Application risk detection method and device, storage medium and electronic device
By judging dynamic piles during application execution and using Hook technology for code specification abnormality detection, the risk problems caused by dynamic piles during application execution are solved in the prior art that cannot be effectively detected and solved, and automated risk detection and prompts are realized, saving manpower and time, and ensuring terminal stability.
Patent Information
- Application Number
- CN202111282848.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-01
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2041-11-01
AI Technical Summary
The prior art cannot effectively detect and solve the risk problems caused by dynamic piles during application execution, resulting in a lot of manpower and time required for positioning and repairing, affecting the stability of the terminal.
By determining whether there is a dynamic pile during the application execution process, if it exists, Hook technology is used to find the standard method function name corresponding to the name of each method function from the pre-generated function list, and perform code specification abnormality detection. If it does not match, it is determined that the application has risks.
It realizes that suspicious risks are discovered in advance during application execution, and that by outputting risk warning information, it facilitates technicians to troubleshoot problems. The entire process does not require manual participation, saves manpower and time, and provides a basis for the stability of subsequent terminals.
Smart Images

Figure CN114003906B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of risk detection technology, and more specifically, to a risk detection method and device for an application program, a storage medium, and an electronic device. Background Art
[0002] With the upgrading of terminals, the configuration of terminals is getting higher and higher, and there are more and more applications to realize various functions. At present, terminals usually install many applications to provide users with a more convenient work and life platform. In order to enhance the stability and R&D quality of terminals, many R&D teams introduced static code scanning tools (such as OCLint, infer and godeyes) during the R&D stage, and used different static scanning rules to detect in advance through different channels during the continuous integration stage that applications are difficult to reproduce in daily testing, and are prone to use anomalies, crashes and experience impairment after going online.
[0003] Although the introduction of static code scanning tools can enhance the stability of the terminal to a certain extent, the problems that occur during the execution of the application cannot be solved by static analysis using static code scanning tools, and require the assistance of experienced developers to locate them. Therefore, it not only consumes a lot of manpower and time, but also affects the stability of the subsequent terminals. Summary of the invention
[0004] In view of this, the present invention discloses a risk detection method and device for an application program, a storage medium and an electronic device, so as to implement risk detection of an application program during its execution.
[0005] A risk detection method for an application program, comprising:
[0006] During the execution of the application, determining whether there is a dynamic pile in the application, wherein the dynamic pile includes at least one method function name and a corresponding function pointer address;
[0007] If yes, then searching the pre-generated function list for the standard method function name corresponding to each method function name as the target function name, wherein the function list records all the standard method function names;
[0008] Matching the target function name with the method function name, and performing code standard anomaly detection on the method function name;
[0009] When the target function name does not match the method function name, it is determined that the application has a risk.
[0010] Optionally, also include:
[0011] If not, copying the content corresponding to the application to a newly created page, the memory including the method functions in the application;
[0012] Dynamically injecting the same number of test functions as the method functions in the newly created page into the newly created page;
[0013] Using each of the test functions, modifying the execution permission of the corresponding method function in the newly created page to an executable detection state, and adding a preset risk function detection specification to the corresponding method function;
[0014] After all the test functions are successfully injected into the newly created page, a new function name is generated for each of the injected test functions, and the application is released;
[0015] The new function name and the corresponding function pointer address are bound to the newly created page, and the binding relationship between the new function name and the corresponding function pointer address is used as a dynamic stub of the newly created page.
[0016] Optionally, the process of generating the function list includes:
[0017] Obtain each method function corresponding to the application;
[0018] Using Hook technology and risk function detection specifications, risk functions with risks are detected from all the method functions;
[0019] Searching a method function database for a standard method function corresponding to each risk function, and replacing the risk function with the standard method function;
[0020] The function names of all replaced standard method functions and the function names of all method functions in the application program that do not have risks are summarized as standard method function names to generate the function list.
