Advertising Protection Method under Privacy Protection of Android Mobile Phones

Through static analysis and dynamic monitoring, and the privileged calls of the advertising library are identified, and data perturbation technology is used to anonymize, the problem of the advertising library accessing user sensitive information through permission inheritance is solved, and effective privacy protection and stability of the advertising ecosystem is achieved.

CN118674502BActive Publication Date: 2025-06-24XIAMEN KUANGSHI ALLIANCE NETWORK TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410727403.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-06
Publication Date
2025-06-24
Estimated Expiration
2044-06-06

AI Technical Summary

Technical Problem

In the Android system, the advertising library can access user's sensitive information through the permissions of the host application, resulting in user privacy being violated. It is difficult for the existing technology to effectively prevent such permission inheritance access threats.

Method used

The combination of static program analysis and dynamic operation monitoring is adopted. By identifying the ad library's signature code and permission call stack, the ad library's privileged calls are blurred using anonymization processing based on data perturbation to ensure that user privacy is not leaked.

Benefits of technology

Effectively prevent the ad library from accessing user's sensitive information through permission inheritance, protecting user privacy, maintaining the stability of the mobile advertising ecosystem, and not affecting the normal delivery of advertisements and the functions of the application.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118674502B_ABST
    Figure CN118674502B_ABST
Patent Text Reader

Abstract

The advertisement protection method under the privacy protection of the Android mobile phone in this application comprehensively analyzes the use of permissions by popular advertisement libraries. In view of the fact that existing defense methods cannot solve such threats, a mobile phone anonymous advertisement protection method based on data perturbation is proposed. Combining the threat of permission inheritance access in the mobile advertisement ecosystem, regarding how to identify advertisement libraries in application programs, what privileges the advertisement library code has, and how to identify the current call source during the operation of application programs, a method combining static program parsing and dynamic operation monitoring is proposed. The signature of the advertisement library is used to identify the privileged call source in the function call stack, and then the data perturbation-based method is used to perform fuzzy calculation on the privileged calls of the advertisement library, and different anonymization rules are adopted for different data types to anonymize the access results, solving the infringement behavior of advertisement libraries on user privacy. The advertisement protection is accurate, efficient, and reasonable in cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to an advertisement protection method under mobile phone privacy protection, and more particularly to an advertisement protection method under mobile phone privacy protection on an Android mobile phone, belonging to the technical field of mobile terminal advertisement protection methods. Background Art

[0002] The development model of embedding ad libraries in mobile applications will be a major trend in the future development of the mobile ecosystem. While it brings a win-win effect to developers and advertisers, it also raises some new security issues. In addition, the uneven quality and scale of mobile advertising platforms, and the lack of unified platform standards are also part of the reason for the security issues. In the Android environment, applications need to declare permissions to access relevant sensitive information or perform specific operations. Due to the special symbiotic relationship between applications and ad libraries, and the Android permission control system assigns permissions at the application level, there are two consequences: first, the ad library can use all permissions applied for by the host application; second, the application that embeds the ad library must apply for all permissions declared in the ad library developer configuration document.

[0003] When a user installs an application containing an ad library on their device, the ad library exists on the user's device as part of the application. The Android operating system assigns the same UID to the application and the ad library as a whole, even if the ad library and the application have different package names. In addition, the ad library runs in the same process space as the host application, and the Android operating system cannot distinguish whether the current privileged call comes from the ad library or the main application code. While implementing the advertising function in the application, the ad library may actively collect user privacy information to implement its so-called "ad personalization" service. The collection of user information by the ad library damages user privacy.

[0004] The situation where the ad library uses the host application permissions to call privileged methods to access user privacy information is called the ad library permission inheritance access threat. This threat is different from common threats, such as threats from malicious developers and threats from malicious ads. Because there is no malicious third party in the permission inheritance access threat itself, all of its calls are accessed using "legal" declared permissions, but these permission-protected information is often highly sensitive, especially dangerous permissions. As a third-party library, the ad library's access to sensitive data poses a privacy threat. In principle, it only needs INTERNET permissions to implement its advertising delivery function (because it requires a network connection to the ad server).

[0005] Several related solutions have been proposed in the prior art, many of which revolve around the permission system. The permission manifest configuration file of the application being installed is checked according to the permission assignment policy to block any potentially insecure combination of requests. By allowing application developers to restrict permission assignment at installation and use permissions at runtime. Other systems attempt to add further expressiveness to the permission system, rewriting privacy-sensitive API calls to simulate the situation where they fail. This approach is further refined by adding taint tracking, allowing for more subtle policies. However, these systems generally treat the application as a whole and do not further distinguish between the advertising library and the host application for parsing and defense.

[0006] In terms of advertising, the prior art selects advertisements to be delivered to the client according to rules, but achieves this in a way that minimizes disruption to the existing advertising network industry model, and this is only applicable to web online advertising and is not effective for mobile advertising protection. The biggest problem with providing a mobile advertising framework is that it is necessary to reconstruct all the advertising materials on all advertising platforms in the existing advertising market, which is obviously an impossible task.

[0007] The problems that need to be solved in the prior art's mobile privacy protection for advertising and the key technical difficulties of this application include:

[0008] (1) The free release of most Android applications in numerous application markets has led to the prevalence of mobile advertising. Application developers only need to integrate the advertising SDK provided by the advertising network into their applications to use the advertising service. In the Android system, prior art applications need to declare permissions to access relevant sensitive information or perform specific operations. Due to the special symbiotic relationship between the application and the advertising library, and the Android permission control system assigning permissions at the application level, two consequences arise: First, the advertising library can use all the permissions applied for by the host application; Second, the application embedding the advertising library must apply for all the permissions declared in the advertising library developer's configuration document. In addition, the advertising library can also perform permission detection. After detecting the permissions, they can use this permission to collect sensitive information and send it to a remote server. Fine-grained sensitive information is easily accessible to the advertising library by inheriting the host application's permissions, resulting in missed reports and a high false positive rate due to the untimely update of static parsing files, affecting the operation of the application and blocking the display of advertisements, unable to maintain the stability of the mobile advertising ecosystem and prevent the advertising from stealing users' privacy information.

[0009] (2)Regarding the potential security issues that may exist after embedding a mobile advertising library in a mobile application, most of the existing technologies focus on malicious network environments or malicious attackers. Therefore, they protect the application as a whole, which has significant limitations and can at most ensure that the application as a whole is not attacked or interfered with. However, the advertising SDK also contains privileged access APIs for sensitive user information. Developers import the advertising SDK as a jar package into the application and finally release it as a whole to the app market. When the application runs, the advertising SDK and the application run in the same process space, and the Android system cannot identify the source of privileged method calls, allowing the advertising SDK to access any resources it wants within the scope of permissions. Existing protection methods do not propose good solutions to this problem.

