Abnormal interface alarm method and device, electronic equipment and computer readable medium

By acquiring and analyzing interface privacy information and access relationship information, updating the database and performing group processing, the problem of not identifying some abnormal interfaces in the existing technology is solved, and the identification of various alarms and specific abnormal information of abnormal interfaces is realized.

CN116361121BActive Publication Date: 2026-08-25MULTIPOINT (SHENZHEN) DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310162596.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-17
Publication Date
2026-08-25
Estimated Expiration
2043-02-17

AI Technical Summary

Technical Problem

In existing technologies, the access relationships between interfaces are not considered when identifying abnormal interfaces, resulting in some abnormal interfaces not being identified and unable to generate effective alerts. Furthermore, the privacy information of website interfaces cannot be identified, and specific abnormal information of abnormal interfaces cannot be alerted.

Method used

By acquiring the interface privacy information and interface access relationship information of each interface in the target application, updating the database, generating an information processing list and grouping processing, and using preset alarm conditions to control the alarm device to perform various alarm processing, including the first alarm and the second alarm.

Benefits of technology

It enables effective alerts for some abnormal interfaces, identifies cross-border interfaces that do not use encryption algorithms, and provides alerts for specific abnormal information of the abnormal interfaces.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116361121B_ABST
    Figure CN116361121B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose an abnormal interface alarm method and device, electronic equipment and a computer readable medium. A specific embodiment of the method comprises: obtaining interface privacy information and interface access relationship information of each interface in a target application; updating a normal interface database, a privacy interface database and an unknown interface database; determining privacy interface data in the privacy interface database as privacy interface information to obtain a privacy interface information set; performing identification processing on a preset privacy template to generate an information processing list; performing grouping processing on the privacy interface information set to generate an application privacy interface information group set; and for each application privacy interface information group in the application privacy interface information group set, in response to determining that the application privacy interface information group meets a preset privacy alarm condition, controlling an associated alarm device to perform first alarm processing. The embodiment can alarm part of abnormal interfaces.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments disclosed herein relate to the field of computer technology, and more specifically to abnormal interface alarm methods, apparatus, electronic devices, and computer-readable media. Background Technology

[0002] Applications may include interfaces that can access users' private information. However, abnormal interfaces may arbitrarily access and transmit this information, leading to privacy leaks. Currently, identifying abnormal interfaces typically involves using dynamic sandbox analysis to obtain interface privacy information and then verifying its validity against relevant privacy policies.

[0003] However, the above methods typically present the following technical problems:

[0004] First, the system only uses the interface privacy information to identify whether an interface is abnormal, without taking into account the access relationship between interfaces. As a result, some abnormal interfaces are not identified and cannot be alerted.

[0005] Second, using dynamic sandbox analysis to obtain interface privacy information imposes high restrictions on applications. It can only identify the interface privacy information of each interface included in the APP (Application), but cannot identify the interface privacy information of each interface included in the website, resulting in the inability to obtain the interface privacy information of some interfaces.

[0006] Third, identifying interfaces through privacy policies can only identify whether an interface is abnormal and can only issue alerts for abnormal interfaces, but cannot issue alerts for specific abnormal information about abnormal interfaces.

[0007] The information disclosed in this background section is only intended to enhance the understanding of the background of the inventive concept, and therefore may contain information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0008] The summary portion of this disclosure is intended to provide a brief overview of the concepts, which will be described in detail in the detailed description portion. This summary portion is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.

[0009] Some embodiments of this disclosure provide methods, apparatus, electronic devices, and computer-readable media for alarming abnormal interfaces to address one or more of the technical problems mentioned in the background section above.

[0010] In a first aspect, some embodiments of this disclosure provide an abnormal interface alarm method, the method comprising: acquiring interface privacy information and interface access relationship information of each interface in a target application to obtain an interface privacy information set and an interface access relationship information set; updating a normal interface database, a privacy interface database, and an unknown interface database based on the interface privacy information set and the interface access relationship information set; identifying privacy interface data in the privacy interface database as privacy interface information to obtain a privacy interface information set; performing identification processing on a preset privacy template to generate an information processing list; grouping the privacy interface information set to generate an application privacy interface information group set; for each application privacy interface information group in the application privacy interface information group set, in response to determining that the application privacy interface information group meets a preset privacy alarm condition, controlling an associated alarm device to perform a first alarm processing, wherein the preset privacy alarm condition is constructed by the information processing list and the application privacy interface information group; and for each privacy interface information in the privacy interface information set, in response to determining that the privacy interface information meets a preset access alarm condition, controlling the alarm device to perform a second alarm processing.