[0021] Optionally, after determining that the application has a risk when the target function name does not match the method function name, the method further includes:
[0022] Determine the method function name that does not match the target function name as the target risk function name;
[0023] Calling the real address of the target risk function according to the function pointer address corresponding to the target risk function name in the dynamic pile;
[0024] The target risk function is called according to the real address.
[0025] A risk detection device for an application program, comprising:
[0026] A judging unit, used for judging whether there is a dynamic pile in the application during the execution of the application, wherein the dynamic pile includes at least one method function name and a corresponding function pointer address;
[0027] a search unit, configured to search, if the judgment unit determines that the result is yes, a standard method function name corresponding to each method function name from a pre-generated function list as a target function name, wherein the function list records all standard method function names;
[0028] An anomaly detection unit, used to match the target function name with the method function name, and perform code standard anomaly detection on the method function name;
[0029] The risk determination unit is used to determine that the application has a risk when the target function name does not match the method function name.
[0030] Optionally, also include:
[0031] A copy unit, used for copying the content corresponding to the application to a newly created page when the judgment unit judges that it is no, and the memory includes the method function in the application;
[0032] A test function injection unit, used for dynamically injecting into the newly created page the same number of test functions as the method functions in the newly created page;
[0033] A permission modification unit, used to modify the execution permission of the corresponding method function in the newly created page to an executable detection state by using each of the test functions, and to add a preset risk function detection specification to the corresponding method function;
[0034] A function name generating unit, configured to generate a new function name for each of the injected test functions after all the test functions are successfully injected into the newly created page, and release the application;
[0035] The dynamic stub generation unit is used to bind the new function name and the corresponding function pointer address to the newly created page, and use the binding relationship between the new function name and the corresponding function pointer address as the dynamic stub of the newly created page.
[0036] Optionally, also include:
[0037] A function list generating unit, used for generating the function list;
[0038] The function list generating unit is specifically used for:
[0039] Obtain each method function corresponding to the application;
[0040] Using Hook technology and risk function detection specifications, risk functions with risks are detected from all the method functions;
[0041] Searching a method function database for a standard method function corresponding to each risk function, and replacing the risk function with the standard method function;
[0042] The function names of all replaced standard method functions and the function names of all method functions in the application program that do not have risks are summarized as standard method function names to generate the function list.
[0043] Optionally, also include:
[0044] a name determination unit, configured to determine the method function name that does not match the target function name as a target risk function name after the risk determination unit determines that the application has a risk when the target function name does not match the method function name;
[0045] An address calling unit, used to call the real address of the target risk function according to the function pointer address corresponding to the target risk function name in the dynamic pile;
[0046] A function calling unit is used to call the target risk function according to the real address.
[0047] A storage medium stores a computer program, and when the computer program runs on a computer, the computer executes the risk detection method for an application program described above.
[0048] An electronic device comprises: a processor and a memory, wherein a computer program is stored in the memory, and the processor is used to execute the risk detection method of the application program described above by calling the computer program stored in the memory.
[0049] As can be seen from the above technical solution, the present invention discloses a risk detection method and device, storage medium and electronic device for an application program. During the execution of the application program, when it is determined that there is a dynamic pile in the application program, the Hook technology is used to find the target function name corresponding to each method function name in the dynamic pile from the function list that records all the standard method function names, and by matching each target function name with the corresponding method function name, the code specification anomaly detection is performed on each method function name, and when the target function name does not match the method function name, it is determined that the application program has a risk. The present invention detects suspicious risks in the execution of the application program in advance by performing code specification anomaly detection on the method function name, and facilitates technical personnel to troubleshoot problems by outputting risk prompt information. The entire risk detection process does not require manual participation, thereby saving manpower and time, and also provides a basis for subsequent guarantee of the stability of the terminal. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the disclosed drawings without paying creative work.
