Method, apparatus and device for target application determination, and storage medium

By acquiring the identification information of sample applications and analyzing it using frequent itemset mining algorithms, the application installation list of the target device is identified, which solves the problem of the lag in identifying insecure applications in the existing technology and enables timely detection of insecure applications.

CN115730298BActive Publication Date: 2026-04-24SHANGHAI SMK NETWORK TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANGHAI SMK NETWORK TECH CO LTD
Filing Date
2022-08-10
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing methods for identifying insecure applications rely on victim reports, which leads to delays and makes it difficult to detect and identify insecure applications in a timely manner.

Method used

By obtaining the identification information of the sample applications, the target devices with the sample applications installed are determined, and the application installation list is analyzed using a frequent itemset mining algorithm to identify target applications whose correlation with the sample applications meets preset conditions.

Benefits of technology

By promptly identifying and recognizing potential insecure applications before users use the target application, the latency issue is resolved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115730298B_ABST
    Figure CN115730298B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a target application determination method, device, equipment and storage medium. First, identification information of a plurality of sample applications is acquired, wherein the sample applications are applications whose security does not satisfy a preset security condition; then a plurality of target devices on which the sample applications are installed are determined according to the identification information; then an application installation list of the plurality of target devices is acquired; finally, a target application associated with the sample application and satisfying a preset condition is determined according to the application installation list and a whitelist application by using a preset frequent item set mining algorithm, wherein the whitelist application is an application whose security satisfies the preset security condition. Embodiments of the present application solve the hysteresis existing in the prior art, and can determine non-secure applications in time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of user security, and more particularly to a method, apparatus, device, and storage medium for determining a target application. Background Technology

[0002] With the rapid development of information technology, various applications have become important channels to meet the needs of the people for information access, investment and financial management, loan transfers and other purposes. While bringing convenience to daily life and production, they have also been used by some people to engage in abnormal activities.

[0003] Existing methods for identifying insecure applications heavily rely on reports from victims. Therefore, in the current process of identifying insecure applications, it is often necessary to wait for victims to report financial losses before they can be identified.

[0004] Therefore, the existing process for identifying insecure applications is lagging and cannot identify them in a timely manner. Summary of the Invention

[0005] This invention provides a method, apparatus, device, and storage medium for determining a target application, which solves the problem of lag and inability to determine insecure applications in existing processes, thereby enabling timely determination of insecure applications.

[0006] To solve the above-mentioned technical problems, the present invention:

[0007] Firstly, a method for determining a target application is provided, the method comprising:

[0008] Obtain the identification information of multiple sample applications, where the sample applications are those whose security does not meet the preset security conditions;

[0009] Based on the identification information, multiple target devices for installing the sample application were identified;

[0010] Retrieve the application installation list from multiple target devices;

[0011] Using a preset frequent itemset mining algorithm, target applications that meet preset conditions in terms of relevance to sample applications are identified based on the application installation list and whitelist applications. Among them, whitelist applications are those that meet preset security conditions.

[0012] In some implementations of the first aspect, the identification information of multiple sample applications is obtained, including:

[0013] Obtain identification information for multiple applications;

[0014] Remove the identification information of whitelisted applications from the identification information and generate identification information for multiple sample applications.

[0015] In some implementations of the first aspect, the application installation list of multiple target devices is obtained, including:

[0016] The application installation list is determined based on the applications installed on multiple target devices and the installation time of the applications.

[0017] In some implementations of the first aspect, a preset frequent itemset mining algorithm is used to determine target applications whose relevance to the sample applications meets preset conditions, based on the application installation list and whitelist of applications, including:

[0018] Based on the application installation list, a preset frequent itemset mining algorithm is used to identify multiple applications associated with the sample applications;

[0019] Based on multiple applications and whitelisted applications, at least one application among the multiple applications that meets the preset conditions is identified as the target application.

[0020] In some implementations of the first aspect, based on multiple applications and a whitelist of applications, at least one application among the multiple applications whose quantity meets a preset condition is identified as the target application, including:

[0021] Remove whitelisted apps from various applications;

[0022] Determine the number of each type of application after removing the whitelisted applications;

[0023] At least one application that meets the preset conditions for the quantity of each application is selected as the target application.

