Privacy compliance detection method, device, server, terminal and storage medium
Privacy compliance detection parameters are obtained and sent through the server. The client executes the target script and combines the rules to automatically detect the privacy compliance of the APP. This solves the problems of low detection efficiency, difficulty in guaranteeing accuracy and high cost in the existing technology, and achieves efficient and accurate privacy compliance detection.
Patent Information
- Application Number
- CN202210740251.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-27
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2042-06-27
AI Technical Summary
In the prior art, APP privacy compliance detection is inefficient, difficult to guarantee accuracy, and high cost.
Privacy compliance detection parameters are obtained through the server, sent to the client to execute target scripts, simulate user operations, and automatically detect the privacy compliance of the tested application in combination with privacy compliance rules.
It realizes automated privacy compliance inspection of the tested applications in the detection scenario, improves detection efficiency, ensures accuracy and reduces costs.
Smart Images

Figure CN115146309B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the field of computer application technology, and in particular to a privacy compliance detection method, device, server, terminal and storage medium. Background Art
[0002] The privacy compliance testing process for an application (APP) can be understood as the process of checking whether the information obtained or transmitted by the APP during operation complies with relevant privacy compliance policies. Currently, APP privacy compliance testing is mainly achieved through manual methods.
[0003] In the process of realizing the present invention, the inventors discovered that the prior art has the following technical problems: low detection efficiency, difficulty in ensuring detection accuracy, and high detection cost. Summary of the Invention
[0004] The embodiments of the present invention provide a privacy compliance detection method, device, server, terminal and storage medium. By automatically detecting the privacy compliance of the application under test in the detection scenario, it solves the problems of low detection efficiency, difficulty in ensuring detection accuracy and high detection cost in manual detection.
[0005] According to one aspect of the present invention, a privacy compliance detection method is provided, which is applied to a server and may include:
[0006] In response to the privacy compliance detection instruction, obtaining privacy compliance detection parameters, wherein the privacy compliance detection parameters include an application identifier and a scenario parameter;
[0007] Sending the privacy compliance detection parameters to the client, so that the client determines a target script based on the received privacy compliance detection parameters and executes the target script, wherein the target script includes a script for simulating user operations related to the detection scenario on the tested application, the tested application is an application having an application identifier, and the detection scenario is a scenario having scenario parameters;
[0008] Obtain target information and, in combination with privacy compliance rules corresponding to scenario parameters, detect the privacy compliance of the application under test in the detection scenario, wherein the target information includes information involved during the execution of the target script by the detection terminal deployed with the client.
[0009] According to another aspect of the present invention, a privacy compliance detection method is provided, which is applied to a client and may include:
[0010] Receive privacy compliance detection parameters sent by the server, where the privacy compliance detection parameters include application identifier and scenario parameters;
[0011] Determine the target script based on the received privacy compliance detection parameters, execute the target script so that the server can obtain the target information, and detect the privacy compliance of the tested application in the detection scenario in combination with the privacy compliance rules corresponding to the scenario parameters;
[0012] Among them, the target script includes a script for simulating the user's operations related to the detection scenario on the tested application, the tested application is an application with an application identifier, the detection scenario is a scenario with scenario parameters, and the target information includes information involved in the detection terminal deployed with the client during the execution of the target script on the client.
[0013] According to another aspect of the present invention, a privacy compliance detection device is provided, which is configured on a server and may include:
[0014] A privacy compliance detection parameter acquisition module, configured to obtain privacy compliance detection parameters in response to a privacy compliance detection instruction, wherein the privacy compliance detection parameters include an application identifier and scenario parameters;
[0015] a first target script execution module, configured to send privacy compliance detection parameters to a client, so that the client determines a target script based on the received privacy compliance detection parameters and executes the target script, wherein the target script includes a script for simulating user operations on a tested application related to a detection scenario, the tested application being an application having an application identifier, and the detection scenario being a scenario having scenario parameters;
[0016] The privacy compliance detection module is used to obtain target information and, in combination with the privacy compliance rules corresponding to the scenario parameters, detect the privacy compliance of the application under test in the detection scenario. The target information includes information involved during the execution of the target script by the detection terminal deployed with the client.
[0017] According to another aspect of the present invention, a privacy compliance detection device is provided, which is configured on a client and may include:
[0018] A privacy compliance detection parameter receiving module is used to receive privacy compliance detection parameters sent by the server, where the privacy compliance detection parameters include application identifiers and scenario parameters;
[0019] A second target script execution module is configured to determine a target script based on the received privacy compliance detection parameters and execute the target script so that the server obtains the target information and detects the privacy compliance of the tested application in the detection scenario in combination with the privacy compliance rules corresponding to the scenario parameters;
[0020] Among them, the target script includes a script for simulating the user's operations related to the detection scenario on the tested application, the tested application is an application with an application identifier, the detection scenario is a scenario with scenario parameters, and the target information includes information involved in the detection terminal deployed with the client during the execution of the target script on the client.
[0021] According to another aspect of the present invention, a detection server is provided, which may include:
[0022] at least one processor; and
[0023] a memory communicatively connected to at least one processor; wherein,
[0024] The memory stores a computer program that can be executed by at least one processor, and the computer program is executed by at least one processor so that when the at least one processor executes it, the privacy compliance detection method applied to the server provided by any embodiment of the present invention is implemented.
[0025] According to another aspect of the present invention, a detection terminal is provided, which may include:
[0026] at least one processor; and
[0027] a memory communicatively connected to at least one processor; wherein,
[0028] The memory stores a computer program that can be executed by at least one processor. The computer program is executed by at least one processor so that the at least one processor implements the privacy compliance detection method applied to the client provided by any embodiment of the present invention when executing the computer program.
[0029] According to another aspect of the present invention, a computer-readable storage medium is provided, on which computer instructions are stored. The computer instructions are used to enable a processor to implement the privacy compliance detection method provided by any embodiment of the present invention when executed.