[0011] Secondly, some embodiments of this disclosure provide an abnormal interface alarm device, the device comprising: an acquisition unit configured to acquire interface privacy information and interface access relationship information of each interface in a target application, thereby obtaining an interface privacy information set and an interface access relationship information set; an update unit configured to update a normal interface database, a privacy interface database, and an unknown interface database based on the aforementioned interface privacy information set and the aforementioned interface access relationship information set; a determination unit configured to determine the privacy interface data in the aforementioned privacy interface database as privacy interface information, thereby obtaining a privacy interface information set; an identification unit configured to perform identification processing on a preset privacy template to generate an information processing list; and a grouping unit. The system is configured to group the aforementioned privacy interface information set to generate an application privacy interface information set; a first alarm unit is configured to, for each application privacy interface information set in the aforementioned application privacy interface information set, in response to determining that the aforementioned application privacy interface information set meets a preset privacy alarm condition, control the associated alarm device to perform a first alarm processing, wherein the aforementioned preset privacy alarm condition is constructed by the aforementioned information processing list and the aforementioned application privacy interface information set; a second alarm unit is configured to, for each privacy interface information in the aforementioned privacy interface information set, in response to determining that the aforementioned privacy interface information meets a preset access alarm condition, control the aforementioned alarm device to perform a second alarm processing.

[0012] Thirdly, some embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation of the first aspect above.

[0013] Fourthly, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method described in any of the implementations of the first aspect above.

[0014] The above embodiments of this disclosure have the following beneficial effects: The abnormal interface alarm method of some embodiments of this disclosure can alarm some abnormal interfaces. Specifically, the reason why alarms cannot be alarmed for some abnormal interfaces is that: only interface privacy information is used to identify whether an interface is abnormal, without considering the access relationships between interfaces, resulting in some abnormal interfaces not being identified. Based on this, the abnormal interface alarm method of some embodiments of this disclosure first obtains the interface privacy information and interface access relationship information of each interface in the target application, obtaining an interface privacy information set and an interface access relationship information set. Thus, the interface privacy information and interface access relationship information of each interface can be obtained, taking into account the interface access relationship information, which facilitates subsequent identification of abnormal interfaces. Second, based on the above interface privacy information set and the above interface access relationship information set, the ordinary interface database, the privacy interface database, and the unknown interface database are updated. Thus, each interface can be classified, thereby selecting the data of interfaces involving user privacy information and storing it in the privacy interface database. Next, the privacy interface data in the above privacy interface database is determined as privacy interface information, obtaining a privacy interface information set. Thus, the privacy interface information set corresponding to each interface involving user privacy information can be obtained. Then, the preset privacy template is identified to generate an information processing list. This allows for the identification of the preset privacy template, enabling the generated information processing list to be compared with the privacy data included in the privacy interface information to identify abnormal interfaces. Next, the aforementioned privacy interface information set is grouped to generate application privacy interface information sets. This allows for processing of each application separately. Then, for each application privacy interface information set within the aforementioned application privacy interface information sets, in response to determining that the application privacy interface information set meets preset privacy alarm conditions, the associated alarm device is controlled to perform a first alarm processing. This allows for alarm processing of applications that do not conform to the privacy template. Finally, for each privacy interface information in the aforementioned privacy interface information set, in response to determining that the privacy interface information meets preset access alarm conditions, the aforementioned alarm device is controlled to perform a second alarm processing. This also considers the access relationships between interfaces, allowing for the identification of whether an interface is abnormal based on these relationships. Therefore, alarm processing can be performed on interfaces that cross borders and do not use cross-border encryption algorithms. Thus, considering the access relationships between interfaces, some abnormal interfaces can be identified. Furthermore, alerts can be issued for some abnormal interfaces. Attached Figure Description

[0015] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent when taken in conjunction with the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.

[0016] Figure 1 This is a flowchart of some embodiments of the abnormal interface alarm method according to this disclosure;

[0017] Figure 2 This is a schematic diagram of the structure of some embodiments of the abnormal interface alarm device according to the present disclosure;

[0018] Figure 3 This is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. Detailed Implementation

[0019] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0020] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.

[0021] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0022] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0023] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0024] This disclosure will now be described in detail with reference to the accompanying drawings and embodiments.

[0025] refer to Figure 1 The diagram illustrates a flow 100 of some embodiments of an abnormal interface alarm method according to the present disclosure. This abnormal interface alarm method includes the following steps:

[0026] Step 101: Obtain the interface privacy information and interface access relationship information of each interface in the target application to obtain the interface privacy information set and the interface access relationship information set.

[0027] In some embodiments, the executing entity of the abnormal interface alarm method (e.g., a computing device) can obtain interface privacy information and interface access relationship information of each interface in the target application from the terminal device via a wired or wireless connection, thus obtaining an interface privacy information set and an interface access relationship information set. The target application can be an application that obtains user privacy information. Here, user privacy information may include, but is not limited to, at least one of the following: name, mobile phone number, ID card number, date of birth, and address. A target application may include at least one interface. For example, a target application may be, but is not limited to, a social media app, a news app, a shopping app, or a shopping website.

