Method, device and electronic device for identifying sensitive data of Internet of Things devices
The method constructs a semantic dictionary to identify IoT device sensitive data in applications, addressing scalability and cost issues by automating the identification process through semantic analysis of code blocks and alias tagging.
Patent Information
- Application Number
- CN202211247608.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-12
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-10-12
AI Technical Summary
The existing technology is difficult to automate and identify sensitive data of IoT devices on a large scale, and hardware acquisition is expensive, data interaction behavior depends on specific scenario triggering, and data encryption is difficult to parse.
By extracting sensitive data items from the description text information of IoT devices, building a sensitive semantic dictionary, using semantic information to filter code blocks of IoT applications, identify sensitive data points, and find their alias tag groups to achieve automated identification.
It realizes rapid, accurate and comprehensive identification of sensitive data of IoT devices, supports large-scale analysis, reduces identification costs, and broadens the scope of analysis.
Smart Images

Figure CN115544567B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a method, device and electronic equipment for identifying sensitive data of an Internet of Things device. Background Art
[0002] With the rapid development of mobile Internet, mobile terminals such as smartphones have become management terminals for various smart devices. IoT devices use mobile applications to achieve pairing, connection, management and other functions. In the process of interacting with smartphones, a large amount of sensitive data of IoT devices is involved.
[0003] Among the existing methods for analyzing sensitive data of IoT devices, researchers often use dynamic operation to collect the communication traffic of IoT devices and analyze the sensitive data involved in IoT devices. The main disadvantages of this type of method are: the hardware acquisition cost of IoT devices is high, making it difficult to conduct large-scale analysis; data interaction behavior depends on specific scenario triggers, making it difficult to cover all aspects; data encryption makes it difficult to parse sensitive data. Summary of the invention
[0004] The purpose of the present invention is to provide a method, device and electronic device for identifying sensitive data of IoT devices, so as to solve the technical problem that the prior art is difficult to automate and carry out on a large scale in the process of identifying sensitive data of IoT devices.
[0005] The purpose of the present invention can be achieved through the following technical solutions:
[0006] A method for identifying sensitive data of an Internet of Things device, comprising:
[0007] Extracting multiple IoT sensitive data items from the description text information of the IoT device, and constructing an IoT sensitive semantic dictionary based on the multiple IoT sensitive data items;
[0008] Filtering a number of IoT code blocks from the source code of the IoT application according to the semantic information, wherein the IoT code blocks are semantically related to the IoT device;
[0009] Identify a number of IoT sensitive data points contained in each IoT code block according to the IoT sensitive semantic dictionary, where the IoT sensitive data points are text labels semantically related to the IoT device;
[0010] An alias tag group corresponding to each of the IoT sensitive data points is found from the source code of the IoT application, and the alias tag groups corresponding to all the IoT sensitive data points and program variables associated with the several IoT sensitive data points are taken as IoT device sensitive data, wherein the alias tag group is multiple copies and / or multiple references of the IoT sensitive data point in the source code of the IoT application.
[0011] Optionally, extracting multiple IoT sensitive data items from the description text information of the IoT device includes:
[0012] Using a named entity recognition model to extract multiple IoT sensitive data items from the description text information of the IoT device, where the description text information includes at least news reports of the IoT device, code descriptions of IoT applications, and developer documentation.
[0013] Optionally, screening out several IoT code blocks from the source code of the IoT application according to semantic information includes:
[0014] Segmenting the source code of the IoT application into multiple semantic code blocks, each of the semantic code blocks contains at least one text label, and the text label has semantic information;
[0015] Screening out IoT code blocks related to the semantics of the IoT device according to the text labels contained in each of the semantic code blocks.
[0016] Optionally, screening out IoT code blocks related to the semantics of the IoT device according to the text labels contained in each of the semantic code blocks includes:
[0017] Extracting all text labels in each of the semantic code blocks;
[0018] Expanding the text labels semantically associated with each of the text labels into each of the semantic codes to enrich the semantics of each of the semantic code blocks;
[0019] Forming all text labels in each of the semantic code blocks into a text label list, and preprocessing the text label list;
[0020] Converting the preprocessed text label list into a numerical vector, and inputting the numerical vector into a trained text classification model to obtain an IoT code block.