[0030] According to the technical solution in the embodiment of the present invention, the server obtains privacy compliance detection parameters including the application identifier of the application under test and the scenario parameters of the detection scenario in response to the privacy compliance detection instruction. The privacy compliance detection parameters can reflect what application is being tested for privacy compliance in what scenario; then, the privacy compliance detection parameters are sent to the client, so that the client determines the target script according to the received privacy compliance detection parameters and executes the target script. The target script is a script for simulating the user's operations related to the detection scenario on the application under test, thereby achieving the effect of automatically simulating the detection scenario; then, the target information involved in the execution of the target script by the detection terminal deployed with the client is obtained, and the privacy compliance of the application under test in the detection scenario is detected in combination with the pre-set privacy compliance rules corresponding to the scenario parameters, thereby achieving the effect of automatically judging privacy compliance. The above technical solution can automatically detect the privacy compliance of the application under test in the detection scenario, thereby improving detection efficiency, ensuring detection accuracy and reducing detection costs.
[0031] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0033] Figure 1 This is a flowchart of a privacy compliance detection method provided according to an embodiment of the present invention;
[0034] Figure 2 is a flowchart of another privacy compliance detection method provided according to an embodiment of the present invention;
[0035] Figure 3 is a timing diagram of another privacy compliance detection method provided according to an embodiment of the present invention;
[0036] Figure 4 This is a structural block diagram of a privacy compliance detection device provided according to an embodiment of the present invention;
[0037] Figure 5 is a structural block diagram of another privacy compliance detection device provided according to an embodiment of the present invention;
[0038] Figure 6It is a structural diagram of a detection server or a detection terminal that implements the privacy compliance detection method of an embodiment of the present invention. DETAILED DESCRIPTION
[0039] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0040] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. The situations of "target", "original", etc. are similar and will not be repeated here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or that are inherent to these processes, methods, products or devices.
[0041] Figure 1 This is a flowchart of a privacy compliance detection method provided in an embodiment of the present invention. This embodiment is applicable to automated detection of the privacy compliance of a tested application in a detection scenario. This method can be performed by a privacy compliance detection device provided in an embodiment of the present invention. This device can be implemented in software and / or hardware and can be integrated into a detection server.
[0042] See also Figure 1 The method of the embodiment of the present invention specifically includes the following steps:
[0043] S110 . In response to the privacy compliance detection instruction, obtain privacy compliance detection parameters, where the privacy compliance detection parameters include an application identifier and scenario parameters.
[0044] Among them, the privacy compliance detection instruction may include an instruction for detecting the privacy compliance of the tested application in the detection scenario. In response to the privacy compliance detection instruction, privacy compliance detection parameters are obtained. The privacy compliance detection parameters may include an application identifier and a scenario parameter. The application identifier may be the identifier of the tested application, and the scenario parameter may be the parameter of the detection scenario. Therefore, the privacy compliance detection parameters can be used to determine which application and in what scenario the privacy compliance is to be detected.
[0045] In actual applications, optionally, the privacy compliance detection instruction can be obtained under the following circumstances: for the front-end corresponding to the server, the user can select the application to be tested (or upload the application installation package of the application to be tested) and the detection scenario on the front-end page displayed on the front-end, and after clicking the detection option, the server receives the privacy compliance detection instruction triggered by the front-end. Optionally, the application identifier can be the package name of the application installation package, specifically, it can be the package name of the application to be tested under the running system of the detection terminal (that is, the terminal with the application to be tested installed) obtained by decompiling the package name of the application installation package uploaded by the user. Optionally, when the running system is the Android system, the server can encapsulate the obtained privacy compliance detection parameters into Android Debug Bridge (adb) commands for application, that is, apply the adb commands as privacy compliance detection parameters, which is very suitable for application scenarios of automated detection.
[0046] S120. Send the privacy compliance detection parameters to the client, so that the client determines the target script based on the received privacy compliance detection parameters and executes the target script, wherein the target script includes a script for simulating the user's operations related to the detection scenario on the tested application, the tested application is an application with an application identifier, and the detection scenario is a scenario with scenario parameters.
[0047] Among them, the privacy compliance detection parameters are sent to the client, so that the client can determine which application and in what scenario the server needs to detect privacy compliance based on the received privacy compliance detection parameters, and then determine which application and scenario-related operations it needs to simulate the user performing. Specifically, because the privacy compliance detection parameters received by the client include application identification and scenario parameters, the target script determined thereby can include a script for simulating the user's operations on the tested application related to the detection scenario, and then simulate the user's performance of the above operations by executing the target script, thereby achieving the effect of automatically operating the tested application according to the detection scenario.
[0048] Exemplarily, the detection scenario may be that user privacy information (i.e., user personal information) cannot be obtained or transmitted before agreeing to the privacy policy; the application under test frequently starts up without informing the user and without the user's consent; after agreeing to the privacy policy, user personal information not stated in the privacy policy cannot be used; and so on. The simulated operations may be before agreeing to the privacy policy, clicking on the button that agrees to the privacy policy, user login, switch push, copying and pasting text, entering user personal information, and so on. Specifically, if the detection scenario is that user personal information cannot be obtained or transmitted before agreeing to the privacy policy, then the simulated operation may be operating the application under test until the consent button appears according to the application page elements; if the detection scenario is that user personal information not stated in the privacy policy cannot be used after agreeing to the privacy policy, then the simulated operation may be to find the consent button on the privacy policy page and click it; if the application under test frequently starts up without informing the user and without the user's consent, then the simulated operation may be to kill the process of the application under test after starting the application under test; and so on.
[0049] S130. Obtain target information, and detect the privacy compliance of the tested application in the detection scenario in combination with the privacy compliance rules corresponding to the scenario parameters, wherein the target information includes information involved during the execution of the target script by the detection terminal deployed with the client.
