Security verification methods, devices, electronic equipment and storage media for application software
By verifying sentinel nodes using a dynamic verification matrix, the problem of fixed security verification logic for application software in existing technologies is solved, thus achieving high-reliability security verification for application software.
Patent Information
- Application Number
- CN202310547608.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-16
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2043-05-16
AI Technical Summary
In existing technologies, the security verification logic of application software is fixed. Attackers can bypass the verification anchor by accumulating the number of attacks, resulting in low security and reliability.
A dynamic verification matrix is used to represent the dynamic logical protection relationship between sentinel nodes. The dynamic verification matrix is obtained based on the timestamp of the current moment. N sentinel nodes are verified to obtain the target verification result of the target application software.
The dynamic verification matrix with time-dimensional variability improves the reliability of security verification, prevents attackers from attacking application software by accumulating attack attempts, and enhances the security of application software and the reliability of verification methods.
Smart Images

Figure CN116582326B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of information security technology, specifically to a security verification method, apparatus, electronic device, and storage medium for application software. Background Technology
[0002] With the continuous development of internet technology, the types and number of mobile applications are gradually increasing. For application security protection scenarios, relevant technologies generally rely on the signature protection mechanism provided by the mobile operating system to verify the application, such as verifying the application's signature. When the application runs the signature verification logic and finds a signature mismatch, it indicates that the application's security has been compromised.
[0003] However, because the signature verification logic of the application software in related technologies is static and fixed, attackers can locate the verification anchor point in the signature verification logic by accumulating the number of attacks, and then achieve attack operations by bypassing the verification anchor point. Therefore, related technologies suffer from the technical problem of low security and reliability of application software. Summary of the Invention
[0004] In view of the above problems, this disclosure provides a method, apparatus, electronic device and storage medium for secure verification of application software.
[0005] According to a first aspect of this disclosure, a security verification method for application software is provided, comprising:
[0006] Based on the current timestamp, obtain the dynamic verification matrix for the current time. The dynamic verification matrix represents the dynamic logical protection relationship between N sentinel nodes. The sentinel nodes are used to perform security verification on the target application software, where N≥2.
[0007] The above N sentinel nodes are verified based on the dynamic verification matrix, and the target verification result of the target application software is obtained.
[0008] According to embodiments of this disclosure, the process of verifying the N sentinel nodes based on the dynamic verification matrix to obtain the target verification result of the target application software includes:
[0009] Based on the logical protection relationship represented by the dynamic verification matrix above, the verification order of the above N sentinel nodes is determined;
[0010] Following the verification order described above, the N sentinel nodes are verified sequentially, yielding at least one node verification result. This node verification result represents the verification outcome of the aforementioned sentinel node.
[0011] Based on the verification results of at least one of the above nodes, the verification result of the above target is determined.
[0012] According to embodiments of this disclosure, the above-mentioned verification of the N sentinel nodes is performed sequentially according to the above-mentioned verification order to obtain at least one node verification result, including:
[0013] Verify the above N sentinel nodes until the verification result of the i-th node corresponding to the i-th sentinel node is detected to be abnormal, then stop the detection and obtain the verification result of the i-th node, 1≤i≤N;
[0014] Verify the above N sentinel nodes until the verification result of each node is found to be normal, and obtain the verification results of N nodes.
[0015] According to embodiments of this disclosure, determining the target verification result based on the verification results of at least one node includes:
[0016] If an anomaly is found in the verification results of at least one of the above nodes, the target verification result is identified as an anomaly, and a verification report for the target verification result is generated based on the verification results of at least one of the above nodes.
[0017] If the verification results of at least one of the above nodes are all normal, the verification result of the target is determined to be normal, and a verification report for the verification result of the target is generated based on the verification results of at least one of the above nodes.
[0018] According to embodiments of this disclosure, the method further includes:
[0019] If the above target verification result is determined to be abnormal, protective measures shall be performed based on the above verification report.
[0020] According to embodiments of this disclosure, before obtaining the dynamic verification matrix for the current time based on the current timestamp, the method further includes:
[0021] Based on the target application software described above, the above N sentinel nodes are determined;
[0022] The aforementioned N sentinel nodes form a time-dependent dynamic sentinel linkage network, where each sentinel node in the network has a relationship with at least one other sentinel node; and
[0023] Based on the aforementioned dynamic sentinel linkage network, the aforementioned dynamic verification matrix is generated.
[0024] According to embodiments of this disclosure, determining the N sentinel nodes based on the target application software includes:
[0025] The target application software is divided into M protected objects, where M ≥ 2, by using functions as the unit.
[0026] Based on the aforementioned M protected objects and the aforementioned target application software, L first nodes are determined. These first nodes are used to protect the aforementioned protected objects, where L ≥ M ≥ 2; and
[0027] Based on the aforementioned L first nodes, (NL) second nodes are determined. These second nodes are used to protect the aforementioned first nodes. The aforementioned N sentinel nodes include the aforementioned L first nodes and the aforementioned (NL) second nodes.
[0028] According to embodiments of this disclosure, determining L first nodes based on the M protected objects and the target application software includes:
[0029] Based on the security level and performance data of the target application software, determine the total number of the first nodes mentioned above; and
[0030] Based on the protection strength weight of the protected objects and the total number of the first nodes, one or more first nodes corresponding to each protected object are determined to obtain the L first nodes used to protect the M protected objects.
[0031] A second aspect of this disclosure provides a security verification device for application software, comprising:
[0032] The acquisition module obtains the dynamic verification matrix at the current time based on the current timestamp. The dynamic verification matrix represents the dynamic logical protection relationship between N sentinel nodes. The sentinel nodes are used to perform security verification on the target application software, where N≥2.
[0033] The verification module is used to verify the above N sentinel nodes according to the above dynamic verification matrix, and obtain the target verification result of the above target application software.
[0034] A third aspect of this disclosure provides an electronic device, comprising: one or more processors; and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors perform the security verification method of the application software.
[0035] A fourth aspect of this disclosure also provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the security verification method of the application software described above.
[0036] The fifth aspect of this disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the security verification method of the application software described above.
