High-risk APP detection method, device, electronic device and storage medium

By extracting the URL in the network traffic log and matching it with the preset high-risk APP fingerprint feature library, the problem of low detection efficiency and accuracy of high-risk APPs in the existing technology is solved, and more efficient and accurate detection is achieved.

CN115499237BActive Publication Date: 2025-05-16NSFOCUS INFORMATION TECHNOLOGY CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211198715.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-29
Publication Date
2025-05-16
Estimated Expiration
2042-09-29

AI Technical Summary

Technical Problem

Existing high-risk APP detection methods rely on manual fingerprint capture, resulting in low detection efficiency and accuracy.

Method used

By obtaining the network traffic log of the target account, extracting the URL, and matching it with the features in the preset high-risk APP fingerprint feature library, the fingerprint features of the high-risk APP are determined using the correspondence between the URL and the weight.

Benefits of technology

It improves the efficiency and accuracy of high-risk APP detection, and is more automated and efficient than manual methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115499237B_ABST
    Figure CN115499237B_ABST
Patent Text Reader

Abstract

The present application discloses a high-risk APP detection method, device, electronic device and storage medium to solve the problems of low efficiency and accuracy of existing high-risk APP detection. The high-risk APP detection method includes: obtaining the network traffic log of the target account within the time period to be detected; extracting the uniform resource locator URL in the network traffic log; matching the URL in the network traffic log with the high-risk APP fingerprint feature in the preset high-risk APP fingerprint feature library, and determining the target high-risk APP used by the target account according to the matching result, wherein each high-risk APP fingerprint feature is used to identify the corresponding high-risk APP, and the high-risk APP fingerprint feature includes a set of corresponding relationships between the URL and weight contained in the high-risk APP.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to high-risk APP detection methods, devices, electronic devices and storage media. Background Art

[0002] This section is intended to provide a background or context to the embodiments of the application that are recited in the claims. No description herein is admitted to be prior art by inclusion in this section.

[0003] Due to the diversity of the Internet, Internet black and gray industries such as online fraud, routine loans, marketing promotion cheating (such as order brushing) are emerging in an endless stream and are difficult to identify. Illegal personnel use high-risk APPs (Applications) such as "multiple applications" of smart terminal devices, virtual positioning and machine modification tools to illegally obtain user account information, batch log in, manipulate accounts, disrupt the normal order of the enterprise market, induce users to be deceived, and cause enterprises and users to suffer huge losses. The current detection of high-risk APPs is to manually capture the fingerprint features of high-risk APPs, where the fingerprint features of high-risk APPs are the URLs generated when using the high-risk APPs, and compare the URLs (Uniform Resource Locators) in the network traffic of the account to the Internet with the fingerprint features of the high-risk APPs, and analyze whether the URLs in the network traffic are the URLs of the high-risk APPs. However, the manual capture of the fingerprint features of high-risk APPs is slow, the number is small, the time is long, and the accuracy of the fingerprint features of the high-risk APPs obtained is not high, which affects the detection efficiency and accuracy of high-risk APPs. Summary of the invention

[0004] In order to solve the problems of low efficiency and accuracy in existing high-risk APP detection, the embodiments of the present application provide a high-risk APP detection method, device, electronic device and storage medium.

[0005] In a first aspect, the present application embodiment provides a high-risk APP detection method, including:

[0006] Obtain the network traffic log of the target account within the time period to be detected;

[0007] Extracting a uniform resource locator URL from the network traffic log;

[0008] The URL in the network traffic log is matched with the high-risk APP fingerprint features in the preset high-risk APP fingerprint feature library, and the target high-risk APP used by the target account is determined according to the matching result, wherein each high-risk APP fingerprint feature is used to identify the corresponding high-risk APP, and the high-risk APP fingerprint feature includes a set of corresponding relationships between the URLs and weights contained in the high-risk APP.

[0009] In a possible implementation, the high-risk APP fingerprint feature is obtained by:

[0010] Obtain high-risk APP installation packages, and send each high-risk APP installation package to a test terminal device for installation, so that the test terminal device performs a click operation on each installed high-risk APP using a preset simulation tool;

[0011] For each high-risk APP, obtaining a test URL generated by the test terminal device during a click operation on the high-risk APP;

[0012] Determine the initial weight of each test URL according to the number of each test URL and the total number of test URLs;

[0013] Adjusting the initial weight of each test URL according to the domain name information contained in each test URL and the attribute information of each test URL to obtain the target weight of each test URL;

[0014] A set generated by the correspondence between the test URLs and their respective target weights is determined as the high-risk APP fingerprint feature.

[0015] In a possible implementation, adjusting the initial weight of each test URL according to the domain name information contained in each test URL and the attribute information of each test URL to obtain the target weight of each test URL specifically includes:

[0016] For each test URL, if it is determined that the domain name information included in the test URL is a preset public domain name, the initial weight of the test URL is subtracted from the first set value to obtain the target weight of the test URL;

[0017] If it is determined that the domain name information included in the test URL is a designated high-risk domain name, the initial weight of the test URL is added to the second set value to obtain the target weight of the test URL;

[0018] If it is determined that the attribute information of the test URL is a static URL, the initial weight of the test URL is added to the third set value to obtain the target weight of the test URL.

