Risk device identification method, device, equipment and storage medium
By verifying the core layer information and key files of the terminal device operating system, the risk equipment that has been modified at the bottom of the operating system is identified, which solves the problem that the existing technology is difficult to identify black production equipment and improves the recognition ability.
Patent Information
- Application Number
- CN202310072179.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-13
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2043-01-13
AI Technical Summary
It is difficult to effectively identify black industry equipment in the existing technology, which disguise as ordinary user terminal equipment and commit network violations.
By determining the core layer information of the terminal device operating system, obtaining the target key file information corresponding to the core layer information, verifying the key files in the terminal device, and then identifying the risks of the terminal device.
It improves the ability to identify risk equipment such as black industry equipment, and can effectively analyze whether the underlying layer of the operating system has been tampered with, and identify the risk equipment that has been modified from the underlying layer of the operating system.
Smart Images

Figure CN116055202B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technologies, and in particular to the field of mobile security technologies. Background Art
[0002] The network black industrial chain, abbreviated as the network black production, refers to the use of Internet technologies to implement network illegal acts. For example, network illegal acts may include network fraud, ticket scalping, malicious coupon grabbing, false traffic marketing, etc. A black production device refers to an electronic device used by lawbreakers to conduct network black production. Lawbreakers will disguise the black production device as a terminal device of an ordinary user and send user requests to the server in order to implement network illegal acts. Based on this, how to identify these black production devices is an urgent problem to be solved. Summary of the Invention
[0003] The present disclosure provides a method, an apparatus, a device, a storage medium, and a program product for identifying a risk device.
[0004] According to one aspect of the present disclosure, there is provided a method for identifying a risk device, including: determining core layer information of an operating system for a terminal device; determining target key file information corresponding to the core layer information; verifying key files in the terminal device according to the target key file information to obtain a key file verification result; and identifying a risk for the terminal device according to the key file verification result to obtain a first identification result.
[0005] According to another aspect of the present disclosure, there is provided an apparatus for identifying a risk device, including: a core layer information determination module for determining core layer information of an operating system for a terminal device; a key file information determination module for determining target key file information corresponding to the core layer information; a key file verification module for verifying key files in the terminal device according to the target key file information to obtain a key file verification result; and a first risk identification module for identifying a risk for the terminal device according to the key file verification result to obtain a first identification result.
[0006] Another aspect of the present disclosure provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method shown in the embodiments of the present disclosure.
[0007] According to another aspect of the embodiments of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to execute the method shown in the embodiments of the present disclosure.
[0008] According to another aspect of the embodiments of the present disclosure, there is provided a computer program product, including computer programs / instructions, characterized in that when the computer programs / instructions are executed by a processor, the steps of the method shown in the embodiments of the present disclosure are implemented.
[0009] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understandable through the following description. Description of the Drawings
[0010] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:
[0011] Figure 1 Schematically shows an exemplary system architecture to which the method and apparatus for identifying risk devices according to the embodiments of the present disclosure can be applied;
[0012] Figure 2 Schematically shows a flowchart of the method for identifying risk devices according to the embodiments of the present disclosure;
[0013] Figure 3 Schematically shows a flowchart of the method for determining target key file information corresponding to core layer information according to the embodiments of the present disclosure;
[0014] Figure 4 Schematically shows a flowchart of the method for verifying key files of a terminal device according to the embodiments of the present disclosure;
[0015] Figure 5 Schematically shows a schematic diagram of an operating system according to the embodiments of the present disclosure;
[0016] Figure 6 Schematically shows a schematic diagram of the method for identifying risk devices according to the embodiments of the present disclosure;
[0017] Figure 7 Schematically shows a block diagram of the apparatus for identifying risk devices according to the embodiments of the present disclosure;
[0018] Figure 8 Schematically shows a block diagram of an example electronic device that can be used to implement the embodiments of the present disclosure. Detailed Embodiments
[0019] The exemplary embodiments of the present disclosure will be described below in conjunction with the accompanying drawings. Various details of the embodiments of the present disclosure are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, descriptions of well-known functions and structures are omitted below for clarity and conciseness.