[0028] In practice, the aforementioned executing entity can obtain the interface privacy information and interface access relationship information of each interface in the target application through the following steps, thus obtaining the interface privacy information set and the interface access relationship information set:

[0029] The first step is to obtain the interface address information for each interface, resulting in an interface address information set. This set may include the interface address and application identifier. An interface address uniquely identifies an interface. An application identifier uniquely identifies an application. An application may include at least one interface. In practice, the executing entity can first add pre-defined dependency code to the target application's code. Then, the executing entity can use this pre-defined dependency code to retrieve the interface address information for each interface from the target application's code, thus obtaining the interface address information set. For example, this pre-defined dependency code could be a Swagger (automatic API documentation generation) dependency.

[0030] The second step involves, for each interface address in the aforementioned interface address information set, in response to determining that the interface corresponding to the aforementioned interface address information meets preset acquisition conditions, obtaining the interface privacy information of the aforementioned interface. The preset acquisition conditions may include the fact that the interface corresponding to the aforementioned interface address information has acquired user privacy information. The aforementioned interface privacy information may include, but is not limited to, at least one of the following: interface address, application identifier, and privacy data. The privacy data may be the user privacy information data acquired by the interface. In practice, the aforementioned execution entity can obtain the interface privacy information of the aforementioned interface from the code of the aforementioned target application through the aforementioned preset dependency code.

[0031] The third step is to determine the obtained privacy information from each interface as an interface privacy information set.

[0032] The fourth step is to obtain the first privacy interface information set. In practice, firstly, the aforementioned executing entity can import the target application into the sandbox. Then, the executing entity can replace the source code of the target application with a preset replacement program. Finally, the executing entity can obtain the first privacy interface information set by calling the preset replacement program. The first privacy interface information in the aforementioned first privacy interface information set may include, but is not limited to, at least one of the following: interface address, application identifier, and privacy data. For example, the aforementioned preset replacement program may be a hook program.

[0033] Fifth step: For each piece of first privacy interface information in the first privacy interface information set, in response to determining that the first privacy interface information is not in the interface privacy information set, add the first privacy interface information to the interface privacy information set.

[0034] Step 6: For each interface address in the above interface address information set, in response to determining that the above interface address information is not in the above interface privacy information set, add the above interface address information to the above interface privacy information set.

[0035] Step 7: Perform traffic statistics processing on each interface to generate interface access relationship information, resulting in an interface access relationship information set. The interface access relationship information in this set may include, but is not limited to, at least one of the following: interface address, access information group, and region identifier. The access information in the access information group may include the access address and the number of accesses. The region identifier may be a first region identifier or a second region identifier. The first region identifier indicates that the interface corresponding to the interface access relationship has engaged in cross-border access. The second region identifier indicates that the interface corresponding to the interface access relationship has not engaged in cross-border access. The access address may be the address of the interface accessed by the interface corresponding to the interface access relationship information. The number of accesses may be the number of times the interface corresponding to the interface access relationship information has accessed the interface within a preset time period. For example, the preset time period may be February 1, 2023 - February 2, 2023. The preset time period may also be January 1, 2023 - February 1, 2023. For example, the traffic statistics processing may include, but is not limited to, Baidu Statistics, Dimension Statistics, and Quantum Hengdao Statistics.

[0036] The technical content in step 101, as an inventive point of this disclosure, solves the second technical problem mentioned in the background art: "inability to alert on some abnormal interfaces." The factors causing the inability to alert on some abnormal interfaces are often as follows: using dynamic sandbox analysis to obtain interface privacy information imposes high restrictions on the application, only recognizing the interface privacy information of the interfaces included in the APP (Application), but not the interface privacy information of the interfaces included in the website, resulting in the inability to obtain the interface privacy information of some interfaces and the inability to identify some abnormal interfaces. If the above factors are solved, the effect of alerting on some abnormal interfaces can be achieved. To achieve this effect, firstly, the interface address information of each interface is obtained, resulting in an interface address information set. Thus, the interface address information of each interface included in the APP or website can be obtained through code scanning. Secondly, for each interface address information in the above interface address information set, in response to determining that the interface corresponding to the above interface address information meets the preset acquisition conditions, the interface privacy information of the above interface is obtained. Thus, the interface privacy information of each interface involving user privacy information can be obtained through code scanning. Next, the obtained interface privacy information is determined as an interface privacy information set. Then, a first privacy interface information set is obtained. This allows for the acquisition of the first privacy interface information set for each interface involving user privacy information through dynamic sandbox analysis. Next, for each piece of first privacy interface information in the first privacy interface information set, in response to determining that the first privacy interface information is not in the interface privacy information set, it is added to the interface privacy information set. This allows for the supplementation and updating of the interface privacy information set using the first privacy interface information set obtained through dynamic sandbox analysis, avoiding the omission of some interface privacy information. Following this, for each interface address information in the interface address information set, in response to determining that the interface address information is not in the interface privacy information set, it is added to the interface privacy information set. This allows for the addition of interface address information that does not involve user privacy information to the privacy interface information set, facilitating subsequent updates to the general interface database. Finally, traffic statistics are performed on each interface to generate interface access relationship information, resulting in an interface access relationship information set. This allows for the acquisition of the interface access relationship information set through traffic analysis technology. Therefore, by using code scanning and dynamic sandbox analysis, we can obtain the interface privacy information of each interface included in the app and website, and supplement the interface privacy information with the interface access relationship information of each interface through traffic analysis technology. Furthermore, we can obtain the privacy interface information of some interfaces and the interface access relationship information of each interface. Thus, we can identify some abnormal interfaces and issue alerts for them.