[0010] (3)Companies submitting advertising materials in a mobile advertising platform often hope to promote their products or services to the greatest extent. In order to obtain a higher return on investment, the mobile advertising platform may use certain means to associate potential users with certain advertising materials, so as to maximize the interaction between users and advertisements. This kind of association is often based on users' privacy-sensitive information. Collecting certain information about users can uniquely identify the user among numerous information. For example, collecting the device number, which is assigned when the mobile phone is manufactured and is theoretically unchangeable. After the advertising network collects this information, it can personalize a certain type of advertisement to this user. Many sensitive information is actually protected by Android system permissions, and only applications with this permission can access the corresponding sensitive information or perform specific operations. The symbiotic relationship between the mobile advertising library and the host application makes it difficult for the Android operating system to prevent the mobile advertising library from accessing privacy information. The problem of privilege inheritance access threats in the mobile advertising ecosystem is serious. Existing technologies affect the normal operation of the host application, cannot ensure the normal display of advertisements, cannot maintain the stability of the mobile advertising ecosystem, and are not very practical. Summary of the Invention

[0011] The mobile phone anonymous advertisement protection method proposed in this application starts from the perspective of identifying the source of privileged method calls. It not only does not need to modify the original application program, but also does not need to provide a new advertisement framework for developers or advertisement platforms. It can also ensure that advertisements can be normally placed in the application program without affecting the functions of the original application program, and can effectively solve the problem of accessing protected sensitive information by borrowing permissions except for advertisement fraud. In addition, this method effectively maintains the compatibility and effectiveness of the business model and operation mode of the current mobile advertisement ecosystem. Through static parsing, privileged access existing in the advertisement library can be effectively identified, and through dynamic monitoring, the current source of privileged calls in the Android system can be identified. If it is identified that the call to the privileged method comes from the advertisement library, the anonymous protection module is used to obfuscate the access result. The mobile phone anonymous advertisement protection method can effectively protect against the threat of permission inheritance access, thus ensuring the privacy characteristics of users in the mobile advertisement ecosystem, while also maintaining the stability of the mobile advertisement ecosystem, protecting user privacy, providing accurate and efficient advertisement protection, and having reasonable overhead.

[0012] To achieve the above technical effects, the technical solutions adopted in this application are as follows:

[0013] An advertisement protection method for mobile phone privacy protection in the Android mobile terminal, combined with the threat of permission inheritance access in the mobile advertisement ecosystem, establishes a mobile phone anonymous advertisement protection method based on data perturbation. Regarding how to identify the advertisement library in the application program, what privileges the advertisement library code has, and how to identify the current call source during the running process of the application program, it is proposed to adopt a method combining static program parsing processing and dynamic running monitoring. Use the advertisement library signature to identify the source of privileged calls in the function call stack, and then use the method based on data perturbation to perform fuzzy calculation on the privileged calls of the advertisement library, and adopt different anonymous rules for different data types to anonymize the access results, so as to solve the infringement behavior of the advertisement library on user privacy;

[0014] The mobile phone anonymous advertisement protection consists of a static parsing module, a dynamic monitoring module, and an anonymous protection module. These three parts span the application layer and the application framework layer of the Android system. Among them, the static parsing module is further divided into three parts: reverse calculation, permission mapping, and matching identification. The static parsing module is responsible for parsing and processing the APK source file and constructing an advertisement library-permission table. The dynamic monitoring module adds an anonymous advertisement protection Service to the Android system service, and this service is also started when the Android system starts. This service encapsulates methods for parsing the advertisement library-permission table, dynamically capturing the function call stack, and identifying the current calling source method. The anonymous protection module performs data protection on sensitive information accessed by the advertisement library. After using the method in the anonymous advertisement protection Service system service to identify that the calling source is the advertisement library, it perturbs the data according to different anonymous rules for different data types and then returns it to the advertisement library to protect the user's sensitive information. The three modules work together to prevent the behavior of the advertisement SDK inheriting the host application's permissions to access sensitive information.

[0015] Preferably, the mobile phone anonymous advertisement protection architecture: The re-architecture utilizes permission to access local resources and regards the situation where the advertisement SDK accesses local sensitive resources using the host application's permissions as a threat of permission inheritance access. From the perspective of dynamically identifying the source of the privileged method caller, this application constructs a mobile phone anonymous advertisement protection method based on data perturbation, and adopts a combination of Android static parsing processing and dynamic monitoring. For local application program files, static parsing and Android reverse technology are used to parse the mobile application advertisement library; for the dynamic permission call of the application program, a new system service is used to capture the call stack and perform fuzzy calculation of data perturbation on the call result in combination with the static parsing result to prevent the mobile advertisement library from abusing the host application program to access fine-grained local resources.

[0016] Preferably, the overall structure: When the user uses the application program function, the application layer code in the upper layer of the Android architecture calls the API provided by the framework layer to implement. The application framework layer provides an interface for the application layer to access and implement code reuse. When the API is called, the call stack is obtained to identify the current calling source of the access to sensitive resources. The mobile phone anonymous advertisement protection method performs static parsing in the application layer and dynamic monitoring in the framework layer, spanning these two levels in the Android architecture;

[0017] The static parsing module, the dynamic monitoring module, and the anonymous protection module work together to process the access to sensitive resources in the advertisement library. Specifically, it includes: First, before the application is installed, it is processed by the static parsing module to parse the access to sensitive resources in the advertisement library and construct an advertisement library-permission table. Second, during the operation of the application, the interfaces provided by the framework layer are called to implement resource access or data processing. An anonymous advertisement protection system is added to the application framework layer to obtain the current API call stack for dynamic monitoring. Based on the advertisement library-permission table passed by the static parsing module, it is parsed whether the current call comes from the advertisement library, and the result is submitted to the anonymous protection module for processing. Finally, the anonymous protection module receives the recognition result of the dynamic monitoring module. If the current call comes from the advertisement library, it returns a perturbed result to the framework layer API according to the anonymous rule matching, and the framework layer API then feeds back the perturbed result to the program that calls the interface.

[0018] Preferably, the static parsing module performs static parsing on the application apk file embedded with the mobile advertisement library, identifies the signature of the advertisement library, and constructs an advertisement library-permission table. The static parsing module consists of three parts working together, namely reverse calculation, permission mapping, and matching identification. The reverse calculation sub-module uses Android static decompilation to reverse-transform the apk file into Java source code for subsequent review and parsing. The permission mapping sub-module realizes the mapping between Android dangerous permissions and key classes, constructs a permission-class table, and provides it to the matching identification sub-module for subsequent operations. The matching identification sub-module first identifies the signature of the advertisement library in the Java source file generated by the reverse module, then matches the Java source files in the package identified by the advertisement library signature with the permission-class table, finds out the sensitive permissions exposed by the advertisement library, and then, according to the permission API mapping list provided by PSCout, learns all possible privileged accesses that the advertisement library may have, and finally generates an advertisement library-permission table.

[0019] Preferably, the structure of the dynamic monitoring module: This module adds an anonymous advertisement protection system to the Android application framework layer, which is used to dynamically capture the function call stack and extract the top data of the current function call stack, and compare it with the advertisement library-permission table. If the top call method is a sensitive permission access from the advertisement library, it is recorded in the advertisement library call result and the result is submitted to the anonymous protection module for processing. If there is no sensitive permission access from the advertisement library, the call result is directly returned to the application layer without any other special processing.

[0020] Preferably, the static analysis module identifies the sensitive and high-risk permissions included in the advertisement library embedded in the application, thereby knowing the possible privileged method calls in the advertisement library. It decompiles the Android apk source code in reverse, then uses the advertisement library signature to identify the advertisement library code in the source code, and then matches the sensitive permissions included in the advertisement library according to the key classes accessing sensitive permissions in the advertisement library code. It consists of three parts working together: reverse calculation, permission mapping, and matching identification. The reverse sub-module uses the parsing technology of popular Android static decompilation to obtain the source code of the application program and provides it to the matching identification module for subsequent processing. The permission mapping sub-module constructs a permission-class table for Android high-risk permissions to identify the key calls of sensitive permissions in the source code. The matching identification sub-module first collects the package names of popular mobile advertisement libraries as the mobile advertisement library signatures; then uses the signature fields to identify the advertisement library code in the source code of the application program; finally, uses the permission-class table to find the sensitive permission calls existing in the advertisement library code. The three sub-modules work together to finally generate an advertisement library-permission table.

[0021] Preferably, the reverse module is implemented as follows: The reverse module obtains the source code of the Android application program to provide it to the matching identification module for processing, and uses Android decompilation to batch process the application program files, and reversely converts the apk file into a java source file;

[0022] The reverse route selected in this application is the Java route, and the combination of the dex2jar tool and the jadx tool is used. The dex2jar tool processes and converts the apk format file into the jar format, and the jadx tool processes and converts the class format file into the java format. Both the dex2jar tool and the jadx tool run in the command line mode, and the output of the dex2jar command is the input condition of the jar command, and the output of the jar command is the input condition of the jadx command. When constructing the command, the "&&" is used to splice the commands, and then put into the console for execution to improve the automation performance of the reverse module. The decompilation establishes a thread pool so that multiple threads can run simultaneously to further improve the efficiency of the reverse module.