[0020] The following will be combined with Figure 1 Describe the system architecture of the method and device for identifying risk devices provided by the present disclosure.
[0021] Figure 1 Figure 100 schematically shows an exemplary system architecture to which the method and device for identifying risk devices according to the embodiments of the present disclosure can be applied. It should be noted that Figure 1 The figure shown is only an example of the system architecture to which the embodiments of the present disclosure can be applied, to help those skilled in the art understand the technical content of the present disclosure, but it does not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments or scenarios.
[0022] As Figure 1 shown, the system architecture 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0023] Users can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications may be installed on the terminal devices 101, 102, 103, such as map applications, network disk applications, shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).
[0024] The terminal devices 101, 102, 103 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.
[0025] The server 105 may be a server that provides various services, such as a background management server that supports websites or applications browsed or used by users using the terminal devices 101, 102, 103 (only as an example). The background management server may analyze and process data such as received user requests, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0026] Server 105 may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services (″Virtual Private Server″, or simply ″VPS″). Server 105 may also be a server of a distributed system, or a server combined with a blockchain.
[0027] It should be noted that the method for identifying risk devices provided in the embodiments of the present disclosure can generally be executed by server 105. Correspondingly, the device for identifying risk devices provided in the embodiments of the present disclosure can generally be set in server 105. The method for identifying risk devices provided in the embodiments of the present disclosure can also be executed by a server or a server cluster different from server 105 and capable of communicating with terminal devices 101, 102, 103, and / or server 105. Correspondingly, the device for identifying risk devices provided in the embodiments of the present disclosure can also be set in a server or a server cluster different from server 105 and capable of communicating with terminal devices 101, 102, 103, and / or server 105.
[0028] It should be understood that Figure 1 the numbers of terminal devices, networks, and servers in
[0029] In the technical solution of the present disclosure, the processing of collection, storage, use, processing, transmission, provision, disclosure, and application of user personal information involved all comply with the provisions of relevant laws and regulations, adopt necessary confidentiality measures, and do not violate public order and good customs.
[0030] In the technical solution of the present disclosure, before obtaining or collecting user personal information, the authorization or consent of the user is obtained.
[0031] The method and device for identifying risk devices provided by the present disclosure can be applied to fields such as risk control, anti-crawler, face recognition, and data search.
[0032] The following will combine Figure 2 to describe the method for identifying risk devices provided by the present disclosure.
[0033] Figure 2 Schematically shows a flowchart of the method for identifying risk devices according to an embodiment of the present disclosure.
[0034] As Figure 2 shown, the method 200 for identifying risk devices includes operations S210 to S240.
[0035] Among them, in operation S210, for the operating system of the terminal device, the core layer information of the operating system is determined.
[0036] According to an embodiment of the present disclosure, the core layer information may include, for example, information related to the core layer, such as the version information of the core layer. Exemplarily, in this embodiment, the operating system may include, for example, the Android system. The core layer may include, for example, Kernel.
[0037] Then, in operation S220, the target key file information corresponding to the core layer information is determined.
[0038] According to an embodiment of the present disclosure, the target key file information may include information related to the key file, such as the identifier and storage directory of the key file, etc. The key file may include, for example, the SO files of the operating system, such as libc.so, libandroid.so, libart.so, etc. Among them, the SO file is a dynamic link library file of the operating system.
[0039] In operation S230, according to the target key file information, the key files in the terminal device are verified to obtain a key file verification result.
[0040] According to an embodiment of the present disclosure, by verifying the key files in the terminal device, it is possible to determine whether the key files in the terminal device are abnormal, and a key file verification result is obtained. The key file verification result can be used to indicate whether the key files in the terminal device are abnormal.
[0041] In operation S240, according to the key file verification result, the terminal device is identified for risks to obtain a first identification result.
[0042] According to an embodiment of the present disclosure, if the key file verification result indicates that the key files are abnormal, it means that the risk of the terminal device is relatively high. Therefore, it can be determined that the first identification result is: the terminal device belongs to a risk device. If the key file verification result indicates that the key files are normal, it means that the risk of the terminal device is relatively low. Therefore, it can be determined that the first identification result is: the terminal device does not belong to a risk device.
