifically, the activity information of the first activity can be sent through socket communication.

[0092] For ease of understanding, the following provides the code of the first activity with a 1-pixel keep-alive process:

[0093]

[0094] As can be seen from this code, the width and height of the first activity are both set to 1 pixel, that is, the pixel size of the first activity is 1 pixel. The pixel size information of the first activity is recorded in the ActivityInfo and sent to the Linux system.

[0095] In step 203, the Linux system parses the activity information and can obtain that the size of the first activity is 1 pixel. In steps 204 and 205, according to the pixel size and pixel threshold of the first activity, it can be determined that the first activity is the activity of the keep-alive process, and the judgment result is yes. In step 205, the Linux system kills the process where the first activity is located.

[0096] The kill command is used to terminate a specified process and is a commonly used command for process management in Unix / Linux. Usually, when we need to terminate a certain process or certain processes, we first use tools such as ps / pidof / pstree / top to obtain the process PID, and then use the kill command to kill the process. Another use of the kill command is to send signals to a specified process or process group, or to determine whether the process with the process ID of PID is still running. For example, many programs use the SIGHUP signal as the trigger condition for re-reading the configuration file.

[0097] Format: kill <pid>8,

[0098] Format: kill-TERM <pid>

[0099] Send the SIGTERM signal to the specified process. If the process does not catch the signal, the process will terminate.

[0100] Format: kill -l

[0101] List all signal names. Only the 9th signal (SIGKILL) can unconditionally terminate a process, and other signals can be ignored by the process. The following are common signals:

[0102] HUP 1 Hangup

[0103] INT 2 Interrupt (same as Ctrl+C)

[0104] QUIT 3 Quit (same as Ctrl+\)

[0105] TERM 15 Terminate

[0106] KILL 9 Force termination

[0107] CONT 18 Continue (opposite to STOP, fg / bg commands)

[0108] STOP 19 Pause (same as Ctrl+Z).

[0109] Format: kill -l <signame>

[0110] Displays the value of the specified signal.

[0111] Format: kill-9 <pid>

[0112] Format: kill-KILL <pid>

[0113] Forcibly kill a specified process and unconditionally terminate the specified process.

[0114] Format: kill% <jobid>

[0115] Format: kill-9% <jobid>

[0116] Kill the specified task (which can be listed using the jobs command).

[0117] The front - end process killing device provided by the present invention will be described below. The front - end process killing device described below can be mutually corresponding and referred to with the front - end process killing method described above.

[0118] As Figure 3 shown, the front - end process killing device provided by an embodiment of the present invention is applied to an electronic device. The electronic device includes a first operating system and a second operating system that shares a kernel with the first operating system and is deployed in the first operating system. The killing device includes:

[0119] A first acquisition unit 302, configured to acquire activity information sent by the activities of the front - end processes of the second operating system.

[0120] A second acquisition unit 304, configured to acquire the pixel size of the view of the activity according to the activity information.

[0121] A judgment unit 306, configured to judge whether the front - end process is a process for keeping alive according to the pixel size and a preset pixel threshold.

[0122] A closing unit 308, configured to close the process for keeping alive when the front - end process is a process for keeping alive.

[0123] In the technical solution of the embodiment of the present invention, the pixel size of the activity is compared with the set pixel threshold, and when the pixel size is less than the pixel threshold, it is determined that there is a front - end process for keeping alive, and then the front - end process for keeping alive can be killed.

[0124] In the embodiment of the present invention, the judgment unit is further configured to determine that the front - end process is a process for keeping alive when the pixel size is less than or equal to the pixel threshold.

[0125] In the embodiment of the present invention, the pixel threshold can be 1 pixel, but is not limited thereto. For example, the pixel threshold can also be 2 pixels.

[0126] In the embodiment of the present invention, the front - end process is created by the first operating system, and the activity is created by the second operating system.

[0127] In the embodiment of the present invention, the first operating system and the second operating system share the Linux kernel.

[0128] The pixel size information of the first activity is recorded in ActivityInfo and sent to the Linux system.

[0129] The Android system sends the activity information of the first activity to the Linux system. Specifically, the Android system can send the activity information of the first activity to the Linux system through socket communication.

[0130] In the embodiment of the present invention, the closing unit is further used to obtain the process ID of the front-end process; and close the front-end process according to the process ID.

[0131] Taking Linux and Android as an example, during the running of Android App, the activity of the front-end process will send its own information to Linux. Linux obtains the activity information, directly obtains pixel information such as width and height from the activity info, and determines the activity size based on the pixel information. If the activity is too small, for example, the view size of the activity is 1 pixel, Linux calls the kill method to kill the process where the activity is located. Kill is a kill method that comes with Linux, and its usage can be kill+process number.

[0132] The front-end process killing device may be located in a Linux system, and the Linux system obtains the pixel size of the view of the first activity according to the received activity information. The Linux system determines whether there is a keep-alive process according to the pixel size and a set pixel threshold. When the Linux system determines that there is a keep-alive process, it kills the process of the application in which the first activity is located.

[0133] Specifically, the Linux system is responsible for managing Android application processes, including creating and destroying processes. Destroying a process means killing or closing a process. Linux can obtain information such as the size of the Android front-end activity. The Android system is responsible for creating and displaying activities and sending activity information to the Linux system.