[0023] Preferably, the matching identification module is implemented as follows: The matching identification module identifies the advertisement library signature, and then matches the sensitive permissions of the advertisement library code in the source code of the application program according to the advertisement library signature and the Android permission-class table, so as to know the possible privileged function access of the advertisement library code;

[0024] This application considers popular mobile advertisement libraries. After removing the aggregation platforms and agency platforms in the list, it collects the advertisement developer software toolkits provided by all the remaining mobile advertising companies, and performs static analysis to manually identify the package names of the advertisement libraries as the advertisement library signatures. Through the advertisement library signatures, that is, the advertisement library package names, the advertisement libraries introduced in the application program are uniquely identified;

[0025] After identifying the advertisement library signature, find the introduced advertisement library code in the application source code, and then find the sensitive permissions that can be exploited by the advertisement library. The steps are as follows:

[0026] Step 1: Traverse the source file path to find the file set identified by the advertisement library signature;

[0027] Step 2: Traverse the advertisement library file set and match the permission-class table

[0028] Step 3: Output the sensitive permissions of the advertisement library;

[0029] The mobile anonymous advertisement protection optimizes the folder and file traversal. The rules are as follows:

[0030] Rule 1: Identify whether the INTERNET permission is included in the permission list document. If it is included or not, terminate the traversal;

[0031] Rule 2: Ignore the system library folder during the file and folder traversal;

[0032] After the traversal is completed, the advertisement library-permission table is stored in the form of an xml configuration file.

[0033] Preferably, the dynamic monitoring module dynamically captures the call stack during the running of the application to identify whether the current sensitive call comes from the advertisement library. This application is implemented by using the system service. A new Java system service is added for dynamic monitoring. The framework layer API calls this service to obtain the identification result, and this service can run in the Android system for a long time;

[0034] Modify the source code of the Android application framework layer, dynamically monitor the system service class of the privilege function call source, add the IAnonymize.aidl file, and the AnonymizeService.java file implements the interface defined in the IAnonymize.aidl and the AnonymizeManager.java file for other services or application calls;

[0035] AnonymizeService parses the advertisement library-permission table identified by the static parsing module and stores it in the advertisement library signature array; uses the Android system's custom CallStackTrace type exception class to perform stack tracing on the privilege method attribution class, takes the current top stack element and uses the advertisement library signature to identify whether the current call comes from the advertisement library. If so, return the boolean value true to mark the current permission call return result;

[0036] When the Android system starts, start the custom system service AnonymizeService, register the service in the system service startup process, and modify the SystemServer.java file to add the custom service to the process;

[0037] Next, create a management class AnonymizeManager to call the methods in the service. The member variable in this class is the custom system service AnonymizeService for anonymous advertising protection. Obtain the service instance in the constructor of the management class, and then the methods in the service can be used in the member functions of the management class. Finally, register in the system service, bind AnonymizeManager and Anonymize_SERVICE through the IBinder mechanism, and implement the management class to call the methods in the system service using the aidl interface.

[0038] Preferably, the anonymous protection module is implemented as follows: for the method calls of dangerous permissions identified in the static parsing module, use the AnonymizeService service in the dynamic monitoring module to capture the current function call stack. If the call result at the top of the stack comes from the advertising library, apply the custom anonymous rules to process the result and then return it to the advertising library;

[0039] Improve on the PBKDF2 cryptographic hash algorithm. In the algorithm, use SecureRandom to generate a salt and append it to the end of the original information, and then hash the appended information and return it to the advertising server. Append the highly randomized value of SecureRandom to the original information, so that the value sent to the advertising server each time is different, reducing the possibility of the advertising server tracking users based on a specific constant value. After appending the salt value and hashing, the string no longer has obvious characteristics that expose user privacy, protecting fine-grained user privacy information from being exposed in the advertising network. For the data cursor obtained by calling the query method in the ContentProvider component, perform an anonymous protection form of clearing the cursor data. For composite types in Android, anonymize them to NULL. The implementation of the anonymous rules uses function overloading. When the AnonymizeService system service in the dynamic monitoring module identifies that the current function caller is the advertising library, call the overloaded function to anonymize the call result and then return it;

[0040] When querying data through the ContentProvider class, communication with the Provider is carried out through the ContentResolver object. The request time series process is as follows: call getContentResolver().query(Uri, String, String, String, String). This method calls the query method in ContentResolver. When the request method is called, ContentResolver parses the URI in the parameters and extracts the authorization authority field. This field uniquely identifies the ContentProvider object in Android. ContentResolver guides the request to the ContentProvider object registered using the authority, and then calls the query method therein to obtain data. After calling the request method in ContentProvider, a Cursor object will be returned, and the query result set is encapsulated in this object;

[0041] The anonymous protection module registers the anonymous advertisement protection Service system service in the ContentResolver class for processing. First, an instance of the AnonymizeService system service is obtained in the constructor of the ContentResolver class, and perturbed anonymous data is returned when it is identified as an advertisement library call during the query operation;

[0042] The MatrixCursor type inherits from the AbstractCursor class, and the AbstractCursor class finally implements the Cursor interface. The MatrixCursor class is used to return the result. The Cursor object returned by the MatrixCursor class in anonymous protection is the result of querying an empty table and is returned to the upper layer to avoid leakage of user privacy information;

[0043] During the running process of the application, the advertisement library code obtains the device ID when the advertisement view is initialized and sends it to the advertisement server. The system service AnonymizeService dynamically monitors the call stack information. The isAdsCaller() method in the AnonymizeService system service reads the top data of the stack and matches it with the advertisement library signature. If it is identified that the current call comes from the advertisement library, the advertisement library call result is handed over to function overloading for anonymization, and a hash value is calculated after appending a salt value to the original data and then returned.

[0044] Compared with the prior art, the innovation points and advantages of this application are as follows:

[0045] (1) This application comprehensively analyzes the use of permissions in popular advertising libraries, studies the threats of permission inheritance access, and analyzes that existing defense methods cannot well solve such threats. Therefore, a mobile phone anonymous advertising protection method based on data perturbation is proposed. Combining the threats of permission inheritance access in the mobile advertising ecosystem, a mobile phone anonymous advertising protection method based on data perturbation is established. Regarding how to identify the advertising libraries in the application, what privileges the advertising library code has, and how to identify the current call source during the operation of the application, a method combining static program parsing and dynamic runtime monitoring is proposed. The characteristic codes of the advertising library are used to identify the privileged call sources in the function call stack, and then the data perturbation-based method is used to perform fuzzy calculations on the privileged calls of the advertising library. Different anonymization rules are adopted for different data types to anonymize the access results, solving the problem of the infringement of user privacy by advertising libraries.

[0046] (2) The mobile phone anonymous advertising protection of this application consists of a static parsing module, a dynamic monitoring module, and an anonymous protection module. These three parts span the application layer and the application framework layer of the Android system. Among them, the static parsing module is further divided into three parts: reverse calculation, permission mapping, and matching identification. The static parsing module is responsible for parsing the APK source file and constructing an advertising library-permission table. The dynamic monitoring module adds an anonymous advertising protection Service for the Android system service, and this service is also started when the Android system starts. The methods for parsing the advertising library-permission table, dynamically capturing the function call stack, and identifying the current call source are encapsulated in this service. The anonymous protection module performs data protection on the sensitive information accessed by the advertising library. After using the method in the anonymous advertising protection Service system service to identify that the call source is the advertising library, different anonymization rules are adopted for different data types to perturb the data and then return it to the advertising library to protect the user's sensitive information. The three major modules work together to prevent the behavior of the advertising SDK from inheriting the permissions of the host application to access sensitive information. It is an effective, general, and reasonably performing mobile privacy protection advertising protection tool, and this tool has strong practicality.