[0043] Lawbreakers will modify the operating system of black production devices and use the modified operating system to implement network illegal acts. According to an embodiment of the present disclosure, by verifying the key files of the operating system of the terminal device, it is possible to identify risk devices such as black production devices, and the identification rate is relatively high.
[0044] According to another embodiment of the present disclosure, for example, a target application can be configured in a terminal device, and the target application can include a native layer. Based on this, the core layer information can be obtained through the native layer of the target application.
[0045] The following will be combined with Figure 3 to describe the method for determining target key file information provided by the present disclosure.
[0046] Figure 3 A flowchart of a method for determining target key file information according to an embodiment of the present disclosure is schematically shown.
[0047] As Figure 3 shown, the method 320 for determining target key file information includes operation S321 to operation S322.
[0048] Among them, in operation S321, white list data is obtained.
[0049] According to an embodiment of the present disclosure, the white list data may include at least one reference core layer information, and reference key file information corresponding to each reference core layer information in the at least one reference core layer information.
[0050] In operation S322, the reference key file information corresponding to the target core layer information in the white list data is determined as the target key file information.
[0051] According to an embodiment of the present disclosure, the white list data may include a plurality of sub-data, and each sub-data includes a key and at least one value. Among them, the reference core layer information can be used as the key, and the reference key file information corresponding to the reference core layer information can be used as the corresponding value. Based on this, the sub-data with the target core layer information as the key can be searched in the white list data, and then the target key file information can be determined according to the value in the sub-data.
[0052] The following will be combined with Figure 4 to describe the method for verifying key files of a terminal device provided by the present disclosure.
[0053] Figure 4 A flowchart of a method for verifying key files of a terminal device according to an embodiment of the present disclosure is schematically shown.
[0054] As Figure 4 shown, the method 430 for verifying key files of the terminal device includes operation S431 to operation S434.
[0055] Among them, in operation S431, according to the reference storage directory of at least one reference key file, it is determined whether the storage directory of the target key file in the terminal device is abnormal, and a first judgment result is obtained.
[0056] According to an embodiment of the present disclosure, for example, it can be checked whether the storage directory of the target key file in the terminal device is consistent with the reference storage directory. If they are inconsistent, it can be determined that the first judgment result is abnormal. If they are consistent, it can be further checked whether the size of the storage directory has changed compared with the corresponding reference storage directory. If the size has changed, it can be determined that the first judgment result is abnormal. In addition, it can be checked whether the modification time of the storage directory is consistent with the reference storage directory. If they are inconsistent, it can be determined that the first judgment result is abnormal. If all the above checks pass, it can be determined that the first judgment result is normal.
[0057] In operation S432, according to at least one reference key file, it is determined whether there is an increase in the target key file in the terminal device, and a second judgment result is obtained.
[0058] According to an embodiment of the present disclosure, it can be determined whether there are other key files in the memory of the terminal device except for at least one reference key file. If there are, it can be determined that the second judgment result is abnormal. In addition, it can be searched in the memory of the terminal device whether there are other key files except for at least one reference key file. If there are, it can be determined that the second judgment result is abnormal. If no other key files are found, it can be determined that the second judgment result is normal.
[0059] In operation S433, according to at least one reference key file, it is determined whether the target key file in the terminal device has been tampered with, and a third judgment result is obtained.
[0060] According to an embodiment of the present disclosure, for example, time information, MD5 information, etc. of the target key file can be obtained. Among them, MD5 is a kind of message digest algorithm. It is determined whether the time information of the target key file has been tampered with compared with the time information of the corresponding reference key file. If it has been tampered with, it is determined that the third judgment result is abnormal, and it is determined whether the MD5 information of the target key file has been tampered with compared with the MD5 information of the corresponding reference key file. If it has been tampered with, it is determined that the third judgment result is abnormal. If neither has been tampered with, it is determined that the third judgment result is normal.
[0061] In operation S434, according to the first judgment result, the second judgment result and the third judgment result, the key file verification result is determined.
