A privacy protection detection method and system based on custom ROM
Patent Information
- Application Number
- CN202211202245.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-29
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2042-09-29
AI Technical Summary
[0031]采用本发明所述一种基于定制ROM的隐私保护检测方法及系统,通过获取历史隐私样本,构建隐私样本先验集合;建立敏感函数列表以及敏感函数与权限关系表。通过第一神经网络模型对先验权限特征向量集进行训练,得到先验权限样本集模型文件;对应用程序的安装文件进行解析,获取与应用程序调用函数对应的应用程序权限文件,基于第一神经网络模型对匹配应用程序权限文件的特征向量进行训练,生成匹配应用程序权限模型文件,将匹配应用程序权限模型文件与先验权限样本集模型文件进行比对,可判断应用程序调用函数权限是否可开启。本发明所述一种基于定制ROM的隐私保护检测方法及系统通过定制ROM的方式对移动客户端函数行为进行监控并打印,判断应用程序是否存在违规收集用户个人信息行为。
Smart Images

Figure CN115422595B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of privacy protection technology, and in particular to a privacy protection detection method and system based on a custom ROM. Background Technology
[0002] With the widespread adoption of mobile smart terminals and the continuous penetration of the mobile internet, various mobile apps have emerged. Among them, financial, lifestyle, and entertainment apps are numerous, greatly facilitating people's lives and enabling them to shop, order food, and access financial services without leaving home. The continued penetration of the mobile internet has directly promoted the enrichment and prosperity of digital life, with massive user needs being continuously explored, leading to a sustained increase in the types and number of mobile applications. These apps have become the main providers of internet services. However, while greatly facilitating people, these apps have also brought a series of privacy protection and leakage issues, such as frequent requests for user permissions, silent background data transmission, and excessive collection of user personal information. With increasingly stringent domestic and international regulations, how to develop and operate mobile apps while adhering to compliance has become a key focus for enterprises.
[0003] Current privacy compliance testing methods include: manual privacy compliance testing and semi-automated auxiliary testing components / scripts based on injection frameworks such as Xposed and Frida. Manual privacy compliance testing involves manually testing mobile applications item by item according to relevant domestic and international regulatory documents. This method relies on engineer experience, and some technical aspects require security hardening measures to bypass the mobile application's security measures. Semi-automated auxiliary testing components / scripts based on injection frameworks like Xposed and Frida rely on senior engineers to maintain the scripts and modify them for specific security hardening scenarios. However, both methods have their own problems: manual testing relies heavily on engineer experience, has a coarse granularity, and is costly and inefficient; semi-automated Xposed / Frida testing requires intrusion into the application and senior engineers to maintain scripts / plugins for security hardening in specific scenarios, resulting in high implementation costs. Therefore, existing privacy protection testing mechanisms suffer from drawbacks such as coarse-grained implementation or high implementation costs, necessitating a non-intrusive, seamless, and low-cost approach to privacy compliance testing. Summary of the Invention
[0004] To address the shortcomings of existing technologies, this invention proposes a privacy protection detection method and system based on a customized ROM. By using a customized ROM, the method monitors the function behavior of mobile clients and prints the results to determine whether the application is illegally collecting users' personal information.
[0005] To achieve the above objectives, the technical solution adopted by the present invention includes:
[0006] A privacy protection detection method based on a custom ROM, characterized by comprising:
[0007] S1. Obtain historical privacy samples and construct a prior set of privacy samples; extract sensitive function information of the application and the corresponding permission information from the prior set of privacy samples; establish a list of sensitive functions based on the sensitive function information; construct a prior permission feature vector set based on the permission information corresponding to the sensitive functions; train the prior permission feature vector set using the first neural network model to obtain the prior permission sample set model file; establish a table showing the relationship between sensitive functions and permissions.
[0008] S2. Obtain the applications installed by the user; parse the application's installation files, and the parsing results include: application call functions and application permission file set;
[0009] S3. Determine if the function called by the application is in the list of sensitive functions; if the function called by the application is in the list of sensitive functions, obtain the application permission file corresponding to the function called by the application, which is the matching application permission file;
[0010] S4. Construct feature vectors for matching application permission files; train the feature vectors for matching application permission files based on the first neural network model to obtain the matching application permission model file;
[0011] S5. Compare the matching application permission model file with the prior permission sample set model file to determine whether the application's function call permission can be enabled, and obtain the result of enabling the application's function call permission.