[0047] (3) The mobile phone anonymous advertisement protection method proposed in this application, from the perspective of identifying the source of privileged method calls, not only does not need to modify the original application program, but also does not need to provide a new advertisement framework for developers or advertisement platforms. It can also ensure that advertisements can be normally placed in the application program without affecting the functions of the original application program, and can effectively solve the problem of accessing protected sensitive information by borrowing permissions in addition to advertisement fraud. In addition, this method effectively maintains the compatibility and effectiveness of the business model and operation mode of the current mobile advertisement ecosystem. Through static parsing, privileged access existing in the advertisement library can be effectively identified, and through dynamic monitoring, the current source of privileged calls in the Android system can be identified. If it is identified that the call to the privileged method comes from the advertisement library, the anonymous protection module is used to obfuscate the access result. The mobile phone anonymous advertisement protection method can effectively protect against the threat of permission inheritance access, thus ensuring the privacy characteristics of users in the mobile advertisement ecosystem, while also maintaining the stability of the mobile advertisement ecosystem, protecting user privacy, with accurate and efficient advertisement protection and reasonable overhead. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 is the architecture diagram of the mobile phone anonymous advertisement protection system.

[0049] Figure 2 is the reverse module flow chart of the static parsing module.

[0050] Figure 3 is the schematic diagram of the extraction result of dangerous permissions in Android.

[0051] Figure 4 is the schematic diagram of the recognition result of the advertisement library feature code.

[0052] Figure 5 is the schematic diagram of the storage logic of the advertisement library - permission table.

[0053] Figure 6 is the class diagram and construction schematic diagram of the modified TelephonyManager.

[0054] Figure 7 is the schematic diagram of the statistics of the number of popular mobile advertisement libraries in the static parsing module. DETAILED IMPLEMENTATION MANNER

[0055] The following further describes the technical solution of the advertisement protection method under the privacy protection of the Android mobile phone provided in this application with reference to the accompanying drawings, so that those skilled in the art can better understand this application and be able to implement it.

[0056] Embed a mobile advertising library in a mobile application so that when the application runs, through advertising display or interaction, the application developer can obtain compensation after freely publishing the application in the application market. Companies submitting advertising materials on a mobile advertising platform often hope to promote their products or services to the greatest extent. In order to obtain a higher return on investment, the mobile advertising platform may use certain means to associate potential users with certain advertising materials, so as to maximize the interaction between users and advertisements. This kind of association is often based on users' privacy-sensitive information. Collecting certain information of users can uniquely identify the user among numerous information. For example, collecting the device number, which is assigned when the mobile phone leaves the factory and is theoretically unchangeable. After the advertising network collects this information, it can personalize the positioning of a certain type of advertisement to this user. Many sensitive information is actually protected by Android system permissions, and only applications with this permission can access the corresponding sensitive information or perform specific operations. The symbiotic relationship between the mobile advertising library and the host application makes it difficult for the Android operating system to prevent the mobile advertising library from accessing privacy information.

[0057] This application combines the threat of privilege inheritance access in the mobile advertising ecosystem and establishes a mobile phone anonymous advertising protection method based on data perturbation. Regarding issues such as how to identify the advertising library in the application, what privileges the advertising library code has, and how to identify the current call source during the operation of the application, a method combining static program parsing and dynamic operation monitoring is proposed. Use the advertising library signature to identify the privileged call source in the function call stack, and adopt different anonymization rules for different data types to anonymize the access results, so as to solve the infringement behavior of the advertising library on user privacy.

[0058] Using the "BurpSuite" penetration testing tool, this application completed threat implementation and protection tests on an Android emulator compiled from the Android source code. The experimental results show that the mobile phone anonymous advertising protection method can not only not affect the normal operation of the host application but also ensure the normal display of advertisements, maintaining the stability of the mobile advertising ecosystem. And this method does not need to modify the existing application or advertising framework, and has strong practicability.

[0059] I. Mobile Phone Anonymous Advertising Protection Architecture

[0060] Regarding the potential security issues that may arise after embedding a mobile advertising library in a mobile application, most of the existing technologies focus on malicious network environments or malicious attackers. Therefore, they regard the application as a whole for security protection, which has quite large limitations and can at most ensure that the application as a whole is not attacked or interfered with. However, the advertising SDK also contains privileged access APIs for sensitive user information. Developers import the advertising SDK into the application as a jar package and finally release it as a whole to the application market. When the application runs, the advertising SDK and the application run in the same process space, and the Android system cannot identify the source of the privileged method call, enabling the advertising SDK to access any resources it wants within the permitted scope of permissions. Existing protection methods do not propose good solutions to this problem.

[0061] This application reconstructs the use of permissions to access local resources and regards the situation where the advertising SDK accesses local sensitive resources using the host application's permissions as a threat of permission inheritance access. The fundamental reason for this threat is that the Android system itself cannot identify who the current privileged caller is. If the application itself has this permission, the Android system will return the call result. Therefore, from the perspective of dynamically identifying the source of the privileged method caller, this application constructs a mobile anonymous advertising protection method based on data perturbation. Since the application is dynamically running, a combination of Android static parsing processing and dynamic monitoring is adopted. For local application files, static parsing and Android reverse engineering techniques are used to parse the mobile application advertising library; for the dynamic permission calls of the application, the new system service is used to capture the call stack and combined with the static parsing results to perform fuzzy calculation of data perturbation on the call results, so as to achieve the purpose of preventing the mobile advertising library from abusing the host application to access fine-grained local resources.

[0062] (1) Overall structure

[0063] When the user uses the application function, the application layer code in the upper layer of the Android architecture calls the APIs provided by the framework layer to implement. The application framework layer provides interfaces for the application layer to access and implement code reuse without providing the underlying implementation details. The call stack is obtained during the API call to identify the source of the current access to sensitive resources. As Figure 1 shown, the mobile anonymous advertising protection method performs static parsing in the application layer and dynamic monitoring in the framework layer, spanning these two levels in the Android architecture.

[0064] The mobile anonymous advertising protection consists of a static parsing module, a dynamic monitoring module, and an anonymous protection module. The three modules work together to handle the access to sensitive resources existing in the advertising library, specifically including:

[0065] First, before the application is installed, it is processed by the static analysis module to parse the sensitive resource access situation in the advertising library and construct an advertising library - permission table. Secondly, during the operation of the application, the interfaces provided by the framework layer are called to achieve resource access or data processing. An anonymous advertising protection system (as shown by the AA service in the architecture diagram) is added to the application framework layer to obtain the current API call stack for dynamic monitoring. Based on the advertising library - permission table passed by the static analysis module, it is parsed whether the current call originates from the advertising library, and the result is submitted to the anonymous protection module for processing. Finally, the anonymous protection module receives the recognition result of the dynamic monitoring module. If the current call originates from the advertising library, it returns a perturbation result to the framework layer API according to the anonymous rules, and the framework layer API then feeds back the perturbation result to the program that calls this interface.

[0066] (2) Structure of the Static Analysis Module

[0067] The static analysis module performs static analysis on the application apk file embedded with the mobile advertising library, identifies the signature of the advertising library, and constructs an advertising library - permission table. The static analysis module consists of three parts working together, namely reverse calculation, permission mapping, and matching identification. The reverse calculation sub - module uses Android static decompilation to reverse - convert the apk file into Java source files (Java files have good readability) for subsequent review and parsing. The permission mapping sub - module realizes the mapping between Android dangerous permissions and key classes, constructs a permission - class table, and provides it to the matching identification sub - module for subsequent operations. The matching identification sub - module first identifies the signature of the advertising library in the Java source files generated by the reverse module, then matches the Java source files in the package identified by the advertising library signature with the permission - class table, finds out the sensitive permissions exposed by the advertising library, and then, according to the permission API mapping list provided by PSCout, knows all possible privileged accesses of the advertising library, and finally generates an advertising library - permission table.