[0019] In a possible implementation, the method further includes:

[0020] Obtaining a first URL generated by the test terminal device before performing a click operation on the high-risk APP; and

[0021] After obtaining the test URL generated by the test terminal device during the click operation on the high-risk APP, the method further includes:

[0022] If it is determined that the test URL contains the first URL, the first URL is removed from the test URL.

[0023] In a possible implementation, matching the URL in the network traffic log with the high-risk APP fingerprint feature in a preset high-risk APP fingerprint feature library, and determining the target high-risk APP used by the target account according to the matching result, specifically includes:

[0024] Compare each test URL in each high-risk APP fingerprint feature with the test URLs in other high-risk APP fingerprint features, and remove the same test URLs and their target weights in each high-risk APP fingerprint feature as those in other high-risk APP fingerprint features, to obtain each updated high-risk APP fingerprint feature;

[0025] For each updated high-risk APP fingerprint feature, take the intersection of the URL in the network traffic log and the test URL in the updated high-risk APP fingerprint feature;

[0026] If it is determined that the sum of the target weights of the test URLs in the intersection is greater than a preset threshold, it is determined that the target account has used the high-risk APP.

[0027] In a second aspect, an embodiment of the present application provides a high-risk APP detection device, including:

[0028] A first acquisition unit is used to acquire a network traffic log of a target account within a time period to be detected;

[0029] An extraction unit, used to extract a uniform resource locator URL from the network traffic log;

[0030] A determination unit is used to match the URL in the network traffic log with the high-risk APP fingerprint features in a preset high-risk APP fingerprint feature library, and determine the target high-risk APP used by the target account according to the matching result, wherein each high-risk APP fingerprint feature is used to identify the corresponding high-risk APP, and the high-risk APP fingerprint feature includes a set of corresponding relationships between the URLs and weights contained in the high-risk APP.

[0031] In a possible implementation, the determination unit is specifically used to obtain the high-risk APP fingerprint feature in the following manner: obtain a high-risk APP installation package, send each high-risk APP installation package to a test terminal device for installation, so that the test terminal device performs a click operation on each installed high-risk APP using a preset simulation tool; for each high-risk APP, obtain a test URL generated by the test terminal device during the click operation on the high-risk APP; determine the initial weight of each test URL according to the number of each test URL and the total number of test URLs; adjust the initial weight of each test URL according to the domain name information contained in each test URL and the attribute information of each test URL, and obtain the target weight of each test URL; determine the set generated by the correspondence between each test URL and their respective target weights as the high-risk APP fingerprint feature.

[0032] In one possible implementation, the determination unit is specifically used to, for each test URL, if it is determined that the domain name information contained in the test URL is a preset public domain name, then subtract the first set value from the initial weight of the test URL to obtain the target weight of the test URL; if it is determined that the domain name information contained in the test URL is a designated high-risk domain name, then add the second set value to the initial weight of the test URL to obtain the target weight of the test URL; if it is determined that the attribute information of the test URL is a static URL, then add the third set value to the initial weight of the test URL to obtain the target weight of the test URL.

[0033] In a possible implementation manner, the device further includes:

[0034] A second acquisition unit is used to acquire a first URL generated by the test terminal device before a click operation is performed on the high-risk APP;

[0035] The removing unit is used to remove the first URL from the test URL if it is determined that the test URL contains the first URL after obtaining the test URL generated by the test terminal device during the click operation on the high-risk APP.

[0036] In one possible implementation, the determination unit is specifically used to compare each test URL in each high-risk APP fingerprint feature with the test URLs in other high-risk APP fingerprint features, and eliminate the test URLs and their target weights in each high-risk APP fingerprint feature that are the same as those in other high-risk APP fingerprint features, to obtain each updated high-risk APP fingerprint feature; for each updated high-risk APP fingerprint feature, take the intersection of the URLs in the network traffic log and the test URLs in the updated high-risk APP fingerprint feature; if it is determined that the sum of the target weights of the test URLs in the intersection is greater than a preset threshold, it is determined that the target account has used the high-risk APP.

[0037] In a third aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the high-risk APP detection method described in the present application when executing the program.

[0038] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium on which a computer program is stored, which, when executed by a processor, implements the steps in the high-risk APP detection method described in the present application.

[0039] The beneficial effects of the embodiments of the present application are as follows:

[0040] In a high-risk APP detection method provided in an embodiment of the present application, a server obtains a network traffic log of a target account within a time period to be detected, extracts a URL in the network traffic log, matches the URL in the network traffic log with a high-risk APP fingerprint feature in a preset high-risk APP fingerprint feature library, and determines a target high-risk APP used by the target account according to the matching result, wherein each high-risk APP fingerprint feature is used to identify a corresponding high-risk APP, and the high-risk APP fingerprint feature includes a set of corresponding relationships between URLs and weights contained in the high-risk APP. Compared with the existing method of manually capturing fingerprint features of high-risk APPs to detect high-risk APPs, in the high-risk APP detection method provided in an embodiment of the present application, a high-risk APP fingerprint feature library is pre-established, and a set of corresponding relationships between a set of URLs and weights contained in the high-risk APP is used as a high-risk APP fingerprint feature, which has higher accuracy. By matching all URLs in the network traffic log of the target account's Internet access within the time period to be detected with a set of corresponding relationships between URLs and weights contained in each high-risk APP, it is determined whether the target account has used the high-risk APP, thereby improving the efficiency of high-risk APP detection and the accuracy of high-risk APP detection.