[0024] Secondly, a target application determination apparatus is provided, the apparatus comprising:

[0025] The acquisition module is used to acquire the identification information of multiple sample applications, where the sample applications are those whose security does not meet the preset security conditions;

[0026] The processing module is used to determine multiple target devices for installing the sample application based on the identification information;

[0027] The acquisition module is also used to acquire the application installation list of multiple target devices;

[0028] The processing module is also used to use a preset frequent itemset mining algorithm to determine target applications whose correlation with the sample applications meets preset conditions, based on the application installation list and whitelist applications. Among them, whitelist applications are applications whose security meets preset security conditions.

[0029] In some implementations of the second aspect, the acquisition module is also used to acquire the identification information of multiple applications;

[0030] The processing module is also used to remove the identification information of whitelisted applications from the identification information and generate identification information for multiple sample applications.

[0031] In some implementations of the second aspect, the processing module is also used to determine an application installation list based on the applications installed on multiple target devices and the installation time of the applications.

[0032] In some implementations of the second aspect, the processing module is also used to determine multiple applications associated with the sample application based on the application installation list using a preset frequent itemset mining algorithm.

[0033] The processing module is also used to determine, based on multiple applications and whitelisted applications, at least one application among the multiple applications whose quantity meets preset conditions as the target application.

[0034] In some implementations of the second aspect, the processing module is also used to remove whitelisted applications from various applications;

[0035] The processing module is also used to determine the number of each type of application after removing whitelisted applications;

[0036] The processing module is also used to select at least one application that meets the preset conditions for the quantity of each application as the target application.

[0037] Thirdly, an electronic device is provided, the device comprising: a processor and a memory storing computer program instructions;

[0038] The processor implements the first aspect when executing computer program instructions, and the target application in some implementations of the first aspect is determined by a method.

[0039] Fourthly, a computer storage medium is provided, on which computer program instructions are stored, which, when executed by a processor, implement the first aspect, and a method for determining the target application in some implementations of the first aspect.

[0040] This invention provides a method, apparatus, device, and storage medium for determining target applications. First, identification information of multiple sample applications is obtained, whereby sample applications are those whose security does not meet preset security conditions. Then, multiple target devices with the sample applications installed are determined based on the identification information. Next, an application installation list is obtained from the multiple target devices. Finally, a preset frequent itemset mining algorithm is used to determine target applications whose association with the sample applications meets preset conditions, based on the application installation list and a whitelist of applications, where whitelisted applications are those whose security meets preset security conditions. Because the target applications whose association with the sample applications meets preset conditions are determined from the application installation list of the target devices, target applications can be discovered and identified before the user uses the target application or before the target application engages in abnormal behavior, thus timely identifying insecure applications and overcoming the lag in existing solutions. Attached Figure Description

[0041] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments of the present invention will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0042] Figure 1 This is a flowchart illustrating a method for determining a target application provided in an embodiment of the present invention;

[0043] Figure 2 This is a schematic diagram of the structure of a target application determination device provided in an embodiment of the present invention;

[0044] Figure 3 This is a structural diagram of a computing device provided in an embodiment of the present invention. Detailed Implementation

[0045] The features and exemplary embodiments of various aspects of the present invention will now be described in detail. To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only configured to explain the present invention and are not configured to limit the present invention. For those skilled in the art, the present invention can be practiced without some of these specific details. The following description of the embodiments is merely intended to provide a better understanding of the present invention by illustrating examples of the invention.

[0046] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.

[0047] In recent years, with the rapid development of the mobile internet and the widespread adoption of smartphones, people's work, life, and social interactions have undergone tremendous changes. However, while the internet brings convenience to the public, it has also begun to be exploited by criminals. Leveraging communication technologies and mobile payments, and tempted by low costs and high profits, they are constantly innovating their methods, iterating their technologies, and refining their division of labor to carry out abnormal activities in a more covert and intelligent manner.

