Data Detection Method, Device, Storage Medium and Electronic Device
By obtaining and forwarding operation data of the first type of application to the device server in the electronic device, the problem of illegal operation is solved, and reliability detection and security improvement of third-party applications is achieved.
Patent Information
- Application Number
- CN202410116174.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-26
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2044-01-26
AI Technical Summary
Illegal personnel use the interaction between third-party applications and system applications to perform illegal operations, and the prior art is difficult to effectively detect and prevent.
By obtaining operation data of the first type of application in the electronic device and forwarding it to the device server through the second type of application, the device server determines the reliability of the first type of application based on these operation data, and detecting illegal operations is achieved.
Quickly identify and prevent illegal operations performed by illegal personnel through third-party applications and system applications, improving the security and reliability of electronic devices.
Smart Images

Figure CN119182682B_ABST
Abstract
Description
Technical Field
[0001] The technical solution of the present disclosure relates to the field of data transmission technology, and in particular, to a data detection method, device, storage medium, and electronic device. Background Art
[0002] System applications (abbreviated as system apps) are installed in an electronic device by default. After a user gets an electronic device, they will also install some third-party applications according to their usage needs. For example, when the electronic device is a mobile phone, common system applications include: Mobile Manager, Application Permission Management, Messages, etc.; common third-party applications include: short video playback software, photo editing software, etc.
[0003] Since system applications are pre-installed in the electronic device when it leaves the factory, they are highly reliable, so system applications usually have high permissions; while third-party applications are provided by other manufacturers and their reliability is unknown, so third-party applications usually have low permissions.
[0004] When a user runs a third-party application on an electronic device, they usually grant the third-party application permission to access system applications, such as permission to access the contact list, permission to obtain the user's photo album, permission to obtain the user's identity information, etc. This makes it easy for illegal personnel to perform some illegal operations by taking advantage of the interaction between the third-party application and the system application after discovering system vulnerabilities. Based on this, a solution is needed. Summary of the Invention
[0005] In view of this, the present disclosure provides a data detection method, device, storage medium, and electronic device, which helps to solve the problem of illegal personnel performing illegal operations by taking advantage of the interaction between third-party applications and system applications.
[0006] According to a first aspect of an embodiment of the present disclosure, there is provided a data detection method applied to an electronic device, the method including:
[0007] Obtain operation data of a first type of application in the electronic device;
[0008] Forward the operation data to a device server through a second type of application in the electronic device, so that the device server determines the reliability of the first type of application based on the operation data; wherein, the first type of application is not connected to the device server.
[0009] According to a second aspect of an embodiment of the present disclosure, there is provided a data detection method applied to a device server, the method including:
[0010] Obtain the operation data transmitted by a second type of application in the electronic device; the operation data is the data generated when a first type of application in the electronic device performs a target operation;
[0011] Based on the operation data, determine the reliability of the first type of application running on the electronic device.
[0012] According to the third aspect of the embodiments of the present disclosure, there is provided a data detection device, the device includes:
[0013] An acquisition module, configured to acquire the operation data of a first type of application in the electronic device;
[0014] A forwarding module, configured to forward the operation data to a device server through a second type of application in the electronic device, so that the device server determines the reliability of the first type of application based on the operation data; wherein, the first type of application is not connected to the device server.
[0015] According to the fourth aspect of the embodiments of the present disclosure, there is provided a data detection device, the device includes:
[0016] A response module, configured to acquire the operation data transmitted by a second type of application in the electronic device; the operation data is the data generated when a first type of application in the electronic device performs a target operation;
[0017] A risk determination module, configured to determine the reliability of the first type of application running on the electronic device based on the operation data.
[0018] According to the fifth aspect of the embodiments of the present disclosure, there is provided an electronic device, including:
[0019] A processor;
[0020] A memory for storing processor-executable instructions;
[0021] Wherein, the processor is configured to implement the steps of any of the methods in the first aspect or the second aspect by running the executable instructions.