[0062] According to an embodiment of the present disclosure, when the first judgment result, the second judgment result, and the third judgment result are all normal, it can be determined that the key file verification result is: passed verification. When at least one of the first judgment result, the second judgment result, and the third judgment result is abnormal, it can be determined that the key file verification result is: failed verification.
[0063] Related technologies are difficult to identify risk devices that have modified the underlying operating system. According to an embodiment of the present disclosure, by verifying key files, it is possible to analyze whether the underlying operating system has been tampered with, and then identify risk devices that have modified the underlying operating system, improving the ability to identify risk devices.
[0064] According to another embodiment of the present disclosure, for example, the correspondence between reference startup process information and reference core layer information can also be obtained. Among them, the reference core layer information is the core layer information of the reference device, and the reference startup process information can include the process identifier and modification time of the startup process, etc. Then, according to the correspondence, the reference startup process information corresponding to the reference core layer information can be determined as the target startup process information. Next, according to the target startup process information, the file identifier and modification time of the startup process in the terminal device can be verified to obtain the startup process verification result. Then, according to the startup process verification result, the second identification result can be determined. If the file identifier and modification time of the startup process are inconsistent with the target startup process information, it can be determined that the second identification result is: the terminal device is a risk device. Exemplarily, for example, the core layer information and startup process information of multiple reference devices can be collected, and by counting the number of times the core layer information and startup process information of these reference devices appear in the same device, the occurrence frequency of the core layer information and startup process information appearing simultaneously can be determined, and the core layer information and startup process information with an occurrence frequency higher than the first occurrence frequency threshold are determined as the reference startup process information and the reference core layer information, and the correspondence between the reference startup process information and the reference core layer information is recorded. Among them, the first occurrence frequency threshold can be set according to actual needs.
[0065] According to another embodiment of the present disclosure, for example, application permission information of the terminal device can also be obtained. The application permission information represents the permissions that an application can obtain, such as camera permission, location information acquisition permission, memory read and write permission, etc. Then, standard application permission information corresponding to the core layer information can be determined. The standard application permission information can be used to represent the permissions provided by the normal operating system to the application. Next, based on the application permission information and the standard application permission information of the terminal device, the terminal device can be identified for risks to obtain a third identification result. For example, if the application permission information of the terminal device shows that the permissions that the application can obtain exceed the permissions represented by the standard application permission information, it means that someone has performed a privilege escalation operation by modifying the operating system of the terminal device. Based on this, it can be determined that the third identification result is: the terminal device is a risky device.
[0066] According to another embodiment of the present disclosure, for example, device manufacturer information of the terminal device can also be obtained. The device manufacturer information can be used to represent the manufacturer of the terminal device, for example, it can include a manufacturer identifier. According to the corresponding relationship between the manufacturer and the core layer information, it is determined whether the device manufacturer information matches the core layer information to obtain a matching result. Then, based on the matching result, the terminal device is identified for risks to obtain a fourth identification result. If the device manufacturer information does not match the core layer information, it can be determined that the fourth identification result is: the terminal device is a risky device. There is a relatively fixed corresponding relationship between the manufacturer and the operating system. For example, a manufacturer often uses its own developed or customized operating system and does not use the operating system developed or customized by its competitors. Based on this, the device manufacturer information and the core layer information of a large number of terminal devices can be statistically analyzed, and the combinations of the device manufacturer information and the core layer information with an appearance frequency higher than the second appearance frequency threshold are recorded to obtain the corresponding relationship, where the second appearance frequency threshold can be set according to actual needs.
[0067] The following refers to Figures 5 - 6 , and further illustrates the method for identifying a risky device shown above in combination with specific embodiments. Those skilled in the art can understand that the following exemplary embodiments are only for understanding the present disclosure, and the present disclosure is not limited thereto.
[0068] Figure 5 FIG. schematically shows a schematic diagram of an operating system according to an embodiment of the present disclosure. Exemplarily, in this embodiment, the operating system can be an Android system.
[0069] In Figure 5 it is shown that the operating system can include an application part, a core part, and a bottom layer part.
[0070] According to an embodiment of the present disclosure, the application part can include an application layer, and the application layer can include various applications, such as a search application, a map application, a network disk application, and so on.