[0041] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or be understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0043] Figure 1 A schematic diagram of an application scenario of the high-risk APP detection method provided in an embodiment of the present application;

[0044] Figure 2 A schematic diagram of the implementation process of the high-risk APP detection method provided in the embodiment of the present application;

[0045] Figure 3 A schematic diagram of the implementation process of generating high-risk APP fingerprint features provided in an embodiment of the present application;

[0046] Figure 4 A schematic diagram of an implementation process for determining high-risk APPs used by a target account provided in an embodiment of the present application;

[0047] Figure 5 A schematic diagram of the structure of a high-risk APP detection device provided in an embodiment of the present application;

[0048] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0049] In order to solve the problems in the background technology, the embodiments of the present application provide a high-risk APP detection method, device, electronic device and storage medium.

[0050] The preferred embodiments of the present application are described below in conjunction with the drawings in the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application. In addition, the embodiments and features in the embodiments of the present application may be combined with each other if there is no conflict.

[0051] First reference Figure 1, which is a schematic diagram of an application scenario of the high-risk APP detection method provided in the embodiment of the present application, and may include a terminal device 101, a network traffic monitoring platform 102, a server 103 and a test terminal device 104. The terminal device 101 and the network traffic monitoring platform 102 are connected through a network, the network traffic monitoring platform 102 and the server 103 are connected through a network, and the server 103 and the test terminal device 104 are connected through a network. The terminal device 101 is the terminal used by the target account (i.e., the account to be detected), and the network traffic monitoring platform 102 can monitor and record the Internet traffic of the target account by binding the mobile phone card number of the target account, and generate a network traffic log, which contains the URL information visited by the target account when surfing the Internet. The server 103 obtains a large number of high-risk APP installation packages in advance, sends each high-risk APP installation package to the test terminal device 104, and instructs the test terminal device 104 to automatically install each high-risk APP installation package. The high-risk APP installation package uses a simulation tool to perform a click operation on each high-risk APP after installation. The server 103 starts a packet capture command to obtain the test URL generated by the test terminal device during the click operation on each high-risk APP, generates a respective fingerprint feature according to each test URL of each high-risk APP and its corresponding weight, and stores the fingerprint feature of each high-risk APP in the high-risk APP fingerprint feature library. When performing a high-risk APP usage detection on the target account, the server 103 obtains the network traffic log of the target account within the time period to be detected from the network traffic monitoring platform 102, extracts the URL visited by the target account in the network traffic log, matches the URL in the network log with the high-risk APP fingerprint feature in the high-risk APP fingerprint feature library, and determines the high-risk APP used by the target account based on the matching result.

[0052] The server 103 may be an independent physical server or a cloud server that provides basic cloud computing services such as cloud servers, cloud databases, and cloud storage. The terminal device 110 may be, but is not limited to, a smart phone, a tablet computer, a laptop computer, a desktop computer, etc. The server 103 and the test terminal device terminal 104 may be connected via a network, which is not limited in the present embodiment of the application.

[0053] Based on the above application scenarios, the following will refer to the attached Figures 2 to 4 The exemplary embodiments of the present application are described in more detail. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principle of the present application, and the implementation of the present application is not limited in any way. On the contrary, the implementation of the present application can be applied to any applicable scenario.

[0054] like Figure 2As shown, it is a schematic diagram of the implementation process of the high-risk APP detection method provided in the embodiment of the present application. The high-risk APP detection method can be applied to the above-mentioned server 103, and specifically may include the following steps:

[0055] S21. Obtain the network traffic log of the target account within the time period to be detected.

[0056] In specific implementation, the server can detect the use of high-risk APPs of the target account (i.e., the account to be detected) according to the preset detection time period. The preset detection time period can be set according to the needs. For example, the detection time period can be set to 1 hour, and the detection is performed once every hour. The embodiment of the present application does not limit this. Assuming that the time period to be detected is the previous hour, the server obtains the network traffic log of the target account's Internet access in the previous hour from the network traffic monitoring platform according to the mobile phone card number bound to the target account. The network traffic log contains all URL information visited by the target account when it was online in the previous hour.

[0057] S22. Extract URLs from the network traffic log.

[0058] In specific implementation, the server extracts all URLs in the network log, that is, all URLs visited by the target user during the time period to be detected.

[0059] S23. Match the URL in the network traffic log with the high-risk APP fingerprint features in the preset high-risk APP fingerprint feature library, and determine the target high-risk APP used by the target account according to the matching result, wherein each high-risk APP fingerprint feature is used to identify the corresponding high-risk APP, and the high-risk APP fingerprint feature includes a set of corresponding relationships between the URLs and weights contained in the high-risk APP.