[0012] Furthermore, the privacy sample set includes: samples that violate privacy and samples that do not violate privacy.
[0013] Furthermore, the sensitive function list includes: function codes and function names; the prior permission sample set model file includes: permission names, permission codes, and whether the permission can be enabled; the sensitive function and permission relationship table includes: function codes, permission codes, and the correspondence between functions and permissions.
[0014] Furthermore, step S3 includes the following sub-steps: S31, obtaining the function code of the function called by the application;
[0015] S32. Based on the function code of the application call function, query the permission code corresponding to the function code of the application call function in the sensitive function and permission relationship table, and find the matching permission code;
[0016] S33. Search for application permission files in the application permission file set based on matching permission codes, and find the matching application permission files.
[0017] Furthermore, it also includes step S6, printing the application call function permission opening result by modifying the AOSP source code.
[0018] Furthermore, the first neural network model is a data mining classification model.
[0019] This invention also relates to a privacy protection detection system based on a custom ROM, characterized in that it includes:
[0020] The prior knowledge building module is used to acquire historical privacy samples and construct a prior set of privacy samples; extract sensitive function information of the application and the corresponding permission information from the prior set of privacy samples; build a list of sensitive functions based on the sensitive function information; construct a prior permission feature vector set based on the permission information corresponding to the sensitive functions; train the prior permission feature vector set using the first neural network model to obtain the prior permission sample set model file; and establish a table showing the relationship between sensitive functions and permissions.
[0021] The parsing module is used to obtain the applications installed by the user; it parses the application's installation files, and the parsing results include: application call functions and application permission file sets;
[0022] The permission file acquisition module is used to determine whether the application's called function is in the sensitive function list; if the application's called function is in the sensitive function list, the module acquires the application permission file corresponding to the application's called function, which is the matching application permission file.
[0023] The permission model file construction module is used to construct feature vectors that match application permission files; the feature vectors of the matching application permission files are trained based on the first neural network model to obtain the matching application permission model file;
[0024] The permission enable judgment module is used to compare the matching application permission model file with the prior permission sample set model file to determine whether the application's function call permission can be enabled, and obtain the result of enabling the application's function call permission.
[0025] The present invention also relates to a computer-readable storage medium, characterized in that the storage medium stores a computer program, which, when executed by a processor, implements the above-described privacy protection detection method based on a custom ROM.
[0026] The present invention also relates to an electronic device, characterized in that it includes a processor and a memory;
[0027] The memory is used to store the prior permission sample set model file, the list of sensitive functions, and the table of the relationship between sensitive functions and permissions;
[0028] The processor is used to execute the aforementioned privacy protection detection method based on a customized ROM by calling the prior permission sample set model file, the sensitive function list, and the sensitive function-permission relationship table.
[0029] The present invention also relates to a computer program product, including a computer program and / or instructions, characterized in that, when the computer program and / or instructions are executed by a processor, they implement the steps of the above-described privacy protection detection method based on a custom ROM.
[0030] The beneficial effects of this invention are as follows:
[0031] The privacy protection detection method and system based on a custom ROM, as described in this invention, constructs a priori set of privacy samples by acquiring historical privacy samples; establishes a list of sensitive functions and a table showing the relationship between sensitive functions and permissions. A first neural network model is used to train the priori permission feature vector set to obtain a priori permission sample set model file. The application's installation file is parsed to obtain the application permission files corresponding to the functions called by the application. Based on the first neural network model, the feature vectors of the matching application permission files are trained to generate a matching application permission model file. The matching application permission model file is compared with the priori permission sample set model file to determine whether the application's function call permissions can be enabled. This invention monitors and prints the function behavior of mobile clients through a custom ROM to determine whether the application is illegally collecting users' personal information. Attached Figure Description
[0032] Figure 1 This is a schematic diagram of the privacy protection detection method based on a custom ROM according to the present invention.
[0033] Figure 2 This is a schematic diagram of the privacy protection detection system based on a custom ROM according to the present invention. Detailed Implementation
[0034] To better understand the content of this invention, a detailed description will be provided in conjunction with the accompanying drawings and embodiments.
[0035] Custom ROM: Android ROM is an open-source operating system based on Linux, mainly used in portable devices. Custom ROM is an operating system image generated by modifying the source code and compiling it.