[0051] Figure 1 A flow chart of a risk detection method for an application disclosed in an embodiment of the present invention;
[0052] Figure 2 A flow chart of a method for generating a function list disclosed in an embodiment of the present invention;
[0053] Figure 3 A flow chart of another risk detection method for an application disclosed in an embodiment of the present invention;
[0054] Figure 4 A risk detection principle diagram of an application disclosed in an embodiment of the present invention;
[0055] Figure 5 A schematic diagram of the structure of a risk detection device for an application disclosed in an embodiment of the present invention. DETAILED DESCRIPTION
[0056] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0057] The embodiment of the present invention discloses a risk detection method and device for an application, a storage medium and an electronic device. During the execution of the application, when it is determined that there is a dynamic pile in the application, the Hook technology is used to find the target function name corresponding to each method function name in the dynamic pile from the function list that records all the standard method function names, and each target function name is matched with the corresponding method function name to perform code specification anomaly detection on each method function name, and when the target function name does not match the method function name, it is determined that the application has a risk. The present invention detects suspicious risks in the execution of the application in advance by performing code specification anomaly detection on the method function name, and outputs risk prompt information to facilitate technical personnel to troubleshoot problems. The entire risk detection process does not require manual participation, thereby saving manpower and time, and also provides a basis for the stability control of subsequent terminals.
[0058] See also Figure 1 , a flow chart of a risk detection method for an application disclosed in an embodiment of the present invention, the method comprising:
[0059] Step S101, during the execution of the application, determine whether there is a dynamic pile in the application, if yes, execute step S102;
[0060] The dynamic stub includes at least one method function name and a corresponding function pointer address.
[0061] A method function is a program or code that can be directly referenced by another program or code. In order to implement risk detection of an application, the present invention modifies the execution behavior of each method function in the application, distinguishes functions with the same name in different classes by constructing new method functions, and saves the function pointer addresses of different method functions to different dynamic piles.
[0062] During the execution of the application, the function of the application is realized by calling the method function in the application code, and each application needs to call a large number of method functions when realizing the corresponding function. In the present embodiment, during the execution of the application, a large number of method functions are called when realizing the corresponding function of the application, so the application can be detected to determine whether there is a dynamic pile in the application.
[0063] Step S102: Find the standard method function name corresponding to each method function name from the pre-generated function list as the target function name;
[0064] In this embodiment, a function list is pre-set, in which all standard method function names are recorded. The so-called standard method function name refers to a method function name in which the method function and the corresponding function pointer address are correct.
[0065] Specifically, in practical applications, the Hook technology can be used to find the target function name corresponding to each method function name from a pre-generated function list.
[0066] Hook is a system mechanism for "interrupting" commands provided in computer systems. It is translated into Chinese as "hook" or "hook". After a specific system event is hooked, once the hooked event occurs, the program that hooks the event will receive a system notification, and the program can respond to the event immediately.
[0067] In this embodiment, by adopting the Hook technology, the corresponding target function name can be quickly located from the function list for the method function name currently called by the application.
[0068] Step S103: Match the target function name with the method function name, and perform code standard anomaly detection on the method function name;
[0069] Since all standard method function names are recorded in the function list, by matching the target function name with the method function name in the dynamic stub, it can be determined whether the method function name has any code standard exceptions.
[0070] In this embodiment, through Hook technology, each time the application executes a method function, the pre-established code specifications are used to detect risky codes, and the target function name (i.e., the standard method function name) is matched with the method function name in the dynamic stub to determine whether the method function name meets the risk function range. For example, the "Code Specification" defines the function name with the lowercase camel case definition rule: clickButtonAction(). If the developer writes ClickButtonAction() in the code, it will be judged as an exception. Or, if the "Code Specification" defines that the +(void)load() method cannot be written in the function, if +(void)load() is detected in the developer's code, it will be judged as an exception.
[0071] The code specification in this embodiment refers to the coding specification pre-customized by the R&D team, and "anomaly detection" refers to whether the code written by the developer complies with the pre-customized coding specification.
[0072] Step S104: When the target function name does not match the method function name, it is determined that the application has a risk.
[0073] In actual applications, when it is determined that an application has risks, relevant technical personnel can be alerted by determining that the application has risks.
[0074] When the method function name does not match the corresponding target function name, it is determined that there is an exception in the method function corresponding to the method function name. At this time, it can be determined that there is a risk in the application.