[0068] (3) Structure of the Dynamic Monitoring Module

[0069] The dynamic monitoring module is the core module of the entire mobile phone anonymous advertising protection method. This module adds an anonymous advertising protection system to the Android application framework layer to dynamically capture the function call stack, extract the top - of - stack data of the current function call stack, and compare it with the advertising library - permission table. If the top - of - stack call method is a sensitive permission access from the advertising library, it is recorded in the advertising library call result and the result is submitted to the anonymous protection module for processing. If there is no sensitive permission access from the advertising library, the call result is directly returned to the application layer without any other special processing.

[0070] (4) Structure of the Anonymous Protection Module

[0071] The anonymous protection module plays a role in data protection. Based on the advertisement library call results submitted by the dynamic monitoring module, the anonymous protection module performs fuzzy calculations on the data using anonymous rules to prevent the advertisement library from actively collecting fine-grained privacy information. The anonymous rules determine what perturbation value to return according to the current data type. For ContentProvider, one of the four major components of Android (the content provider), the advertisement library integrated in the application obtains a data cursor by calling the query() query method. This data includes contact information, calendar information, short message information, video information, and audio information. After identifying the advertisement library call results, the anonymous protection module clears the data in the cursor and then returns it.

[0072] II. Mobile Anonymous Advertising Protection Method

[0073] The mobile anonymous advertising protection method is to identify the calls of the advertisement library to sensitive permissions and return anonymized data to protect user privacy. It directly identifies the advertising company based on "domain name.company name" and adopts a combination of static program parsing and dynamic runtime monitoring. Among them, static program parsing uses Android decompilation methods to obtain the source code of the application, and then uses the permission-class table and advertisement library feature codes to identify all sensitive permission calls of the advertisement library. Dynamic monitoring uses the newly added Android system service to monitor the calls of privileged methods to identify the call sources and cooperate with the anonymous protection module to control the advertisement library call results.

[0074] (I) Implementation of the Static Parsing Module

[0075] The static parsing module identifies the sensitive and high-risk permissions contained in the advertisement library embedded in the application, and thus knows the possible privileged method calls of the advertisement library. It reverses the source code of the apk through Android decompilation, then uses the advertisement library feature codes to identify the advertisement library code in the source code, and then matches the sensitive permissions contained in the advertisement library according to the key classes accessing sensitive permissions in the advertisement library code. It is composed of three parts working together: reverse calculation, permission mapping, and matching and identification. The reverse sub-module uses the parsing technology of popular Android static decompilation to obtain the source code of the application and provides it to the matching and identification module for subsequent processing. The permission mapping sub-module constructs a permission-class table for Android high-risk permissions to identify the key calls of sensitive permissions in the source code. The matching and identification sub-module first collects the package names of popular mobile advertisement libraries as mobile advertisement library feature codes; then uses the feature code fields to identify the advertisement library code in the application source code; finally, uses the permission-class table to find the sensitive permission calls existing in the advertisement library code. The three sub-modules work together to finally generate the advertisement library-permission table.

[0076] 1. Implementation of the Reverse Module

[0077] The reverse module obtains the source code of the Android application to provide it to the matching and identification module for processing. It uses Android decompilation to batch process application files and reversely converts the apk file into a Java source file.

[0078] Android reverse engineering is a decisive step in static analysis. The products of its reverse engineering are Smali files or Java source files. The way of reversely converting into Smali files is usually called the disassembly route, and the file conversion process is apk - dex - Smali. The success rate of this conversion method is very high, and the degree of damage to the source file is relatively small. However, the readability of Smali files is too poor, and the syntax is obscure, which is not convenient for subsequent static analysis processing. The final product of the way of reversely converting into Java files is a Java source file, and the file conversion process is apk - jar - java. This conversion method may damage the source program to a certain extent, but the readability of Java files is convenient for subsequent static analysis. Therefore, the reverse route selected in this application is the Java route.

[0079] The combined use of the dex2jar tool and the jadx tool is adopted. The dex2jar tool processes and converts the apk - format file into a jar - format file, and the jadx tool processes and converts the class - format file into a java - format file. The flow chart of the reverse module is as Figure 2 shown. Both the dex2jar tool and the jadx tool run in the command - line mode, and the output of the dex2jar command is the input condition of the jar command, and the output of the jar command is the input condition of the jadx command. When constructing the command, the "&&" is used to splice the commands and then put them into the console for execution to improve the automation performance of the reverse module. And the decompilation process is time - consuming, so a thread pool is established here to enable multiple threads to run simultaneously to further improve the efficiency of the reverse module.

[0080] 2. Implementation of the permission mapping module

[0081] This application only focuses on the permissions marked as the dangerous category. The permissions included in the dangerous category allow the application to potentially access sensitive information or perform specific operations, and the harmfulness is relatively large.

[0082] Dangerous permissions include areas where the application requests data or resources involving user privacy information, and also include operations that affect the data stored on the user's device or other applications.

[0083] There are nine groups (a total of 24 items) of dangerous permissions in Android. An application only needs to apply for the group category. This application extracts the key classes in each group of dangerous permissions based on the permission-API mapping table provided by PSCout, and determines the access of the advertising library to privileges based on the existence or non-existence of the key classes, so as to improve the efficiency of the matching and identification module in the mobile phone anonymous advertising protection method. The extraction results are as Figure 3 shown.

[0084] 3. Implementation of the matching and identification module

[0085] The matching and identification module identifies the advertising library signature, and then matches the sensitive permissions of the advertising library code in the application source code according to the advertising library signature and the Android permission-class table, so as to know the possible privileged function access of the advertising library code.

[0086] This application considers popular mobile advertising libraries. After removing the aggregation platforms and proxy platforms in the list, it collects the advertising developer toolkits provided by all remaining mobile advertising companies and performs static parsing to manually identify the package names of the advertising libraries as the advertising library signatures. Through the advertising library signatures, that is, the advertising library package names, the advertising libraries introduced in the application are uniquely identified. The identification results are as Figure 4 shown.

[0087] After identifying the advertising library signature, find the introduced advertising library code in the application source code, and then find the sensitive permissions that the advertising library can use. The steps are as follows:

[0088] Step 1: Traverse the source file path to find the file set identified by the advertising library signature;

[0089] Step 2: Traverse the advertising library file set and match the permission-class table

[0090] Step 3: Output the sensitive permissions of the advertising library;

[0091] The mobile phone anonymous advertising protection optimizes the folder and file traversal. The rules are as follows:

[0092] Rule 1: Identify whether the INTERNET permission is included in the permission list document. If it is not included, terminate the traversal;

[0093] Rule 2: Ignore the system library folder during the file and folder traversal;

[0094] After the traversal is completed, the advertising library-permission table is stored in the form of an xml configuration file. The logical results are as Figure 5 shown.

[0095] (2) Implementation of the dynamic monitoring module

[0096] The dynamic monitoring module dynamically captures the call stack during the running of the application to identify whether the current sensitive call comes from the advertising library. Considering that this process needs to run for a long time, a Service service is used to implement it. However, the traditional Service service needs to be started manually to run, and the Android system cannot control which services the developers start during the running of the application. Therefore, this application uses the system service to implement it. A new Java system service is added for dynamic monitoring. The framework layer API calls this service to obtain the recognition result, and this service can run in the Android system for a long time.

[0097] Android system services usually have a management class Manager and a system service class Service, and the inter-process communication between the two is implemented through the aidl class. To implement the system service class for dynamically monitoring the source of privileged function calls,

[0098] therefore, the source code of the Android application framework layer is modified to add the IAnonymize.aidl file, the AnonymizeService.java file to implement the interface defined in IAnonymize.aidl, and the AnonymizeManager.java file for other services or applications to call.