[0022] According to the sixth aspect of the embodiments of the present disclosure, there is provided a non-transitory computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the steps of any of the methods in the first aspect or the second aspect.
[0023] According to the seventh aspect of the embodiments of the present disclosure, there is provided a computer program, and when the computer program is executed by a processor, it implements the steps of any of the methods in the first aspect or the second aspect.
[0024] The technical solutions provided by the embodiments of the present disclosure may include the following beneficial effects:
[0025] In an electronic device, the operating system is like a basic platform, pre-installed by the manufacturer and configured with a device server. This device server is used to provide important services for the electronic device, such as operating system upgrades, account management, and security vulnerability repairs. Generally, two different types of application programs are installed in the electronic device: one is the system application, which is built-in by the device manufacturer at the time of factory shipment and has the ability to communicate directly with the device server; the other is the third-party application, which is downloaded and installed by the user from the app store or other channels and mainly communicates with their respective third-party servers rather than the device server.
[0026] Therefore, if an application (such as the second type of application) can establish communication with the device server, we can infer that it belongs to the system application pre-installed at the factory; on the contrary, if an application does not establish communication with the device server, it indicates that it is a third-party application installed by the user himself.
[0027] At this time, after obtaining the operation data of the first type of application in the electronic device, the operation data can be forwarded to the device server through the second type of application in the electronic device, so that the device server can determine whether the first type of application can run reliably in the electronic device based on the operation data.
[0028] Through the above method, the device server can quickly detect suspicious behaviors of the first type of application, which helps to solve the problems of illegal personnel using system vulnerabilities and continuous execution of illegal operations through the interaction between third-party applications and system applications.
[0029] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure and used together with the specification to explain the principles of the present disclosure.
[0031] Figure 1 is a flowchart of a data detection method shown according to an exemplary embodiment of the present disclosure;
[0032] Figure 2 is an application framework diagram of a data detection method shown according to an exemplary embodiment of the present disclosure;
[0033] Figure 3 is an application framework diagram of another data detection method shown according to an exemplary embodiment of the present disclosure;
[0034] Figure 4It is an application framework diagram of another data detection method shown according to an exemplary embodiment of the present disclosure;
[0035] Figure 5a It is a flowchart of another data detection method shown according to an exemplary embodiment of the present disclosure;
[0036] Figure 5b It is a flowchart of another data detection method shown according to an exemplary embodiment of the present disclosure;
[0037] Figure 6 It is an application framework diagram of another data detection method shown according to an exemplary embodiment of the present disclosure;
[0038] Figure 7 It is a flowchart of another data detection method shown according to an exemplary embodiment of the present disclosure;
[0039] Figure 8 It is an application framework diagram of a data detection method shown according to an exemplary embodiment of the present disclosure;
[0040] Figure 9 It is a structural schematic diagram of a data detection device shown according to an exemplary embodiment of the present disclosure;
[0041] Figure 10 It is a structural schematic diagram of a data detection device shown according to an exemplary embodiment of the present disclosure;
[0042] Figure 11 It is a structural schematic diagram of an electronic device shown according to an exemplary embodiment of the present disclosure. Detailed implementation manners
[0043] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.
[0044] The terms used in the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure. The singular forms "a", "the" and "said" used in the present disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0045] It should be understood that although terms such as first, second, and third may be used in this disclosure to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this disclosure, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to a determination".
[0046] Figure 1 is a flowchart of a data detection method shown by this disclosure according to an exemplary embodiment. As Figure 1 shown, the method is applied to an electronic device (or in the operating system of the electronic device) and includes the following steps:
[0047] Step 101, obtain the operation data of the first type of application in the electronic device.
[0048] The first type of application generally refers to a third-party application installed in the electronic device (running in the operating system of the electronic device). The operation data of the first type of application is the data generated when the first type of application runs, which can be partial data or all data, mainly reflected in the data generated when the first type of application calls the system services of the electronic device, so as to timely discover the behavior of the first type of application attacking system vulnerabilities by calling system services based on these operation data.