[0037] The embodiments of this disclosure obtain a dynamic verification matrix based on the current timestamp. This dynamic verification matrix represents the dynamic logical protection relationships between N sentinel nodes. By verifying the N sentinel nodes according to the dynamic verification matrix, the target verification result of the target application software is obtained, achieving security verification based on time-dimensional variability and improving the reliability of the security verification method. Since the dynamic verification matrix in this embodiment changes over time, the logical protection relationships within the dynamic verification matrix are also dynamic, resulting in different numbers of sentinel nodes and different logical protection relationships between multiple sentinel nodes at each time point. Therefore, using a timestamp-related dynamic verification matrix for verification ensures that attackers cannot attack the application software by accumulating attack attempts, improving the security of the application software and the reliability of the security verification method. Attached Figure Description
[0038] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:
[0039] Figure 1 This diagram illustrates an application scenario of the security verification method for application software according to an embodiment of the present disclosure.
[0040] Figure 2 A flowchart illustrating a security verification method for application software according to an embodiment of the present disclosure is shown schematically.
[0041] Figure 3 A flowchart illustrating a method for determining a target verification result according to an embodiment of the present disclosure is shown schematically;
[0042] Figure 4 This illustration schematically depicts a security verification scenario according to a specific embodiment of the present disclosure;
[0043] Figure 5A This illustration schematically depicts a security verification scenario at time A according to embodiment A of this disclosure;
[0044] Figure 5B This illustration schematically depicts a security verification scenario at time B according to embodiment B of this disclosure;
[0045] Figure 6 A flowchart illustrating a method for generating a dynamic verification matrix according to an embodiment of the present disclosure is shown schematically;
[0046] Figure 7 A schematic diagram illustrating the generation of a dynamic verification matrix according to an embodiment of the present disclosure is shown.
[0047] Figure 8 This schematically illustrates a structural block diagram of a security verification device for application software according to embodiments of the present disclosure; and
[0048] Figure 9 A block diagram of an electronic device suitable for a security verification method for application software according to an embodiment of the present disclosure is shown schematically. Detailed Implementation
[0049] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.
[0050] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0051] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0052] When using expressions such as "at least one of A, B, and C", they should generally be interpreted in accordance with the meaning that is commonly understood by a person skilled in the art (e.g., "a system having at least one of A, B, and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B, and C, etc.).
[0053] In the technical solutions disclosed herein, the collection, storage, use, processing, transmission, provision, disclosure, and application of data (including but not limited to user personal information) comply with the provisions of relevant laws and regulations, necessary confidentiality measures have been taken, and they do not violate public order and good morals.
[0054] In related technologies, for Android operating system applications, signature verification logic is typically pre-generated based on mobile device operation information. Then, verification anchor points are set at preset locations within the application software based on this logic. During signature verification, the signature verification result of each anchor point is verified by traversing the entire application software. If a signature inconsistency is found, it indicates a security risk in the application software.
[0055] However, the signature verification logic of the aforementioned security verification scheme is fixed and its characteristics are obvious. Attackers can accumulate attack attempts to locate verification anchors within the application software one by one. After locating the verification anchors, attackers can bypass them using techniques such as dynamic injection or hooks to carry out their attacks. Even if the number of verification anchors is increased, attackers can still achieve their goals by accumulating attack attempts. Therefore, the related technologies suffer from low reliability in security verification.
[0056] The embodiments of this disclosure provide a security verification method for application software, including: obtaining a dynamic verification matrix at the current time based on the current timestamp, the dynamic verification matrix representing the dynamic logical protection relationship between N sentinel nodes, the sentinel nodes being used to perform security verification on the target application software, where N≥2; verifying the N sentinel nodes based on the dynamic verification matrix to obtain the target verification result of the target application software.
[0057] Figure 1 The illustration shows an application scenario diagram of the security verification method for application software according to an embodiment of the present disclosure.
[0058] like Figure 1 As shown, the application scenario 100 according to this embodiment may include a terminal 101 and a server 102. The terminal 101 includes a variety of terminal devices, such as a first terminal device 101-1, a second terminal device 101-2, and a third terminal device 101-3.
[0059] The first terminal device 101-1, the second terminal device 101-2, the third terminal device 101-3, and the server 102 can communicate via a network. The network can include various connection types, such as wired or wireless communication links or fiber optic cables, etc.
[0060] The first terminal device 101-1, the second terminal device 101-2, and the third terminal device 101-3 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0061] Various communication client applications can be installed on the first terminal device 101-1, the second terminal device 101-2, and the third terminal device 101-3, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only). Users can use at least one of the first terminal device 101-1, the second terminal device 101-2, and the third terminal device 101-3 to interact with the server 102 through the network to receive or send messages, etc.
[0062] Server 102 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101-1, the second terminal device 101-2, and the third terminal device 101-3 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0063] For example, server 102 can generate a dynamic verification matrix that changes over time and send the dynamic verification matrix to at least one of the first terminal device 101-1, the second terminal device 101-2, and the third terminal device 101-3 to achieve secure verification of application software in the terminal devices.
[0064] It should be noted that the application software security verification method provided in this disclosure embodiment can generally be executed by the terminal 101. Accordingly, the application software security verification device provided in this disclosure embodiment can generally be set in the terminal 101.
[0065] For example, terminal 101 obtains the dynamic verification matrix of the current time from server 102 based on the current timestamp; verifies N sentinel nodes based on the dynamic verification matrix, and obtains the target verification result of the target application software.
[0066] The application software security verification method provided in this embodiment can also be executed by server 102. Accordingly, the application software security verification device provided in this embodiment can generally be located in server 102.
[0067] For example, server 102 obtains the timestamp of the current moment, obtains the dynamic verification matrix of the current moment based on the timestamp, verifies N sentinel nodes based on the dynamic verification matrix, obtains the target verification result of the target application software, and returns the target verification result to terminal 101.
[0068] The application software security verification method provided in this disclosure can also be executed by a server or server cluster that is different from server 102 and can communicate with terminal 101 and / or server 102. Correspondingly, the application software security verification device provided in this disclosure can also be set in a server or server cluster that is different from server 102 and can communicate with terminal 101 and / or server 102.
[0069] For example, after obtaining the current timestamp, the third-party server retrieves the dynamic verification matrix from server 102 based on the current timestamp. The third-party server then verifies N sentinel nodes using the dynamic verification matrix to obtain the target verification result for the target application software and returns the target verification result to terminal 101.