[0075] It should be noted that for each web page browsed by the application, Figure 1 The risk detection method shown in the embodiment performs risk detection on the application.
[0076] In summary, the present invention discloses a risk detection method for an application program. During the execution of the application program, when it is determined that there is a dynamic pile in the application program, the Hook technology is used to find the target function name corresponding to each method function name in the dynamic pile from the function list that records all the standard method function names, and each target function name is matched with the corresponding method function name to perform code specification anomaly detection on each method function name, and when the target function name does not match the method function name, it is determined that the application program has a risk. The present invention detects suspicious risks in the execution of the application program in advance by performing code specification anomaly detection on the method function name, and facilitates technical personnel to troubleshoot problems by outputting risk prompt information. The entire risk detection process does not require manual participation, thereby saving manpower and time, and also provides a basis for the stability control of subsequent terminals.
[0077] To further optimize the above embodiment, see Figure 2 , a flow chart of a method for generating a function list disclosed in an embodiment of the present invention, the method comprising:
[0078] Step S201, obtaining each method function corresponding to the application;
[0079] During the execution of an application, the application implements the function of the application by calling the method functions in the application code. Each application needs to call a large number of method functions when implementing the corresponding function. In this embodiment, all the method functions of the application can be obtained. In actual applications, some method functions of the application can be obtained according to actual needs, for example, all method functions of the application that are prone to exceptions can be obtained, or method functions of the application that are used more frequently can be obtained. The specific method functions depend on actual needs and are not limited in the present invention.
[0080] Step S202: Using the Hook technology and risk function detection specification, detect the risk functions with risks from all method functions;
[0081] Among them, the risk function detection specification may include: code specification protocol and function detection rule code. In practical applications, the risk function detection specification may be set according to difficult problems such as multi-threaded interaction, UI (User Interface) main thread drawing, IO (Input / Output) reading and writing jams, etc. The specific content of the risk function detection specification may be determined according to actual needs, and the present invention is not limited here.
[0082] Step S203: Search the method function database for the standard method function corresponding to each risk function, and replace the risk function with the standard method function;
[0083] In practical applications, all standard method functions can be stored in the database in advance. The so-called standard method function refers to the method function with the correct method function name and the corresponding function pointer address. In this way, when a method function is determined to be a risky function, the corresponding target method function can be found in the database for replacement.
[0084] The method function database in this embodiment is: a storage container for storing all standard method function sets collected previously, which can be understood as a data table. After the application is started, it collects the executed method functions step by step according to the user operation steps.
[0085] Step S204: The function names of all replaced standard method functions and the function names of all method functions without risks in the application program are summarized as standard method function names to generate a function list.
[0086] Since the function list records all the standard method function names of the application, the risk detection of the application can be performed by matching the method function names in the dynamic pile with the method function names of the standard method functions in the function list. It can be seen from this that the present invention realizes the risk detection of the application by adding dynamic piles in the web page of the application. Therefore, when the dynamic pile is not added to the web page of the application, it is necessary to add dynamic piles to the web page without adding dynamic piles.
[0087] Therefore, to further optimize Figure 1 The embodiment shown, see Figure 3 , another embodiment of the present invention discloses a flow chart of a risk detection method for an application, the method comprising:
[0088] Step S301, during the execution of the application, determine whether there is a dynamic pile in the application, if not, execute step S302;
[0089] Step S302, copy the content corresponding to the application to a new page;
[0090] The content includes method functions in the application.
[0091] When it is determined that there is no dynamic stub for the application, this embodiment will copy the content corresponding to the application without stub to a newly created page, so that the dynamic stub can be added to the newly created web page later.
[0092] Step S303, dynamically injecting the same number of test functions as the method functions in the newly created page into the newly created page;
[0093] Since the content corresponding to the application is copied to the newly created web page, the method function in the newly created web page is the same as the method function in the application. To add a dynamic stub in the newly created web page, the present invention first injects a test function that is the same as the method function into the newly created web page.