[0060] In the specific implementation, the server pre-establishes a high-risk APP fingerprint feature library, which stores a large number of high-risk APP fingerprint features. High-risk APPs can include but are not limited to the following types of APPs: key wizard, multiple clones, machine modification, IMEI (International Mobile Equipment Identity, International Mobile Equipment Identity Code), order brushing, flash sales, virtual positioning, etc. A high-risk APP fingerprint feature is used to uniquely identify the high-risk APP. A high-risk APP fingerprint feature is a set of corresponding relationships between a set of URLs and their weights, where a set of URLs is the URL generated when the high-risk APP is used, and each URL is a unique URL for the high-risk APP.

[0061] You can follow Figure 3 The process shown generates fingerprint features for each high-risk APP, including the following steps:

[0062] S31. Obtain high-risk APP installation packages, and send each high-risk APP installation package to a test terminal device for installation, so that the test terminal device performs a click operation on each installed high-risk APP using a preset simulation tool.

[0063] During specific implementation, the server can use crawler tools to obtain a large number of high-risk APP installation packages from websites that provide APP installation package downloads (such as APP application markets). The server can use crawler tools to search major APP application markets with keywords such as "key wizard", "multiple clones", "change machine", "change IMEI", "brushing orders", "flash sales", and "virtual positioning" to obtain a series of high-risk APP installation packages of the above types. Then, the server parses each high-risk APP installation package, extracts the name and version information of each high-risk APP, and stores the name and version information of each high-risk APP in a database. The server sends each high-risk APP installation package to the test terminal device, and sends an installation instruction to the test terminal device. After receiving the installation instruction sent by the server, the test terminal device automatically installs each high-risk APP according to each high-risk APP installation package. Then, the test terminal device can perform a click operation on each high-risk APP in turn using a preset simulation tool. When performing a click operation on a high-risk APP, the test terminal device will issue a URL request, which is recorded as a test URL. For each high-risk APP, in order to obtain a fingerprint feature that uniquely identifies the high-risk APP, in order to avoid misjudging the URL generated when using other high-risk APPs as the URL generated when using the high-risk APP, it is not possible to perform a click operation on multiple high-risk APPs at the same time. It is necessary to wait for the terminal device to complete the click operation on a high-risk APP using the preset simulation tool before testing the next high-risk APP. Among them, the preset simulation tool can be, but is not limited to, the Monkey simulation tool, and the embodiments of the present application do not limit this.

[0064] S32. For each high-risk APP, obtain a test URL generated by the test terminal device during a click operation on the high-risk APP.

[0065] In specific implementation, before the test terminal device uses the simulation tool to perform a click operation on each high-risk APP after installation, that is, when the test terminal device does not run any high-risk APP, the test terminal device will still send a URL, for example, the URL generated by the OTA (Over-the-Air Technology) of the test terminal device manufacturer, such as the URL generated when the manufacturer of the test terminal device releases a new system version and the system version needs to be upgraded and updated; there are also some external link URLs generated when the background services of some non-high-risk applications are running, such as the URL generated when the WeChat APP sends and receives messages. Obviously, these URLs do not belong to the URLs generated when the high-risk APP is running. Therefore, in order to improve the accuracy of extracting high-risk APP fingerprint features, the URL generated when the test terminal device does not run any high-risk APP can be removed from the test URLs corresponding to each high-risk APP generated by the test terminal when using the simulation tool to perform a click operation on each high-risk APP.

[0066] Specifically, the server obtains a URL generated by the test terminal device before using the simulation tool to perform a click operation on each high-risk APP, which can be recorded as the first URL.

[0067] Furthermore, for each high-risk APP, when the test terminal device uses the simulation tool to perform a click operation on the high-risk APP, the server initiates a packet capture command to obtain the test URL generated by the test terminal device during the click operation on the high-risk APP, wherein the number of click operations performed by the test terminal device using the simulation tool on the high-risk APP can be set in advance, for example, it can be set to 1,000 clicks, and can be set according to needs during implementation, and the embodiments of the present application are not limited to this.

[0068] For each high-risk APP, after obtaining the test URL generated by the test terminal device during the click operation on the high-risk APP, the server performs the following operations: if it is determined that the test URL contains the first URL, the first URL is removed from the test URL. In this way, a set of test URLs corresponding to each high-risk APP after the first URL is removed can more accurately identify the fingerprint of each high-risk APP.

[0069] In order to ensure that the fingerprint characteristics of high-risk APPs do not cause the URL in the network traffic log of the blacklisted mobile phone card number to be unable to match the URL in the high-risk APP fingerprint characteristic library (i.e., the test URL) due to different accounts (such as different mobile phone models, mobile phone card numbers, etc. of the users), a large number of parameter values ​​contained in the test URL can be deleted, while the parameter names are retained. During implementation, the parameter values ​​can be deleted by matching regular expressions. For example, if a parameter name in the test URL is "mobile phone card number" and the parameter value is "1XXXXXXXXXX", "1XXXXXXXXXX" can be deleted, while the parameter name "mobile phone card number" is retained.

[0070] S33. Determine the initial weight of each test URL according to the number of each test URL and the total number of test URLs.