[0021] Optionally, the text classification model is:
[0022] FastText model.
[0023] Optionally, identifying several IoT sensitive data points included in each of the IoT code blocks according to the IoT sensitive semantic dictionary includes:
[0024] Calculating the similarity between the text labels in each of the IoT code blocks and each of the IoT sensitive data items in the IoT sensitive semantic dictionary;
[0025] If the similarity is greater than a preset similarity threshold, the text label is an IoT sensitive data point; otherwise, the text label is not an IoT sensitive data point.
[0026] Optionally, the preset similarity threshold is 70%.
[0027] Optionally, the alias tag groups corresponding to each of the IoT sensitive data points found from the source code of the IoT application include:
[0028] Using a variable association component based on semantic information, multiple copies and / or multiple references of each of the IoT sensitive data points are found from the source code of the IoT application.
[0029] The present invention also provides an identification device for IoT device sensitive data, including:
[0030] A sensitive semantic dictionary construction module, configured to extract multiple IoT sensitive data items from the description text information of the IoT device, and construct an IoT sensitive semantic dictionary according to the multiple IoT sensitive data items;
[0031] An IoT code screening module, configured to screen out several IoT code blocks from the source code of the IoT application according to semantic information, and the IoT code blocks are semantically related to the IoT device;
[0032] A sensitive data point identification module, configured to identify several IoT sensitive data points included in each of the IoT code blocks according to the IoT sensitive semantic dictionary, and the IoT sensitive data points are text labels semantically related to the IoT device;
[0033] A device sensitive data identification module, configured to find the alias tag groups corresponding to each of the IoT sensitive data points from the source code of the IoT application, and associate the alias tag groups corresponding to all the IoT sensitive data points and the program variables associated with the several IoT sensitive data points as the IoT device sensitive data, and the alias tag groups are multiple copies and / or multiple references of the IoT sensitive data points in the source code of the IoT application.
[0034] The present invention also provides an electronic device, including:
[0035] A memory, configured to store a computer program;
[0036] A processor, configured to execute the computer program to implement a method for identifying IoT device sensitive data.
[0037] The present invention provides a method, apparatus, and electronic device for identifying sensitive data of Internet of Things (IoT) devices. The method includes: extracting a plurality of IoT sensitive data items from the description text information of the IoT device, and constructing an IoT sensitive semantic dictionary based on the plurality of IoT sensitive data items; screening out a number of IoT code blocks from the source code of the IoT application according to semantic information, where the IoT code blocks are semantically related to the IoT device; identifying a number of IoT sensitive data points included in each of the IoT code blocks according to the IoT sensitive semantic dictionary, where the IoT sensitive data points are text tags that are semantically related to the IoT device; finding an alias tag group corresponding to each of the IoT sensitive data points from the source code of the IoT application, and using the alias tag groups corresponding to all the IoT sensitive data points and the program variables associated with the number of IoT sensitive data points as the sensitive data of the IoT device, where the alias tag group is multiple copies and / or multiple references of the IoT sensitive data point in the source code of the IoT application.
[0038] In view of this, the beneficial effects brought by the present invention are:
[0039] The present invention constructs an IoT sensitive semantic dictionary by extracting IoT sensitive data items, and uses code semantics to screen out IoT code blocks in the source code of the mobile application supporting the IoT device, which can automatically identify the privacy data transmitted from the IoT device to the IoT application and track the leakage of privacy data; uses the IoT sensitive semantic dictionary to identify text tags that are semantically related to the IoT device in the IoT code blocks as sensitive data points, and finds the alias tags of all sensitive data points in the source code of the IoT application, which can quickly, accurately, and comprehensively identify all the sensitive data of the IoT device that is semantically related to the IoT device in the source code of the IoT application.