[0050] Among them, the target information is obtained, and the target information can be the information involved during the execution of the target script by the detection terminal deployed with the client (also the detection terminal deployed with the application under test), such as the transmission information transmitted outward by the detection terminal, the acquisition information obtained, the function call information of the target function called by the application under test, etc., which is not specifically limited here. In actual applications, optionally, the transmission information and / or acquisition information may be information related to the application under test, or it may be information related to the remaining applications in the detection terminal except the application under test, which is not specifically limited here. Privacy compliance rules can be rules used to indicate whether the application under test has or does not have privacy compliance in the detection scenario when the target information meets certain conditions, such as rules related to the privacy compliance of the application under test in the detection scenario when the user privacy information obtained or transmitted does not exist in the pre-set privacy policy; rules related to the privacy compliance of the application under test in the detection scenario when the target function does not exist in the pre-set sensitive function library; and so on. Therefore, based on the target information and privacy compliance rules, the effect of automated detection of the privacy compliance of the application under test in the detection scenario can be achieved.
[0051] It should be noted that the above technical solution, on the one hand, achieves the effect of automatic detection of privacy compliance in the detection scenario through automated simulation. Detection scenario (i.e., automated simulation of user operations related to the detection scenario on the application under test), and then automatically judges the privacy compliance of the application under test in the detection scenario based on the target information obtained, thereby improving detection efficiency and reducing detection costs. On the other hand, although the existing privacy compliance policies are complex and difficult to understand, and the interpretation of privacy compliance policies by the testing agencies is updated at a fast pace (such as sometimes stricter and sometimes looser), by pre-setting privacy compliance rules based on privacy compliance policies, the latest privacy compliance policies can be applied in a timely and automatic manner during the detection process, thereby ensuring detection efficiency and detection accuracy. In addition, the dynamic detection method of automatically detecting the target information obtained during the operation of the application under test also effectively guarantees detection accuracy.
[0052] According to the technical solution in the embodiment of the present invention, the server obtains privacy compliance detection parameters including the application identifier of the application under test and the scenario parameters of the detection scenario in response to the privacy compliance detection instruction. The privacy compliance detection parameters can reflect what application is being tested for privacy compliance in what scenario; then, the privacy compliance detection parameters are sent to the client, so that the client determines the target script according to the received privacy compliance detection parameters and executes the target script. The target script is a script for simulating the user's operations related to the detection scenario on the application under test, thereby achieving the effect of automatically simulating the detection scenario; then, the target information involved in the execution of the target script by the detection terminal deployed with the client is obtained, and the privacy compliance of the application under test in the detection scenario is detected in combination with the pre-set privacy compliance rules corresponding to the scenario parameters, thereby achieving the effect of automatically judging privacy compliance. The above technical solution can automatically detect the privacy compliance of the application under test in the detection scenario, thereby improving detection efficiency, ensuring detection accuracy and reducing detection costs.
[0053] An optional technical solution for obtaining target information may include: intercepting transmission information transmitted by the detection terminal during the execution of the target script by the client, and forwarding the transmission information to a receiving device to receive the transmission information; and / or intercepting acquisition information to be obtained by the detection terminal during the execution of the target script by the client, and forwarding the acquisition information to the detection terminal; and using the intercepted transmission information and / or acquisition information as the target information. The transmission information transmitted by the detection terminal during the execution of the target script by the client and / or the acquisition information obtained are important bases for detecting the privacy compliance of the application under test. Therefore, the server can intercept this information and use it as the target information. It should be noted that when the server intercepts the target information, this means that the receiving device and / or detection terminal that was originally intended to receive the target information will not be able to receive the target information, affecting the effective operation of the application under test. Therefore, when the server intercepts the transmission information, it can forward the transmission information to the corresponding receiving device, thereby implementing an information exchange process between the detection terminal and the receiving device; when the server intercepts the acquisition information, it can forward the acquisition information to the detection terminal, thereby implementing an information exchange process between the detection terminal and the sending device that sent the acquisition information. On this basis, optionally, both the receiving device and the sending device can be application servers corresponding to the application under test; further optionally, the target information intercepted by the server may be encrypted information, such as HTTPS encrypted information, which may include user personal information, specifically IMEI, IP, MAC address, etc. Therefore, after intercepting the encrypted information, it can be decrypted, and the decryption result can be used as the basis for privacy compliance detection, and the target information before decryption (i.e., intercepted) can be forwarded. The above technical solution ensures that the server can intercept the target information used for privacy compliance detection without affecting the effective operation of the application under test. It should be noted that the effective operation of the application under test is also an important prerequisite for the implementation of privacy compliance detection.
[0054] On this basis, optionally, the privacy compliance detection parameters also include a parameter proxy address for locating a proxy port opened on a detection server deployed with a server. After sending the privacy compliance detection parameters to the client, the above-mentioned privacy compliance detection method may further include: enabling the client to configure the terminal system proxy of the detection terminal to receive the parameter proxy address; intercepting the transmission information transmitted by the detection terminal during the execution of the target script by the client, which may include: intercepting the transmission information transmitted by the detection terminal during the execution of the target script by the client based on the proxy port; intercepting the acquisition information to be obtained by the detection terminal during the execution of the target script by the client, which may include: intercepting the acquisition information to be obtained by the detection terminal during the execution of the target script by the client based on the proxy port. Among them, the proxy port can be a port opened on the detection server for realizing the proxy function, such as the port of the middleman proxy (mitmproxy) opened on the detection server. The parameter proxy address can be an address for locating the proxy port on the detection server. In actual applications, it can optionally include the Internet Protocol Address (IP) of the detection server and the port address of the proxy port, so that the proxy port on this detection server can be uniquely located. After the parameter proxy address is sent to the client as part of the privacy compliance detection parameters, the client can configure the terminal system proxy of the detection terminal as the parameter proxy address, thereby associating the proxy port and the detection terminal together, so that the server can intercept the transmission information and / or obtain information based on the proxy port, thereby realizing the automation of the server proxy intercepting the transmission information and / or obtaining information.