[0036] Existing privacy protection detection mechanisms suffer from drawbacks such as coarse-grained implementation or high implementation costs. A non-intrusive, imperceptible, and low-cost approach is needed to achieve privacy compliance detection.
[0037] The first aspect of this invention relates to a privacy protection detection method based on a custom ROM, the steps of which are as follows: Figure 1 The method shown includes:
[0038] Obtain historical privacy samples and construct a priori set of privacy samples;
[0039] Historical privacy samples include: samples that violated privacy and samples that did not violate privacy; the prior set of privacy samples includes: samples that violated privacy and samples that did not violate privacy.
[0040] Collect an application sample set that includes both privacy-infringing and privacy-non-infringing samples, and extract the application software's permission information set from this application sample set to construct a feature vector set;
[0041] Extract sensitive function information of the application and the corresponding permission information of the sensitive functions from the privacy sample prior set;
[0042] A list of sensitive functions is created based on the sensitive function information; the list of sensitive functions includes: function codes and function names;
[0043] The list of sensitive functions includes the following functions:
[0044] Get MAC address: getMacAddress() / getHardwareAddress()
[0045] Get the list of installed packages: getInstalledPackages()
[0046] Get the location: getLastKnownLocation() / requestLocationUpdates()
[0047] Get IMSI: getSubscriberId() / TelephonyManager / getSimSerialNumber()
[0048] Get phone number: getLine1Number()
[0049] Get Device ID (IMEI): getDeviceId() / getImei()
[0050] Get the running application processes: getRunningAppProcesses()
[0051] Get device serial number: ro.serialno()
[0052] Retrieve contacts: ContactsContract.getDeclaredField(“AUTHORITY”)
[0053] Retrieve calendar content: CalendarContract.getDeclareField(“AUTHORITY”)
[0054] Get browser content: BroserContract
[0055] Get other application information: getInstalledApplications / queryIntentActivities
[0056] / getApplicationInfo
[0057] Get camera: android.hardware.Camera.open()
[0058] Construct a set of prior permission feature vectors using the permission information corresponding to the sensitivity functions;
[0059] The prior permission feature vector set is trained using the first neural network model to obtain the prior permission sample set model file; the prior permission sample set model file includes: permission name, permission code, and whether the permission can be enabled;
[0060] The feature vector set is trained using a random forest classifier to obtain the application sample set model file;
[0061] In existing machine learning, ensemble learning, by combining multiple learners, often achieves significantly better performance than a single learner. Random forest is an extended variant of parallel ensemble learning, Bagging. Building upon Bagging ensembles using decision trees as base learners, it further introduces random attribute selection during the training process of the decision trees. It is simple, easy to implement, and computationally inexpensive, exhibiting powerful performance in many real-world tasks. Moreover, it demonstrates better performance than other single classifiers in this invention; therefore, this embodiment uses random forest as the classifier.
[0062] Number all permission information provided by the Android system: Since permission information consists of strings of English letters, they are numbered alphabetically from A to Z.
[0063] All permission information provided by the system is arranged and numbered to obtain the permission number Pj corresponding to each permission information.
[0064] The first neural network model is a data mining classification model.
[0065] Establish a table showing the relationship between sensitive functions and permissions; the table includes: function codes, permission codes, and the correspondence between functions and permissions;
[0066] Get the user's installed applications;
[0067] ADB Invocation: ADB stands for Android Debug Bridge, which acts as a debugging bridge. Using ADB to invoke an application can simulate some of the user's manual operations.
[0068] adb actively starts a process to observe whether the application collects user personal information before user authorization. `adb shell am start -n com.demo.app / .mainActivity`
[0069] The application's installation files are parsed, and the results include: application call functions and a set of application permission files;
[0070] {"function":"getLastKnownLocation","package":"com.tecent.map","time":"1663302234.4727125","info":"${process name} calls the getLastKnownLocation function"}
[0071] Determine if the function called by the application is in the sensitive function list; if so, obtain the function code of the function called by the application; based on the function code of the function called by the application, search for the corresponding permission code in the sensitive function and permission relationship table, and find the matching permission code.
[0072] The system searches for application permission files in the application permission file set based on matching permission codes to identify matching application permission files; it constructs feature vectors for matching application permission files; and it trains the feature vectors of matching application permission files based on the first neural network model to obtain matching application permission model files.
[0073] The application permission model file is compared with the prior permission sample set model file to determine whether the application's function call permission can be enabled.
[0074] The results of printing application call function permissions are enabled by modifying the AOSP source code.