[0040] At the same time, since the analysis object of the present invention is the source code of the IoT application, it has good scalability, realizes large-scale review of IoT device data, greatly broadens the analysis scale of IoT device data, can analyze large-scale IoT device data, and can automatically, efficiently, and accurately identify large-scale IoT device sensitive data. It is a low-cost, highly extensible, and automated method for identifying sensitive data of IoT devices, and can support large-scale, automated, efficient, and accurate identification of sensitive data contained in IoT devices. Description of the Drawings
[0041] Figure 1 It is a schematic diagram of the first interaction mode of an existing IoT device;
[0042] Figure 2 It is a schematic diagram of the second interaction mode of an existing IoT device;
[0043] Figure 3 Schematic flowchart of an embodiment of the method of the present invention;
[0044] Figure 4 Schematic flowchart of another embodiment of the method of the present invention;
[0045] Figure 5 Schematic structural diagram of the device of the present invention. Detailed implementation manners
[0046] Term explanations:
[0047] Internet of Things device: An Internet of Things device refers to a non-standard computing device that can be wirelessly connected to a network and has the ability to transmit data, and communicates and interacts via the Internet by embedding relevant technologies internally.
[0048] Internet of Things device supporting application program: The Internet of Things device supporting application refers to the computer software medium for connecting the Internet of Things device and the mobile phone terminal, simply referred to as the Internet of Things application program.
[0049] Sensitive data of Internet of Things device: It refers to the data related to the Internet of Things device and may cause serious harm to society or individuals if leaked.
[0050] Text classification: Text classification refers to the automatic classification and tagging of text (or other entities or objects) by a computer according to a certain classification system or standard.
[0051] Internet of Things code block: For the Internet of Things supporting mobile application program, the present invention believes that the Internet of Things code block includes a set of text labels with semantic information (such as constant strings, class member variable names) that describe information related to the Internet of Things device.
[0052] Internet of Things sensitive data point: For a given Internet of Things code block, if the text labels therein clearly indicate information related to the Internet of Things device, the present invention defines each text label (such as constant string, class member variable name) included in the code block as an Internet of Things sensitive data point.
[0053] The embodiments of the present invention provide a method, device and electronic device for identifying sensitive data of Internet of Things devices, so as to solve the technical problem that it is difficult to automate and large-scale identify sensitive data of Internet of Things devices in the prior art.
[0054] To facilitate the understanding of the present invention, the present invention will be described more comprehensively below with reference to the relevant drawings. The preferred embodiments of the present invention are shown in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, these embodiments are provided to make the disclosure of the present invention more thorough and comprehensive.
[0055] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs. The terms used in the description of the present invention herein are for the purpose of describing specific embodiments only and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.
[0056] Please refer to Figure 1 and Figure 2 , in both interaction modes of the Internet of Things (IoT) devices, the IoT data all passes through the application program supporting the IoT devices. There are two interaction modes for IoT devices: as Figure 1 shown, the first is the IoT device - mobile phone - cloud interaction mode. For example, for traditional devices such as NFC, Bluetooth, BLE, etc., the supplier uses the application program supporting the IoT device as an intermediary to process the data of the IoT device and then transmits this data to the cloud. This data processing method is mostly applied to short - range communication devices that tend to make full use of the computing power of the mobile phone to process and transmit data. As Figure 2 shown, the second is the IoT device - cloud - mobile phone interaction mode. For example, for devices such as Google Home, Amazon Echo, etc., these IoT devices directly transmit their data to the back - end of their cloud platform. Although the communication paths of these IoT devices do not pass through the application program supporting the IoT device, for the purpose of device management, the cloud of these devices tends to forward the data to the application program supporting the IoT.
[0057] For a long time, there have been great challenges in how to automatically analyze the sensitive data involved in IoT devices. The acquisition cost of IoT device hardware is high, the data interaction behavior depends on specific scenario triggers, and is limited by factors such as data encryption, making it difficult for traditional analysis techniques to effectively capture the actual useful data of IoT devices.
[0058] The inventors of the present application have found through research that the existing IoT device sensitive data recognition technologies focus on dynamic analysis of IoT devices. Some solutions deploy multiple IoT devices in a laboratory environment, collect the communication traffic of these IoT devices, and use the collected communication traffic of the corresponding devices to identify the data types transmitted on the Internet, the data receivers, etc. There are also some solutions that collect crowdsourced traffic through applications voluntarily installed by IoT users in a real - world home network to capture the communication between IoT devices and the Internet. Although this can effectively expand the coverage of IoT device research, the number of involved suppliers is small.
[0059] Meanwhile, developers often adopt means such as data encryption for security reasons. Therefore, the data collected in specific environments such as home application scenarios has certain limitations and cannot be effectively applied to data analysis techniques. In addition, given the breadth of IoT data and the relatively limited coverage of existing research on sensitive IoT data, there is no detailed method for identifying sensitive data of IoT devices.