[0070] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0071] The following will be based on Figure 1 The described scene, through Figures 2-7 The security verification method for application software according to the disclosed embodiments is described in detail.
[0072] Figure 2 A flowchart illustrating a security verification method for application software according to an embodiment of the present disclosure is shown schematically.
[0073] like Figure 2 As shown, the method 200 includes operations S210 to S220.
[0074] In operation S210, the dynamic verification matrix for the current time is obtained based on the current timestamp. The dynamic verification matrix represents the dynamic logical protection relationship between N sentinel nodes. The sentinel nodes are used to perform security verification on the target application software, where N≥2.
[0075] According to embodiments of this disclosure, when running application software (APP), specific business behaviors or security verification behaviors occurring at each moment of the application software can be recorded based on timestamps.
[0076] A sentinel node is a piece of code in computer software responsible for performing specific security protection or defense functions. Sentinel nodes can be set up within the target application software without affecting its normal business operations.
[0077] According to embodiments of this disclosure, in the case of security verification, a timestamp of the current moment is obtained from the target application software. Based on the timestamp, a dynamic verification matrix for the current moment is obtained from the server. Since the dynamic verification matrix changes over time, the logical protection relationship of N sentinel nodes at the current moment can be determined based on the dynamic verification matrix at the current moment.
[0078] In operation S220, N sentinel nodes are verified according to the dynamic verification matrix to obtain the target verification result of the target application software.
[0079] According to embodiments of this disclosure, since the dynamic verification matrix includes dynamic logical protection relationships between N sentinel nodes, after obtaining the dynamic verification matrix, not only can the number of sentinel nodes implementing security verification be obtained at the current moment, but also the logical protection relationships between the sentinel nodes at the current moment can be obtained.
[0080] According to embodiments of this disclosure, the dynamic verification matrix at multiple times may include a plurality of sentinel nodes and logical protection relationships between the plurality of sentinel nodes. The dynamic verification matrix at different times may include different sentinel nodes.
[0081] For example, the dynamic verification matrix at time C includes 5 sentinel nodes, such as sentinel node a, sentinel node b, sentinel node c, sentinel node d, and sentinel node e, as well as the logical protection relationships between these 5 sentinel nodes. The dynamic verification matrix at time D includes 3 sentinel nodes, such as sentinel node a, sentinel node b, and sentinel node c, as well as the logical protection relationships between these 3 sentinel nodes. That is, the dynamic verification matrix at different times includes different numbers of sentinel verification nodes.
[0082] The dynamic verification matrix at time E includes three sentinel nodes, such as sentinel node c, sentinel node d, and sentinel node e, as well as the logical protection relationships between these three sentinel nodes. The dynamic verification matrix at time F also includes three sentinel nodes, such as sentinel node a, sentinel node b, and sentinel node c, as well as the logical protection relationships between these three sentinel nodes. In other words, the dynamic verification matrix at different times includes different sentinel verification nodes.
[0083] The dynamic protection matrices at times B and F both include sentinel node a, sentinel node b, and sentinel node c. The logical protection relationship between the three sentinel nodes represented by the dynamic protection matrix at time B can be a→b→c→a, while the logical protection relationship represented by the dynamic protection matrix at time F can be b→a→c→b. That is, the dynamic verification matrices at different times include different logical protection relationships.
[0084] According to an embodiment of this disclosure, after obtaining the dynamic verification matrix at the current moment, the N sentinel nodes are verified based on the logical protection relationship between the N sentinel nodes represented in the dynamic verification matrix, and the target verification result of the target application software is obtained.
[0085] According to embodiments of this disclosure, the verification of sentinel nodes can be performed by verifying the checksum calculated by N sentinel nodes to obtain the target verification result; alternatively, one or more target functions can be called by N sentinel nodes to obtain the calculation result of the function, and then verification can be performed based on the calculation result of the function to obtain the target verification result; alternatively, one or more digital signatures can be obtained by N sentinel nodes for verification to obtain the target verification result.
[0086] The above verification method is only an exemplary embodiment, but is not limited thereto. It may also include verification methods known in the art, as long as the application software security verification method can be implemented through a dynamic verification matrix.
[0087] The embodiments of this disclosure obtain a dynamic verification matrix based on the current timestamp. This dynamic verification matrix represents the dynamic logical protection relationships between N sentinel nodes. By verifying the N sentinel nodes according to the dynamic verification matrix, the target verification result of the target application software is obtained, achieving security verification based on time-dimensional variability and improving the reliability of the security verification method. Since the dynamic verification matrix in this embodiment changes over time, the logical protection relationships within the dynamic verification matrix are also dynamic, resulting in different numbers of sentinel nodes and different logical protection relationships between multiple sentinel nodes at each time point. Therefore, using a timestamp-related dynamic verification matrix for verification ensures that attackers cannot attack the application software by accumulating attack attempts, improving the security of the application software and the reliability of the security verification method.
[0088] Figure 3 A flowchart illustrating a method for determining a target verification result according to an embodiment of the present disclosure is shown schematically.
[0089] like Figure 3 As shown, the method 300 for determining the target verification result in this embodiment includes operations S321 to S323, which can be used as a specific embodiment of operation S220.
[0090] In operation S321, the verification order of N sentinel nodes is determined based on the logical protection relationship represented by the dynamic verification matrix.
[0091] In operation S322, N sentinel nodes are verified sequentially according to the verification order to obtain at least one node verification result. The node verification result represents the verification result of the sentinel node.
[0092] In operation S323, the target verification result is determined based on the verification result of at least one node.
[0093] According to embodiments of this disclosure, sentinel nodes are used to perform security verification on target application software. The target application software includes numerous program blocks with various business functions, each program block comprising multiple lines of program code, and each sentinel node can protect a portion of this program code. N sentinel nodes with logical protection relationships can collectively protect the security of the target application software.
[0094] According to embodiments of this disclosure, the logical protection relationship between N sentinel nodes can characterize the sequential verification order among the N sentinel nodes. After obtaining the dynamic verification matrix, the verification order of the N sentinel nodes is determined by analyzing the dynamic verification matrix.