[0071] In specific implementation, for each high-risk APP, the ratio of the number of each test URL corresponding to the high-risk APP to the total number of test URLs corresponding to the high-risk APP can be used to determine the initial weight of each test URL. For example, the total number of test URLs corresponding to a certain high-risk APP is 10, including one test URL1, three test URL2s, two test URL3s, and four test URL4s. The initial weight of test URL1 is: 1 / 10 = 0.1, the initial weight of test URL2 is: 3 / 10 = 0.3, the initial weight of test URL3 is: 2 / 10 = 0.2, and the initial weight of test URL4 is: 4 / 10 = 0.4.

[0072] S34. Adjust the initial weight of each test URL according to the domain name information contained in each test URL and the attribute information of each test URL to obtain the target weight of each test URL.

[0073] During specific implementation, in order to further improve the accuracy of extracting fingerprint features of high-risk apps, the server may adjust the initial weight of each test URL according to the domain name information contained in each test URL and the attribute information of each test URL.

[0074] Specifically, the adjustment of the initial weight of each test URL may include at least the following three situations:

[0075] Case 1: If it is determined that the domain name information included in the test URL is a preset public domain name, the initial weight of the test URL is subtracted from the first set value to obtain the target weight of the test URL.

[0076] The preset public domain name is a non-high-risk public domain name, such as common public domain names such as "qq.com", "taobao.com", "weixin.com", etc. If a test URL corresponding to a high-risk APP contains a public domain name, then the test URL is most likely not a URL unique to the high-risk APP. Therefore, the initial weight of the test URL can be subtracted from the first set value, which can be set voluntarily, for example, it can be set to 0.3, and this embodiment of the application does not limit this.

[0077] Case 2: If it is determined that the domain name information included in the test URL is a designated high-risk domain name, the initial weight of the test URL is added to the second set value to obtain the target weight of the test URL.

[0078] Among them, the designated high-risk domain name is a domain name containing keywords related to the high-risk APP type. For example, the high-risk APP is a "multi-open clone" APP, and the test URL contains "duokai" (the pinyin of "multiple openings"), "dk" (abbreviation of "multiple openings"), "fenshen" (the pinyin of "clone"), "fs" (abbreviation of "clone") and other keywords related to the "multi-open clone" APP. If a test URL corresponding to a high-risk APP contains a designated high-risk domain name, then the test URL is most likely a URL unique to the high-risk APP. Therefore, the initial weight of the test URL can be added to the second set value, and the second set value can be set by itself, for example, it can be set to 0.3, and the embodiments of the present application do not limit this.

[0079] Case three: If it is determined that the attribute information of the test URL is a static URL, the initial weight of the test URL is added to the third set value to obtain the target weight of the test URL.

[0080] Among them, a static URL refers to a URL ending with a static suffix such as ".png" or ".jpeg". If a test URL in the test URL corresponding to a high-risk APP is a static URL, then the test URL is most likely the URL issued when the high-risk APP page is loaded. Therefore, the initial weight of the test URL can be added to the third set value, and the second set value can be set by itself, for example, it can be set to 0.2, and this embodiment of the present application is not limited to this.

[0081] S35. Determine a set generated by the correspondence between each test URL and each target weight as a high-risk APP fingerprint feature.

[0082] During specific implementation, the above-mentioned weight adjustment operation is performed for the test URL corresponding to each high-risk APP, and the set generated by the correspondence between each test URL corresponding to each high-risk APP and their respective target weights is respectively determined as the fingerprint feature of each high-risk APP, and each high-risk APP fingerprint feature is stored in the high-risk APP fingerprint feature library. If a new high-risk APP appears, the new high-risk APP fingerprint feature can also be obtained and stored in the high-risk APP fingerprint feature library to expand the high-risk APP fingerprint feature library in real time.

[0083] In implementation, after extracting the URL from the target account's network traffic log, the server can follow the steps below: Figure 4 The process shown matches the URL in the network traffic log with the fingerprint features of each high-risk APP in the high-risk APP fingerprint library to determine the target high-risk APP used by the target account, including the following steps:

[0084] S41. Compare each test URL in each high-risk APP fingerprint feature with the test URLs in other high-risk APP fingerprint features, and eliminate the test URLs and their target weights in each high-risk APP fingerprint feature that are the same as those in other high-risk APP fingerprint features, to obtain updated high-risk APP fingerprint features.

[0085] During specific implementation, in order to further ensure the uniqueness of each high-risk APP fingerprint feature in the high-risk APP fingerprint feature library and to further improve the accuracy of each high-risk APP fingerprint feature, the server compares each test URL in the high-risk APP fingerprint feature with the test URLs in other high-risk APP fingerprint features for each high-risk APP fingerprint feature, and removes the test URLs and their target weights in each high-risk APP fingerprint feature that are the same as those in other high-risk APP fingerprint features, to obtain each updated high-risk APP fingerprint feature. In this way, each updated high-risk APP fingerprint feature only retains the URL that belongs to itself and not to other high-risk APPs.