[0094] In this embodiment, dynamic refers to that properties such as other functions, methods, parameters, etc. are uncertain, so different parameter data corresponding to different results may be generated according to the current page or usage environment.
[0095] Injection: refers to inserting the different parameter data generated above into certain locations of the specified code, function, or method according to the specified logic or rules, thereby changing the original logic and execution effect.
[0096] Step S304: using each test function, modify the execution permission of the corresponding method function in the new page to an executable detection state, and add a risk function detection specification for the corresponding method function;
[0097] Among them, the risk function detection specification may include: code specification protocol and function detection rule code. In practical applications, the risk function detection specification may be set according to difficult problems such as multi-threaded interaction, UI (User Interface) main thread drawing, IO (Input / Output) reading and writing jams, etc. The specific content of the risk function detection specification may be determined according to actual needs, and the present invention is not limited here.
[0098] Execution permission means that all functions in the page can be detected. This embodiment predefines a whitelist. The functions in the whitelist all comply with the protocol specifications. Only if the method function is a function in the whitelist, the method function has execution permission; or if the method function is a commonly used general function, the method function has execution permission.
[0099] "Risk": refers to a set of items that are often overlooked through years of accumulated experience and team norms. This item is considered a risk.
[0100] "Risk function detection specifications" refer to standard coding specifications prepared in advance by R&D personnel. If the code written by the R&D personnel does not comply with the standard coding specifications, the written function will be considered a risk function.
[0101] Step S305: after all the test functions are successfully injected into the newly created page, a new function name is generated for each of the injected test functions, and the application is released;
[0102] Step S306: Bind the new function name and the corresponding function pointer address to the newly created page, and use the binding relationship between the new function name and the corresponding function pointer address as the dynamic stub of the newly created page.
[0103] Specifically, through a series of operations such as collecting executed method functions, function risk detection, and matching the method function names in the dynamic pile with the method function names of the standard method functions in the function list, the generated new function name and the corresponding function pointer address are bound to the newly created page to be detected, and the correspondence between the function and the page is obtained. The correspondence is encapsulated to obtain the pile information, and the pile information is bound to the page as a dynamic pile. In this way, when the program is executed, the execution function that needs to be detected can be obtained through multiple conditions such as dynamic piles and pages.
[0104] In this embodiment, binding can be understood as mapping or association, which is a public relation table established for the function pointer and the page name, and the function pointer address is associated with the newly created page through the public relation table.
[0105] In this embodiment, the "dynamic" in the "dynamic pile" means that each time the application is run, different piles will be generated during the run time according to different parameters and environmental white energy factors.
[0106] Since the content corresponding to the application without dynamic stubs has been copied to the newly created page, and dynamic stubs have been added to the newly created page, during the execution of the application, the newly created page is directly used Figure 1 The illustrated embodiment performs risk detection, thereby realizing risk detection of the application program.
[0107] Figure 1 In the illustrated embodiment, when the method function name does not match the corresponding target function name, it can be determined that the method function corresponding to the method function name has an exception. Although the method function exception may cause risks to the application, in actual applications, the method function with an exception does not necessarily affect the normal operation of the application, and it can also be called and executed.
[0108] Therefore, in Figure 1Based on the embodiment shown, after step S104, the following may also be included:
[0109] The method function name that does not match the target function name is determined as the target risk function name;
[0110] According to the function pointer address corresponding to the target risk function name in the dynamic pile, call the real address of the target risk function;
[0111] The target risk function is called according to the real address.
[0112] Among them, the real address of the target risk function, that is, the real address of the method function corresponding to the method function name that does not match the target function name in the application.
[0113] It should be noted that function call is the process of underlying code executing method. In the regular execution process, functional code and logic are run. If the function effect reaches the expected, it is considered a normal function. The present invention summarizes some risk functions that are easily overlooked through a large amount of research and development experience. If functions are implemented in these functions that may have risks, the abnormality of the functions will increase. If you only look at the code, you cannot really determine the existence of risks, because the code will have many conditional branches to execute different functions. Therefore, in the process of underlying code executing method, the real address in the application is obtained, and then the real execution code in the function is obtained according to these real addresses to detect whether the function has risks.