[0060] Please refer to Figure 3 , an embodiment of a method for identifying sensitive data of IoT devices provided by the present invention includes:
[0061] S100: Extract multiple IoT sensitive data items from the description text information of the IoT device, and construct an IoT sensitive semantic dictionary based on the multiple IoT sensitive data items;
[0062] S200: Screen out several IoT code blocks from the source code of the IoT application according to the semantic information, and the IoT code blocks are semantically related to the IoT device;
[0063] S300: Identify several IoT sensitive data points included in each of the IoT code blocks according to the IoT sensitive semantic dictionary, and the IoT sensitive data points are text labels semantically related to the IoT device;
[0064] S400: Find the alias tag group corresponding to each of the IoT sensitive data points from the source code of the IoT application, and use the alias tag group corresponding to all the IoT sensitive data points and the program variables associated with the several IoT sensitive data points as the sensitive data of the IoT device, and the alias tag group is multiple copies and / or multiple references of the IoT sensitive data point in the source code of the IoT application.
[0065] Before identifying IoT sensitive data, it is first necessary to construct an IoT sensitive semantic dictionary. In step S100 of an embodiment of the present invention, multiple IoT sensitive data items are extracted from the description text information of the IoT device, and an IoT sensitive semantic dictionary is constructed based on these IoT sensitive data items. Among them, the description text information includes at least news reports of IoT devices, code descriptions of IoT applications, and developer documents, etc. In a preferred implementation, a named entity recognition model relying on the security field is used to extract multiple IoT sensitive data items. Table 1 shows an IoT sensitive semantic dictionary of an embodiment. The present invention can expand the IoT sensitive data items to 553 data items, and each subclass contains an average of 61 IoT sensitive data items.
[0066] Table 1
[0067]
[0068]
[0069] In the field of natural language processing technology, named entity recognition (NER) is used to extract entities in a statement, and different entity types are defined according to different domain tasks, so as to obtain the required entities. For example, defining the entity type "festival", the named entity recognition model can extract entities such as "Mid-Autumn Festival" and "Dragon Boat Festival". In a preferred embodiment, the named entity recognition model used in this embodiment can be the Xfinder model, which can extract entity information related to the security field in the text, such as the security critical data "password", the SDK sensitive data "user device identifier", etc.
[0070] In step S200, a number of Internet of Things code blocks are screened out from the source code of the Internet of Things application according to semantic information, and the Internet of Things code blocks are semantically related to the Internet of Things device.
[0071] The installation package of the obtained Internet of Things application is decompiled to obtain the source code of the Internet of Things application, and all Internet of Things code blocks are found from the source code of the Internet of Things application. In addition to semantic information, the source code of the Internet of Things application is also mixed with a large amount of useless information. Therefore, before identifying the sensitive data of the Internet of Things device, it is necessary to locate the code block where the sensitive data of the Internet of Things device is located, that is, the Internet of Things code block.
[0072] In this embodiment, screening out a number of Internet of Things code blocks from the source code of the Internet of Things application according to semantic information includes: First, the source code of the Internet of Things application is segmented into multiple semantic code blocks, and each semantic code block contains at least one text label with semantic information; Then, the Internet of Things code blocks that are semantically related to the Internet of Things device are screened out according to the text labels contained in each semantic code block.
[0073] In this embodiment, after the source code of the Internet of Things application is divided into multiple semantic code blocks, it is further determined whether each semantic code block is related to the sensitive data of the Internet of Things device. The semantic code block related to the sensitive data of the Internet of Things device is called the Internet of Things code block, and the semantic code block not related to the sensitive data of the Internet of Things device is called the non-Internet of Things code block. The Internet of Things code block in this embodiment contains at least one text label with semantic information in the classes, methods, variables or constant strings it contains, such as containing a word or a noun phrase.
[0074] Specifically, the IoT code blocks related to the semantics of IoT devices are screened according to the text tags included in each semantic code block, including: extracting all text tags in each semantic code block; extending the text tags semantically related to each text tag to each semantic code to enrich the semantics of each semantic code block; forming a text tag list from all text tags in each semantic code block, preprocessing the text tag list; converting the preprocessed text tag list into a numerical vector, and inputting the numerical vector into a trained text classification model to obtain IoT code blocks.