[0086] Specifically, the updated high-risk APP fingerprint features can be obtained in the following way: the server can perform difference operations on the sets of test URLs and target weights corresponding to the high-risk APP fingerprint features, and simultaneously remove the same test URLs and their target weights in the sets of test URLs and target weights corresponding to every two high-risk APP fingerprint features from the sets of test URLs and target weights corresponding to the two high-risk APP fingerprint features. For example, the high-risk APP1 fingerprint includes test URL0, test URL1, test URL2, test URL3, test URL4, and the target weights corresponding to test URL0-test URL4 respectively; the high-risk APP2 fingerprint includes test URL1, test URL4, test URL5, test URL6, test URL7, test URL8, and the target weights corresponding to test URL1, URL4-test URL8 respectively; the high-risk APP3 fingerprint includes URL1, test URL2, test URL9, test URL10, and the target weights corresponding to test URL1, test URL2, test URL9, and test URL10 respectively. Since the high-risk APP1 fingerprint and the high-risk APP2 both include: test URL1 and test URL4, the test URL1, test URL4 and their respective target weights are added from the test URL set corresponding to the high-risk APP1 fingerprint and the test URL set corresponding to the high-risk APP2 fingerprint. Remove from the test URL set. Since test URL1 and test URL2 are included in the high-risk APP1 fingerprint feature and the high-risk APP3 fingerprint feature, test URL1, test URL2 and their respective target weights should be removed from the test URL set corresponding to the high-risk APP1 fingerprint feature and the test URL set corresponding to the high-risk APP3 fingerprint feature. Since test URL1 is included in both high-risk APP2 and high-risk APP3, test URL1 and its target weight should be removed from the test URL set corresponding to the high-risk APP2 fingerprint feature and the test URL set corresponding to the high-risk APP3 fingerprint feature. The updated high-risk APP1 fingerprint feature is: test URL0, test URL3 and their respective target weights. The updated high-risk APP2 fingerprint feature is: test URL5, test URL6, test URL7, test URL8 and their respective target weights. The updated high-risk APP3 fingerprint feature is: test URL9, test URL10 and their respective target weights.

[0087] S42. For each updated high-risk APP fingerprint feature, take the intersection of the URL in the network traffic log and the test URL in the updated high-risk APP fingerprint feature.

[0088] In specific implementation, the server takes the intersection of the URL in the network traffic log with the test URL in each updated high-risk APP fingerprint feature, and obtains the intersection corresponding to the URL in the network traffic log and the test URL in each updated high-risk APP fingerprint feature.

[0089] S43: If it is determined that the sum of the target weights of the test URLs in the intersection is greater than a preset threshold, it is determined that the target account has used the high-risk APP.

[0090] In the specific implementation, for the intersection of the URL in the network traffic log and the test URL in each updated high-risk APP fingerprint feature, if it is determined that the sum of the target weights of the test URLs in the intersection is greater than the preset threshold, it can be determined that the target account has used the high-risk APP during the time period to be detected, and the high-risk APP is determined as the target high-risk APP. In this way, it is possible to detect which high-risk APPs the target account has used during the time period to be detected, where the preset threshold can be set according to the experience value, for example, it can be set to 1, and the embodiments of the present application are not limited to this.

[0091] A high-risk APP detection method provided in an embodiment of the present application comprises the following steps: a server obtains a network traffic log of a target account within a time period to be detected, extracts a URL in the network traffic log, matches the URL in the network traffic log with a high-risk APP fingerprint feature in a preset high-risk APP fingerprint feature library, and determines a target high-risk APP used by the target account according to the matching result, wherein each high-risk APP fingerprint feature is used to identify a corresponding high-risk APP, and the high-risk APP fingerprint feature includes a set of corresponding relationships between URLs and weights contained in the high-risk APP. Compared with the existing method of manually capturing fingerprint features of high-risk APPs to detect high-risk APPs, in the high-risk APP detection method provided in an embodiment of the present application, a high-risk APP fingerprint feature library is established in advance, and a set of corresponding relationships between a set of URLs and weights contained in the high-risk APP is used as a high-risk APP fingerprint feature, which has higher accuracy. By matching all URLs in the network traffic log of the target account's Internet access within the time period to be detected with a set of corresponding relationships between URLs and weights contained in each high-risk APP, it is determined whether the target account has used the high-risk APP, thereby improving the efficiency of high-risk APP detection and the accuracy of high-risk APP detection.

[0092] Based on the same inventive concept, an embodiment of the present application also provides a high-risk APP detection device. Since the principle of solving the problem by the above-mentioned high-risk APP detection device is similar to that of the above-mentioned high-risk APP detection method, the implementation of the above-mentioned device can refer to the implementation of the method, and the repeated parts will not be repeated.

[0093] like Figure 5As shown, it is a schematic diagram of the structure of a high-risk APP detection device provided in an embodiment of the present application, which may include:

[0094] The first acquisition unit 51 is used to acquire the network traffic log of the target account within the time period to be detected;

[0095] An extraction unit 52, used to extract a uniform resource locator URL from the network traffic log;

[0096] The determination unit 53 is used to match the URL in the network traffic log with the high-risk APP fingerprint features in a preset high-risk APP fingerprint feature library, and determine the target high-risk APP used by the target account according to the matching result, wherein each high-risk APP fingerprint feature is used to identify the corresponding high-risk APP, and the high-risk APP fingerprint feature includes a set of corresponding relationships between the URL and the weight contained in the high-risk APP.