[0071] According to an embodiment of the present disclosure, the core part may include an Application Framework, a Zygote, and Libraries. Among them, the Application Framework may include modules such as component management, window management, system data, and control frameworks. The Zygote may include a virtual machine, such as a Dalvik Virtual Machine, Java core libraries, etc. The Libraries may include data such as libc.so, libandroid.so, libart.so, SQLite, and OpenGL. Among them, libc.so, libandroid.so, and libart.so are dynamic link library files of the operating system, SQLite is a lightweight database, and OpenGL is a 3D graphics software package.
[0072] According to an embodiment of the present disclosure, the underlying part may include a Hardware Abstract Layer and a Linux Kernel. Among them, the Hardware Abstract Layer may include audio-video interfaces, call interfaces, WiFi interfaces, etc. The Linux Kernel may include processes, threads, power management, drivers, etc.
[0073] Figure 6 A schematic diagram showing a method for identifying a risk device according to an embodiment of the present disclosure is schematically illustrated.
[0074] According to an embodiment of the present disclosure, at least one core layer information and startup process information corresponding to each core layer information may be stored in a correspondence library.
[0075] In Figure 6As shown, when the application starts, a corresponding startup process will be created. Among them, the startup process can include, for example, the zygote process and other child processes started by the zygote process. In this embodiment, the startup process can be protected. For example, the core layer information of the terminal device operating system can be obtained. The core layer information can include, for example, the Kernel version information. Then, in the corresponding relationship library, using the core layer information as the primary key, the corresponding startup process information can be searched to obtain at least one piece of target startup process information. Next, check whether there is a startup process file in the terminal device that does not match the at least one piece of target startup process information. If not, it means the risk of the terminal device is relatively low. If there is, it means the risk of the terminal device is relatively high, and the corresponding recognition result can be determined as: the terminal device is a risky device. Check whether there is a startup process in the memory of the terminal device that does not match the at least one piece of target startup process information. If not, it means the risk of the terminal device is relatively low. If there is, it means the risk of the terminal device is relatively high, and the corresponding recognition result can be determined as: the terminal device is a risky device. In addition, the target startup process information includes the modification time of the startup process. It can be determined whether the modification time of the startup process in the terminal device matches the target startup process information. If it matches, it means the risk of the terminal device is relatively low. If it does not match, it means the risk of the terminal device is relatively high, and the corresponding recognition result can be determined as: the terminal device is a risky device. Then, record the terminal devices with relatively high risk in the black device library. Subsequently, the risky devices can be identified according to the records in the black device library.
[0076] According to an embodiment of the present disclosure, the key files of the operating system can also be protected. Among them, the key files can include, for example, SO files.
[0077] According to an embodiment of the present disclosure, at least one white list is stored in the white list library. Each white list includes at least one piece of reference core layer information and reference key file information corresponding to each piece of reference core layer information in the at least one piece of reference core layer information. Exemplarily, in the white list, the reference core layer information can be used as the primary key and the reference key file information can be used as the value. Based on this, the target key file information corresponding to the core layer information can be searched in the white list library. For example, the value corresponding to the core layer information in the white list can be searched to obtain the target key file information.
[0078] According to an embodiment of the present disclosure, the target key file information can include, for example, at least one reference key file and the standard storage directory of the at least one reference key file.
[0079] According to an embodiment of the present disclosure, it is possible to determine whether the storage directory of a target critical file in a terminal device is abnormal according to the standard storage directory of at least one reference critical file, and obtain a first judgment result. For example, it is possible to check whether the storage directory of the target critical file is consistent with the reference storage directory. If they are inconsistent, it can be determined that the first judgment result is abnormal. If they are consistent, it is possible to further check whether the size of the storage directory has changed compared with the corresponding reference storage directory. If the size has changed, it can be determined that the first judgment result is abnormal. In addition, it is also possible to check whether the modification time of the storage directory is consistent with the reference storage directory. If they are inconsistent, it can be determined that the first judgment result is abnormal. If all the above checks pass, it can be determined that the first judgment result is normal.