[0075] In one embodiment, a text binary classification task is used to check the semantic information of text tags. The following is a detailed description of the steps for identifying IoT code blocks:
[0076] (1) Extract all semantic information (such as constant strings, variable names, etc.) in each semantic code block to be tested as text tags;
[0077] (2) Expand the semantic information of each semantic code block. Since the number of valid text tags in each semantic code block may be limited, or text tags with fuzzy semantics are included, this embodiment proposes a set of heuristic methods to enrich the semantic information of these semantic code blocks by associating scattered text tags with these semantic code blocks.
[0078] Taking the semantic code block shown in the following code as an example, member variables a, b, and c are included in the same semantic code block, but the semantics of the tags "a", "b", and "c" are fuzzy and it cannot be determined whether they are IoT code blocks. To enrich the semantics, the present invention uses data flow analysis technology to analyze all methods in the class and find text tags related to the member variables. The text tag ", isRunning =" in the semantic code is related to the semantic code block because it describes the "this.a" field (line 19). Through this process, the semantic information of the semantic code block containing fuzzy semantic fields can be enriched, and the accuracy of IoT code block identification can be improved.
[0079]
[0080] (3) Form a text tag list from all text tags in each semantic code block. Table 2 shows an example of a text tag list formed from all text tags in a semantic code block.
[0081] Table 2
[0082]
[0083]
[0084] (4) Preprocess the obtained text label list, convert the preprocessed text label list into a numerical vector, and input the numerical vector into a trained text classification model (such as the FastText model) for classification to determine whether the semantic code block corresponding to the text label list is an Internet of Things code, and further obtain all Internet of Things code blocks.
[0085] It can be understood that the text labels in the Internet of Things code block include both the text labels directly extracted from the code block and the text labels with semantic associations with the extracted text labels, that is, the extended text labels. The directly extracted text labels and the extended text labels together constitute a text label list.
[0086] It should be noted that in the Internet of Things sensitive semantic dictionary of the present invention, some data items describe both the sensitive data collected by Internet of Things devices and the sensitive data directly collected by Internet of Things mobile applications. To reduce or eliminate false positives, the following measures are taken in this embodiment:
[0087] (1) Filter based on the package name. This embodiment relies on the package name to identify the code related to Internet of Things device management and filters out the code unrelated to Internet of Things devices in the third-party library.
[0088] (2) Identify sensitive data based on aggregated semantics. This embodiment uses the FastText model to detect Internet of Things code blocks with aggregated semantics. FastText determines whether the input code block is an Internet of Things code block based on the aggregated semantics composed of multiple text labels, so that the code block will not be determined as an Internet of Things code block related to Internet of Things devices due to a single data point.
[0089] In addition, this embodiment also classifies the sensitive data directly collected by Internet of Things mobile applications and related to Internet of Things devices into the Internet of Things sensitive data items, improving the recognition effect.
[0090] In the process of locating Internet of Things codes in this embodiment, a supervised text classification model based on word embedding and neural network - the FastText model is used to learn text labels, and it is determined whether it is related to Internet of Things devices according to the aggregated text label list included in the code block.
[0091] The training steps of the FastText model are as follows:
[0092] Collect Internet of Things code blocks and non-Internet of Things code blocks to construct a positive and negative sample training set and perform manual inspection.
[0093] Extract the semantic information (i.e., constant strings and variable names) of each code block in the training dataset as text labels. Multiple text labels constitute a text label list, and text preprocessing is performed on all label texts in the list.
[0094] Use a Sentence Embedding Model to convert the processed list of text tags into a numerical vector. Preferably, the Sentence Embedding Model is the SBERT model. Input the processed list of text tags into the SBERT model to convert the text tags into numerical vectors. Since the SBERT model is trained on the Stanford Natural Language Inference (SNLI) corpus, the numerical vectors (Embeddings) it gives can accurately reflect the semantic features of the text tags in the multi-dimensional space.
[0095] Input the obtained numerical vectors into model training.