[0099] AnonymizeService is to parse the advertising library-permission table identified by the static parsing module and store it in the advertising library feature code array; use the Android system's custom CallStackTrace type exception class to perform stack tracing on the class to which the privileged method belongs, take the current top element of the stack and use the advertising library feature code identifier to identify whether the current call comes from the advertising library. If so, return the boolean value true to mark the return result of the current permission call.

[0100] Since the time consumed by the dynamic monitoring module is the extra time added during the operation of the application, it is necessary to minimize this time overhead as much as possible. Therefore, an event-based pull parsing method with higher efficiency is adopted when parsing the advertisement library - permission table. The traditional dom parsing method needs to read the xml file into memory first and then traverse the file for processing. Obviously, this method will consume memory and affect the operation of mobile devices. In addition, when the advertisement library - permission table is relatively large, the efficiency of using the dom parsing method is low, and the delay caused to the application operation will also increase. When capturing the call stack, the custom exception class of the Android system is used for stack tracing. Therefore, an exception needs to be thrown actively, but no exception handling is done. The call chain of the privileged method is detailedly recorded in the stack tracing, and the form of each record is "package name.class name.function name". The end of the call chain, that is, the top of the stack of the privileged method call stack, identifies the source of the current call request to the privileged method. The package name in the top call information record is matched with the advertisement library signature array. If the package name is included in the signature array, the current call is initiated by the advertisement library code, and the dynamic monitoring process of the privileged method is realized.

[0101] When the Android system starts, start the custom system service AnonymizeService, register this service into the system service startup process, and modify the SystemServer.java file to add the custom service to the process.

[0102] Next, create a management class AnonymizeManager to call the methods in the service. The member variable in this class is the custom system service Anonymize Service for anonymous advertisement protection. Obtain the service instance in the constructor of the management class, and then the methods in the service can be used in the member functions of the management class. Finally, register in the system service, bind AnonymizeManager and Anonymize_SERVICE through the IBinder mechanism, and realize that the management class calls the methods in the system service using the aidl interface.

[0103] (3) Implementation of the anonymous protection module

[0104] The anonymous protection module plays a role in data protection. Since the mobile advertisement library may actively collect user privacy information or device sensitive information, and in principle, the mobile advertisement library only needs network permissions to implement its advertisement delivery function. For the dangerous permission method calls identified in the static parsing module in this application, the Anonymize Service service in the dynamic monitoring module is used to capture the current function call stack. If the call result at the top of the stack comes from the advertisement library (identified by the advertisement library signature), the application custom anonymous rules are used to process the result and then return it to the advertisement library.

[0105] The anonymization rules are processed at the granularity of Java data types. The information fed back to the advertising library needs to be de-identified, and it should be made difficult for the advertising server to reverse-infer the original information from the feedback information. Therefore, for basic data types, this application improves on the PBKDF2 cryptographic hash algorithm to meet the requirements. In the algorithm, SecureRandom is used to generate a salt and append it to the end of the original information, and then the appended information is hashed and returned to the advertising server. The highly randomized value of SecureRandom is appended to the original information, making the value sent to the advertising server different each time, reducing the possibility of the advertising server tracking users based on a specific constant value. After appending the salt value and hashing, the string no longer has obvious characteristics that reveal user privacy, protecting fine-grained user privacy information from being exposed in the advertising network. For the data cursor obtained by calling the query method in the ContentProvider component, an anonymization protection form of clearing the cursor data is adopted. In addition, the Object type is the parent class of all data types. For composite types in Android, they are also anonymized to NULL. The implementation of the anonymization rules is achieved through function overloading. When the AnonymizeService system service in the dynamic monitoring module identifies that the current function caller is the advertising library, it calls the overloaded function to anonymize the call result and then return it.

[0106] When querying data through the ContentProvider class, it does not directly interact with the Provider, but communicates with the Provider through a ContentResolver object. The request time sequence is as follows: call getContentResolver().query(Uri, String, String, String, String). This method calls the query method in ContentResolver. When the request method is called, ContentResolver parses the URI in the parameters and extracts the authorization authority field, which uniquely identifies the ContentProvider object in Android. ContentResolver redirects the request to the ContentProvider object registered with the authority, and then calls the query method therein to obtain the data. After calling the request method in ContentProvider, a Cursor object will be returned, which encapsulates the query result set.

[0107] The anonymous protection module registers the anonymous advertisement protection Service system service in the ContentResolver class for processing. First, it obtains an instance of the AnonymizeService system service in the constructor of the ContentResolver class, and returns the perturbed anonymous data when it is recognized as an advertisement library call during the query operation.

[0108] The MatrixCursor type inherits from the AbstractCursor class, and the AbstractCursor class finally implements the Cursor interface. The MatrixCursor class is used to return the result. The Cursor object returned by the MatrixCursor class in anonymous protection is the result of querying an empty table, which is returned to the upper layer to avoid the leakage of user privacy information.

[0109] This application adds the custom anonymous advertisement protection Service system service in the dynamic monitoring module of the TelephonyManager, and obtains this service in the constructor of the TelephonyManager. The class diagram and constructor method of the modified TelephonyManager are as Figure 6 shown.

[0110] During the running of the application, the advertisement library code obtains the device ID when initializing the advertisement view and sends it to the advertisement server. The system service AnonymizeService dynamically monitors the call stack information. The isAdsCaller() method in the AnonymizeService system service reads the top data of the stack and matches it with the advertisement library signature. If it is recognized that the current call comes from the advertisement library, the result of the advertisement library call is handed over to function overloading for anonymization, and a hash value is calculated after appending a salt value to the original data and then returned.

[0111] III. Experiments and Analyses

[0112] In actual applications, the mobile phone anonymous advertisement protection method is tested and evaluated to verify whether it can effectively protect fine-grained privacy information from being accessed by the advertisement SDK using the host application's permissions, and whether the consumption of device resources introduced by this method will significantly affect the overall performance of the device.

[0113] (I) Test Environment

[0114] The system test of mobile phone anonymous advertisement protection is carried out using the Android emulator started after modifying the source code and recompiling. Since the test environment is an emulator encapsulated by the Android source code, the BurpSuite penetration testing tool is used, which can intercept the network traffic between the client and the server. The test application is the threat instance EaseWeb.

[0115] (2) Test Process and Result Analysis

[0116] Add a listening proxy in the BurpSuite tool to obtain network transmission data packets. Set InterceptClientRequests, and match the URL setting to the IP address of the advertising server. Next, set the network proxy for the Android emulator to specify that the emulator data packets input and output from a specific port. The emulator network proxy is set in "Setting", and set the proxy "Proxy" and port "Port" in the emulator. Note that the "Proxy" setting and the "Port" setting should be consistent with the previous "BurpSuite" tool settings. After the Android emulator network proxy is set, enter the adb install EaseWeb.apk command in the terminal to install the test application in the emulator. Then select the Interceptison option in the Intercept tab of the BurpSuite tool.

[0117] Select the Forward button, and the network request will be fully transmitted to the advertising server. Run the test application multiple times, and the IMEI device numbers received by the advertising server after being hashed are all different, further verifying the effectiveness of the anonymous protection module.

[0118] From the data screenshot received from the advertising server, it can be seen that the advertising SDK in the test application EaswWeb obtained the IMEI number of the device when the application was running. Analyzing the source code of the advertising SDK, it can be known that this advertising library obtained an instance object of TelephonyManager protected by the READ_PHONE_STATE permission in its code, and obtained the Android emulator device number through the getDeviceld method of this object.

[0119] The anonymous advertising protection system service learned during the dynamic operation of its application that it was the advertising library package (the package name is recorded in the advertising library signature) that accessed the device IMEI at present, so it called the anonymous protection module, making the current device IMEI be anonymously protected as a hashed string and returned to the advertising server. Thus, the effectiveness of the mobile phone anonymous advertising protection method was verified.