[0037] Step 102: Update the ordinary interface database, privacy interface database, and unknown interface database based on the interface privacy information set and the interface access relationship information set.

[0038] In some embodiments, the aforementioned executing entity may update the ordinary interface database, the privacy interface database, and the unknown interface database based on the aforementioned interface privacy information set and the aforementioned interface access relationship information set. The ordinary interface database may be used to store ordinary interface data. Ordinary interface data may be data from interfaces that have not acquired privacy data. The privacy interface database may be used to store privacy interface data. Privacy interface data may be data from interfaces that have acquired privacy data. The unknown interface database may be used to store unknown interface data. Unknown interface data may be data from interfaces other than the aforementioned ordinary interfaces and privacy interfaces. Ordinary interface data may include, but is not limited to, at least one of the following: interface address, access information group, and region identifier. Privacy interface data may include, but is not limited to, at least one of the following: interface address, application identifier, privacy data, access information group, and region identifier. Unknown interface data may include, but is not limited to, at least one of the following: interface address, access information group, and region identifier.

[0039] In practice, based on the aforementioned interface privacy information set and interface access relationship information set, the aforementioned executing entity can update the ordinary interface database, privacy interface database, and unknown interface database through the following steps:

[0040] The first step is to add each piece of interface privacy information in the aforementioned interface privacy information set to the general interface database in response to determining that the interface privacy information meets preset privacy conditions. The preset privacy conditions may include the interface privacy information containing empty privacy data.

[0041] The second step involves updating the general interface database for each interface access relationship in the aforementioned interface access relationship information set, in response to determining that the interface address included in the interface access relationship information is in the general interface database. In practice, for each interface access relationship in the aforementioned interface access relationship information set, in response to determining that the interface address included in the interface access relationship information is in the general interface database, the executing entity can add the interface access information to the general interface data corresponding to the interface access information in the general interface database.

[0042] Optionally, the above method further includes:

[0043] The first step is to perform the following update steps for each interface privacy information in the above interface privacy information set:

[0044] The first update step, in response to determining that the above interface privacy information does not meet the above preset privacy conditions, is to determine whether the above interface privacy information is in the privacy interface database.

[0045] In some embodiments, in response to determining that the interface privacy information does not meet the preset privacy conditions, the execution entity may determine whether the interface privacy information is in the privacy interface database.

[0046] The second update step is to update the privacy interface database in response to determining that the aforementioned interface privacy information is in the aforementioned privacy interface database.

[0047] In some embodiments, in response to determining that the interface privacy information is in the privacy interface database, the executing entity may update the privacy interface database. In practice, in response to determining that the interface privacy information is in the privacy interface database, the executing entity may perform fusion processing on the privacy interface data corresponding to the interface privacy information in the privacy interface database and the interface privacy information itself, in order to update the privacy interface data in the privacy interface database.

[0048] The third update step is to add the aforementioned interface privacy information to the aforementioned privacy interface database in response to the determination that the aforementioned interface privacy information is not in the aforementioned privacy interface database.

[0049] In some embodiments, in response to determining that the aforementioned interface privacy information is not in the aforementioned privacy interface database, the aforementioned execution entity may add the aforementioned interface privacy information to the aforementioned privacy interface database.

[0050] The second step is to update the privacy interface database in response to determining that the interface address included in the interface access relationship information set is in the privacy interface database for each interface access relationship information set.

[0051] In some embodiments, for each interface access relationship in the aforementioned interface access relationship information set, in response to determining that the interface address included in the interface access relationship information is in the aforementioned privacy interface database, the executing entity may update the aforementioned privacy interface database. In practice, for each interface access relationship in the aforementioned interface access relationship information set, in response to determining that the interface address included in the aforementioned interface access relationship information is in the aforementioned privacy interface database, the executing entity may add the interface access information to the privacy interface data corresponding to the interface access information in the aforementioned privacy interface database.

[0052] Optionally, for each interface access relationship information in the above interface access relationship information set, in response to determining that the interface address included in the above interface access relationship information is not in the above ordinary interface database and not in the above privacy interface database, the above interface access relationship information is added to the unknown interface database.

[0053] In some embodiments, for each interface access relationship information in the above interface access relationship information set, in response to determining that the interface address included in the above interface access relationship information is not in the above ordinary interface database and not in the above privacy interface database, the execution entity may add the above interface access relationship information to the unknown interface database.

[0054] Step 103: Identify the privacy interface data in the privacy interface database as privacy interface information to obtain the privacy interface information set.