[0048] Data mining is a hot research topic in the fields of artificial intelligence and databases. Data mining refers to the non-trivial process of revealing implicit, previously unknown, and potentially valuable information from large amounts of data in a database. Data mining is a decision support process that, based primarily on artificial intelligence, machine learning, pattern recognition, statistics, databases, and visualization techniques, highly automates the analysis of enterprise data, makes inductive inferences, and uncovers potential patterns to help decision-makers adjust market strategies, reduce risks, and make correct decisions. The knowledge discovery process consists of three stages: ① data preparation; ② data mining; ③ result representation and interpretation. Data mining can interact with users or knowledge bases. Data mining is a technique that analyzes each piece of data to find patterns in large amounts of data, mainly involving three steps: data preparation, pattern finding, and pattern representation. Data preparation involves selecting the necessary data from relevant data sources and integrating it into a dataset for data mining; pattern finding uses a certain method to identify the patterns contained in the dataset; and pattern representation presents the identified patterns in a user-understandable way (such as visualization). Data mining tasks include association analysis, cluster analysis, classification analysis, anomaly analysis, outlier analysis, and evolution analysis.

[0049] Currently, with the rapid development of information technology, various applications have become important channels for meeting the public's needs for information access, investment and financial management, loan transfers, and other services. While bringing convenience to daily life and production, they have also been used by some for illicit activities. Relevant authorities have discovered that some groups engaging in illicit telecommunications activities are using the guise of legitimate platforms to lure victims into downloading fake applications, then guiding them to perform actions such as transferring assets within these applications, thereby transferring the victims' property. Since the beginning of this year, cases of illicit telecommunications activities carried out through fake applications have been rampant, seriously endangering the safety of people's property and the social and economic order.

[0050] In reality, cases of telecommunications network aberration activities perpetrated by malicious actors using fake applications account for approximately 60% of such cases. Fake applications have become an indispensable key link in the entire chain of aberration activities, giving rise to a massive gray industry chain of technology development, with numerous malicious actors involved. Related technical developers have clear divisions of labor and operate in an organized manner, "tailor-making" various applications to achieve aberration functions based on the specific needs of malicious actors in the telecommunications network. Some are responsible for writing program code, some for purchasing domain names and renting servers, and some for packaging and distributing the applications. Through layers of operation, the fake application is ultimately constructed into a device for carrying out malicious activities. Subsequently, the malicious actors, based on their illegal purposes and the characteristics of the application's functions, package it into a highly deceptive "legitimate" application platform, guiding victims to click links or scan QR codes to download the application, thereby carrying out malicious activities. Current methods for finding applications used in aberration activities rely on reports from victims, which mainly have the following problems:

[0051] 1. Victims only report the situation to relevant organizations after suffering property losses, resulting in a delay in information dissemination, by which time the perpetrators of the abnormal activities have already completed their actions;

[0052] 2. For applications that fail to report abnormal behavior, it is impossible to detect and alert potential victims in advance;

[0053] 3. Applications that engage in abnormal behavior are updated rapidly. The application package names reported previously become unrecognizable after the personnel engaging in abnormal behavior make slight modifications.

[0054] This shows that the existing methods for finding insecure applications heavily rely on reports from victims. Therefore, in the current process of identifying insecure applications, it is often necessary to wait until the victim reports a loss of property before it can be detected, which is a lag and makes it impossible to detect insecure applications in advance.

[0055] Therefore, the existing process for identifying insecure applications is lagging and cannot identify them in a timely manner.

[0056] To address the issue of delays and untimely identification of insecure applications in existing methods, this invention provides a method, apparatus, device, and storage medium for target application identification. First, identification information of multiple sample applications is obtained, whereby sample applications are those whose security does not meet preset security conditions. Then, multiple target devices with the sample applications installed are identified based on the identification information. Next, an application installation list is obtained from these target devices. Finally, a preset frequent itemset mining algorithm is used to identify target applications whose association with the sample applications meets preset conditions, based on the application installation list and a whitelist of applications, where whitelisted applications are those whose security meets the preset security conditions. Because this process identifies target applications with the association with the sample applications from the application installation list of the target devices, target applications can be discovered and identified before the user uses them or before the target applications engage in abnormal behavior, thus timely identifying insecure applications and overcoming the delays present in existing solutions.