[0095] According to embodiments of this disclosure, after determining the verification order of N sentinel nodes, the N sentinel nodes are verified sequentially according to the verification order.
[0096] According to embodiments of this disclosure, attackers can carry out attacks by bypassing sentinel nodes; they can also attack sentinel nodes to prevent them from triggering alarms when attacked, thereby enabling them to carry out attacks.
[0097] The sentinel node consists of a first node and a second node. The first node protects the target application software, and the second node protects the first node. By protecting the target application software through the first node and then protecting the first node through the second node, the security of the entire target application software is achieved.
[0098] According to embodiments of this disclosure, after verifying the sentinel node, the sentinel node outputs a node verification result, wherein the node verification result represents the verification result of the current sentinel node, in order to determine whether the multi-line program code protected by the current sentinel node has been modified or whether the current sentinel node is secure.
[0099] According to embodiments of this disclosure, since the verification order of the N sentinel nodes depends on a dynamic verification matrix, and the dynamic verification matrix changes over time, the verification order of the N sentinel nodes is time-variable. Because the verification order is time-variable, attackers cannot bypass the sentinel nodes to carry out attacks. Therefore, as long as the multiple lines of code protected by a sentinel node are modified, the sentinel node protecting the aforementioned multiple lines of code can issue an alert.
[0100] According to embodiments of this disclosure, following the verification sequence, the security of a portion of the code can be determined for each sentinel node verified and yielding a node verification result indicating normal operation. If a node verification result indicates an anomaly, it can be determined that the target application software is currently under attack, and the attack location can be pinpointed. Therefore, during the verification of N sentinel nodes, at least one node verification result can be obtained, and the target verification result of the target application software can be determined based on this at least one node verification result.
[0101] In related technologies, when performing security verification on application software, the signature verification logic needs to traverse and calculate all asset information or executable code of the entire application software. However, the size of current application software is usually over 100MB. Therefore, related technologies still suffer from technical problems such as long execution time, poor performance, and low execution efficiency of the signature verification logic.
[0102] The embodiments of this disclosure determine the verification order of N sentinel nodes based on the logical protection relationships represented by a dynamic verification matrix; verify the N sentinel nodes sequentially according to the verification order to obtain at least one node verification result; and determine the target verification result based on the verification result of at least one node. In the embodiments of this disclosure, the verification order of the sentinel nodes is time-variable. If an anomaly is detected in the verification result of a certain node, the target verification result can be determined to be anomaly, thus achieving secure verification of the application software.
[0103] Therefore, the embodiments of this disclosure only require calculating the verification result of at least one node to determine the target verification result. Compared with the traditional method of verifying the entire software, the embodiments of this disclosure reduce the computational load of security verification, reduce the performance consumption of security verification on software operation, and improve the execution efficiency of security verification.
[0104] According to embodiments of this disclosure, N sentinel nodes are verified sequentially according to the verification order to obtain at least one node verification result, including: verifying N sentinel nodes until the verification result of the i-th node corresponding to the i-th sentinel node is detected as abnormal, stopping the detection and obtaining the i-th node verification result, 1≤i≤N; verifying N sentinel nodes until the verification result of each node is detected as normal, obtaining N node verification results.
[0105] According to embodiments of this disclosure, during the verification of N sentinel nodes based on the verification order, it is necessary to determine whether the current node verification result is abnormal after obtaining each node verification result. If the current node verification result is determined to be normal, the current node verification result is stored and the verification of the next sentinel node is performed. If the current node verification result is determined to be abnormal, the detection is stopped, and the remaining sentinel nodes are no longer detected. Based on the current node verification result and the previous node verification results, the target verification result is determined to be abnormal.
[0106] For example, following the verification order, sentinel nodes a, b, c, d, and e are verified sequentially. The verification results for sentinel nodes a, b, and c all indicate that they are functioning normally.
[0107] After verifying sentinel node d and obtaining its verification result, an anomaly was detected in the verification result for sentinel node d. Therefore, sentinel node e was no longer verified, resulting in four verification results. Based on these four verification results, it can be determined that the target application's verification result is abnormal.
[0108] In the embodiments disclosed herein, N sentinel nodes are verified sequentially to obtain at least one node verification result. If an abnormality is detected in the node verification result, the detection is stopped, thereby reducing performance consumption.
[0109] According to embodiments of this disclosure, determining a target verification result based on at least one node verification result includes: if an anomaly is found in the verification results of at least one node, determining the target verification result as an anomaly, and generating a verification report for the target verification result based on the verification results of at least one node.
[0110] If at least one node verification result is found to be normal, the target verification result is determined to be normal, and a verification report for the target verification result is generated based on the verification results of at least one node.
[0111] According to embodiments of this disclosure, during the verification of N sentinel nodes in the verification order, if the verification result of a certain sentinel node is abnormal, the executable code in the target application software may be attacked, and the sentinel node itself may also be attacked. All of the above situations indicate that the target application software has a security risk. Therefore, if it is determined that at least one node verification result is abnormal, the target verification result is determined to be abnormal; if it is determined that at least one node verification result is normal, the target verification result is determined to be normal.
[0112] According to embodiments of this disclosure, the verification report for the target verification result includes the number of node verification results and the specific result of the node verification result, such as abnormal or normal. If the target verification result is abnormal, the verification report also includes the attack location.
[0113] After determining the target verification result based on the verification results of at least one node, the embodiments of this disclosure also generate a verification report including the number of node verification results and the specific results, which helps operation and maintenance personnel to perform protection operations based on the verification report.
[0114] According to embodiments of this disclosure, when the target verification result is determined to be abnormal, protective operations are performed based on the verification report.
[0115] According to embodiments of this disclosure, a sentinel node may include a pre-triggered trigger, a validator, and a responder. The pre-triggered trigger is used to start the sentinel node, the validator is used to perform a verification operation, and the responder is used to process the output of the validator.
[0116] According to embodiments of this disclosure, after obtaining the dynamic verification matrix at the current moment, a wake-up list is determined based on the dynamic verification matrix. This wake-up list includes identifiers of N sentinel nodes to be verified. Trigger commands are then sent to the pre-triggers of the N sentinel nodes according to the wake-up list to activate the N sentinel nodes.