[0096] In step S300 of the embodiment, several Internet of Things (IoT) sensitive data points included in each of the IoT code blocks are identified according to the IoT sensitive semantic dictionary. The IoT sensitive data points are text tags semantically related to the IoT devices.
[0097] After finding all the IoT code blocks semantically related to the IoT devices, use the constructed IoT sensitive semantic dictionary to identify all the IoT sensitive data points included in the IoT code blocks. Specifically, according to the IoT sensitive semantic dictionary shown in Table 1, calculate the similarity between all the text tags in each IoT code block and each IoT sensitive data item; then, compare the similarity with a preset similarity threshold. If the similarity is greater than the preset similarity threshold, the corresponding text tag is an IoT sensitive data point; otherwise, the corresponding text tag is not an IoT sensitive data point but a text tag unrelated to the IoT device sensitive data.
[0098] It should be noted that when calculating the similarity between all the text tags in each IoT code block and each IoT sensitive data item, first, form a list of text tags from all the text tags in the IoT code block; then, use a Sentence Embedding Model to convert all the text tags in the text tag list into numerical vectors, and the numerical vectors can accurately reflect the semantic features of the corresponding text tags in the multi-dimensional space; finally, use the Sentence Embedding Model to measure the sentence semantic similarity. If the measurement result is greater than the preset similarity threshold, the corresponding text tag is used as an IoT sensitive data point. In a preferred implementation, the preset similarity threshold is 70%.
[0099] In the similarity analysis technology, in this embodiment, the Sentence-BERT model (abbreviated as SBERT model) is used. The text data to be compared is separately input into the model to obtain the word vectors of each sentence, and then the cosine distance between the pairwise word vectors is calculated using the cosine function to obtain the similarity.
[0100] In step S400, an alias tag group corresponding to each of the IoT sensitive data points is found from the source code of the IoT application program, and all alias tags and the program variables associated with the several IoT sensitive data points are used as the IoT device sensitive data. The alias tag group is multiple copies and / or multiple references of the IoT sensitive data points in the source code of the IoT application program.
[0101] In the code space of the entire IoT application program, an IoT sensitive data point may have multiple copies or references in different methods. Therefore, in this embodiment, a variable association component based on semantic information is designed.
[0102] Given an identified IoT sensitive data point, the variable association component searches for and maintains a set of alias tags of the IoT sensitive data point in the IoT application program. Due to the code structure characteristics, in this embodiment, it is considered that variable names and string tags in the same line of code have similar and related natural semantic information, which can be used to represent the same Internet of Things (IoT) data. For example, string light_status = json.get("bulb_on"), in this embodiment, it is considered that bulb_on has the same semantics as light_status, both representing the lighting status.
[0103] The variable association component in this embodiment will search for operations such as data assignment related to this variable, find all aliases of the IoT sensitive data point, and by searching for the aliases of semantic variables, the variable semantics can be enriched more, and text tags with semantic information can be better associated.
[0104] The method for identifying IoT device sensitive data provided in this embodiment can automatically identify the privacy data transmitted from the IoT device to the IoT application program and track the leakage of the privacy data by extracting IoT sensitive data items to construct an IoT sensitive semantic dictionary and using code semantics to filter out the IoT code blocks in the source code of the IoT device supporting mobile application program; by using the IoT sensitive semantic dictionary to identify the text tags related to the IoT device semantics in the IoT code block as sensitive data points and finding all alias tags of the sensitive data points in the source code of the IoT application program, all IoT device sensitive data related to the IoT device semantics in the source code of the IoT application program can be quickly, accurately and comprehensively identified.
[0105] Meanwhile, since the analysis object in this embodiment is the source code of the Internet of Things application program, it has good scalability, realizes the large-scale review of the data of Internet of Things devices, greatly broadens the scale of analysis of the data of Internet of Things devices, can analyze the data of a large number of Internet of Things devices, and can automatically, efficiently and accurately identify the sensitive data of a large number of Internet of Things devices. It is a low-cost, highly scalable and automated method for identifying sensitive data of Internet of Things devices.