[0055] Another optional technical solution is that the target information includes the transmission information and / or the acquisition information transmitted by the detection terminal during the execution of the target script on the client, and the privacy compliance rules include rules related to the privacy compliance of the tested application in the detection scenario when the user privacy information obtained or transmitted does not exist in the pre-set privacy policy; combined with the privacy compliance rules corresponding to the scenario parameters, the privacy compliance of the tested application in the detection scenario is detected, which may include: determining the user privacy information in the target information, and detecting the privacy compliance of the tested application in the detection scenario based on whether the user privacy information exists in the privacy policy. Among them, the detection scenario that matches the above privacy compliance rules can be that after agreeing to the privacy policy, the user privacy information not declared in the privacy policy cannot be used. Therefore, the privacy compliance of the tested application in the detection scenario can be detected by determining the user privacy information in the target information and based on whether the user privacy information exists in the privacy policy. For example, when the user privacy information exists in the privacy policy (that is, it matches the user privacy information declared to be used in the privacy policy), the tested application has privacy compliance in the detection scenario; otherwise, it does not have privacy compliance. The above technical solution can accurately detect privacy compliance.
[0056] Another optional technical solution is that the detection terminal is one of the candidate terminals connected to the terminal management server, and each candidate terminal is pre-configured with a privacy compliance detection environment. After responding to the privacy compliance detection instruction, the above-mentioned privacy compliance detection method may also include: determining the detection terminal from the candidate terminals connected to the terminal management server; sending the privacy compliance detection parameters to the client, including: sending the privacy compliance detection parameters to the client pre-deployed on the detection terminal. In order for the client deployed on the detection terminal to implement any of the above-mentioned privacy compliance detection processes, the detection terminal needs to be pre-configured with a privacy compliance detection environment, such as a root environment, an xposed framework, system partition unlocking, certificate installation, etc. The configuration process of the privacy compliance detection environment is relatively time-consuming and requires a certain technical professional background, and the threshold is high. On this basis, in order to reduce the difficulty of implementing privacy compliance detection and improve its implementation efficiency, at least two candidate terminals that have been configured with a privacy compliance detection environment can be prepared in advance, and each candidate terminal can be connected to the terminal management server (such as through a data cable) so that these candidate terminals can be discovered by the terminal management server. Therefore, in response to the privacy compliance detection instruction, the server can determine the detection terminal from the candidate terminals connected to the terminal management server, and then send the privacy compliance detection parameters to the client pre-deployed on the detection terminal. In this way, the user does not need to configure the privacy compliance detection environment by himself before conducting the detection, and can directly apply the candidate terminal with the configured privacy compliance detection environment, thereby solving the problem of difficulty in implementing privacy compliance detection and low efficiency. In actual applications, optionally, the candidate terminal can be a virtual terminal (such as a virtual machine) or an actual terminal (i.e., a real machine), which is not specifically limited here. Optionally, since each candidate terminal is connected to the terminal management server, the candidate terminal can also be called a cloud terminal, which is a cloud control method that can greatly improve the dynamic detection capability.
[0057] Figure 2 This is a flowchart of another privacy compliance detection method provided in an embodiment of the present invention. This embodiment can be applied to automatically detect the privacy compliance of the tested application in the detection scenario. This method can be performed by the privacy compliance detection device provided in an embodiment of the present invention. The device can be implemented in software and / or hardware and can be integrated into the detection terminal.
[0058] See also Figure 2 The method of this embodiment may specifically include the following steps:
[0059] S210: Receive privacy compliance detection parameters sent by the server, where the privacy compliance detection parameters include application identifier and scenario parameters.
[0060] Among them, the client receives the privacy compliance detection parameters sent by the server, and the privacy compliance detection parameters may include application identification and scenario parameters. The application identification may be the identification of the application being tested, and the scenario parameters may be the parameters of the detection scenario. This means that the client can determine the privacy compliance of what application and in what scenario the server is testing based on the received privacy compliance detection parameters, and then determine what application and scenario-related operations it needs to simulate the user to perform.
[0061] S220. Determine the target script based on the received privacy compliance detection parameters, and execute the target script so that the server obtains the target information, and detects the privacy compliance of the tested application in the detection scenario in combination with the privacy compliance rules corresponding to the scenario parameters, wherein the target script includes a script for simulating the user's operations related to the detection scenario on the tested application, the tested application is an application with an application identifier, the detection scenario is a scenario with scenario parameters, and the target information includes information involved in the detection terminal deployed with the client during the execution of the target script on the client.
[0062] Among them, since the privacy compliance detection parameters received by the client include application identification and scenario parameters, the target script determined thereby can include a script for simulating the user's operations on the tested application related to the detection scenario, and then by executing the target script to simulate the user's process of performing the above operations, the effect of automating the operation of the tested application according to the detection scenario is achieved. Furthermore, the server can obtain the target information involved in the detection terminal during the execution of the target script on the client, and thus, combined with the privacy compliance rules corresponding to the scenario parameters, it can achieve the effect of automated detection of the privacy compliance of the tested application in the detection scenario.
[0063] According to the technical solution in the embodiment of the present invention, the client receives privacy compliance detection parameters including the application identifier of the application under test and the scenario parameters of the detection scenario sent by the server. The privacy compliance detection parameters can reflect what application and in what scenario the server needs to detect the privacy compliance of; then, the target script is determined according to the received privacy compliance detection parameters, and the target script is executed. The target script is a script used to simulate the user's operations related to the detection scenario on the application under test, thereby achieving the effect of automated simulation of the detection scenario. In this way, the server can obtain the target information involved in the execution of the target script by the detection terminal deployed with the client, and detect the privacy compliance of the application under test in the detection scenario in combination with the pre-set privacy compliance rules corresponding to the scenario parameters, thereby achieving the effect of automated judgment of privacy compliance. The above technical solution realizes the automated detection of the privacy compliance of the application under test in the detection scenario, thereby improving the detection efficiency, ensuring the detection accuracy and reducing the detection cost.