[0117] According to embodiments of this disclosure, J sentinel nodes can be set within the target application, and N sentinel nodes to be verified are determined from the J sentinel nodes based on a dynamic verification matrix, where J ≥ N.
[0118] According to an embodiment of this disclosure, after N sentinel nodes are started by a pre-triggered trigger, a verification operation is performed by a verifier to obtain the node verification result.
[0119] According to embodiments of this disclosure, after the verifier outputs the node verification result, a responder can detect whether the node verification result is abnormal. If an abnormal node verification result is detected, the responder can directly execute predefined response logic to perform protective operations, such as interrupting service execution or triggering an alarm.
[0120] According to embodiments of this disclosure, the verification report includes specific verification results of node verification results. If the target verification result is determined to be abnormal, the sentinel node corresponding to the verification result of the i-th node can be determined according to the verification report, and protection instructions and protection schemes can be sent to the responder of the sentinel node corresponding to the verification result of the i-th node so that the responder can perform protection operations.
[0121] Figure 4 The illustration depicts a security verification scenario according to a specific embodiment of the present disclosure.
[0122] like Figure 4 As shown, security verification scenario 400 includes terminal device 401 and sentinel network generator 402. Terminal device 401 includes application main process 4011, which comprises main thread 4011-1 and daemon thread 4011-2. In the main thread, K represents the core part of the target application, T represents the pre-triggered trigger, V represents the verifier, and R represents the responder. Daemon thread 4011-2 is controlled by the monitoring center component MCC and is used to schedule sentinel nodes and interact with sentinel network generator 402 in the business backend or server.
[0123] like Figure 4 As shown, the main thread 4011-1 includes a verifier V1 for the first sentinel node, a verifier V2 for the second sentinel node, a verifier V3 for the third sentinel node, a verifier V4 for the fourth sentinel node, a pre-triggered trigger T1 for the first sentinel node, a responder R1 for the first sentinel node, and a first core part K1 of the target application. The first sentinel node is used to protect the first core part K1.
[0124] The pre-triggered trigger T1 of the first sentinel node sends the trigger result to the monitoring center in the daemon thread 4011-2. The monitoring center can send a verification request to the verifier V1 of the first sentinel node, the verifier V2 of the second sentinel node, the verifier V3 of the third sentinel node, or the verifier V4 of the fourth sentinel node according to the dynamic verification matrix, so that the verifiers can perform the verification operation and return the node verification result.
[0125] The monitoring center in daemon thread 4011-2 can also send node verification results to the responder R1 of the first sentinel section, so that the responder R1 of the first sentinel section can detect the node verification results and perform protection operations. The monitoring center in daemon thread 4011-2 can also send protection instructions and protection schemes to the responder R1 of the first sentinel section, so that the responder R1 of the first sentinel section can perform protection operations.
[0126] Based on Figure 2 The described scene, through Figure 5A and Figure 5B Describe the dynamic logical protection relationships represented by the dynamic verification matrix.
[0127] Figure 5A The illustration schematically depicts a security verification scenario at time A according to embodiment A of this disclosure.
[0128] like Figure 5A As shown, security verification scenario 500A includes dynamic logical protection relationships at time A and runtime security verification scenarios. The dynamic logical protection relationships at time A include the protection relationships between four sentinel nodes, which are used to protect the first core part K1 of the target application. The verification order determined according to the dynamic logical protection relationships at time A is V1→V2→V3→V4.
[0129] During runtime, the first sentinel node, the second sentinel node, the third sentinel node, and the fourth sentinel node are verified in sequence according to the above verification order.
[0130] Figure 5B The illustration schematically depicts a security verification scenario at time B according to embodiment B of this disclosure.
[0131] like Figure 5B As shown, security verification scenario 500B includes dynamic logical protection relationships at time B and runtime security verification scenarios. The dynamic logical protection relationships at time B include the protection relationships between three sentinel nodes, which are used to protect the first core part K1 of the target application. The verification order determined according to the dynamic logical protection relationships at time B is V1→V2→V1→V4.
[0132] During runtime, the first sentinel node, the second sentinel node, the first sentinel node, and the fourth sentinel node are verified in sequence according to the above verification order.
[0133] Compared to the isolation of security protection nodes in traditional methods, the embodiments of this disclosure enhance the protection strength by enabling linkage between sentinel nodes through sentinel network technology. Furthermore, a three-level structure of "pre-trigger-verifier-responder" is designed for the protection of sentinel nodes and the sentinel network itself. Through time-dimensional variability, the attack and bypass difficulty of the protection logic is effectively increased, making the anti-security verification method of the embodiments of this disclosure more reliable.
[0134] The embodiments disclosed herein provide a method that is simple to implement, low in implementation cost, and can effectively prevent malicious programs from obtaining user passwords, while also overcoming the shortcomings of existing password authentication technologies.
[0135] Figure 6 A flowchart illustrating a method for generating a dynamic verification matrix according to an embodiment of the present disclosure is shown.
[0136] like Figure 6 As shown, the method includes operations S610 to S630. Operations S610 to S630 can be set before operation S210.
[0137] When operating the S610, N sentinel nodes are determined based on the target application software.
[0138] When operating the S620, a time-dependent dynamic sentinel linkage network is formed using N sentinel nodes. Each sentinel node in the sentinel linkage network has a relationship with at least one sentinel node.
[0139] When operating the S630, a dynamic verification matrix is generated based on the dynamic sentinel linkage network.
[0140] According to embodiments of this disclosure, various types of application software can perform various functions, such as financial management application software, asset management application software, and internal bank office software. These various application software programs possess varying levels of security protection.
[0141] According to embodiments of this disclosure, the number of sentinel nodes corresponding to the target application software is determined by the type of the target application software, so as to flexibly determine the protection strength that matches the target application software.
[0142] According to embodiments of this disclosure, after determining N sentinel nodes for protecting target application software, a time-dependent dynamic sentinel linkage network is formed using the N sentinel nodes based on generation rules. The sentinel linkage network is a graph-like logical structure formed by interconnecting multiple sentinel nodes, which possess the ability to communicate and coordinate with each other. A dynamic sentinel linkage network refers to a network whose logical structure changes over time.
[0143] According to embodiments of this disclosure, the generation rules include: there is a logical protection relationship between the entry sentinel node and at least two sentinel nodes; and there is a relationship between each sentinel node and at least one sentinel node.