[0106] Please refer to Figure 4 , another embodiment of a method for identifying sensitive data of Internet of Things devices provided by the present invention includes:
[0107] Internet of Things sensitive data items related to the sensitive data of Internet of Things devices are extracted in advance, and an Internet of Things sensitive semantic dictionary is made as the basis for Internet of Things data identification;
[0108] Next, the supporting application program of the Internet of Things device is decompiled to obtain the source code of the Internet of Things application program. The source code is segmented into multiple semantic code blocks, and all the Internet of Things code blocks related to the Internet of Things device are screened out according to the semantic information contained in the semantic code blocks;
[0109] The similarity between the text tags in the semantic code blocks and the pre-constructed Internet of Things sensitive data items is compared, and the sensitive data points contained in the Internet of Things code blocks are located according to the similarity;
[0110] The identified Internet of Things sensitive data points are located to the variable aliases corresponding to the sensitive data in the source code through the variable association component based on semantic information.
[0111] The purpose of this embodiment is to construct a method for identifying sensitive data of Internet of Things devices, which is a low-cost, highly scalable and automated method for identifying sensitive data of Internet of Things devices. The present invention utilizes the code semantics in the supporting mobile application of Internet of Things devices and uses natural language processing technology to automatically identify the privacy data transmitted from Internet of Things devices to the mobile application. At the same time, since the analysis object is the supporting application program of Internet of Things devices, the method provided by the present invention has good scalability and can be applied to the analysis of sensitive data of a large number of Internet of Things devices.
[0112] Please refer to Figure 5 , an embodiment of an apparatus for identifying sensitive data of Internet of Things devices provided by the present invention includes:
[0113] A sensitive semantic dictionary construction module 11, configured to extract a plurality of Internet of Things sensitive data items from the description text information of the Internet of Things device, and construct an Internet of Things sensitive semantic dictionary according to the plurality of Internet of Things sensitive data items;
[0114] The Internet of Things code screening module 22 is used to screen out a number of Internet of Things code blocks from the source code of the Internet of Things application according to semantic information, and the Internet of Things code blocks are semantically related to the Internet of Things device;
[0115] The sensitive data point identification module 33 is used to identify a number of Internet of Things sensitive data points included in each of the Internet of Things code blocks according to the Internet of Things sensitive semantic dictionary, and the Internet of Things sensitive data points are text labels that are semantically related to the Internet of Things device;
[0116] The device sensitive data identification module 44 is used to find the alias tag group corresponding to each of the Internet of Things sensitive data points from the source code of the Internet of Things application, and regard the alias tag group corresponding to all the Internet of Things sensitive data points and the program variables associated with the number of Internet of Things sensitive data points as the Internet of Things device sensitive data, and the alias tag group is multiple copies and / or multiple references of the Internet of Things sensitive data point in the source code of the Internet of Things application.
[0117] In the field of Internet of Things device data analysis, the present invention utilizes the variable semantics in the supporting application to automatically identify the privacy data transmitted by the Internet of Things device and track the leakage of the privacy data, thereby realizing the large-scale review of the Internet of Things device data, greatly broadening the scale of Internet of Things data analysis, and being able to support the large-scale, automatic, efficient and accurate identification of the sensitive data contained in the Internet of Things device.
[0118] The present invention also provides an electronic device, including:
[0119] A memory for storing a computer program;
[0120] A processor for executing the computer program to implement a method for identifying the sensitive data of an Internet of Things device.
[0121] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0122] In the embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the device or unit can be in electrical, mechanical or other forms.
[0123] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0124] In addition, each functional unit in various embodiments of the present invention may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0125] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0126] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of various embodiments of the present invention.
Claims
1. A method for identifying sensitive data of an Internet of Things device, characterized in that Including: Extracting a plurality of Internet of Things (IoT) sensitive data items from the description text information of IoT devices, and constructing an IoT sensitive semantic dictionary according to the plurality of IoT sensitive data items; Screening out a number of IoT code blocks from the source code of an IoT application according to semantic information, where the IoT code blocks are semantically related to the IoT devices; Identifying a number of IoT sensitive data points included in each of the IoT code blocks according to the IoT sensitive semantic dictionary, where the IoT sensitive data points are text labels that are semantically related to the IoT devices; Finding, from the source code of the IoT application, an alias tag group corresponding to each of the IoT sensitive data points, and taking the alias tag groups corresponding to all the IoT sensitive data points and the program variables associated with the number of IoT sensitive data points as IoT device sensitive data, where the alias tag group is multiple copies and / or multiple references of the IoT sensitive data point in the source code of the IoT application; Screening out a number of IoT code blocks from the source code of an IoT application according to semantic information includes: Segmenting the source code of the IoT application into multiple semantic code blocks, where each of the semantic code blocks contains at least one text tag with semantic information; Screening out IoT code blocks that are semantically related to the IoT devices according to the text tags included in each of the semantic code blocks; Finding, from the source code of the IoT application, an alias tag group corresponding to each of the IoT sensitive data points includes: Using a variable association component based on semantic information to find multiple copies and / or multiple references of each of the IoT sensitive data points from the source code of the IoT application.