[0080] According to an embodiment of the present disclosure, it is possible to determine whether there is an increase in the target critical file in the terminal device or whether there is a suspicious critical file according to at least one reference critical file, and obtain a second judgment result. For example, it is determined whether there are other critical files in the memory of the terminal device except for at least one reference critical file. If there are, it can be determined that the second judgment result is abnormal. In addition, it is possible to search in the memory of the terminal device to see if there are other critical files except for at least one reference critical file. If there are, the other critical file is a suspicious critical file, and it can be determined that the second judgment result is abnormal. If no other critical files are found, it can be determined that the second judgment result is normal.
[0081] According to an embodiment of the present disclosure, it is possible to determine whether the target critical file in the terminal device has been tampered with according to at least one reference critical file, and obtain a third judgment result. For example, for the target critical file in the storage directory and the target critical file that is running, time information, MD5 information and other information of the target critical file can be obtained respectively. It is determined whether the time information of the target critical file has been tampered with compared with the time information of the corresponding reference critical file. If it has been tampered with, it is determined that the third judgment result is abnormal, and it is determined whether the MD5 information of the target critical file has been tampered with compared with the MD5 information of the corresponding reference critical file. If it has been tampered with, it is determined that the third judgment result is abnormal. If neither has been tampered with, it is determined that the third judgment result is normal.
[0082] After obtaining the first judgment result, the second judgment result, and the third judgment result, the key file verification result can be determined based on the first judgment result, the second judgment result, and the third judgment result. For example, if at least one of the first judgment result, the second judgment result, and the third judgment result is abnormal, it is determined that the key file verification result is: failed verification, and the target key file is recorded in the black file library. If the first judgment result, the second judgment result, and the third judgment result are all normal, it is determined that the key file verification result is: passed verification, and the target key file is recorded in the white file library. Subsequently, the key files of the operating system can be directly identified based on the records in the black file library and the white file library, thereby determining whether the operating system is abnormal, and further identifying the risk devices.
[0083] Next, the operating systems of the risk devices can also be classified. The classification types can include, for example, modifying the manufacturer information, modifying the system parameters, abnormal face-swiping behavior, etc. Then, the classified operating systems and the corresponding types can be recorded in the operating system tag library. Subsequently, the type of the operating system can be determined based on the records in the operating system tag library.
[0084] The following will combine Figure 7 to describe the risk device identification apparatus provided by the present disclosure.
[0085] Figure 7 Schematically shows a block diagram of a risk device identification apparatus according to an embodiment of the present disclosure.
[0086] As Figure 7 shown, the risk device identification apparatus 700 includes a core layer information determination module 710, a key file information determination module 720, a key file verification module 730, and a first risk identification module 740.
[0087] The core layer information determination module 710 is configured to determine the core layer information of the operating system for the terminal device.
[0088] The key file information determination module 720 is configured to determine the target key file information corresponding to the core layer information.
[0089] The key file verification module 730 is configured to verify the key files in the terminal device according to the target key file information to obtain a key file verification result.
[0090] The first risk identification module 740 is configured to identify the risk of the terminal device according to the key file verification result to obtain a first identification result.
[0091] According to an embodiment of the present disclosure, the target critical file information may include at least one reference critical file and a reference storage directory of the at least one reference critical file. The critical file verification module may include: a first determination sub-module, configured to determine whether the storage directory of the target critical file in the terminal device is abnormal according to the reference storage directory of the at least one reference critical file, to obtain a first determination result; a second determination sub-module, configured to determine whether the target critical file in the terminal device has been added according to the at least one reference critical file, to obtain a second determination result; a third determination sub-module, configured to determine whether the target critical file in the terminal device has been tampered with according to the at least one reference critical file, to obtain a third determination result; and a critical file verification sub-module, configured to determine a critical file verification result according to the first determination result, the second determination result, and the third determination result.
[0092] According to an embodiment of the present disclosure, the critical file information determination module may include: a whitelist acquisition sub-module, configured to acquire whitelist data, where the whitelist data includes at least one reference core layer information and reference critical file information corresponding to each reference core layer information in the at least one reference core layer information; and a target critical file information determination sub-module, configured to determine the reference critical file information corresponding to the target core layer information in the whitelist data as the target critical file information.