[0144] According to embodiments of this disclosure, a dynamic sentinel linkage network is generated using a time-based random algorithm, provided that the generation rules are met. The time interval for changes in the dynamic sentinel linkage network can be 1 second, 1 minute, 1 hour, or 1 day, or other time intervals.
[0145] Since the logical protection relationship between multiple sentinel nodes in the dynamic sentinel linkage network changes randomly based on the generation rules, attackers cannot determine the logical protection relationship by accumulating the number of attacks, thereby improving the reliability of the security verification method of this embodiment.
[0146] According to embodiments of this disclosure, the graph-based logical structure in the dynamic sentinel linkage network has a direction. After generating the dynamic sentinel linkage network, a graph-based algorithm is used to analyze the dynamic sentinel linkage network and generate a dynamic verification matrix.
[0147] According to embodiments of this disclosure, graph-based algorithms may include user-defined graph resolution methods, as well as other graph resolution algorithms. As an exemplary embodiment only, other graph resolution algorithms can be used to achieve the transformation between graphs and matrices, and are not limited thereto.
[0148] The embodiments of this disclosure determine the number of sentinel nodes matching the application software, generate a dynamic sentinel linkage network based on the determined sentinel nodes, and then generate a dynamic verification matrix. This eliminates the need for developers to manually write logical protection relationships and allows for the determination of logical protection relationships without human intervention, thus improving verification efficiency and protection flexibility. Furthermore, since the number of sentinel nodes is related to the application software, the number of sentinel nodes, the dynamic sentinel linkage network, and the dynamic verification matrix can be flexibly determined for different application software, further enhancing the flexibility of logical protection relationships.
[0149] According to embodiments of this disclosure, determining N sentinel nodes based on the target application software includes: dividing the target application software into M protected objects, where M ≥ 2, by using functions as units; determining L first nodes based on the M protected objects and the target application software, where the first nodes are used to protect the protected objects, where L ≥ M ≥ 2; and determining (NL) second nodes based on the L first nodes, where the second nodes are used to protect the first nodes. The N sentinel nodes include the L first nodes and (NL) second nodes.
[0150] According to embodiments of this disclosure, executable code in application software can be categorized into core logic code and peripheral logic code based on business importance. For the same application software, the protection requirements for core logic code and peripheral logic code differ.
[0151] According to embodiments of this disclosure, a function is part of a computer software code asset, representing a minimal set of code fragments capable of independently implementing a business logic. The target application software is segmented using functions as units to obtain M protected objects, each representing a function. Each protected object corresponds to at least one first node.
[0152] According to embodiments of this disclosure, after determining L first nodes for protecting the protected object, (NL) second nodes for protecting the L first nodes are then determined.
[0153] According to embodiments of this disclosure, based on L first nodes and sentinel node protection rules, (NL) second nodes are determined to protect the L first nodes. The sentinel node protection rules can be determined according to actual circumstances.
[0154] For example, based on a preset ratio, the number of second nodes corresponding to L first nodes can be determined. Alternatively, based on a number lookup table, the number of second nodes can be determined according to the number of first nodes.
[0155] In the embodiments disclosed herein, the protected object is sliced at the function level, reducing the computational load for verification. Furthermore, by using the first and second nodes, the node itself is protected while the target program is protected, thus improving the reliability of the security verification scheme.
[0156] Figure 7 A schematic diagram illustrating the generation of a dynamic verification matrix according to an embodiment of the present disclosure is shown.
[0157] like Figure 7 As shown, the dynamic verification matrix generation diagram 700 includes the current dynamic sentinel linkage network 701 and the dynamic verification matrix 702. The target application software includes two protected objects G1 and G2, and four sentinel nodes Ab1, Ab2, Ab3, Ab4 and Ab5.
[0158] According to embodiments of this disclosure, after determining five sentinel nodes, a dynamic sentinel linkage network 701 is generated using the five sentinel nodes. The sentinel nodes include a first node for protecting the protected object and a second node for protecting the first node.
[0159] In the dynamic sentinel linkage network 701, the first nodes used to protect protected object G1 are Ab1 and Ab2, and the first nodes used to protect protected object G2 are Ab2 and Ab3. The second nodes used to protect the first node Ab1 are Ab1 and Ab5. The second node used to protect the first node Ab2 is Ab4. The second nodes used to protect the first node Ab3 are Ab1 and Ab4. The second nodes used to protect the first node Ab4 are Ab2 and Ab5. The second nodes used to protect the first node Ab5 are Ab1 and Ab3.
[0160] The dynamic sentinel linkage network 701 includes 5 sentinel nodes and directed logical protection relationships between them. By performing graph analysis on the dynamic sentinel linkage network 701, a dynamic verification matrix 702 is obtained. The dynamic verification matrix 702 includes the pointing characteristics of the logical protection relationships between the sentinel nodes.
[0161] According to embodiments of this disclosure, determining L first nodes based on M protected objects and target application software includes: determining the total number of first nodes based on the security level and performance data of the target application software; and determining one or more first nodes corresponding to each protected object based on the protection strength weight of the protected object and the total number of first nodes, so as to obtain L first nodes for protecting the M protected objects.
[0162] According to embodiments of this disclosure, the security level of the target application software can be determined based on the business type, business purpose, and target user type of the target application software. A higher security level results in a larger number of first nodes, and a lower security level results in a smaller number of first nodes.
[0163] Performance data can include the size of the target application software. Higher performance data indicates a larger number of first nodes, while lower performance data indicates a smaller number of first nodes.
[0164] According to embodiments of this disclosure, both security level and performance data can be determined based on an application software development table, which includes at least the application software's identifier, business type, business purpose, target user type, size, security level, and performance data.
[0165] According to embodiments of this disclosure, the protection strength weight of a protected object can be determined based on the service type involved in the protected object. Specifically, the protection strength weight of a protected object can be determined based on a weight configuration table. Table 1 illustrates an example of the protection strength weight of a protected object.
[0166] Table 1
[0167]
[0168] According to embodiments of this disclosure, payment-related items are identified as K1 with a protection strength weight w of 15; settlement-related items are identified as K2 with a protection strength weight w of 15; identity verification-related items are identified as K3 with a protection strength weight w of 15; wealth management-related items are identified as K4 with a protection strength weight w of 10; and announcement-related items are identified as K5 with a protection strength weight w of 5.