[0075] Extract the "time" value from the log information, print detailed log information, and mark the violation, as shown in the example below:
[0076] The process name {$process} calls function {$function} within time {$time}, package name: package {$package}, which violates the rules!
[0077] This invention presents a privacy protection detection method and system based on a customized ROM. By combining ROM customization and sensitive function monitoring, it proposes a detection system for evaluating the privacy compliance of mobile client applications on the Android platform. This system addresses the pain points of high implementation costs and reliance on manual judgment in mobile client privacy protection detection. Through specific detection and evaluation directions and practical detection schemes, it provides a privacy compliance detection solution for mobile data security professionals.
[0078] Another aspect of this invention relates to a privacy protection detection system based on a custom ROM, the structure of which is as follows: Figure 2 As shown, it includes:
[0079] The prior knowledge building module is used to acquire historical privacy samples and construct a prior set of privacy samples; extract sensitive function information of the application and the corresponding permission information from the prior set of privacy samples; build a list of sensitive functions based on the sensitive function information; construct a prior permission feature vector set based on the permission information corresponding to the sensitive functions; train the prior permission feature vector set using the first neural network model to obtain the prior permission sample set model file; and establish a table showing the relationship between sensitive functions and permissions.
[0080] The parsing module is used to obtain the applications installed by the user; it parses the application's installation files, and the parsing results include: application call functions and application permission file sets;
[0081] The permission file acquisition module is used to determine whether the application's called function is in the sensitive function list; if the application's called function is in the sensitive function list, the module acquires the application permission file corresponding to the application's called function, which is the matching application permission file.
[0082] The permission model file construction module is used to construct feature vectors that match application permission files; the feature vectors of the matching application permission files are trained based on the first neural network model to obtain the matching application permission model file;
[0083] The permission enable judgment module is used to compare the matching application permission model file with the prior permission sample set model file to determine whether the application's function call permission can be enabled, and obtain the result of enabling the application's function call permission.
[0084] By using this system, the aforementioned computational processing methods can be executed and the corresponding technical effects can be achieved.
[0085] Embodiments of the present invention also provide a computer-readable storage medium capable of implementing all the steps of the methods in the above embodiments, wherein the computer-readable storage medium stores a computer program that, when executed by a processor, implements all the steps of the methods in the above embodiments.
[0086] Embodiments of the present invention also provide an electronic device for executing the above-described method. As an implementation device for the method, the electronic device has at least a processor and a memory. In particular, the memory stores data and related computer programs required for executing the method, such as a priori permission sample set model file, a list of sensitive functions, and a table showing the relationship between sensitive functions and permissions. The processor calls the data and programs in the memory to execute all the steps of the method and obtain the corresponding technical effect.
[0087] Preferably, the electronic device may include a bus architecture, which may include any number of interconnected buses and bridges. The bus will include various circuits linked together by one or more processors and memories. The bus may also link together various other circuits such as peripherals, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface between the bus and the receiver and transmitter. The receiver and transmitter may be the same element, i.e., a transceiver, providing a unit for communicating with various other systems over a transmission medium. The processor is responsible for managing the bus and general processing, while the memory may be used to store data used by the processor during operation.
[0088] Additionally, the electronic device may further include components such as a communication module, an input unit, an audio processor, a display, and a power supply. The processor (or controller, operating control) used may include a microprocessor or other processor device and / or logic device, which receives input and controls the operation of various components of the electronic device; the memory may be one or more of a buffer, flash memory, hard drive, removable media, volatile memory, non-volatile memory, or other suitable devices, which can store the aforementioned data information, and may also store programs for executing the information, and the processor can execute the program stored in the memory to achieve information storage or processing, etc.; the input unit is used to provide input to the processor, for example, it can be a button or touch input device; the power supply is used to provide power to the electronic device; the display is used to display images and text, for example, it can be an LCD display. The communication module is a transmitter / receiver that transmits and receives signals via an antenna. The communication module (transmitter / receiver) is coupled to the processor to provide input signals and receive output signals, which can be the same as in conventional mobile communication terminals. Based on different communication technologies, multiple communication modules can be incorporated into the same electronic device, such as cellular network modules, Bluetooth modules, and / or wireless LAN modules. The communication module (transmitter / receiver) is also coupled to a speaker and microphone via an audio processor to provide audio output through the speaker and receive audio input from the microphone, thereby enabling typical telecommunications functions. The audio processor can include any suitable buffer, decoder, amplifier, etc. Furthermore, the audio processor is coupled to a central processing unit, enabling on-device recording via the microphone and on-device playback of stored sound via the speaker.