[0055] In some embodiments, the executing entity may determine the privacy interface data in the privacy interface database as privacy interface information to obtain a privacy interface information set. The privacy interface information in the privacy interface information set may include, but is not limited to, at least one of the following: interface address, application identifier, privacy data, access information group, and region identifier. The access information in the access information group may include, but is not limited to, at least one of the following: access address and number of accesses.

[0056] Step 104: Identify and process the preset privacy template to generate an information processing list.

[0057] In some embodiments, the aforementioned executing entity may perform identification processing on a preset privacy template to generate an information processing list. For example, the identification processing may be, but is not limited to, OCR (optical character recognition) text recognition, image recognition, etc. The preset privacy template may represent a pre-defined privacy policy or privacy agreement for collecting user privacy information. For example, the preset privacy template may include, but is not limited to, at least one of the following: name, mobile phone number, ID card number, and address. Before performing any operations involving the collection, storage, or use of user privacy information (such as name, mobile phone number, ID card number, and address) related to the preset privacy template, the relevant organization or individual shall fulfill obligations including conducting a privacy information security impact assessment, informing the privacy information subject, and obtaining prior authorization and consent from the privacy information subject.

[0058] Step 105: Group the privacy interface information set to generate an application privacy interface information set.

[0059] In some embodiments, the executing entity may group the privacy interface information set to generate an application privacy interface information set. In practice, firstly, the executing entity may determine each privacy interface information in the privacy interface information set that shares the same application identifier as a privacy interface information group. Then, the executing entity may define the determined privacy interface information groups as a privacy interface information set.

[0060] Step 106: For each application privacy interface information group in the application privacy interface information group set, in response to determining that the application privacy interface information group meets the preset privacy alarm conditions, control the associated alarm device to perform the first alarm processing.

[0061] In some embodiments, for each application privacy interface information group in the aforementioned application privacy interface information group set, in response to determining that the application privacy interface information group meets preset privacy alarm conditions, the executing entity can control an associated alarm device to perform a first alarm processing. The preset privacy alarm conditions are constructed from the aforementioned information processing list and the aforementioned application privacy interface information group. The preset privacy alarm conditions may be that the privacy data included in the application privacy interface information in the aforementioned application privacy interface information group is not equal to that in the aforementioned information processing list. The associated alarm device may be a device that alarms the application corresponding to the aforementioned application privacy interface information group. The first alarm processing may be displaying warning text or controlling a speaker to emit a prompt sound.

[0062] Step 107: For each privacy interface information in the privacy interface information set, in response to determining that the privacy interface information meets the preset access alarm conditions, control the alarm device to perform the second alarm processing.

[0063] In some embodiments, for each privacy interface information in the aforementioned privacy interface information set, in response to determining that the aforementioned privacy interface information meets preset access alarm conditions, the aforementioned execution entity may control the aforementioned alarm device to perform a second alarm processing. The aforementioned preset access alarm conditions may include the region identifier included in the aforementioned privacy interface information being a first region identifier, and the absence of encrypted transmission. The aforementioned encrypted transmission may be SSL (Secure Socket Layer) transmission, TLS (Transport Layer Security) transmission, or HTTPS (Hypertext Transfer Protocol Secure) transmission. The aforementioned second alarm processing may involve displaying warning text or controlling a speaker to emit a prompt sound.

[0064] Optionally, the above method further includes:

[0065] The first step is to generate a privacy dataset based on the aforementioned privacy interface information set.

[0066] In some embodiments, the aforementioned executing entity may generate a privacy dataset based on the aforementioned privacy interface information set. In practice, the aforementioned executing entity may compare each privacy interface information in the aforementioned privacy interface information set with a preset template to generate privacy data, thus obtaining a privacy dataset. The aforementioned privacy data may include data identical to the privacy interface information and the preset template. The aforementioned preset template may be a pre-set template used to assess whether the information obtained by the interface is compliant. For example, the preset template may be the "Information Security Technology Personal Information Security Impact Assessment Guidelines". The preset template may also include, but is not limited to, at least one of the following: whether user privacy information is obtained, whether SSL or TLS encryption is used, and whether user privacy information is shared or transferred to a third party without the user's permission. Before performing any operations involving the collection, storage, or use of user privacy information (e.g., name, mobile phone number, ID card number, address) in the preset template, the relevant organization or individual must fulfill obligations including conducting a privacy information security impact assessment, informing the privacy information subject, and obtaining prior authorization and consent from the privacy information subject.

[0067] The second step is to generate an information data flow diagram based on the aforementioned privacy interface information set.

[0068] In some embodiments, the aforementioned executing entity may generate an information data flow diagram based on the aforementioned privacy interface information set. The privacy interface information in the aforementioned privacy interface information set includes access information further comprising: an access application identifier. The access application identifier may be the application identifier of the interface accessed by the interface corresponding to the privacy interface information. A preset access condition may be that the number of accesses reaches a preset value. For example, the preset value may be 20. The preset value may also be 50.