[0057] The technical solutions provided by the embodiments of the present invention will now be described with reference to the accompanying drawings.

[0058] Figure 1 This is a flowchart illustrating a method for determining a target application provided in an embodiment of the present invention. The execution subject of this method can be based on a terminal device.

[0059] like Figure 1 As shown, the methods for determining the target application may include:

[0060] S101: Obtain the identification information of multiple sample applications.

[0061] Specifically, the sample application is an application whose security does not meet the preset security conditions, that is, a dangerous application suspected of engaging in abnormal behavior.

[0062] In one embodiment, during the process of obtaining the identification information of multiple sample applications, since the identification information of the multiple applications may include the identification information of whitelisted applications, the whitelisted applications can be removed from the multiple applications to reduce subsequent calculation time. Specifically, the process can be to remove the identification information of whitelisted applications from the identification information of multiple applications, thereby generating the identification information of the sample applications in S101, where the whitelisted applications specifically refer to applications whose security meets preset security conditions.

[0063] After obtaining the identification information of multiple sample applications, since the sample application does not meet the preset security conditions, the device on which the sample application is installed can be determined based on the sample application, and then the target application can be determined based on the device, i.e., S102-S104 are executed.

[0064] S102: Identify multiple target devices for installing the sample application based on the identification information.

[0065] In this process, the goal is to identify the devices on which the sample application is installed. The aforementioned multiple target devices can refer to all devices on which the sample application is installed, and these devices can include at least one of mobile phones and tablets.

[0066] S103: Obtain the application installation list for multiple target devices.

[0067] Optionally, in one embodiment, in order to include as much application-related information as possible in the obtained application installation list, the application installation list can be determined based on the applications installed on multiple target devices and the installation time of the applications.

[0068] After determining the list of installed applications, the target application can be determined based on the list of installed applications, i.e., S104 is executed.

[0069] S104: Using a preset frequent itemset mining algorithm, determine target applications whose correlation with sample applications meets preset conditions based on the application installation list and whitelist applications.

[0070] It should be noted that this whitelist applies to applications that meet the preset security conditions.

[0071] In one embodiment, multiple applications associated with the sample application can be identified using a preset frequent itemset mining algorithm based on the application installation list. Based on the multiple applications and whitelisted applications, at least one application among the multiple applications whose quantity meets preset conditions can be identified as the target application.

[0072] Specifically, the preset frequent itemset mining algorithm can refer to the Frequent Pattern Growth (FP-Growth) algorithm, and the multiple applications associated with the sample application refer to applications that exist simultaneously with the sample application in the application installation list.

[0073] In one embodiment, the correlation degree in S104 refers to the numerical value of the connection between each application calculated by the FP-Growth algorithm. For example, the correlation value between application A and application B is α, the correlation value between application A and application C is β, and so on. The correlation values ​​α and β between applications form a correlation chain to represent the relationship between each application in a variety of applications. Here, application A can be understood or referred to as the sample application, so the correlation degree can be used to determine whether the sample application is similar to other applications.

[0074] In one embodiment, a preset frequent itemset mining algorithm is used to determine target applications whose relevance to sample applications meets preset conditions, based on the application installation list and whitelist of applications, including:

[0075] The number of target devices for installing the sample application is determined based on the identification information;

[0076] Based on the number of installations, the sample applications are divided into different levels according to a preset rule.

[0077] Multiple sample applications belonging to the same level are selected as the target sample application set. Based on the target sample application set, a preset frequent itemset mining algorithm is used to determine multiple target applications whose correlation with the target sample application set meets preset conditions, according to the application installation list and whitelist applications.

[0078] Therefore, it can be seen that the embodiments of the present invention can simultaneously mine multiple applications that are engaging in abnormal behavior. Specifically, for multiple applications engaging in abnormal behavior, these applications can be divided into several groups according to the order of magnitude of the number of installed devices. Applications with the same number of installed devices in each group can be mined simultaneously. Then, these applications are matched with the mining results to obtain similar applications to multiple applications engaging in abnormal behavior. Here, the number of installed devices is the number of target devices of the above-mentioned sample applications, and the applications with the same number of installed devices in each group are the multiple sample applications belonging to the same level.