[0134] When Linux obtains Android activity information and determines that the size of the view of the activity is less than or equal to the set pixel threshold, the kill method can be called to kill the process of the Android application.

[0135] It can be understood that the above-mentioned front-end process killing device can implement the various steps of the front-end process killing method provided in the aforementioned embodiment. The relevant explanations about the front-end process killing method are applicable to the front-end process killing device and will not be repeated here.

[0136] The front-end process killing device of the embodiment of the present invention determines whether there is a keep-alive process based on the active view pixels and pixel threshold of the front-end process, and kills the keep-alive process, which can monitor malicious keep-alive processes of security applications and achieve the purpose of protecting user rights.

[0137] Figure 4 Illustrates a schematic diagram of the physical structure of an electronic device, such as Figure 4 shown. The electronic device may include: a processor 410, a communications interface 420, a memory 430, and a communication bus 440. Among them, the processor 410, the communications interface 420, and the memory 430 complete mutual communication through the communication bus 440. The processor 410 may call logic instructions in the memory 430 to execute a front-end process killing method, and the method includes: being applied to an electronic device, the electronic device includes a first operating system and a second operating system that shares a kernel with the first operating system and is deployed in the first operating system. The method includes: obtaining activity information sent by the activity of the front-end process of the second operating system; obtaining the pixel size of the view of the activity according to the activity information; judging whether the front-end process is a keep-alive process according to the pixel size and a preset pixel threshold; and closing the front-end process when the front-end process is a keep-alive process.

[0138] In addition, when the logic instructions in the above-mentioned memory 430 can be implemented in the form of a software functional unit and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. And the foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs, Read-Only Memories), random access memories (RAMs, Random Access Memories), magnetic disks, or optical discs and other various media that can store program codes.

[0139] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the front-end process killing method provided by each of the above methods. The method includes: being applied to an electronic device, where the electronic device includes a first operating system and a second operating system that shares a kernel with the first operating system and is deployed in the first operating system. The method includes: obtaining activity information sent by the activity of the front-end process of the second operating system; obtaining the pixel size of the view of the activity according to the activity information; judging whether the front-end process is a keep-alive process according to the pixel size and a preset pixel threshold; and closing the front-end process when the front-end process is a keep-alive process.

[0140] In yet another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the front-end process killing method provided by each of the above. The method includes: being applied to an electronic device, where the electronic device includes a first operating system and a second operating system that shares a kernel with the first operating system and is deployed in the first operating system. The method includes: obtaining activity information sent by the activity of the front-end process of the second operating system; obtaining the pixel size of the view of the activity according to the activity information; judging whether the front-end process is a keep-alive process according to the pixel size and a preset pixel threshold; and closing the front-end process when the front-end process is a keep-alive process.

[0141] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative effort.

[0142] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0143] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.< / jobid> < / jobid> < / pid> < / pid> < / signame> < / pid> < / pid>

Claims

1. A front-end process killing method, which is applied to an electronic device. The electronic device includes a first operating system and a second operating system that shares a kernel with the first operating system and is deployed in the first operating system. The method is characterized in that, The method includes: Obtaining the running information sent by the activities of the foreground process of the second operating system; wherein, the foreground process is created by the first operating system, and the activities include components created by the second operating system that contain a user interface and interact with the user; Obtaining the pixel size of the view of the activity according to the running information; Judging whether the foreground process is a process to be kept alive according to the pixel size and a preset pixel threshold; Closing the foreground process when the foreground process is a process to be kept alive.

2. The method according to claim 1, wherein The judging whether the foreground process is a process to be kept alive according to the pixel size and a preset pixel threshold includes: Determining that the foreground process is a process to be kept alive when the pixel size is less than or equal to the pixel threshold.

3. The method according to claim 1, wherein The pixel threshold is 1 pixel.

4. The method according to claim 1, wherein The first operating system and the second operating system share the Linux kernel.

5. The method according to claim 1, wherein The closing the foreground process includes: Obtaining the process number of the foreground process; Closing the foreground process according to the process number.

6. A front-end process killing device is applied to an electronic device. The electronic device includes a first operating system and a second operating system that shares a kernel with the first operating system and is deployed in the first operating system. It is characterized in that The device includes: A first obtaining unit, configured to obtain the running information sent by the activities of the foreground process of the second operating system; wherein, the foreground process is created by the first operating system, and the activities include components created by the second operating system that contain a user interface and interact with the user; A second obtaining unit, configured to obtain the pixel size of the view of the activity according to the running information; A judging unit, configured to judge whether the foreground process is a process to be kept alive according to the pixel size and a preset pixel threshold; A closing unit, configured to close the foreground process when the foreground process is a process to be kept alive.

7. The device according to claim 6, characterized in that, The judging unit is further configured to determine that the foreground process is a process to be kept alive when the pixel size is less than or equal to the pixel threshold.

8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, the steps of the method according to any one of claims 1 to 5 are implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Malware detection method and system

    CN108491722A

  • Malicious file detection method and device, equipment and storage medium

    CN113139176A