[0064] An optional technical solution, the above-mentioned privacy compliance detection method may also include: obtaining function call information, wherein the function call information is the identification information of the target function called by the tested application installed on the detection terminal during the execution of the target script on the client; obtaining a pre-set sensitive function library, and determining whether the target function corresponding to the function call information exists in the sensitive function library; if so, sending the function call information as target information to the server. The function call information can indicate what function (here referred to as the target function) is called by the tested application installed on the detection terminal during the execution of the target script on the client, and the sensitive function library can be a pre-set library for storing sensitive functions, which can be understood as a function for obtaining or transmitting user privacy information. After the client obtains the function call information, it can compare the target function corresponding to it with the sensitive function stored in the sensitive database. If the target function is a sensitive function, the function call information can be sent to the server as target information. In this way, when the privacy compliance rules are related to the target function not existing in the sensitive function library, and the tested application is privacy-compliant in the detection scenario, the detection scenario at this time may be that the user's privacy information cannot be obtained or transmitted before the privacy policy is agreed. The server can determine that the tested application has called the sensitive function based on the obtained target information, and thus it can be determined that the tested application does not have privacy compliance in the detection scenario, thereby achieving the effect of accurate detection of privacy compliance. In actual applications, the above-mentioned sensitive function library can optionally be collected by at least one of the following methods: obtaining functions for collecting user privacy information from official websites through crawlers, collecting through user online feedback mechanisms, and collecting after interpreting and analyzing the privacy compliance policies announced by regulatory agencies, etc.
[0065] On this basis, optionally, obtaining function call information may include: receiving function call information sent based on a broadcast method, wherein the function call information is information sent after being obtained based on a hook script registered in the process where the application under test is located. The hook script may be a script related to a hook function, which is actually a program segment for processing messages, and can be hung on the terminal system through a call by the terminal system. The hook script is pre-registered in the process where the application under test is located, so that function call information can be obtained based on the hook script, but this also means that the process where the hook script is located is not the same process as the process where the client is located, and information cannot be directly exchanged between two different processes. Therefore, the function call information obtained based on the hook script can be sent by broadcast, so that the process where the client is located can receive the function call information based on the receiver, thereby achieving the effect of effectively receiving the function call information.
[0066] Another optional technical solution is that the privacy compliance detection parameters also include the storage address of the application installation package of the application under test in the storage server. After receiving the privacy compliance detection parameters sent by the server, the above-mentioned privacy compliance detection method may also include: determining whether the application under test is installed on the detection terminal based on the received application identifier; if so, uninstalling the application under test installed on the detection terminal; downloading the application installation package from the storage server based on the received storage address, and installing the downloaded application installation package on the detection terminal. Among them, considering the application scenarios that may be involved in the embodiments of the present invention, when the application under test is run for the first time, it may be necessary to store some application information in a certain application file. Then, when the detection scenario is related to application information and / or application files, the application under test cannot have been run before being detected to ensure that it is run for the first time during the detection process. To this end, after receiving the application identifier, the client can determine whether the corresponding tested application is installed on the detection terminal; if so (this means that the tested application is likely to have been run), then the tested application installed on the detection terminal is uninstalled, and the application installation package of the tested application is downloaded from the storage server based on the received storage address, and then the downloaded application installation package is installed on the detection terminal, thereby ensuring that the tested application running during the detection process is running for the first time. On this basis, optionally, the storage server and the detection server for storing the application installation package can be the same or different servers, which is not specifically limited here. When the two are different, the server can obtain the storage address of the application installation package in the storage server from the storage server. Optionally, when the terminal system is an Android system, the above-mentioned application installation package can be called APK (Android Application Package), which is a file format designed specifically for distributing Android applications on the platform.
[0067] Figure 3 This is a timing diagram of another privacy compliance detection method provided in an embodiment of the present invention. This embodiment is optimized based on the above technical solutions. Among them, the explanations of the same or corresponding terms in the above embodiments are not repeated here.
[0068] See also Figure 3 The method of this embodiment may specifically include the following steps:
[0069] S1. The server responds to the privacy compliance detection instruction and obtains privacy compliance detection parameters, where the privacy compliance detection parameters include the application package name of the application under test, the scenario parameters of the detection scenario, the parameter proxy address for locating the proxy port opened on the detection server where the server is deployed, and the storage address of the apk of the application under test in the detection server.
[0070] For the front-end corresponding to the server, users can upload the APK to the storage server through the front-end page displayed on the front-end, select the detection scenario, and then click the detection control. As a result, the server can receive the privacy compliance detection instruction triggered by the front-end, and the automatic detection process will be initiated.
[0071] S2. The server determines the detection terminal from the candidate terminals connected to the terminal management server, generates an adb command based on the privacy compliance detection parameters, and sends the adb command to the client pre-deployed on the detection terminal. Each candidate terminal is pre-configured with a privacy compliance detection environment.
[0072] S3. The client receives the adb command through a pre-set interface and obtains the privacy compliance detection parameters from the adb command.
[0073] S4. The client determines whether the tested application is installed on the detection terminal according to the application package name. If so, the tested application installed on the detection terminal is uninstalled, and the apk is downloaded from the detection server based on the storage address, and the downloaded apk is installed on the detection terminal.
[0074] S5. The client configures the terminal system proxy of the detection terminal as a parameter proxy address, then starts the installed application under test and starts the hook script, wherein the hook script includes function call information registered in the process where the application under test is located, which is used to obtain the target function called by the application under test during the execution of the target script on the client, and the function call information is sent outward via broadcast.
[0075] S6. The client determines a target script according to the application package name and the scenario parameters, and executes the target script, wherein the target script is a script for simulating user operations related to the detection scenario performed on the application under test.
[0076] S7. The client receives the function call information sent based on the broadcast mode.
[0077] S8. The client obtains a preset sensitive function library and determines whether the target function corresponding to the function call information exists in the sensitive function library. If yes, the function call information is sent to the server as target information.
[0078] This step may be performed during the execution of the target script or after the execution of the target script is completed, and is not specifically limited here.
[0079] S9. The server intercepts the transmission information and the acquisition information to be acquired transmitted by the detection terminal during the execution of the target script by the client based on the proxy port, and forwards the intercepted transmission information to the receiving device to receive the transmission information and the intercepted acquisition information to the detection terminal.
[0080] S10. The server uses function call information, transmission information, and acquisition information as target information, and combines it with the privacy compliance rules corresponding to the scenario parameters to detect the privacy compliance of the tested application in the detection scenario.