[0079] In one embodiment, in the process of determining at least one application among multiple applications that meets a preset condition as the target application based on multiple applications and whitelisted applications, since whitelisted applications are applications that meet preset security conditions and are not dangerous applications suspected of engaging in abnormal behavior, whitelisted applications can be removed from the multiple applications first. Then, the number of each type of application after removing whitelisted applications is determined. Finally, at least one application that meets a preset condition is selected as the target application. The preset condition refers to the maximum number of applications. The target application is an application that does not meet the preset security conditions, such as an application that engages in abnormal behavior.

[0080] It should be noted that when removing whitelisted applications from multiple applications, the removal can be carried out according to the association chain constructed above. In the process of selecting at least one application that meets the preset conditions for each type of application as the target application, the number of applications after the whitelisted applications have been removed can be counted and sorted according to the number of applications. The application with the largest number is the target application, which is an application with similar security to the sample application that does not meet the preset security conditions.

[0081] Furthermore, the aforementioned preset conditions can be adjusted according to the actual situation, and are not limited to the case where the number is the maximum value. For example, in order to expand the scope of the target application, the preset conditions can be adjusted so that the number of applications is arranged in descending order of the top N applications.

[0082] Because in this embodiment of the invention, the FPGrowth algorithm is used to calculate the correlation between the application and the sample application to determine the target application during the process of determining the target application based on the sample application, it is not necessary to wait for the victim to be deceived before reporting it. Dangerous applications suspected of carrying out abnormal behavior activities can be detected in a timely manner, which solves the problem of lag in the existing solutions.

[0083] The method for determining target applications provided in this invention first obtains the identification information of multiple sample applications, where the sample applications are those whose security does not meet preset security conditions. Then, based on the identification information, multiple target devices with the sample applications installed are identified. Next, an application installation list is obtained from the multiple target devices. Finally, a preset frequent itemset mining algorithm is used to determine target applications whose correlation with the sample applications meets preset conditions, based on the application installation list and whitelisted applications, where the whitelisted applications are those whose security meets preset security conditions. Because the FPGrowth algorithm is used to calculate the correlation between each application and to determine the target applications whose correlation with the sample applications meets preset conditions from the application installation list of the target devices, these target applications are considered insecure applications. This allows for the detection of insecure (abnormal behavior) applications without requiring a report from the complainant. Therefore, target applications can be discovered and identified before the user uses them or before the target application engages in abnormal behavior, thus timely identifying insecure applications and overcoming the lag in existing solutions.

[0084] The target application determination method provided in this invention can, when only a few application samples of abnormal behavior are known, discover more unknown applications of abnormal behavior based on the information of these sample applications. This solves the problem of how to discover more applications of abnormal behavior and find more suspects and victims of abnormal behavior when there is no data on all applications of abnormal behavior and only a small number of samples.

[0085] and Figure 1 Corresponding to the flowchart of the method for determining the target application, this embodiment of the invention also provides an apparatus for determining the target application.

[0086] Figure 2 This is a schematic diagram of the structure of a target application determination device provided in an embodiment of the present invention, as shown below. Figure 2 As shown, the device for determining the target application may include: an acquisition module 201 and a processing module 202.

[0087] The acquisition module 201 can be used to acquire the identification information of multiple sample applications, wherein the sample applications are applications whose security does not meet the preset security conditions.

[0088] The processing module 202 can be used to determine multiple target devices for installing the sample application based on the identification information.

[0089] The acquisition module 201 can also be used to obtain the application installation list of multiple target devices.

[0090] The processing module 202 can also be used to use a preset frequent itemset mining algorithm to determine target applications whose correlation with the sample applications meets preset conditions based on the application installation list and whitelist applications. Among them, the whitelist applications are applications whose security meets preset security conditions.

[0091] In one embodiment, the acquisition module 201 can also be used to acquire the identification information of multiple applications, remove the identification information of whitelisted applications from the identification information, and generate the identification information of multiple sample applications.