[0114] To facilitate understanding of the risk detection process of the application disclosed in the present invention, see Figure 4 , a risk detection principle diagram of an application disclosed in an embodiment of the present invention, the application in the process of caller execution is detected to determine whether there is a dynamic pile in the application, if there is a dynamic pile, the application is intercepted to the dynamic pile represented by the executable code segment ( Figure 4stub in the dynamic pile), using Hook technology, find the target function name corresponding to each method function name in the dynamic pile from the function list, match the target function name with the method function name, perform code specification anomaly detection on the method function, when the target function name does not match the method function name, determine the method function corresponding to the method function name that does not match the target function name as the target risk function Func, determine that the application is at risk, and report the prompt information to the server. From the data segment corresponding to the offset of the dynamic pile, obtain the real address of the original Func in the writable data segment, and call Func according to the real address. Among them, the data segment corresponding to the offset of the dynamic pile refers to: when the device adopts the Hook technology, the real address of Func is changed. In order to allow the application to continue to execute normally, the real address of the original Func is also saved in the label of the dynamic pile, so that when the application executes the specified function corresponding to the real address of the original Func, it can perform related operations normally.
[0115] Corresponding to the above method embodiment, the present invention also discloses a risk detection device for an application program.
[0116] See also Figure 5 , a schematic diagram of a structure of a risk detection device for an application disclosed in an embodiment of the present invention, the device comprising:
[0117] A judging unit 401 is used to judge whether there is a dynamic pile in the application during the execution of the application;
[0118] The dynamic stub includes at least one method function name and a corresponding function pointer address.
[0119] A searching unit 402 is used for, when the judging unit judges that it is yes, using the Hook technology to search for the standard method function name corresponding to each method function name from the pre-generated function list as the target function name, wherein the function list records all the standard method function names;
[0120] In this embodiment, a function list is pre-set, in which all standard method function names are recorded. The so-called standard method function name refers to a method function name in which the method function and the corresponding function pointer address are correct.
[0121] An anomaly detection unit 403 is used to match the target function name with the method function name and perform code standard anomaly detection on the method function name;
[0122] Since all standard method function names are recorded in the function list, by matching the target function name with the method function name in the dynamic stub, it can be determined whether the method function name has any code standard exceptions.
[0123] The risk determination unit 404 is configured to determine that the application has a risk when the target function name does not match the method function name.
[0124] In summary, the present invention discloses a risk detection device for an application program. During the execution of the application program, when it is determined that there is a dynamic pile in the application program, the Hook technology is used to find the target function name corresponding to each method function name in the dynamic pile from the function list that records all the standard method function names, and each target function name is matched with the corresponding method function name to perform code specification anomaly detection on each method function name, and when the target function name does not match the method function name, it is determined that the application program has a risk. The present invention detects suspicious risks in the execution of the application program in advance by performing code specification anomaly detection on the method function name, and outputs risk prompt information to facilitate technical personnel to troubleshoot problems. The entire risk detection process does not require manual participation, thereby saving manpower and time, and also provides a basis for the stability control of subsequent terminals.
[0125] The present invention implements risk detection of an application by adding a dynamic stake in a web page of the application. Therefore, when a dynamic stake is not added to a web page of the application, a dynamic stake needs to be added to the web page without the dynamic stake.
[0126] Therefore, to further optimize Figure 5 In the embodiment shown, the risk detection device may further include:
[0127] A copy unit, used for copying the content corresponding to the application to a newly created page when the judgment unit 401 judges that it is no, and the memory includes the method function in the application;
[0128] A test function injection unit, used for dynamically injecting into the newly created page the same number of test functions as the method functions in the newly created page;
[0129] A permission modification unit, used to modify the execution permission of the corresponding method function in the newly created page to an executable detection state by using each of the test functions, and to add a preset risk function detection specification to the corresponding method function;
[0130] A function name generating unit, configured to generate a new function name for each of the injected test functions after all the test functions are successfully injected into the newly created page, and release the application;
[0131] The dynamic stub generation unit is used to bind the new function name and the corresponding function pointer address to the newly created page, and use the binding relationship between the new function name and the corresponding function pointer address as the dynamic stub of the newly created page.