[0081] It should be noted that in the above technical solution, the client performs many actions, such as determining whether the tested application is installed on the detection terminal, uninstalling the installed tested application, downloading apk, installing the downloaded apk, determining the target script, executing the target script and sending target information, etc. These actions can be reflected at once in the adb command sent by the server to the client. This is an asynchronous operation, which reduces the possibility of time-consuming blocking on the server; of course, each action can also be reflected through its own adb command, which is a synchronous operation, and is not specifically limited here.
[0082] The technical solution of the embodiment of the present invention, through the cooperation of the above steps, can realize the automated detection of the privacy compliance of the tested application in the detection scenario, thereby improving the detection efficiency, ensuring the detection accuracy and reducing the detection cost.
[0083] In actual applications, the implementation framework of the above technical solution can optionally include the following four modules: a detection terminal module, a function call module, an information interception module, and a scenario simulation module. Among them, the detection terminal module can also be called a cloud real machine, which can be used to implement functions such as privacy compliance detection environment configuration and adb command issuance. The function call module can also be called a client function hook, which can be used to implement functions such as function call information acquisition and sensitive function comparison. The information interception module can also be called a traffic interception module, which can be used to implement functions such as proxy links and traffic interception and forwarding. The scenario simulation module can also be called a scenario automation module, which can be used to implement functions such as detection scenario simulation and privacy compliance judgment.
[0084] Figure 4 This is a block diagram of the structure of a privacy compliance detection device provided in an embodiment of the present invention. The device can be used to execute the privacy compliance detection method provided in any of the above embodiments. The device and the privacy compliance detection method of each of the above embodiments belong to the same inventive concept. For details not fully described in the embodiment of the privacy compliance detection device, please refer to the embodiment of the above privacy compliance detection method. Figure 4 The device is configured on the server side and may include: a privacy compliance detection parameter acquisition module 410, a target script first execution module 420 and a privacy compliance detection module 430.
[0085] The privacy compliance detection parameter acquisition module 410 is configured to obtain privacy compliance detection parameters in response to the privacy compliance detection instruction, wherein the privacy compliance detection parameters include application identifiers and scenario parameters;
[0086] a target script first execution module 420, configured to send privacy compliance detection parameters to a client, so that the client determines a target script based on the received privacy compliance detection parameters and executes the target script, wherein the target script includes a script for simulating user operations on a tested application related to a detection scenario, the tested application being an application having an application identifier, and the detection scenario being a scenario having scenario parameters;
[0087] The privacy compliance detection module 430 is used to obtain target information and, in combination with the privacy compliance rules corresponding to the scenario parameters, detect the privacy compliance of the application under test in the detection scenario, wherein the target information includes information involved during the execution of the target script by the detection terminal deployed with the client.
[0088] Optionally, the privacy compliance detection module 430 may include:
[0089] a transmission information interception and forwarding unit, configured to intercept transmission information transmitted by the detection terminal during execution of the target script by the client, and forward the transmission information to a receiving device to receive the transmission information; and / or,
[0090] an acquisition information interception and forwarding unit, configured to intercept acquisition information to be acquired by the detection terminal during execution of the target script by the client, and forward the acquisition information to the detection terminal;
[0091] The target information obtaining unit is configured to use the intercepted transmission information and / or acquisition information as target information.
[0092] On this basis, optionally, the privacy compliance detection parameters also include a parameter proxy address for locating the proxy port opened on the detection server where the server is deployed;
[0093] The above-mentioned privacy compliance detection device may further include:
[0094] A terminal system proxy configuration module is used to enable the client to configure the terminal system proxy of the detection terminal to the received parameter proxy address after sending the privacy compliance detection parameters to the client;
[0095] Accordingly, the transmission information interception and forwarding unit may include: a transmission information interception subunit for intercepting, based on the proxy port, transmission information transmitted by the detection terminal during execution of the target script on the client;
[0096] The acquisition information interception and forwarding unit may include: an acquisition information interception subunit, which is used to intercept, based on the proxy port, acquisition information to be acquired by the detection terminal during execution of the target script on the client.
[0097] Optionally, the target information includes transmission information transmitted and / or acquisition information obtained by the detection terminal during execution of the target script on the client, and the privacy compliance rules include rules related to privacy compliance of the tested application in the detection scenario when the acquired or transmitted user privacy information does not exist in a pre-set privacy policy;
[0098] The privacy compliance detection module 430 may include:
[0099] The privacy compliance detection unit is used to determine the user privacy information in the target information and detect the privacy compliance of the tested application in the detection scenario based on whether the user privacy information exists in the privacy policy.
[0100] Optionally, the detection terminal is one of the candidate terminals connected to the terminal management server, and each candidate terminal is pre-configured with a privacy compliance detection environment;
[0101] The above-mentioned privacy compliance detection device may further include:
[0102] a detection terminal determination module, configured to determine a detection terminal from candidate terminals connected to the terminal management server after responding to the privacy compliance detection instruction;
[0103] The target script first execution module 420 may include:
[0104] The privacy compliance detection parameter sending unit is used to send the privacy compliance detection parameters to the client pre-deployed on the detection terminal.
[0105] In the privacy compliance detection device provided by an embodiment of the present invention, a server obtains privacy compliance detection parameters including an application identifier of a tested application and scenario parameters of a detection scenario in response to a privacy compliance detection instruction through a privacy compliance detection parameter acquisition module, wherein the privacy compliance detection parameters can reflect the privacy compliance of a specific application in a specific scenario. Furthermore, the privacy compliance detection parameters are sent to a client through a target script first execution module, so that the client determines a target script based on the received privacy compliance detection parameters and executes the target script. The target script is a script for simulating user operations related to the detection scenario on the tested application, thereby achieving the effect of automatically simulating the detection scenario. Then, the target information involved in the execution of the target script by the detection terminal deployed with the client is obtained through the privacy compliance detection module, and the privacy compliance of the tested application in the detection scenario is detected in combination with the pre-set privacy compliance rules corresponding to the scenario parameters, thereby achieving the effect of automatically judging privacy compliance. The above device can automatically detect the privacy compliance of the tested application in the detection scenario, thereby improving detection efficiency, ensuring detection accuracy and reducing detection costs.