2. The method for identifying sensitive data of an Internet of Things device according to claim 1, wherein Extracting a plurality of IoT sensitive data items from the description text information of IoT devices includes: Using a named entity recognition model to extract a plurality of IoT sensitive data items from the description text information of IoT devices, where the description text information includes at least news reports of IoT devices, code descriptions of IoT applications, and developer documents.
3. The method for identifying sensitive data of an Internet of Things device according to claim 1, characterized in that Screening out IoT code blocks that are semantically related to the IoT devices according to the text tags included in each of the semantic code blocks includes: Extracting all the text tags in each of the semantic code blocks; Extending the text tags that are semantically associated with each of the text tags to each of the semantic codes to enrich the semantics of each of the semantic code blocks; Constructing a text tag list from all the text tags in each of the semantic code blocks, and preprocessing the text tag list; Converting the preprocessed text tag list into a numerical vector, and inputting the numerical vector into a trained text classification model to obtain IoT code blocks.
4. The method for identifying sensitive data of an Internet of Things device according to claim 3, wherein The text classification model is: FastText model.
5. The method for identifying sensitive data of an Internet of Things device according to claim 1, wherein, Identifying a number of IoT sensitive data points included in each of the IoT code blocks according to the IoT sensitive semantic dictionary includes: Calculating the similarity between all the text tags in each of the IoT code blocks and each of the IoT sensitive data items in the IoT sensitive semantic dictionary; If the similarity is greater than a preset similarity threshold, the text label is an IoT sensitive data point; otherwise, the text label is not an IoT sensitive data point.
6. The method for identifying sensitive data of the Internet of Things device according to claim 5, characterized in that, The preset similarity threshold is 70%.
7. An identification device for sensitive data of an Internet of Things device, characterized in that, It includes: A sensitive semantic dictionary construction module, which is used to extract multiple IoT sensitive data items from the description text information of IoT devices and construct an IoT sensitive semantic dictionary according to the multiple IoT sensitive data items; An IoT code screening module, which is used to screen out several IoT code blocks from the source code of an IoT application according to semantic information, and the IoT code blocks are semantically related to the IoT device; A sensitive data point identification module, which is used to identify several IoT sensitive data points included in each of the IoT code blocks according to the IoT sensitive semantic dictionary, and the IoT sensitive data points are text labels that are semantically related to the IoT device; A device sensitive data identification module, which is used to find an alias tag group corresponding to each of the IoT sensitive data points from the source code of the IoT application, and regard the alias tag group corresponding to all the IoT sensitive data points and the program variables associated with the several IoT sensitive data points as IoT device sensitive data, and the alias tag group is multiple copies and / or multiple references of the IoT sensitive data point in the source code of the IoT application; The IoT code screening module is specifically used to divide the source code of the IoT application into multiple semantic code blocks, each of the semantic code blocks contains at least one text label, and the text label has semantic information; and screen out IoT code blocks that are semantically related to the IoT device according to the text labels included in each of the semantic code blocks; Finding an alias tag group corresponding to each of the IoT sensitive data points from the source code of the IoT application includes: Using a variable association component based on semantic information to find multiple copies and / or multiple references of each of the IoT sensitive data points from the source code of the IoT application.
8. An electronic device, characterized in that, It includes: A memory, which is used to store a computer program; A processor, which is used to execute the computer program to implement the method for identifying IoT device sensitive data according to any one of claims 1 to 6.
Citation Information
Patent Citations
Electric power Internet-of-things terminal vulnerability detection method and system based on firmware analysis
CN112134761A
Judicial public opinion sensitive information identification method integrated with domain term dictionary
CN112231472A