[0049] Exemplarily, obtaining the operation data of the first type of application includes but is not limited to at least one of the following:
[0050] Obtain the interface call information of the first type of application, obtain the system permission information of the first type of application, obtain the running information of the first type of application, the user's interaction information, etc.
[0051] It can be embodied as: the information of the interface to be called, the call frequency, the information of the desktop widget added (size, adding method), the information of the running floating window, the information of pulling up the payment application, the duration of holding the power management wake lock (WakeLock), the background running duration and running mode, the information of running in the system bar, the information of the popped-up page, etc.
[0052] Step 102, forward the operation data to the device server through the second type of application in the electronic device, so that the device server determines the reliability of the first type of application based on the operation data; wherein, the first type of application is not connected to the device server.
[0053] Among them, since the first type of application and the second type of application are actually installed in the same electronic device, after the operating system in the electronic device obtains the operation data of the first type of application, it can directly forward the operation data of the first type of application to the device server through the second type of application.
[0054] Among them, the fact that the first type of application is not connected to the device server means that: regardless of what device the first type of application is installed on, there is no direct communication ability (no ability to directly exchange data) between the first type of application and the device server, or, although they have the ability of direct communication, since the device server and the first type of application are produced by different manufacturers, in order to ensure its own security, the device server does not allow the first type of application to directly communicate with the device server. At this time, the data of the first type of application must be transmitted via the second type of application that can directly exchange data with the device server.
[0055] Exemplarily, it can be that the operating system reads the operation data at the storage location of the first type of application and stores the operation data at the storage location of the second type of application (the location to be uploaded to the device server).
[0056] In this way, after the device server obtains the operation data of the first type of application, it can identify whether there is a situation where the first type of application performs illegal operations. Illegal operations can be, for example: writing illegal files, advertising pop-ups, stealing data, and so on.
[0057] Figure 2 It is an application framework diagram of a data detection method shown according to an exemplary embodiment of the present disclosure. As Figure 2 shown, the operating system provides core services (including core service components and / or core service interfaces). The core services are used to provide the most basic and crucial function support for the operating system, such as: process management, file system management, processing, data storage, security authentication, account management, location services, and so on. When there are interfaces to be called in the core services, the first type of application can call the second type of application by calling these interfaces, so as to illegally operate the second type of application or perform illegal operations after obtaining higher system privileges through the second type of application.
[0058] Therefore, after the core service determines that its interfaces or components are called by the first type of application, it will transmit the corresponding operation data to the second type of application, and then to the device server.
[0059] On this basis, Figure 3 It is another application framework diagram of a data detection method shown according to an exemplary embodiment of the present disclosure. As Figure 3 shown:
[0060] The core services include: the first core service 301 and the second core service 302.
[0061] Among them, multiple service components are shown in the first core service 301, namely: UriGrantsManagerService (Resource Authorization Management Service, Uniform Resource Identifier GrantsManager Service), WindowManagerService (Window Management Service), AppOpsService (Application Behavior Service, Application Operations Service), AppWidgetServiceImpl (Application Widget Service), BroadcastQueue (Broadcast Queue Management Service), ContentProviderHelper (Content Provider Management Service), ActivityStarter (Activity Launch Service), ActiveServices (Service Management Service).