[0106] The privacy compliance detection device provided in the embodiment of the present invention can execute the privacy compliance detection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0107] It is worth noting that in the embodiment of the above-mentioned privacy compliance detection device, the various units and modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention.
[0108] Figure 5 This is a block diagram of the structure of a privacy compliance detection device provided in an embodiment of the present invention. The device can be used to execute the privacy compliance detection method provided in any of the above embodiments. The device and the privacy compliance detection method of each of the above embodiments belong to the same inventive concept. For details not fully described in the embodiment of the privacy compliance detection device, please refer to the embodiment of the above privacy compliance detection method. Figure 5 The device is configured on the client and may specifically include: a privacy compliance detection parameter receiving module 510 and a target script second execution module 520.
[0109] The privacy compliance detection parameter receiving module 510 is configured to receive the privacy compliance detection parameters sent by the server, wherein the privacy compliance detection parameters include application identifiers and scenario parameters;
[0110] A second target script execution module 520 is configured to determine a target script based on the received privacy compliance detection parameters and execute the target script so that the server obtains the target information and detects the privacy compliance of the tested application in the detection scenario in combination with the privacy compliance rules corresponding to the scenario parameters;
[0111] Among them, the target script includes a script for simulating the user's operations related to the detection scenario on the tested application, the tested application is an application with an application identifier, the detection scenario is a scenario with scenario parameters, and the target information includes information involved in the detection terminal deployed with the client during the execution of the target script on the client.
[0112] Optionally, the privacy compliance detection device may further include:
[0113] A function call information acquisition module is used to acquire function call information, which is identification information of a target function called by a tested application installed on a detection terminal during execution of a target script on a client;
[0114] A target function determination module is used to obtain a preset sensitive function library and determine whether the target function corresponding to the function call information exists in the sensitive function library;
[0115] The target information sending module is used to send the function call information as the target information to the server if yes.
[0116] On this basis, the function call information acquisition module may optionally include:
[0117] The function call information receiving unit is used to receive function call information sent based on a broadcast mode, wherein the function call information is information sent after being obtained based on a hook script registered in the process where the tested application is located.
[0118] Optionally, the privacy compliance detection parameters also include the storage address of the application installation package of the tested application in the storage server;
[0119] The privacy compliance detection device may also include:
[0120] A tested application determination module is used to determine whether the tested application is installed on the detection terminal based on the received application identifier after receiving the privacy compliance detection parameters sent by the server;
[0121] a tested application uninstallation module, configured to uninstall the tested application installed on the detection terminal if yes;
[0122] The application installation package installation module is used to download the application installation package from the storage server based on the received storage address, and install the downloaded application installation package on the detection terminal.
[0123] In the privacy compliance detection device provided by the embodiment of the present invention, the client receives the privacy compliance detection parameters including the application identifier of the tested application and the scenario parameters of the detection scenario sent by the server through the privacy compliance detection parameter receiving module, wherein the privacy compliance detection parameters can reflect which application the server needs to detect for privacy compliance in which scenario; further, the target script second execution module determines the target script according to the received privacy compliance detection parameters and executes the target script, which is a script used to simulate the user's operations related to the detection scenario on the tested application, thereby achieving the effect of automatically simulating the detection scenario. In this way, the server can obtain the target information involved in the execution of the target script by the detection terminal deployed with the client, and detect the privacy compliance of the tested application in the detection scenario in combination with the pre-set privacy compliance rules corresponding to the scenario parameters, thereby achieving the effect of automatically judging privacy compliance. The above device can realize the automated detection of the privacy compliance of the tested application in the detection scenario, thereby improving the detection efficiency, ensuring the detection accuracy and reducing the detection cost.
[0124] The privacy compliance detection device provided in the embodiment of the present invention can execute the privacy compliance detection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0125] It is worth noting that in the embodiment of the above-mentioned privacy compliance detection device, the various units and modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention.
[0126] Figure 6 A schematic structural diagram of a detection server or detection terminal (hereinafter collectively referred to as an electronic device) 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0127] like Figure 6 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0128] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0129] The processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors that run machine learning model algorithms, a digital signal processor (DSP), and any other suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the privacy compliance detection method.
[0130] In some embodiments, the privacy compliance detection method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the privacy compliance detection method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to perform the privacy compliance detection method in any other appropriate manner (e.g., by means of firmware).
[0131] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0132] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0133] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0134] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0135] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0136] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0137] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0138] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A privacy compliance detection method, characterized in that: Applied to the server, the method includes: In response to the privacy compliance detection instruction, obtaining privacy compliance detection parameters, wherein the privacy compliance detection parameters include an application identifier and a scenario parameter; Sending the privacy compliance detection parameters to a client, so that the client determines a target script based on the received privacy compliance detection parameters and executes the target script, wherein the target script includes a script for simulating a user's operation on the application under test related to a detection scenario, the application under test is an application having the application identifier, and the detection scenario is a scenario having the scenario parameters; intercepting transmission information transmitted by the detection terminal where the client is located during the execution of the target script by the client, and forwarding the transmission information to a receiving device to receive the transmission information; and / or, intercepting acquisition information to be acquired by the detection terminal during execution of the target script by the client, and forwarding the acquisition information to the detection terminal; The intercepted transmission information and / or the acquired information is used as target information, and combined with the privacy compliance rules corresponding to the scenario parameters, the privacy compliance of the tested application in the detection scenario is detected, wherein the privacy compliance rules are rules indicating whether the tested application has or does not have privacy compliance in the detection scenario when the target information meets certain conditions.
2. The method according to claim 1, characterized in that The privacy compliance detection parameters also include a parameter proxy address for locating a proxy port opened on the detection server where the server is deployed; After sending the privacy compliance detection parameter to the client, the method further includes: enabling the client to configure the terminal system proxy of the detection terminal as the received parameter proxy address; Accordingly, intercepting the transmission information transmitted by the detection terminal during the execution of the target script by the client includes: intercepting the transmission information transmitted by the detection terminal during the execution of the target script by the client based on the proxy port; The intercepting the acquisition information to be acquired by the detection terminal during the execution of the target script by the client includes: intercepting the acquisition information to be acquired by the detection terminal during the execution of the target script by the client based on the proxy port.