[0169] According to embodiments of this disclosure, determining the first node corresponding to each protected object based on the protection strength weight of the protected object and the total number of first nodes includes: determining the proportion of the protection strength weight of the m-th protected object in the total protection strength weight of the M protected objects; and determining one or more first nodes corresponding to the m-th protected object based on the above proportion and the number of first nodes, where 1 ≤ m ≤ M. Thus, L first nodes protecting the M protected objects are obtained.
[0170] According to embodiments of this disclosure, one or more first nodes corresponding to each protected object are determined, satisfying: K(m) number of first nodes = C*w(m) / (w1+w2+w3+...+w(m)...+w(M)), where C represents the total number of first nodes and w(m) represents the protection strength weight of the m-th protected object.
[0171] According to embodiments of this disclosure, in the process of generating a dynamic sentinel linkage network, the generation rules also satisfy the restrictions on the number of first nodes of the protected object and the restrictions on the number of second nodes of the first node.
[0172] Related technologies are generally based on the application software perspective, performing unified, coarse-grained verification and signing on the entire application software. They cannot differentiate between core logic code and peripheral logic code for protection, thus limiting the scope of practical application.
[0173] The embodiments of this disclosure determine the total number of first nodes based on the security level and performance data of the target application software; and determine one or more first nodes corresponding to each protected object based on the protection strength weight of the protected object and the total number of first nodes, thus achieving flexible protection for code with different strengths. Because the technical solution of this disclosure provides differentiated protection for core logic code and edge logic code, it expands the practicality of the aforementioned application security verification method.
[0174] Figure 8 A schematic block diagram of a security verification device for application software according to an embodiment of the present disclosure is shown.
[0175] like Figure 8 As shown, the application software security verification device 800 of this embodiment includes an acquisition module 810 and a verification module 820.
[0176] The acquisition module 810 is used to acquire the dynamic verification matrix at the current time based on the current timestamp. The dynamic verification matrix represents the dynamic logical protection relationship between N sentinel nodes. The sentinel nodes are used to perform security verification on the target application software, where N≥2. In one embodiment, the acquisition module 810 can be used to execute the operation S210 described above, which will not be repeated here.
[0177] The verification module 820 is used to verify N sentinel nodes according to the dynamic verification matrix to obtain the target verification result of the target application software. In one embodiment, the verification module 820 can be used to perform the operation S220 described above, which will not be repeated here.
[0178] According to embodiments of this disclosure, the verification module 820 includes a first verification unit, a second verification unit, and a third verification unit.
[0179] The first verification unit is used to determine the verification order of the N sentinel nodes based on the logical protection relationship represented by the dynamic verification matrix. In one embodiment, the first verification unit can be used to perform the operation S321 described above, which will not be repeated here.
[0180] The second verification unit is used to verify N sentinel nodes sequentially according to the verification order, and obtain at least one node verification result. The node verification result represents the verification result of the sentinel node. In one embodiment, the second verification unit can be used to perform the operation S322 described above, which will not be repeated here.
[0181] The third verification unit is used to determine the target verification result based on the verification results of at least one node. In one embodiment, the third verification unit can be used to perform the operation S323 described above, which will not be repeated here.
[0182] According to embodiments of this disclosure, the second verification unit includes a first verification subunit and a second verification subunit.
[0183] The first verification subunit is used to verify N sentinel nodes until the verification result of the i-th node corresponding to the i-th sentinel node is detected to be abnormal. Then, the detection stops and the verification result of the i-th node is obtained, where 1≤i≤N.
[0184] The second verification subunit is used to verify N sentinel nodes until the verification result of each node is found to be normal, thus obtaining the verification results of N nodes.
[0185] According to embodiments of this disclosure, the third verification unit includes a third verification subunit and a fourth verification subunit.
[0186] The third verification subunit is used to determine the target verification result as abnormal if an anomaly is found in the verification result of at least one node, and to generate a verification report for the target verification result based on the verification result of at least one node.
[0187] The fourth verification subunit is used to determine the target verification result as normal when at least one node verification result is normal, and to generate a verification report for the target verification result based on the verification results of at least one node.
[0188] According to an embodiment of this disclosure, the verification module 820 includes a protection unit for performing protection operations based on the verification report when the target verification result is determined to be abnormal.
[0189] According to embodiments of this disclosure, the application software security verification device 800 further includes a determination module, a first generation module, and a second generation module.
[0190] The determination module is used to determine N sentinel nodes based on the target application software. In one embodiment, the determination module can be used to perform the operation S610 described above, which will not be repeated here.
[0191] The first generation module is used to form a time-dependent dynamic sentinel linkage network using N sentinel nodes. Each sentinel node in the sentinel linkage network has a relationship with at least one other sentinel node. In one embodiment, the first generation module can be used to perform the operation S620 described above, which will not be repeated here.
[0192] The second generation module is used to generate a dynamic verification matrix based on the dynamic sentinel linkage network. In one embodiment, the second generation module can be used to perform the operation S630 described above, which will not be repeated here.
[0193] According to embodiments of this disclosure, the determining module includes a first determining unit, a second determining unit, and a third determining unit.
[0194] The first determining unit is used to divide the target application software into M protected objects, where M≥2, by function.
[0195] The second determining unit is used to determine L first nodes based on M protected objects and target application software. The first nodes are used to protect the protected objects, and L≥M≥2.
[0196] The third determining unit is used to determine (NL) second nodes based on L first nodes. The second nodes are used to protect the first nodes. The N sentinel nodes include L first nodes and (NL) second nodes.
[0197] According to embodiments of this disclosure, the first determining unit includes a first determining subunit and a second determining subunit.
[0198] The first determining subunit is used to determine the total number of first nodes based on the security level and performance data of the target application software.
[0199] The second determining subunit is used to determine one or more first nodes corresponding to each protected object based on the protection strength weight of the protected object and the total number of first nodes, so as to obtain L first nodes for protecting M protected objects.