[0069] In practice, based on the aforementioned privacy interface information set, the aforementioned executing entity can generate an information data flow diagram through the following sub-steps:

[0070] The first sub-step involves, for each access information included in the aforementioned privacy interface information set, in response to determining that the number of accesses included in the aforementioned access information meets the preset access conditions, performing the following generation steps:

[0071] In the first generation step, in response to determining that the access address included in the access information is in the privacy interface database, the application identifier corresponding to the access address included in the access information is determined as the access application identifier included in the access information.

[0072] The second generation step involves updating the access information in response to the determination that the access address included in the access information is not in the privacy interface database. In practice, firstly, in response to the determination that the access address included in the access information is not in the privacy interface database, the executing entity can send an update reminder message to the operator. Then, in response to the operator updating the access information, the executing entity can use the updated access information as the access information. The update reminder message can be the access application identifier included in the updated access information.

[0073] The third generation step involves generating an information subgraph based on the aforementioned access information. Nodes in this information subgraph can be interfaces corresponding to the access information or interfaces corresponding to the access addresses included in the access information. Connections between nodes in the information subgraph represent the access relationship between two interfaces.

[0074] The second sub-step involves merging the generated information subgraphs to create an information data flow graph. In practice, the executing entity can use common nodes from the various information subgraphs as common nodes to merge them and generate the information data flow graph.

[0075] The third step is to fuse the aforementioned privacy dataset and the aforementioned information data flow graph to generate a privacy data flow graph.

[0076] In some embodiments, the executing entity can fuse the privacy dataset and the information data flow graph to generate a privacy data flow graph. In practice, firstly, the executing entity can send a generation reminder message to the operator. Then, in response to receiving an anomaly information set sent by the operator, the executing entity can add the anomaly information set to the information data flow graph to generate the privacy data flow graph. The generation reminder message can be selected from the privacy dataset as an anomaly. Here, the anomaly information can characterize abnormal information in the privacy dataset. For example, the anomaly information could be: plaintext transmission of user privacy information. The anomaly information could also be: the use of cookies (data stored on the user's local terminal) without consent.

[0077] The fourth step is to control the alarm device to perform the third alarm processing based on the above privacy data flow diagram.

[0078] In some embodiments, the executing entity can control the alarm device to perform third alarm processing based on the privacy data flow graph. This third alarm processing may involve displaying warning text or controlling a speaker to emit a warning sound. In practice, the executing entity can control the alarm device to perform third alarm processing on abnormal information included in the privacy data flow graph. For example, the third alarm processing may involve displaying abnormal information included in the privacy data flow graph.

[0079] The optional technical content in step 107, as an inventive point of this disclosure, solves the third technical problem mentioned in the background art: "inability to alert for specific abnormal information of abnormal interfaces." The factors that prevent alerting for specific abnormal information of abnormal interfaces are often as follows: identifying interfaces through privacy policies can only identify whether an interface is abnormal, and can only alert for abnormal interfaces. If these factors are resolved, the effect of alerting for specific abnormal information of abnormal interfaces can be achieved. To achieve this effect, firstly, a privacy dataset is generated based on the aforementioned privacy interface information set. Thus, privacy data can be generated by comparing a preset template with the privacy interface information, so that abnormal information can be subsequently selected. Secondly, an information data flow graph is generated based on the aforementioned privacy interface information set. Thus, an information data flow graph including the access relationships between interfaces can be generated based on the access information included in the privacy interface information. Next, the aforementioned privacy dataset and the aforementioned information data flow graph are fused to generate a privacy data flow graph. Thus, the abnormal information in the manually selected privacy dataset and the information data flow graph can be fused to generate a privacy data flow graph including the access relationships between interfaces and the abnormal information of the interfaces. Therefore, specific abnormal information for each interface can be obtained. Finally, based on the aforementioned privacy data flow diagram, the alarm device is controlled to perform third-level alarm processing. This allows for alarms to be issued for specific anomalies of abnormal interfaces.