[0132] Among them, the risk function detection specification may include: code specification protocol and function detection rule code. In practical applications, the risk function detection specification may be set according to difficult problems such as multi-threaded interaction, UI (User Interface) main thread drawing, IO (Input / Output) reading and writing jams, etc. The specific content of the risk function detection specification may be determined according to actual needs, and the present invention is not limited here.
[0133] Since the content corresponding to the application without dynamic stubs has been copied to the newly created page, and dynamic stubs have been added to the newly created page, during the execution of the application, the newly created page is directly used Figure 1 The illustrated embodiment performs risk detection, thereby realizing risk detection of the application program.
[0134] To further optimize Figure 5 In the embodiment shown, the risk detection device may further include:
[0135] A function list generating unit, used for generating a function list;
[0136] The function list generating unit is specifically used for:
[0137] Obtain each method function corresponding to the application;
[0138] Using Hook technology and risk function detection specifications, risk functions with risks are detected from all the method functions;
[0139] Searching a method function database for a standard method function corresponding to each risk function, and replacing the risk function with the standard method function;
[0140] The function names of all replaced standard method functions and the function names of all method functions in the application program that do not have risks are summarized as standard method function names to generate the function list.
[0141] It should be noted that during the execution of an application, the application implements the function of the application by calling the method functions in the application code. Each application needs to call a large number of method functions when implementing the corresponding function. In this embodiment, all the method functions of the application can be obtained. In actual applications, some method functions of the application can be obtained according to actual needs, for example, all method functions of the application that are prone to exceptions can be obtained, or method functions that are used more frequently by the application can be obtained. The specific requirements are determined according to actual needs, and the present invention is not limited here.
[0142] When the method function name does not match the corresponding target function name, it can be determined that the method function corresponding to the method function name has an exception. Although the existence of an exception in a method function will cause risks to the application, in actual applications, the existence of an exception in a method function does not necessarily affect the normal operation of the application, and it can also be called and executed.
[0143] Therefore, the risk monitoring device may also include:
[0144] a name determination unit, configured to determine the method function name that does not match the target function name as a target risk function name after the risk determination unit 404 determines that the application has a risk when the target function name does not match the method function name;
[0145] An address calling unit, used to call the real address of the target risk function according to the function pointer address corresponding to the target risk function name in the dynamic pile;
[0146] A function calling unit is used to call the target risk function according to the real address.
[0147] Among them, the real address of the target risk function, that is, the real address of the method function corresponding to the method function name that does not match the target function name in the application.
[0148] To further optimize the above embodiment, the present invention also discloses a storage medium in which a computer program is stored, and when the computer program is run on a computer, the computer executes the risk detection method for the application program in the above embodiment.
[0149] The present invention also discloses an electronic device, which includes: a processor and a memory, wherein a computer program is stored in the memory, and the processor is used to execute the risk detection method of the application program in the above embodiment by calling the computer program stored in the memory.
[0150] It should be noted that the working principles of the risk monitoring device, storage medium and electronic device when performing risk detection on an application program can be found in the corresponding part of the method embodiment and will not be repeated here.
[0151] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0152] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0153] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A risk detection method for an application program, It is characterized in that include: During the execution of the application, determining whether there is a dynamic pile in the application, wherein the dynamic pile includes at least one method function name and a corresponding function pointer address; If yes, then searching the pre-generated function list for the standard method function name corresponding to each method function name as the target function name, wherein the function list records all the standard method function names; Matching the target function name with the method function name, and performing code standard anomaly detection on the method function name; When the target function name does not match the method function name, determining that the application has a risk; If not, copying the content corresponding to the application to a newly created web page, the content including the method functions in the application; Dynamically injecting the same number of test functions as method functions in the newly created webpage into the newly created webpage; Using each of the test functions, modifying the execution permission of the corresponding method function in the newly created webpage to an executable detection state, and adding a preset risk function detection specification to the corresponding method function; After all the test functions are successfully injected into the newly created webpage, a new function name is generated for each of the injected test functions, and the application is released; The new function name and the corresponding function pointer address are bound to the newly created webpage, and the binding relationship between the new function name and the corresponding function pointer address is used as the dynamic stub of the newly created webpage.