[0089] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0090] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A system that specifies functions in one or more boxes.
[0091] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including an instruction set implemented in a process. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0092] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the functions specified in one or more boxes. Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the invention.
[0093] The above description is merely a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A privacy protection detection method based on a custom ROM, characterized in that, include: S1. Obtain historical privacy samples and construct a priori set of privacy samples; Extract sensitive function information of the application and the corresponding permission information of the sensitive functions from the privacy sample prior set; A list of sensitive functions is established using sensitive function information; a set of prior permission feature vectors is constructed using the permission information corresponding to the sensitive functions. The prior permission feature vector set is trained using the first neural network model to obtain the prior permission sample set model file; Establish a table relating sensitive functions to permissions; S2. Obtain the applications installed by the user; The application's installation files are parsed, and the parsing results include: application call functions and a set of application permission files; S3. Determine if the function called by the application is in the list of sensitive functions; if the function called by the application is in the list of sensitive functions, obtain the application permission file corresponding to the function called by the application, which is the matching application permission file; S4. Construct feature vectors for matching application permission files; train the feature vectors for matching application permission files based on the first neural network model to obtain the matching application permission model file; S5. Compare the matching application permission model file with the prior permission sample set model file to determine whether the application's function call permission can be enabled, and obtain the result of enabling the application's function call permission.
2. The method as described in claim 1, characterized in that, The privacy sample set includes both privacy-violating samples and privacy-non-violating samples.
3. The method as described in claim 1, characterized in that, The sensitive function list includes: function codes and function names; the prior permission sample set model file includes: permission name, permission code, and whether the permission can be enabled; the sensitive function and permission relationship table includes: function code, permission code, and the correspondence between function and permission.
4. The method as described in claim 1, characterized in that, Step S3 includes the following steps: S31, obtaining the function code if the application calls a function; S32. Based on the function code of the application call function, query the permission code corresponding to the function code of the application call function in the sensitive function and permission relationship table, and find the matching permission code; S33. Search for application permission files in the application permission file set based on matching permission codes, and find the matching application permission files.
5. The method as described in claim 1, characterized in that, It also includes step S6, which involves modifying the AOSP source code to print the results of enabling application call function permissions.
6. The method as described in claim 1, characterized in that, The first neural network model is a data mining classification model.
7. A privacy protection detection system based on a custom ROM, characterized in that, include: The prior knowledge building module is used to acquire historical privacy samples and construct a prior set of privacy samples; Extract sensitive function information and corresponding permission information of the application from the privacy sample prior set; build a list of sensitive functions based on the sensitive function information; construct a prior permission feature vector set based on the permission information corresponding to the sensitive functions; The prior permission feature vector set is trained using the first neural network model to obtain the prior permission sample set model file; Establish a table relating sensitive functions to permissions; The parsing module is used to obtain the applications installed by the user; The application's installation files are parsed, and the parsing results include: application call functions and a set of application permission files; The permission file acquisition module is used to determine whether the application's called function is in the sensitive function list; if the application's called function is in the sensitive function list, the module acquires the application permission file corresponding to the application's called function, which is the matching application permission file. The permission model file construction module is used to construct feature vectors that match application permission files; the feature vectors of the matching application permission files are trained based on the first neural network model to obtain the matching application permission model file; The permission enable judgment module is used to compare the matching application permission model file with the prior permission sample set model file to determine whether the application's function call permission can be enabled, and obtain the result of enabling the application's function call permission.
8. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements the privacy protection detection method based on a custom ROM as described in any one of claims 1 to 6.
9. An electronic device, characterized in that, Including processor and memory; The memory is used to store the prior permission sample set model file, the list of sensitive functions, and the table of the relationship between sensitive functions and permissions; The processor is configured to execute the privacy protection detection method based on a custom ROM as described in any one of claims 1 to 6 by calling the prior permission sample set model file, the sensitive function list, and the sensitive function and permission relationship table.
10. A computer program product comprising a computer program and / or instructions, characterized in that, When the computer program and / or instructions are executed by the processor, they implement the steps of the privacy protection detection method based on a custom ROM as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Android privacy disclosure detection method and system based on machine learning
CN114996701A