[0120] Next, repeat the above process in the emulator running after compiling the native Android source code without adding the mobile phone anonymous advertising protection method in the same way to further verify that the mobile phone anonymous advertising protection method plays a role in actual applications. Similarly, after configuring the BurpSuite proxy and the Android emulator proxy, start intercepting client requests.

[0121] In summary, the mobile phone anonymous advertisement protection method can effectively identify the source of the current visitor to sensitive resources, effectively anonymize the sensitive data accessed by the advertisement library using the permissions owned by the host application, without affecting the operation of the application and the normal delivery of the advertisement library, and reasonably maintain the privacy of user information.

[0122] (III) Performance Evaluation

[0123] To verify the practicality of the mobile phone anonymous advertisement protection method in the actual environment and to reasonably exert its effectiveness, this application tested the accuracy rate of the static analysis module and detected the time overhead brought about by the monitoring of the newly added system service.

[0124] 1. Accuracy Rate Test of the Static Analysis Module

[0125] The static analysis module matches and identifies the advertisement library-permission table according to the advertisement library signature and the permission-class table after decompiling the APK file. Since the operation process of the reverse calculation module will be affected by the selected decompilation tool and the size of the APK file, no time overhead test is carried out. This application pays more attention to the false alarm situation and the missed report situation of the number of advertisement libraries identified by using the advertisement library signature in the static analysis module.

[0126] In the initial stage of the experiment, 10 application programs marked with the "embedded advertisement" field were randomly downloaded from 19 application categories in the Android market, for a total of 190 application programs. The statistical information of the number of popular mobile advertisement libraries contained in the application programs identified after being processed by the static analysis module is as Figure 7 shown.

[0127] Next, use the apktool + dex2jar tool to batch decompile the above 190 application programs, and use the jd-gui graphical tool to review and identify the advertisement library signature of the decompiled source code files. There is no missed report situation in the static analysis module.

[0128] 2. Analysis of the Time Overhead of the New Service Detection

[0129] To analyze the time overhead introduced by the mobile phone anonymous advertisement protection during the actual operation of the application program, the time overhead analysis is carried out according to the following steps.

[0130] First, modify the advertisement library SDK to add a system timing method to calculate the time to obtain the return result. Call the NanoTime function, and its return result is the current state value of the system timer, with the unit of nanosecond level, so the elapsed time can be calculated more accurately.

[0131] Next, package the modified ad library code into a JAR and re-import it into the EaseWeb test application. Then run it several times respectively in the Android emulator generated after compiling the native Android source code without the mobile anonymous ad protection method and in the Android emulator with the mobile anonymous ad protection method, and select 20 relatively stable calculation results from the Log to record and parse.

[0132] To determine the impact of the modified system on the application's call to the framework layer methods, create another test application whose package name is not recorded in the ad library signature. Then also run it several times respectively in the native Android emulator and in the Android emulator with the mobile anonymous ad protection method. The time overhead brought by the mobile anonymous ad protection method during application calls is at the millisecond level and does not block the application's operation to a large extent. The time overhead is reduced through algorithm optimization.

Claims

1. An advertisement protection method under privacy protection of an Android mobile phone, characterized in that: In combination with the threat of permission inheritance access in the mobile advertising ecosystem, a mobile phone anonymous advertising protection method based on data perturbation is established. This method combines static program parsing and dynamic operation monitoring, uses the advertising library feature code to identify the source of privileged calls in the function call stack, and then uses data perturbation to perform fuzzy calculations on the privileged calls of the advertising library. Different anonymity rules are used for different data types to anonymize the access results, thereby solving the infringement of user privacy by the advertising library. Mobile phone anonymous advertising protection consists of static parsing module, dynamic monitoring module and anonymous protection module. These three parts span the application layer and application framework layer of Android system. The static parsing module is divided into three parts: reverse calculation, permission mapping and matching identification. The static parsing module is responsible for parsing the APK source file and building the advertising library-permission table. The dynamic monitoring module adds the Android system service anonymous advertising protection Service, which is also started when the Android system starts. The service encapsulates the methods for parsing the advertising library-permission table, dynamically capturing the function call stack and identifying the current call source. The anonymous protection module performs data protection for sensitive information accessed by the advertising library. It uses the method in the anonymous advertising protection Service system service to identify the call source as the advertising library, and then uses different anonymous rules according to different data types to perturb the data and return it to the advertising library to protect user sensitive information. The three modules work together to prevent the advertising SDK from inheriting the host application permissions to access sensitive information. Reverse calculation in static analysis module: Reverse calculation obtains Android application source code to provide it to the matching identification module for processing, uses Android decompilation to batch process application files, and reversely converts apk files into java source files; The dex2jar tool and the jadx tool are used in combination. The dex2jar tool converts apk format files into jar format, and the jadx tool converts class format files into java format. Both the dex2jar tool and the jadx tool are run in command line mode, and the output of the dex2jar command is the input condition of the jar command, and the output of the jar command is the input condition of the jadx command. When constructing commands, "&&" is used to splice commands, and then they are put into the console for execution to improve the automation performance of reverse computing. The decompilation process establishes a thread pool so that multiple threads can be executed simultaneously to further improve the efficiency of reverse computing; Matching identification in the static analysis module: Consider the popular mobile advertising libraries. After removing the aggregation platforms and proxy platforms in the list, collect all the remaining advertising developer software toolkits provided by mobile advertising companies, and perform static analysis to manually identify the package name of the advertising library as the advertising library feature code. The advertising library feature code is used to uniquely identify the advertising library introduced in the application through the advertising library package name; after identifying the advertising library feature code, find the introduced advertising library code in the application source code, and then find the sensitive permissions that the advertising library can use. The steps are as follows: Step 1: traverse the source file path to find the file set identified by the advertisement library feature code; Step 2: Traverse the ad library file collection and match the permission-class table Step 3: Output the sensitive permissions of the ad library; Mobile anonymous ad protection optimizes folder and file traversal. The rules are as follows: Rule 1: Identify whether the permission list document contains INTERNET permission. If not, terminate the traversal. Rule 2: Ignore system library folders during file and folder traversal; After the traversal is completed, the ad library-permission table is stored in the form of an XML configuration file; The dynamic monitoring module for mobile anonymous advertising protection dynamically captures the call stack during the application running process to identify whether the current sensitive call comes from the advertising library. It is implemented using system services and adds a new Java system service for dynamic monitoring. The framework layer API calls the service to obtain the identification result, and the service can run in the Android system for a long time. Modify the source code of the Android application framework layer, dynamically monitor the system service class where the privileged function call comes from, add the IAnonymize.aidl file, the AnonymizeService.java file to implement the interface defined in IAnonymize.aidl, and the AnonymizeManager.java file for other services or applications to call; AnonymizeService parses the ad library-permission table identified by the static parsing module and stores it in the ad library feature code array; uses the Android system's custom CallStackTrace exception class to perform stack tracing on the privileged method belonging class, takes the current top element of the stack and uses the ad library feature code to identify whether the current call comes from the ad library. If so, returns a Boolean value of true to mark the current permission call return result; Start the custom system service AnonymizeService when the Android system starts, register the service to the system service startup process, and modify the SystemServer.java file to add the custom service to the process; Next, create a new management class AnonymizeManager to call the methods in the service. The member variables in this class are the custom system service anonymous ad protection Service. Get the service instance in the constructor of the management class to use the methods in the service in the member functions of the management class. Finally, register it in the system service, bind AnonymizeManager and Anonymize_SERVICE through the IBinder mechanism, and implement the management class to call the methods in the system service using the aidl interface. Anonymous protection module: Based on the PBKDF2 encryption hash algorithm, it is improved. In the algorithm, SecureRandom is used to generate salt and append it to the end of the original information. The appended information is hashed and then returned to the advertising server. The highly randomized value of SecureRandom is appended to the original information, so that the value sent to the advertising server each time is different, reducing the possibility of the advertising server tracking users based on a specific unchanging value. After the salt value is appended and hashed, the string no longer has the characteristics of obviously exposing user privacy, protecting fine-grained user privacy information from being exposed in the advertising network. For the data cursor obtained by calling the query method in the ContentProvider component, the cursor data is cleared in an anonymous protection form. For the composite type in Android, it is anonymized to NULL. The implementation of anonymous rules is realized by function overloading. When the AnonymizeService system service in the dynamic monitoring module recognizes that the current function caller is the advertising library, the overloaded function is called to anonymize the call result before returning; When querying data through the ContentProvider class, the ContentResolver object communicates with the Provider. The request time series process is: call getContentResolver ().query(Uri,String,String,String,String), which calls the query method in ContentResolver. When the request method is called, ContentResolver parses the URI in the parameter and extracts the authorization authority field, which uniquely identifies the ContentProvider object in Android. ContentResolver guides the request to the ContentProvider object registered with the authority, and then calls the query method in it to obtain data. After calling the request method in ContentProvider, a Cursor object will be returned, which encapsulates the query result set. The anonymous protection module registers the anonymous ad protection service system service in the ContentResolver class for processing. First, it obtains the AnonymizeService system service instance in the constructor of the ContentResolver class, and returns the perturbed anonymous data when it is identified as an ad library call in the query operation; The MatrixCursor type inherits the AbstractCursor class. The AbstractCursor class finally implements the Cursor interface and uses the MatrixCursor class to return the result. The Cursor object returned by the MatrixCursor class in anonymous protection is the result of the empty table query, which is returned to the upper layer to avoid leakage of user privacy information. During the running of the application, the ad library code obtains the device ID and sends it to the ad server when the ad view is initialized. The system service AnonymizeService dynamically monitors the call stack information. The isAdsCaller() method in the AnonymizeService system service reads the top data of the stack and matches it with the ad library feature code, identifying that the current call comes from the ad library. The ad library call result is anonymized by the function overload, and the salt value is added to the original data to calculate the hash value and then returned.