[0093] According to an embodiment of the present disclosure, a target application program may be configured in the terminal device, and the target application program may include a native layer. The core layer information determination module may include: a core layer information acquisition sub-module, configured to acquire core layer information through the native layer of the target application program.
[0094] According to an embodiment of the present disclosure, the above-mentioned device may further include: a raw information acquisition module, configured to acquire raw core layer information and raw critical file information of a plurality of raw devices; a statistics module, configured to perform statistics on the raw core layer information and the raw critical file information of the plurality of raw devices to obtain a statistical result; and a whitelist determination module, configured to determine whitelist data according to the statistical result.
[0095] According to an embodiment of the present disclosure, the above-mentioned device may further include: a correspondence acquisition module, configured to acquire a correspondence between reference startup process information and reference core layer information, where the reference startup process information includes a process identifier and a modification time of the startup process; a startup process determination module, configured to determine the reference startup process information corresponding to the reference core layer information as the target startup process information according to the correspondence; a startup process verification module, configured to verify the file identifier and the modification time of the startup process in the terminal device according to the target startup process information to obtain a startup process verification result; and a second recognition module, configured to determine a second recognition result according to the startup process verification result.
[0096] According to an embodiment of the present disclosure, the above device may further include: a permission acquisition module, configured to acquire application permission information of the terminal device; a standard permission acquisition module, configured to determine standard application permission information corresponding to the target operating system information; and a third identification module, configured to identify risks for the terminal device according to the application permission information and the standard application permission information of the terminal device, and obtain a third identification result.
[0097] According to an embodiment of the present disclosure, the above device may further include: a manufacturer information acquisition module, configured to acquire device manufacturer information of the terminal device; a matching module, configured to determine whether the device manufacturer information matches the operating system information according to the correspondence between the manufacturer and the operating system, and obtain a matching result; and a fourth identification module, configured to identify risks for the terminal device according to the matching result, and obtain a fourth identification result.
[0098] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0099] Figure 8 A block diagram of an example electronic device 800 that can be used to implement the embodiments of the present disclosure is schematically shown. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0100] As Figure 8 shown, the device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other through a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0101] Multiple components in device 800 are connected to I / O interface 805, including: input unit 806, such as a keyboard, mouse, etc.; output unit 807, such as various types of displays, speakers, etc.; storage unit 808, such as a disk, optical disc, etc.; and communication unit 809, such as a network card, modem, wireless communication transceiver, etc. Communication unit 809 allows device 800 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0102] Computing unit 801 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of computing unit 801 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Computing unit 801 executes the various methods and processes described above, such as the method for identifying a risk device. For example, in some embodiments, the method for identifying a risk device can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 800 via ROM 802 and / or communication unit 809. When the computer program is loaded into RAM 803 and executed by computing unit 801, one or more steps of the method for identifying a risk device described above can be executed. Alternatively, in other embodiments, computing unit 801 can be configured to execute the method for identifying a risk device in any other suitable manner (e.g., by means of firmware).
[0103] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), system-on-a-chip systems (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs, the one or more computer programs can be executed and / or interpreted on a programmable system including at least one programmable processor, the programmable processor can be a dedicated or general-purpose programmable processor, can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0104] The program code for implementing the methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, a special purpose computer, or other programmable data processing device, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program code may be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on the remote machine or server.
[0105] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0106] In order to provide interaction with a user, the systems and techniques described herein may be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, speech input, or tactile input).
[0107] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.
[0108] A computer system can include clients and servers. The clients and servers are generally far from each other and typically interact through a communication network. The client - server relationship is created by computer programs running on the respective computers and having a client - server relationship with each other.
[0109] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and no limitation is imposed herein.
[0110] The above - mentioned specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub - combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.