3. The method according to claim 1, characterized in that The target information includes transmission information transmitted and / or acquisition information obtained by the detection terminal during execution of the target script on the client, and the privacy compliance rules include rules related to privacy compliance of the tested application in the detection scenario when the acquired or transmitted user privacy information does not exist in a preset privacy policy; The detecting the privacy compliance of the tested application in the detection scenario in combination with the privacy compliance rules corresponding to the scenario parameters includes: The user privacy information in the target information is determined, and according to whether the user privacy information exists in the privacy policy, the privacy compliance of the tested application in the detection scenario is detected.
4. The method according to claim 1, wherein The detection terminal is one of the candidate terminals connected to the terminal management server, and each candidate terminal is pre-configured with a privacy compliance detection environment. After responding to the privacy compliance detection instruction, the method further includes: Determine the detection terminal from the candidate terminals connected to the terminal management server; The sending of the privacy compliance detection parameter to the client includes: The privacy compliance detection parameters are sent to a client pre-deployed on the detection terminal.
5. A privacy compliance detection method, characterized in that: Applied to a client, the method includes: Receive privacy compliance detection parameters sent by the server, wherein the privacy compliance detection parameters include application identifiers and scenario parameters; Determining a target script based on the received privacy compliance detection parameters and executing the target script so that the server obtains target information and detects the privacy compliance of the tested application in the detection scenario in combination with the privacy compliance rules corresponding to the scenario parameters; The server obtains the target information by: intercepting transmission information transmitted by the detection terminal where the client is located during the execution of the target script by the client, and forwarding the transmission information to a receiving device to receive the transmission information; and / or intercepting acquisition information to be acquired by the detection terminal during the execution of the target script by the client, and forwarding the acquisition information to the detection terminal; and using the intercepted transmission information and / or acquisition information as target information; Among them, the target script includes a script for simulating the user's operations related to the detection scenario on the tested application, the tested application is an application with the application identifier, the detection scenario is a scenario with the scenario parameters, and the privacy compliance rule is a rule indicating whether the tested application has or does not have privacy compliance in the detection scenario when the target information meets certain conditions.
6. The method according to claim 5, characterized in that Also includes: Acquiring function call information, wherein the function call information is identification information of a target function called by the tested application installed on the detection terminal during execution of the target script by the client; Obtaining a preset sensitive function library, and determining whether the target function corresponding to the function call information exists in the sensitive function library; If yes, the function call information is sent to the server as the target information.
7. The method according to claim 6, characterized in that The obtaining of function call information includes: Function call information sent based on a broadcast mode is received, wherein the function call information is information sent after being acquired based on a hook script registered in a process where the application under test is located.
8. The method according to claim 5, characterized in that The privacy compliance detection parameters also include the storage address of the application installation package of the tested application in the storage server; After receiving the privacy compliance detection parameters sent by the server, the method further includes: Determining whether the application to be tested is installed on the detection terminal according to the received application identifier; If yes, uninstalling the tested application installed on the detection terminal; The application installation package is downloaded from the storage server based on the received storage address, and the downloaded application installation package is installed on the detection terminal.
9. A privacy compliance detection device, characterized in that: Configured on the server side, the device includes: A privacy compliance detection parameter acquisition module, configured to acquire privacy compliance detection parameters in response to a privacy compliance detection instruction, wherein the privacy compliance detection parameters include an application identifier and a scenario parameter; a first target script execution module, configured to send the privacy compliance detection parameters to a client, so that the client determines a target script based on the received privacy compliance detection parameters and executes the target script, wherein the target script includes a script for simulating user operations related to a detection scenario on a tested application, the tested application being an application having the application identifier, and the detection scenario being a scenario having the scenario parameters; a privacy compliance detection module, configured to obtain target information and, in combination with privacy compliance rules corresponding to the scenario parameters, detect the privacy compliance of the tested application in the detection scenario, wherein the privacy compliance rules are rules indicating whether the tested application has or does not have privacy compliance in the detection scenario when the target information meets certain conditions; The privacy compliance detection module includes: a transmission information intercepting and forwarding unit, configured to intercept transmission information transmitted by the detection terminal where the client is located during the execution of the target script by the client, and forward the transmission information to a receiving device to receive the transmission information; and / or, an acquisition information intercepting and forwarding unit, configured to intercept acquisition information to be acquired by the detection terminal during execution of the target script by the client, and forward the acquisition information to the detection terminal; The target information obtaining unit is configured to use the intercepted transmission information and / or the acquired information as target information.
10. A privacy compliance detection device, characterized in that: Configured on the client, the device includes: A privacy compliance detection parameter receiving module, configured to receive privacy compliance detection parameters sent by the server, wherein the privacy compliance detection parameters include application identifiers and scenario parameters; a second target script execution module, configured to determine a target script based on the received privacy compliance detection parameters and execute the target script so that the server obtains target information and detects the privacy compliance of the tested application in the detection scenario in combination with the privacy compliance rules corresponding to the scenario parameters; The server obtains the target information by: intercepting transmission information transmitted by the detection terminal where the client is located during the execution of the target script by the client, and forwarding the transmission information to a receiving device to receive the transmission information; and / or intercepting acquisition information to be acquired by the detection terminal during the execution of the target script by the client, and forwarding the acquisition information to the detection terminal; and using the intercepted transmission information and / or acquisition information as target information; Among them, the target script includes a script for simulating the user's operations related to the detection scenario on the tested application, the tested application is an application with the application identifier, the detection scenario is a scenario with the scenario parameters, and the privacy compliance rule is a rule indicating whether the tested application has or does not have privacy compliance in the detection scenario when the target information meets certain conditions.
11. A detection server, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the privacy compliance detection method according to any one of claims 1 to 4.
12. A detection terminal, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the privacy compliance detection method according to any one of claims 5 to 8.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the privacy compliance detection method as described in any one of claims 1 to 8 when executed.
Citation Information
Patent Citations
Safety detection method, device and system and server
CN107480530A
Application compliance detection method and device, equipment and medium
CN113704102A