[0062] Among them, the UriGrantsManagerService is responsible for managing the access rights of applications to specific URI (Uniform Resource Identifier) resources (such as data in the Content Provider). It processes requests, grants, and revokes access permissions to specific content or files, ensuring the security and privacy protection of the system. The WindowManagerService is used to manage and control the layout, display, hiding, and interaction between all application windows. It is responsible for coordinating the arrangement, size adjustment, animation effects, etc. of each application window on the screen, and cooperating with the SurfaceFlinger (Surface Composition Service) to complete the window composition and display. The AppOpsService is a component in the operating system used to monitor and control the access rights of each application to system functions and user data. Through the AppOpsService, users or system administrators can manage the behavior of applications in a fine-grained manner, such as whether to allow an application to obtain location information, read the contact list, etc. The AppWidgetServiceImpl is a service used to support and manage the life cycle of desktop widgets. It is responsible for creating, updating, deleting desktop widgets provided by applications, and handling interaction events between users and widgets. The BroadcastQueue is part of the message passing mechanism, mainly used to manage broadcast messages sent between the system internal and applications. It orderly places the received broadcast events into the queue according to the priority, and then distributes them to the components registered with the corresponding receivers for processing, ensuring the secure and reliable transmission of broadcast messages. The ContentProviderHelper refers to the relevant tool classes or service modules that assist developers or the system in calling the Content Provider, used to simplify the access and management of shared data between the system or applications. The ActivityStarter usually refers to the component responsible for the relevant logic of starting a new Activity (a type of component). It is responsible for processing the parsing of Intents, finding the target Activity, and executing the corresponding startup process, ensuring the correctness and security when switching from one Activity to another. The ActiveServices is an important component in the operating system responsible for managing running background services and foreground services. It undertakes the life cycle management responsibilities such as starting, binding, and stopping services, and optimizing service scheduling according to the system resource status, ensuring the efficient operation of services and the effective utilization of system resources.
[0063] These service components will provide corresponding interfaces for the first type of applications to call. At this time, the second core service 302 will monitor the components in the first core service 301. When these components are called by the first type of applications, the operation data generated by the first type of applications when calling these components will be stored and transmitted to the second type of applications.
[0064] Among them, as an example, the first core service 301 can be: the basic core service set (CoreServices), which contains all the key basic services provided by the operating system, such as window management, resource management, permission control, etc. The second core service 302 can be: the core service extension specific to a specific operating system (for example, the HyperOS operating system) (that is, Core HyperOS Services), which is a series of core services enhanced or customized for the HyperOS operating system based on the basic core services. In this case, the two may exist in the same system process or different processes, jointly constituting the core functional module of the entire operating system.
[0065] Optionally, when performing step 102 to forward the operation data to the device server through the second type of application in the electronic device, it includes:
[0066] Classify and store the obtained operation data; transmit the classified and stored operation data to the second type of application; control the second type of application to transmit the classified and stored operation data to the device server.
[0067] The classification method can be: classify according to different called interfaces or components; classify according to different storage forms of data; classify according to different first types of applications, etc.
[0068] Schematically, classifying and storing the obtained operation data includes:
[0069] Mark specific identifiers for the operation data according to the type of the operation data; store the operation times and operation durations of each group of operation data respectively according to the mapping relationship between the operation data and the identifiers.
[0070] The identifiers can match the classification. For example, the identifier for the operation data generated by application A is: 1; the identifier for the operation data generated by application A is: 2. Or, the identifier for the operation data of the type of calling the floating window is: x1 (only schematic); the identifier for the operation data of the type of obtaining user information is: y1.
[0071] After determining the identifier, the operation data can also be stored separately according to the number of operations and the operation duration of the operation data. In this way, it is convenient for the staff or the preset model to call the operation data at the corresponding storage location according to different identifiers to determine whether there is a risk in the first type of application, without having to search for the data needed from the entire database.
[0072] After that, the operation data stored by classification is transmitted to the second type of application, and then the operation data is transmitted to the device server through the second type of application.
[0073] Exemplarily, Figure 4 is an application framework diagram of another data detection method shown by the present disclosure according to an exemplary embodiment, as Figure 4 shown:
[0074] The second core service 302 includes the following four services:
[0075] 3021: AppDurationManager (Application Duration Manager), mainly used to monitor or manage the life cycle during the operation of the application or the execution time of specific tasks. For example, it may be used to track service response time, record session activity duration, execute timed tasks, or optimize resource usage efficiency
[0076] 3022: AppBehaviorService (Application Behavior Service), mainly used to monitor and manage the behavior characteristics of the application, such as user behavior analysis, abnormal behavior detection, performance monitoring, business logic compliance check, etc. Through this service, the behavior data during the operation of the application can be collected, analyzed, and processed to improve the user experience, optimize performance, or implement more refined control strategies.