[0092] In one embodiment, the processing module 202 can also be used to determine an application installation list based on the applications installed on multiple target devices and the installation time of the applications.

[0093] In one embodiment, the processing module 202 can also be used to determine multiple applications associated with the sample application based on the application installation list using a preset frequent itemset mining algorithm, and to determine at least one application among the multiple applications and whitelisted applications whose quantity of each application meets preset conditions as the target application.

[0094] The processing module 202 can also be used to remove whitelisted applications from multiple applications, determine the number of each type of application after removing whitelisted applications, and finally select at least one application whose number of each type of application meets the preset conditions as the target application.

[0095] In one embodiment, the processing module 202 can further determine the number of target devices with the installed sample applications based on the identification information; classify the sample applications into levels according to a preset installation quantity classification rule based on the number; take multiple sample applications belonging to the same level as a target sample application set; and, based on the target sample application set, use a preset frequent itemset mining algorithm to determine multiple target applications whose correlation with the target sample application set meets preset conditions, based on the application installation list and whitelist applications. It is understood that... Figure 2 The target application shown has each module in the defined device that has the ability to implement Figure 1 The functions of each step in the process and their corresponding technical effects are described briefly and will not be elaborated here.

[0096] The target application determination device provided in this embodiment of the invention first acquires the identification information of multiple sample applications through an acquisition module, wherein the sample applications are applications whose security does not meet preset security conditions; then, a processing module determines multiple target devices that have the sample applications installed based on the identification information; next, it acquires an application installation list of the multiple target devices; finally, the processing module uses a preset frequent itemset mining algorithm to determine target applications whose association with the sample applications meets preset conditions based on the application installation list and whitelisted applications, wherein the whitelisted applications are applications whose security meets preset security conditions. Because the target applications whose association with the sample applications meets preset conditions are determined from the application installation list of the target devices, non-secure applications (those engaging in abnormal behavior) can be detected without the need for a report from the complainant. Therefore, target applications can be discovered and identified before the user uses the target application or before the target application engages in abnormal behavior, thus timely identifying non-secure applications and solving the lag problem existing in the current solution.

[0097] Figure 3 This is a structural diagram of the hardware architecture of a computing device provided in an embodiment of the present invention. For example... Figure 3 As shown, the computing device 300 includes an input interface 301, a central processing unit 302, a memory 303, and an output interface 304. The input interface 301, the central processing unit 302, the memory 303, and the output interface 304 are interconnected via a bus 310.

[0098] Specifically, the input interface 301 receives input information from the outside and transmits the input information to the central processing unit 302. The central processing unit 302 processes the input information based on the computer-executable instructions stored in the memory 303 to obtain the identification information of multiple sample applications, and determines multiple target devices that have the sample applications installed based on the identification information. Then, it obtains the application installation list of multiple target devices, and finally uses a preset frequent itemset mining algorithm to determine the target applications that meet the preset conditions of correlation with the sample applications based on the application installation list and whitelist applications. The information of the target applications is temporarily or permanently stored in the memory 303, and then the information of the target applications is transmitted to the outside of the computing device 300 for user use through the output interface 304.

[0099] In other words, Figure 3 The computing device shown can also be implemented as a target application-determined device, which may include: a processor and a memory storing computer-executable instructions; the processor can implement the target application determination method provided in the embodiments of the present invention when executing the computer-executable instructions.

[0100] This invention also provides a computer-readable storage medium storing computer program instructions; when executed by a processor, the computer program instructions implement the target application determination method provided in this invention.

[0101] It should be clarified that the present invention is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of the present invention.

[0102] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this invention are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, read-only memory (ROM), flash memory, erasable read-only memory (EROM), floppy disks, compact disc read-only memory (CD-ROM), optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.

[0103] It should also be noted that the exemplary embodiments mentioned in this invention describe methods or systems based on a series of steps or apparatus. However, this invention is not limited to the order of the steps described above; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0104] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0105] The above description is merely a specific embodiment of the present invention. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the protection scope of the present invention.