Claims
1. A method for identifying a risk device, comprising: Determining core layer information of the operating system for the terminal device; Determining target key file information corresponding to the core layer information; Verifying key files in the terminal device according to the target key file information to obtain a key file verification result; Identifying risks for the terminal device according to the key file verification result to obtain a first identification result; Determining reference startup process information corresponding to the core layer information according to the correspondence between the reference startup process information and the reference core layer information, as target startup process information; The target startup process information includes a process identifier and a modification time of the startup process; Verifying the file identifier and modification time of the startup process in the terminal device according to the target startup process information to obtain a startup process verification result; Determining a second identification result according to the startup process verification result; wherein, the correspondence is obtained by the following method: determining the simultaneous occurrence frequency according to the number of times the core layer information and the startup process information of the reference device appear in the same device; using the core layer information and the startup process information with the simultaneous occurrence frequency higher than the first occurrence frequency threshold as the reference startup process information and the reference core layer information, and recording the correspondence.
2. The method according to claim 1, wherein, The target key file information includes at least one reference key file and a reference storage directory of the at least one reference key file; The verifying the key files in the terminal device according to the target key file information to obtain a key file verification result includes: Determining whether the storage directory of the target key file in the terminal device is abnormal according to the reference storage directory of the at least one reference key file to obtain a first judgment result; Determining whether there is an increase in the target key file in the terminal device according to the at least one reference key file to obtain a second judgment result; Determining whether the target key file in the terminal device is tampered with according to the at least one reference key file to obtain a third judgment result; and Determining the key file verification result according to the first judgment result, the second judgment result and the third judgment result.
3. The method according to claim 1, wherein, The determining the target key file information corresponding to the core layer information includes: Obtaining whitelist data, wherein the whitelist data includes at least one reference core layer information and reference key file information corresponding to each reference core layer information in the at least one reference core layer information; and Determining the reference key file information corresponding to the reference core layer information in the whitelist data as the target key file information.
4. The method according to claim 3, wherein, The terminal device is configured with a target application program, and the target application program includes a native layer; the determining the core layer information of the operating system includes: Obtaining the core layer information through the native layer of the target application program.
5. The method according to claim 3, wherein, The whitelist data is generated according to the following operations: Obtain the original core layer information and original key file information of multiple original devices; Statistically analyze the original core layer information and original key file information of multiple original devices to obtain a statistical result; And Determine the whitelist data according to the statistical result.
6. The method according to claim 1, further comprises: Obtain the application permission information of the terminal device; Determine the standard application permission information corresponding to the core layer information; And Identify risks for the terminal device according to the application permission information of the terminal device and the standard application permission information to obtain a third identification result.
7. The method according to claim 1, further comprises: Obtain the device manufacturer information of the terminal device; Determine whether the device manufacturer information matches the core layer information according to the correspondence between the manufacturer and the core layer information to obtain a matching result; And Identify risks for the terminal device according to the matching result to obtain a fourth identification result.
8. An identification device for risk devices, comprises: A core layer information determination module, configured to determine the core layer information of the operating system for the terminal device; A key file information determination module, configured to determine the target key file information corresponding to the core layer information; A key file verification module, configured to verify the key files in the terminal device according to the target key file information to obtain a key file verification result; And A first risk identification module, configured to identify risks for the terminal device according to the key file verification result to obtain a first identification result; A target startup process information determination module, configured to determine the reference startup process information corresponding to the core layer information as the target startup process information according to the correspondence between the reference startup process information and the reference core layer information; The target startup process information includes the process identifier and modification time of the startup process; A process verification module, configured to verify the file identifier and modification time of the startup process in the terminal device according to the target startup process information to obtain a startup process verification result; A second identification module, configured to determine a second identification result according to the startup process verification result; Wherein, the correspondence is obtained by the following method: Determine the simultaneous occurrence frequency according to the number of times the core layer information and the startup process information of the reference device appear in the same device; Use the core layer information and startup process information with the simultaneous occurrence frequency higher than the first occurrence frequency threshold as the reference startup process information and the reference core layer information, and record the correspondence.
9. An electronic device, comprises: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the method according to any one of claims 1-7.
10. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are for causing the computer to execute the method according to any one of claims 1-7.
11. A computer program product, comprising a computer program / instructions, wherein, when the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1-7 are implemented.
Citation Information
Patent Citations
Terminal control method, system and device based on zero trust
CN114124583A