[0097] In a possible implementation, the determination unit 53 is specifically used to obtain the high-risk APP fingerprint feature in the following manner: obtain a high-risk APP installation package, send each high-risk APP installation package to a test terminal device for installation, so that the test terminal device performs a click operation on each installed high-risk APP using a preset simulation tool; for each high-risk APP, obtain a test URL generated by the test terminal device during the click operation on the high-risk APP; determine the initial weight of each test URL according to the number of each test URL and the total number of test URLs; adjust the initial weight of each test URL according to the domain name information contained in each test URL and the attribute information of each test URL, and obtain the target weight of each test URL; determine the set generated by the correspondence between each test URL and their respective target weights as the high-risk APP fingerprint feature.

[0098] In one possible implementation, the determination unit 53 is specifically used to, for each test URL, if it is determined that the domain name information contained in the test URL is a preset public domain name, then subtract the first set value from the initial weight of the test URL to obtain the target weight of the test URL; if it is determined that the domain name information contained in the test URL is a specified high-risk domain name, then add the second set value to the initial weight of the test URL to obtain the target weight of the test URL; if it is determined that the attribute information of the test URL is a static URL, then add the third set value to the initial weight of the test URL to obtain the target weight of the test URL.

[0099] In a possible implementation manner, the device further includes:

[0100] A second acquisition unit is used to acquire a first URL generated by the test terminal device before a click operation is performed on the high-risk APP;

[0101] The removing unit is used to remove the first URL from the test URL if it is determined that the test URL contains the first URL after obtaining the test URL generated by the test terminal device during the click operation on the high-risk APP.

[0102] In a possible implementation, the determination unit 53 is specifically used to compare each test URL in each high-risk APP fingerprint feature with the test URLs in other high-risk APP fingerprint features, and eliminate the test URLs and their target weights in each high-risk APP fingerprint feature that are the same as those in other high-risk APP fingerprint features, to obtain each updated high-risk APP fingerprint feature; for each updated high-risk APP fingerprint feature, take the intersection of the URL in the network traffic log and the test URL in the updated high-risk APP fingerprint feature; if it is determined that the sum of the target weights of the test URLs in the intersection is greater than a preset threshold, it is determined that the target account has used the high-risk APP.

[0103] Based on the same technical concept, the embodiment of the present invention further provides an electronic device 600, referring to Figure 6 As shown, the electronic device 600 is used to implement the high-risk APP detection method described in the above method embodiment. The electronic device 600 of this embodiment may include: a memory 601, a processor 602, and a computer program stored in the memory and executable on the processor, such as a high-risk APP detection program. When the processor executes the computer program, the steps in the above high-risk APP detection method embodiments are implemented, such as Figure 2 Alternatively, the processor implements the functions of each module / unit in the above-mentioned device embodiments, such as step 51, when executing the computer program.

[0104] The specific connection medium between the memory 601 and the processor 602 is not limited in the embodiment of the present invention. Figure 6 In the embodiment, the memory 601 and the processor 602 are connected via a bus 603. The bus 603 is Figure 6 The connection between other components is shown by bold lines, which is only for schematic illustration and is not intended to be limiting. The bus 603 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0105] The memory 601 may be a volatile memory, such as a random-access memory (RAM); the memory 601 may also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD), or the memory 601 may be any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 601 may be a combination of the above memories.

[0106] Processor 602, used to implement Figure 2 A high-risk APP detection method shown includes:

[0107] The processor 602 is used to call the computer program stored in the memory 601 to execute the following Figure 2 Steps S21 to S23 shown in FIG.

[0108] An embodiment of the present application also provides a computer-readable storage medium that stores computer-executable instructions required to execute the above-mentioned processor, which includes a program required to execute the above-mentioned processor.

[0109] In some possible implementations, various aspects of the high-risk APP detection method provided by the present invention may also be implemented in the form of a program product, which includes a program code. When the program product is run on an electronic device, the program code is used to enable the electronic device to execute the steps of the high-risk APP detection method according to various exemplary embodiments of the present invention described above in this specification. For example, the electronic device may execute the following steps: Figure 2 Steps S21 to S23 shown in FIG.

[0110] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, devices, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0111] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (apparatus), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0112] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0113] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0114] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0115] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. A high-risk APP detection method, characterized in that: include: Obtain the network traffic log of the target account within the time period to be detected; Extracting a uniform resource locator URL from the network traffic log; Matching the URL in the network traffic log with the high-risk APP fingerprint features in a preset high-risk APP fingerprint feature library, and determining the target high-risk APP used by the target account according to the matching result, specifically including: comparing each test URL in each high-risk APP fingerprint feature with the test URL in other high-risk APP fingerprint features, respectively eliminating the test URLs and their target weights that are the same in each high-risk APP fingerprint feature and other high-risk APP fingerprint features, respectively, to obtain each updated high-risk APP fingerprint feature, wherein each test URL in each high-risk APP fingerprint feature is a URL generated by the test terminal device during the test of the corresponding high-risk APP; for each updated high-risk APP fingerprint feature, taking the intersection of the URL in the network traffic log and the test URL in the updated high-risk APP fingerprint feature; if it is determined that the sum of the target weights of the test URLs in the intersection is greater than a preset threshold, it is determined that the target account has used the high-risk APP; wherein each high-risk APP fingerprint feature is used to identify the corresponding high-risk APP, and the high-risk APP fingerprint feature includes a set of corresponding relationships between the URLs and weights contained in the high-risk APP.