2. The risk detection method according to claim 1, It is characterized in that The process of generating the function list includes: Obtain each method function corresponding to the application; Using Hook technology and risk function detection specifications, risk functions with risks are detected from all the method functions; Searching a method function database for a standard method function corresponding to each risk function, and replacing the risk function with the standard method function; The function names of all replaced standard method functions and the function names of all method functions in the application program that do not have risks are summarized as standard method function names to generate the function list.
3. The risk detection method according to claim 1, It is characterized in that After determining that the application has a risk when the target function name does not match the method function name, the method further includes: Determine the method function name that does not match the target function name as the target risk function name; Calling the real address of the target risk function according to the function pointer address corresponding to the target risk function name in the dynamic pile; The target risk function is called according to the real address.
4. A risk detection device for an application program, It is characterized in that include: A judging unit, used for judging whether there is a dynamic pile in the application during the execution of the application, wherein the dynamic pile includes at least one method function name and a corresponding function pointer address; a search unit, configured to search, if the judgment unit determines that the result is yes, a standard method function name corresponding to each method function name from a pre-generated function list as a target function name, wherein the function list records all standard method function names; An anomaly detection unit, used to match the target function name with the method function name, and perform code standard anomaly detection on the method function name; a risk determination unit, configured to determine that the application has a risk when the target function name does not match the method function name; A copying unit, configured to copy the content corresponding to the application to a newly created web page if the judgment by the judging unit is negative, wherein the content includes the method function in the application; A test function injection unit, used for dynamically injecting the same number of test functions as method functions in the newly created webpage into the newly created webpage; A permission modification unit, used to modify the execution permission of the corresponding method function in the newly created webpage to an executable detection state by using each of the test functions, and to add a preset risk function detection specification to the corresponding method function; A function name generating unit, configured to generate a new function name for each of the injected test functions after all the test functions are successfully injected into the newly created webpage, and release the application; The dynamic stub generating unit is used to bind the new function name and the corresponding function pointer address to the newly created web page, and use the binding relationship between the new function name and the corresponding function pointer address as the dynamic stub of the newly created web page.
5. The risk detection device according to claim 4, It is characterized in that Also includes: A function list generating unit, used for generating the function list; The function list generating unit is specifically used for: Obtain each method function corresponding to the application; Using Hook technology and risk function detection specifications, risk functions with risks are detected from all the method functions; Searching a method function database for a standard method function corresponding to each risk function, and replacing the risk function with the standard method function; The function names of all replaced standard method functions and the function names of all method functions in the application program that do not have risks are summarized as standard method function names to generate the function list.
6. The risk detection device according to claim 4, It is characterized in that Also includes: a name determination unit, configured to determine the method function name that does not match the target function name as a target risk function name after the risk determination unit determines that the application has a risk when the target function name does not match the method function name; An address calling unit, used to call the real address of the target risk function according to the function pointer address corresponding to the target risk function name in the dynamic pile; A function calling unit is used to call the target risk function according to the real address.
7. A storage medium, It is characterized in that The storage medium stores a computer program, and when the computer program runs on a computer, the computer executes the risk detection method for an application program according to any one of claims 1 to 3.
8. An electronic device, It is characterized in that The electronic device comprises: a processor and a memory, wherein a computer program is stored in the memory, and the processor is used to execute the risk detection method for the application program according to any one of claims 1 to 3 by calling the computer program stored in the memory.
Citation Information
Patent Citations
Rule-based JavaScript security testing method
CN106055980A