[0080] The above embodiments of this disclosure have the following beneficial effects: The abnormal interface alarm method of some embodiments of this disclosure can alarm some abnormal interfaces. Specifically, the reason why alarms cannot be alarmed for some abnormal interfaces is that: only interface privacy information is used to identify whether an interface is abnormal, without considering the access relationships between interfaces, resulting in some abnormal interfaces not being identified. Based on this, the abnormal interface alarm method of some embodiments of this disclosure first obtains the interface privacy information and interface access relationship information of each interface in the target application, obtaining an interface privacy information set and an interface access relationship information set. Thus, the interface privacy information and interface access relationship information of each interface can be obtained, taking into account the interface access relationship information, which facilitates subsequent identification of abnormal interfaces. Second, based on the above interface privacy information set and the above interface access relationship information set, the ordinary interface database, the privacy interface database, and the unknown interface database are updated. Thus, each interface can be classified, thereby selecting the data of interfaces involving user privacy information and storing it in the privacy interface database. Next, the privacy interface data in the above privacy interface database is determined as privacy interface information, obtaining a privacy interface information set. Thus, the privacy interface information set corresponding to each interface involving user privacy information can be obtained. Then, the preset privacy template is identified to generate an information processing list. This allows for the identification of the preset privacy template, enabling the generated information processing list to be compared with the privacy data included in the privacy interface information to identify abnormal interfaces. Next, the aforementioned privacy interface information set is grouped to generate application privacy interface information sets. This allows for processing of each application separately. Then, for each application privacy interface information set within the aforementioned application privacy interface information sets, in response to determining that the application privacy interface information set meets preset privacy alarm conditions, the associated alarm device is controlled to perform a first alarm processing. This allows for alarm processing of applications that do not conform to the privacy template. Finally, for each privacy interface information in the aforementioned privacy interface information set, in response to determining that the privacy interface information meets preset access alarm conditions, the aforementioned alarm device is controlled to perform a second alarm processing. This also considers the access relationships between interfaces, allowing for the identification of whether an interface is abnormal based on these relationships. Therefore, alarm processing can be performed on interfaces that cross borders and do not use cross-border encryption algorithms. Thus, considering the access relationships between interfaces, some abnormal interfaces can be identified. Furthermore, alerts can be issued for some abnormal interfaces.

[0081] Further reference Figure 2 As an implementation of the methods shown in the above figures, this disclosure provides some embodiments of an abnormal interface alarm device, which are similar to... Figure 1 Corresponding to the method embodiments shown, this abnormal interface alarm device can be specifically applied to various electronic devices.

[0082] like Figure 2 As shown, the abnormal interface alarm device 200 in some embodiments includes: an acquisition unit 201, an update unit 202, a determination unit 203, an identification unit 204, a grouping unit 205, a first alarm unit 206, and a second alarm unit 207. The acquisition unit 201 is configured to acquire interface privacy information and interface access relationship information of each interface in the target application, obtaining an interface privacy information set and an interface access relationship information set; the update unit 202 is configured to update the ordinary interface database, the privacy interface database, and the unknown interface database based on the aforementioned interface privacy information set and the aforementioned interface access relationship information set; the determination unit 203 is configured to determine the privacy interface data in the aforementioned privacy interface database as privacy interface information, obtaining a privacy interface information set; the identification unit 204 is configured to perform identification processing on a preset privacy template to generate an information processing list; the grouping unit 205 is configured to group the aforementioned privacy... The interface information set is grouped to generate an application privacy interface information set; the first alarm unit 206 is configured to, for each application privacy interface information set in the above application privacy interface information set, in response to determining that the above application privacy interface information set meets a preset privacy alarm condition, control the associated alarm device to perform a first alarm processing, wherein the above preset privacy alarm condition is constructed by the above information processing list and the above application privacy interface information set; the second alarm unit 207 is configured to, for each privacy interface information in the above privacy interface information set, in response to determining that the above privacy interface information meets a preset access alarm condition, control the above alarm device to perform a second alarm processing.

[0083] It is understandable that the units described in the abnormal interface alarm device 200 are related to the reference. Figure 1 The steps in the described method correspond to each other. Therefore, the operations, features, and beneficial effects described above for the method also apply to the abnormal interface alarm device 200 and the units contained therein, and will not be repeated here.

[0084] The following is for reference. Figure 3 This document illustrates a structural schematic of an electronic device (e.g., a computing device) 300 suitable for implementing some embodiments of the present disclosure. The electronic devices in some embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 3 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of this disclosure.

[0085] like Figure 3 As shown, the electronic device 300 may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage device 308 into a random access memory (RAM) 303. The RAM 303 also stores various programs and data required for the operation of the electronic device 300. The processing unit 301, ROM 302, and RAM 303 are interconnected via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.

[0086] Typically, the following devices can be connected to I / O interface 305: input devices 306 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 307 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 308 including, for example, magnetic tapes, hard disks, etc.; and communication devices 309. Communication device 309 allows electronic device 300 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 3 An electronic device 300 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively. Figure 3 Each box shown can represent a device or multiple devices as needed.

[0087] In particular, according to some embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 309, or installed from a storage device 308, or installed from a ROM 302. When the computer program is executed by the processing device 301, it performs the functions defined in the methods of some embodiments of this disclosure.

[0088] It should be noted that, in some embodiments of this disclosure, the computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In some embodiments of this disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of this disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0089] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.