2. The method according to claim 1, characterized in that The high-risk APP fingerprint features are obtained in the following ways: Obtaining high-risk APP installation packages, and sending each high-risk APP installation package to the test terminal device for installation, so that the test terminal device respectively performs a click operation on each installed high-risk APP using a preset simulation tool; For each high-risk APP, obtaining a test URL generated by the test terminal device during a click operation on the high-risk APP; Determine the initial weight of each test URL according to the number of each test URL and the total number of test URLs; Adjusting the initial weight of each test URL according to the domain name information contained in each test URL and the attribute information of each test URL to obtain the target weight of each test URL; A set generated by the correspondence between the test URLs and their respective target weights is determined as the high-risk APP fingerprint feature.

3. The method according to claim 2, characterized in that The initial weights of the test URLs are adjusted according to the domain name information contained in the test URLs and the attribute information of the test URLs to obtain the target weights of the test URLs, specifically including: For each test URL, if it is determined that the domain name information included in the test URL is a preset public domain name, the initial weight of the test URL is subtracted from the first set value to obtain the target weight of the test URL; If it is determined that the domain name information included in the test URL is a designated high-risk domain name, the initial weight of the test URL is added to the second set value to obtain the target weight of the test URL; If it is determined that the attribute information of the test URL is a static URL, the initial weight of the test URL is added to the third set value to obtain the target weight of the test URL.

4. The method according to claim 3, characterized in that Also includes: Obtaining a first URL generated by the test terminal device before performing a click operation on the high-risk APP; as well as After obtaining the test URL generated by the test terminal device during the click operation on the high-risk APP, the method further includes: If it is determined that the test URL contains the first URL, the first URL is removed from the test URL.

5. A high-risk APP detection device, characterized in that: include: A first acquisition unit is used to acquire a network traffic log of a target account within a time period to be detected; An extraction unit, used to extract a uniform resource locator URL from the network traffic log; A determination unit, used to match the URL in the network traffic log with the high-risk APP fingerprint features in a preset high-risk APP fingerprint feature library, and determine the target high-risk APP used by the target account according to the matching result, wherein each high-risk APP fingerprint feature is used to identify the corresponding high-risk APP, and the high-risk APP fingerprint feature includes a set of corresponding relationships between the URLs and weights contained in the high-risk APP; The determination unit is specifically used to compare each test URL in each high-risk APP fingerprint feature with the test URLs in other high-risk APP fingerprint features, and eliminate the test URLs and their target weights in each high-risk APP fingerprint feature that are the same as those in other high-risk APP fingerprint features, to obtain each updated high-risk APP fingerprint feature, wherein each test URL in each high-risk APP fingerprint feature is a URL generated by the test terminal device during the testing process of the corresponding high-risk APP; for each updated high-risk APP fingerprint feature, the URL in the network traffic log is respectively intersected with the test URL in the updated high-risk APP fingerprint feature; if it is determined that the sum of the target weights of the test URLs in the intersection is greater than a preset threshold, it is determined that the target account has used the high-risk APP.

6. The device according to claim 5, characterized in that The determination unit is specifically used to obtain the high-risk APP fingerprint feature by the following method: obtaining a high-risk APP installation package, sending each high-risk APP installation package to the test terminal device for installation, so that the test terminal device performs a click operation on each installed high-risk APP using a preset simulation tool; For each high-risk APP, obtaining a test URL generated by the test terminal device during a click operation on the high-risk APP; Determine the initial weight of each test URL according to the number of each test URL and the total number of test URLs; Adjusting the initial weight of each test URL according to the domain name information contained in each test URL and the attribute information of each test URL to obtain the target weight of each test URL; A set generated by the correspondence between the test URLs and their respective target weights is determined as the high-risk APP fingerprint feature.

7. The device according to claim 6, characterized in that The determination unit is specifically used for, for each test URL, if it is determined that the domain name information included in the test URL is a preset public domain name, then subtracting a first set value from the initial weight of the test URL to obtain a target weight of the test URL; if it is determined that the domain name information included in the test URL is a designated high-risk domain name, then adding a second set value to the initial weight of the test URL to obtain the target weight of the test URL; If it is determined that the attribute information of the test URL is a static URL, the initial weight of the test URL is added to the third set value to obtain the target weight of the test URL.

8. An electronic device comprising a server, a memory, and a computer program stored in the memory and executable on a processor, wherein: When the server executes the computer program, the steps of the high-risk APP detection method according to any one of claims 1 to 4 are implemented.

9. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by the server, the steps of the high-risk APP detection method described in any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Malicious application program detection method, system and device, equipment and storage medium

    CN111597557A