[0200] According to embodiments of this disclosure, any plurality of modules in the acquisition module 810 and the verification module 820 may be combined into one module, or any one of these modules may be split into multiple modules. Alternatively, at least a portion of the functionality of one or more of these modules may be combined with at least a portion of the functionality of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the acquisition module 810 and the verification module 820 may be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the acquisition module 810 and the verification module 820 may be at least partially implemented as a computer program module, which, when run, can perform corresponding functions.
[0201] Figure 9 A block diagram of an electronic device suitable for a security verification method for application software according to an embodiment of the present disclosure is shown schematically.
[0202] like Figure 9 As shown, an electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage portion 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0203] RAM 903 stores various programs and data required for the operation of electronic device 900. Processor 901, ROM 902, and RAM 903 are interconnected via bus 904. Processor 901 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 902 and / or RAM 903. It should be noted that the programs may also be stored in one or more memories other than ROM 902 and RAM 903. Processor 901 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.
[0204] According to embodiments of this disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to a bus 904. The electronic device 900 may also include one or more of the following components connected to the I / O interface 905: an input section 906 including a keyboard, mouse, etc.; an output section 907 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 908 including a hard disk, etc.; and a communication section 909 including a network interface card such as a LAN card, modem, etc. The communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 910 as needed so that computer programs read from it can be installed into the storage section 908 as needed.
[0205] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.
[0206] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 902 and / or RAM 903 and / or one or more memories other than ROM 902 and RAM 903 described above.
[0207] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code enables the computer system to implement the security verification method for application software provided in the embodiments of this disclosure.
[0208] When the computer program is executed by the processor 901, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0209] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and downloaded and installed via the communication section 909, and / or installed from a removable medium 911. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0210] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from the removable medium 911. When the computer program is executed by the processor 901, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0211] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0212] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0213] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.
[0214] The specific embodiments described above further illustrate the purpose, technical solutions, and beneficial effects of this disclosure. It should be understood that the above descriptions are merely specific embodiments of this disclosure and are not intended to limit this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the protection scope of this disclosure.
Claims
1. A security verification method for application software, comprising: Based on the timestamp of the current moment, obtain the dynamic verification matrix of the current moment. The dynamic verification matrix represents the dynamic logical protection relationship between N sentinel nodes. The sentinel nodes are used to perform security verification on the target application software. N≥2. The dynamic verification matrix at different times includes one of the following: different number of sentinel nodes, different sentinel nodes, and different logical protection relationships. The N sentinel nodes are verified according to the dynamic verification matrix to obtain the target verification result of the target application software. Before obtaining the dynamic verification matrix for the current moment based on the current timestamp, the following steps are also included: Based on the target application software, the N sentinel nodes are determined; A time-dependent dynamic sentinel linkage network is formed using the N sentinel nodes. Each sentinel node in the network has a relationship with at least one other sentinel node, and the logical structure between these sentinel nodes changes over time. The dynamic verification matrix is generated based on the dynamic sentinel linkage network.
2. The method according to claim 1, wherein, The step of verifying the N sentinel nodes according to the dynamic verification matrix to obtain the target verification result of the target application software includes: The verification order of the N sentinel nodes is determined based on the logical protection relationship represented by the dynamic verification matrix. Following the verification order, the N sentinel nodes are verified sequentially to obtain at least one node verification result, whereby the node verification result characterizes the verification result of the sentinel node; and The target verification result is determined based on the verification results of at least one node.
3. The method according to claim 2, wherein, The step of verifying the N sentinel nodes sequentially according to the verification order to obtain at least one node verification result includes: Verify the N sentinel nodes until the verification result of the i-th node corresponding to the i-th sentinel node is detected to be abnormal, then stop the detection and obtain the verification result of the i-th node, 1≤i≤N; The N sentinel nodes are verified until the verification result of each node is found to be normal, thus obtaining the verification results of N nodes.
4. The method according to claim 2, wherein, Determining the target verification result based on the verification results of at least one node includes: If an anomaly is found in the verification results of at least one node, the target verification result is identified as an anomaly, and a verification report for the target verification result is generated based on the verification results of at least one node. If the verification results of at least one node are all normal, the target verification result is determined to be normal, and a verification report for the target verification result is generated based on the verification results of at least one node.
5. The method according to claim 4, further comprising: If the target verification result is determined to be abnormal, protective measures are performed based on the verification report.
6. The method according to claim 1, wherein, The step of determining the N sentinel nodes based on the target application software includes: The target application software is divided into M protected objects, where M ≥ 2, by using functions as units. Based on the M protected objects and the target application software, L first nodes are determined, where the first nodes are used to protect the protected objects, and L ≥ M ≥ 2; and Based on the L first nodes, (NL) second nodes are determined, and the second nodes are used to protect the first nodes. The N sentinel nodes include the L first nodes and the (NL) second nodes.
7. The method according to claim 6, wherein, The step of determining L first nodes based on the M protected objects and the target application software includes: Based on the security level and performance data of the target application software, determine the total number of the first nodes; and Based on the protection strength weight of the protected object and the total number of the first nodes, one or more first nodes corresponding to each protected object are determined to obtain the L first nodes used to protect the M protected objects.
8. A security verification device for application software, comprising: The acquisition module acquires the dynamic verification matrix at the current time based on the current timestamp. The dynamic verification matrix represents the dynamic logical protection relationship between N sentinel nodes. The sentinel nodes are used to perform security verification on the target application software. N≥2. The dynamic verification matrix at different times includes one of the following: different number of sentinel nodes, different sentinel nodes, or different logical protection relationships. The verification module is used to verify the N sentinel nodes according to the dynamic verification matrix to obtain the target verification result of the target application software; The determination module is used to determine the N sentinel nodes based on the target application software; The first generation module is used to form a time-dependent dynamic sentinel linkage network using the N sentinel nodes. Each sentinel node in the network has a relationship with at least one other sentinel node, and the logical structure between the multiple sentinel nodes changes over time. The second generation module is used to generate the dynamic verification matrix based on the dynamic sentinel linkage network.
9. An electronic device, comprising: One or more processors; Storage device for storing one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors perform the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having stored thereon executable instructions that, when executed by a processor, cause the processor to perform the method according to any one of claims 1 to 7.
11. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
User verification method, server, user equipment and system
CN110619208A
Apk file integrity protection method, system and deviceandstorage medium
CN111950035A