Claims

1. A method for determining a target application, characterized in that, The method includes: Obtain the identification information of multiple sample applications, wherein the sample applications are those whose security does not meet the preset security conditions; Based on the identification information, multiple target devices for installing the sample application are identified; Obtain the application installation list of the multiple target devices; Using a preset frequent itemset mining algorithm, target applications that meet preset conditions in terms of correlation with the sample applications are determined based on the application installation list and whitelist applications. The whitelist applications are applications that meet preset security conditions. The method uses a preset frequent itemset mining algorithm to determine target applications whose association with the sample applications meets preset conditions, based on the application installation list and whitelist applications. The number of target devices to install the sample application is determined based on the identification information; Based on the quantity, the sample applications are classified into different levels according to a preset installation quantity classification rule; Multiple sample applications belonging to the same level are selected as the target sample application set. Based on the target sample application set, a preset frequent itemset mining algorithm is used to determine multiple target applications whose correlation with the target sample application set meets preset conditions, according to the application installation list and whitelist applications. The step of using a preset frequent itemset mining algorithm to determine target applications whose association with the sample application meets preset conditions based on the application installation list and whitelisted applications includes: determining multiple applications associated with the sample application using the preset frequent itemset mining algorithm based on the application installation list, wherein the multiple applications refer to applications that exist simultaneously with the sample application in the application installation list; and determining at least one application whose quantity of each of the multiple applications meets preset conditions as the target application based on the multiple applications and the whitelisted applications, wherein the preset conditions refer to the maximum number of applications after removing the whitelisted applications.

2. The method according to claim 1, characterized in that, The acquisition of identification information for multiple sample applications includes: Obtain identification information for multiple applications; Remove the identifier information of the whitelisted applications from the identifier information to generate identifier information for multiple sample applications.

3. The method according to claim 1, characterized in that, The step of obtaining the application installation list of the multiple target devices includes: The application installation list is determined based on the applications installed on the multiple target devices and the installation time of the applications.

4. The method according to claim 1, characterized in that, The step of determining at least one application among the multiple applications and whitelisted applications, where the quantity of each application among the multiple applications meets a preset condition, as the target application includes: Remove whitelisted applications from the aforementioned applications; Determine the number of each type of application after removing the whitelisted applications; The target application is defined as at least one application whose quantity meets the preset conditions.

5. An apparatus for determining a target application, characterized in that, The device includes: The acquisition module is used to acquire the identification information of multiple sample applications, wherein the sample applications are applications whose security does not meet the preset security conditions; The processing module is used to determine multiple target devices for installing the sample application based on the identification information; The acquisition module is also used to acquire the application installation list of the multiple target devices; The processing module is further configured to use a preset frequent itemset mining algorithm to determine target applications whose association with the sample application meets preset conditions based on the application installation list and whitelisted applications. The whitelisted applications are those whose security meets preset security conditions. The step of using the preset frequent itemset mining algorithm to determine target applications whose association with the sample application meets preset conditions based on the application installation list and whitelisted applications includes: determining multiple applications associated with the sample application based on the application installation list using the preset frequent itemset mining algorithm; the multiple applications refer to applications that coexist with the sample application in the application installation list; and determining at least one application whose quantity meets preset conditions as the target application based on the multiple applications and the whitelisted applications. The preset conditions refer to the maximum number of applications after removing the whitelisted applications.

6. The apparatus according to claim 5, characterized in that, The acquisition module is also used to acquire the identification information of multiple applications; The processing module is also used to remove the identification information of the whitelisted applications from the identification information and generate identification information of multiple sample applications.

7. The apparatus according to claim 5, characterized in that, The processing module is further configured to determine the application installation list based on the applications installed on the multiple target devices and the installation time of the applications.

8. The apparatus according to claim 5, characterized in that, The processing module is also used to remove whitelisted applications from the various applications; The processing module is also used to determine the number of each type of application after removing the whitelisted applications; The processing module is further configured to select at least one application whose quantity meets a preset condition as the target application.

9. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the method for determining the target application as described in any one of claims 1-4.

10. A computer storage medium, characterized in that, The computer storage medium stores computer program instructions, which, when executed by a processor, implement the method for determining the target application as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Trust management-based mobile application security setting recommendation system

    CN107122655A