2. According to claim 1, the method for protecting advertisements under privacy protection on an Android mobile phone is characterized in that: Mobile anonymous advertising protection architecture: Restructure the use of permissions to access local resources, and regard the situation where the advertising SDK uses the host application permissions to access local sensitive resources as a permission inheritance access threat. From the perspective of dynamically identifying the source of privileged method callers, build a mobile anonymous advertising protection method based on data perturbation. Adopt a combination of Android static parsing processing and dynamic monitoring. For local application files, static parsing and Android reverse technology are used to parse the mobile application advertising library; for dynamic permission calls of applications, the new system service is used to capture the call stack and combine the static parsing results to perform fuzzy calculations on the call results with data perturbations.

3. According to claim 1, the method for protecting advertisements under privacy protection on an Android mobile phone is characterized in that: Overall structure: When a user uses an application function, the application layer code in the upper layer of the Android architecture calls the API provided by the framework layer. The application framework layer provides the application layer with interface access to implement code reuse. When the API is called, the call stack is obtained to identify the source of the current access to sensitive resources. The mobile phone anonymous advertising protection method performs static analysis at the application layer and dynamic monitoring at the framework layer, spanning these two levels in the Android architecture. The static parsing module, dynamic monitoring module and anonymous protection module work together to process the access to sensitive resources in the advertising library, specifically including: first, the application is processed by the static parsing module before installation, which parses the access to sensitive resources in the advertising library and builds an advertising library-permission table; second, during the operation of the application, the interface provided by the framework layer is called to achieve resource access or data processing, an anonymous advertising protection system is added to the application framework layer, the current API call stack is obtained for dynamic monitoring, and according to the advertising library-permission table passed by the static parsing module, it is parsed whether the current call comes from the advertising library, and the result is submitted to the anonymous protection module for processing; finally, the anonymous protection module receives the recognition result of the dynamic monitoring module. If the current call comes from the advertising library, the perturbation result is returned to the framework layer API according to the anonymous rule matching, and the framework layer API then feeds back the perturbation result to the program that calls the interface.

4. According to claim 1, the method for protecting advertisements under privacy protection on an Android mobile phone is characterized in that: The static parsing module statically parses the application apk file embedded with the mobile advertising library, identifies the feature code of the advertising library, and constructs the advertising library-permission table. The static parsing module consists of three synergistic parts, namely reverse calculation, permission mapping and matching identification. The reverse calculation submodule uses Android static decompilation to reversely convert the apk file into Java source text for subsequent review and analysis; the permission mapping submodule implements the mapping between Android dangerous permissions and key classes, constructs a permission-class table, and provides it to the matching identification submodule for subsequent operations; the matching identification submodule first identifies the advertising library feature code in the Java source file generated by the reverse module, and then matches the Java source file in the package identified by the advertising library feature code with the permission-class table to find out the sensitive permissions exposed by the advertising library, and then obtains all the privileged accesses that may exist in the advertising library according to the permission API mapping list provided by PSCout, and finally generates an advertising library-permission table.

5. According to claim 1, the method for protecting advertisements under privacy protection on an Android mobile phone is characterized in that: Dynamic monitoring module: This module adds an anonymous advertising protection system in the Android application framework layer to dynamically capture the function call stack and extract the top data of the current function call stack, and compare it with the advertising library-permission table. If the top call method is derived from sensitive permission access of the advertising library, it will be recorded in the advertising library call result and the result will be submitted to the anonymous protection module for processing. If there is no sensitive permission access to the advertising library, the call result will be returned directly to the application layer without any other special processing.

6. According to claim 1, the method for protecting advertisements under privacy protection on an Android mobile phone is characterized in that: The static parsing module identifies the sensitive and high-risk permissions contained in the advertising library embedded in the application, and then knows the privileged method calls that may exist in the advertising library. It reverses the source code of the apk through Android decompilation, and then uses the advertising library feature code to identify the advertising library code in the source code. Then, the sensitive permissions contained in the advertising library are matched according to the key classes of accessing sensitive permissions in the advertising library code. It is composed of three parts: reverse calculation, permission mapping, and matching identification. The reverse submodule applies the parsing technology of Android's popular static decompilation to obtain the source code of the application, and provides it to the matching identification module for subsequent processing. The permission mapping submodule constructs a permission-class table for Android high-risk permissions to identify key calls of sensitive permissions in the source code, and the matching identification submodule first collects the package name of the popular mobile advertising library as the mobile advertising library feature code; then uses the feature code field to identify the advertising library code in the application source code; finally, uses the permission-class table to find the sensitive permission calls in the advertising library code. The three submodules work together to finally generate the advertising library-permission table.

7. According to claim 1, the method for protecting advertisements under privacy protection on an Android mobile phone is characterized in that: Matching and identification module implementation: The matching and identification module identifies the ad library feature code, and then matches the sensitive permissions of the ad library code in the application source code based on the ad library feature code and the Android permission-class table, thereby obtaining the privileged function access that may exist in the ad library code.

8. According to claim 1, the method for protecting advertisements under privacy protection on an Android mobile phone is characterized in that: Anonymous protection module implementation: For dangerous permission method calls identified in the static analysis module, the anonymous ad protection Service in the dynamic monitoring module is used to capture the current function call stack. If the call result at the top of the stack comes from the ad library, the custom anonymous rules are applied to process the result and return it to the ad library.

Citation Information

Patent Citations

  • Fine-grained permission management method and system for Android advertisement bank

    CN107194277A

  • Refined enhanced permission control and analysis system of Android platform

    CN111709017A

  • Android application classification authorization method for quantitative judgment of suspicious behaviors

    CN113326502A