[0090] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device. The aforementioned computer-readable medium carries one or more programs. When the aforementioned one or more programs are executed by the electronic device, the electronic device causes the following actions: It acquires interface privacy information and interface access relationship information for each interface in the target application, obtaining an interface privacy information set and an interface access relationship information set; based on the aforementioned interface privacy information set and the aforementioned interface access relationship information set, it updates a general interface database, a privacy interface database, and an unknown interface database; it identifies privacy interface data in the aforementioned privacy interface database as privacy interface information, obtaining a privacy interface information set; it performs identification processing on a preset privacy template to generate an information processing list; it performs group processing on the aforementioned privacy interface information set to generate an application privacy interface information group set; for each application privacy interface information group in the aforementioned application privacy interface information group set, in response to determining that the aforementioned application privacy interface information group meets a preset privacy alarm condition, it controls an associated alarm device to perform a first alarm processing, wherein the aforementioned preset privacy alarm condition is constructed by the aforementioned information processing list and the aforementioned application privacy interface information group; for each privacy interface information in the aforementioned privacy interface information set, in response to determining that the aforementioned privacy interface information meets a preset access alarm condition, it controls the aforementioned alarm device to perform a second alarm processing.

[0091] Computer program code for performing operations of some embodiments of this disclosure can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0092] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0093] The units described in some embodiments of this disclosure can be implemented in software or hardware. The described units can also be housed in a processor; for example, a processor can be described as including an acquisition unit, an update unit, a determination unit, an identification unit, a grouping unit, a first alarm unit, and a second alarm unit. The names of these units do not necessarily limit the specific unit itself; for example, the acquisition unit can also be described as "acquiring interface privacy information and interface access relationship information of each interface in the target application, to obtain an interface privacy information set and an interface access relationship information set."

[0094] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0095] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of this disclosure.

Claims

1. A method for issuing alarms for abnormal interfaces, comprising: Obtain the interface privacy information and interface access relationship information of each interface in the target application to obtain the interface privacy information set and the interface access relationship information set; Based on the interface privacy information set and the interface access relationship information set, update the ordinary interface database, the privacy interface database, and the unknown interface database; The privacy interface data in the privacy interface database is identified as privacy interface information, thus obtaining a privacy interface information set; The preset privacy templates are identified and processed to generate an information processing list; The privacy interface information set is grouped to generate an application privacy interface information set; For each application privacy interface information group in the application privacy interface information group set, in response to determining that the application privacy interface information group meets the preset privacy alarm conditions, the associated alarm device is controlled to perform the first alarm processing, wherein the preset privacy alarm conditions are constructed by the information processing list and the application privacy interface information group; For each privacy interface information in the privacy interface information set, in response to determining that the privacy interface information meets the preset access alarm conditions, the alarm device is controlled to perform a second alarm processing.

2. The method according to claim 1, wherein, The interface access relationship information in the interface access relationship information set includes: interface address; and The step of updating the ordinary interface database, the privacy interface database, and the unknown interface database based on the interface privacy information set and the interface access relationship information set includes: For each piece of interface privacy information in the interface privacy information set, in response to determining that the interface privacy information meets the preset privacy conditions, the interface privacy information is added to the ordinary interface database; For each interface access relationship information in the interface access relationship information set, in response to determining that the interface address included in the interface access relationship information is in the general interface database, the general interface database is updated.

3. The method according to claim 2, wherein, The method further includes: For each piece of interface privacy information in the interface privacy information set, perform the following update steps: In response to determining that the interface privacy information does not meet the preset privacy conditions, determine whether the interface privacy information is in the privacy interface database; In response to determining that the interface privacy information is in the privacy interface database, the privacy interface database is updated; In response to determining that the interface privacy information is not in the privacy interface database, the interface privacy information is added to the privacy interface database; For each interface access relationship in the interface access relationship information set, in response to determining that the interface address included in the interface access relationship information is in the privacy interface database, the privacy interface database is updated.

4. The method according to claim 3, wherein, The method further includes: For each interface access relationship information in the interface access relationship information set, in response to determining that the interface address included in the interface access relationship information is not in the ordinary interface database and not in the privacy interface database, the interface access relationship information is added to the unknown interface database.

5. An abnormal interface alarm device, comprising: The acquisition unit is configured to acquire the interface privacy information and interface access relationship information of each interface in the target application, and obtain the interface privacy information set and the interface access relationship information set. The update unit is configured to update the ordinary interface database, the privacy interface database, and the unknown interface database based on the interface privacy information set and the interface access relationship information set. The determining unit is configured to determine the privacy interface data in the privacy interface database as privacy interface information, thereby obtaining a privacy interface information set. The identification unit is configured to identify and process a preset privacy template in order to generate an information processing list; A grouping unit is configured to group the privacy interface information set to generate an application privacy interface information set. The first alarm unit is configured to, for each application privacy interface information group in the application privacy interface information group set, in response to determining that the application privacy interface information group meets the preset privacy alarm conditions, control the associated alarm device to perform the first alarm processing, wherein the preset privacy alarm conditions are constructed by the information processing list and the application privacy interface information group; The second alarm unit is configured to, for each privacy interface information in the privacy interface information set, in response to determining that the privacy interface information meets the preset access alarm conditions, control the alarm device to perform a second alarm processing.

6. An electronic device, comprising: One or more processors; A storage device on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-4.

7. A computer-readable medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Method and device for detecting data leakage interface

    CN107038372A

  • Privacy information leakage detection method and device and electronic equipment

    CN115004185A