[0077] 3023: DefenseChecker (Defense Module), used to store the operation data monitored by AppDurationManager 3021 and AppBehaviorService 3022, and transmit it to SecurityManagerService 3024.
[0078] 3024: SecurityManagerService (Security Management Service), a core service, used to centrally manage the security policies and operations of the system. It usually implements functions such as authentication, authorization, and auditing to ensure that the access of users or service callers to resources complies with the preset security rules. In this solution, it is mainly used to transmit the operation data stored in DefenseChecker 3023 to the second type of application.
[0079] Optionally,Figure 5a Figure 5a is a flowchart of another data detection method shown according to an exemplary embodiment of the present disclosure. The operation of transmitting the operation data stored by classification to the second type of application includes the following steps:
[0080] Step 501, for each group of operation data, determine the risk level of the operation data.
[0081] The risk level can be set in advance for different applications, or determined based on the detection results of a risk detection application or a risk detection module in the electronic device, or determined according to the installation source of different applications, or determined according to whether the operation is a sensitive operation (such as obtaining the user's privacy data).
[0082] Step 502, determine the target second type of application to obtain the operation data from multiple second type of applications; the higher the risk level of the operation data, the lower the system permission of the target second type of application.
[0083] Exemplarily, assume there are two second type of applications, namely Application One and Application Two. The system permission of Application One is higher than that of Application Two.
[0084] Assume the risk levels of the operation data include: Risk Level One and Risk Level Two, and the risk level of Risk Level One is lower than that of Risk Level Two. Among them, the higher the risk level, the more dangerous the operation of the first type of application.
[0085] When the risk level of the operation data of the first type of application is Risk Level One, it means that this operation is relatively safe, and Application One is determined as the target second type of application; when the risk level of the operation data of the first type of application is Risk Level Two, it means that this operation is relatively dangerous, and Application Two is determined as the target second type of application.
[0086] Step 503, transmit the operation data to the target second type of application.
[0087] In this way, the operation data with a lower risk level can be transmitted to Application One and uploaded to the device server through Application One; the operation data with a higher risk level (more likely to carry viruses) can be transmitted to Application Two, and Application Two is allowed to transmit it to the device server. Even if there are viruses in the operation data, they will not attack Application One and cause the viruses to perform more serious illegal operations using the higher system permission of Application One.
[0088] Figure 6 Figure 6 is an application framework diagram of another data detection method shown according to an exemplary embodiment of the present disclosure, as Figure 6 shown, the second type of application 601 includes:
[0089] 6011: SecurityCenter (Security Center Module); 6012: AuthManager (Permission Management Module), both of which are system applications and can communicate with the device server.
[0090] The SecurityCenter 6011 of the security center module is used to obtain operation data according to a specific period through the (SecurityManagerService 3024) interface, or when the quantity in the DefenseChecker 3023 reaches the specified quantity, actively transmit the SecurityCenter 6011 of the security center module (which can be transmitted through the SecurityManagerService 3024 or by itself, only schematically shown in the figure).
[0091] The AuthManager 6012 of the permission management module is responsible for recording all permission behavior records calls in the device, such as sensitive data transmission behaviors of application software reading contacts, reading call records, reading text messages, recording, positioning, using the camera, etc., and it has relatively high system permissions.
[0092] Optionally, Figure 5b is a flowchart of another data detection method shown by the present disclosure according to an exemplary embodiment. As Figure 5b shown, the step of transmitting the operation data stored by classification to the second type of application further includes the following steps:
[0093] Step 504, in response to detecting that the target second type of application has a risk, transmit the operation data and the risk information of the target second type of application to other second type of applications; the multiple second type of applications include the target second type of application and the other second type of applications.
[0094] Continuing with the above example: When the risk level of the operation data of the first type of application is risk level two, it means that this operation is relatively dangerous. After determining Application Two as the target second type of application and transmitting the operation data with a higher risk level to Application Two, the virus performs some illegal operations through Application Two. At this time, since Application Two has a risk (such as being unable to run, unable to communicate with the device server, etc.), it is impossible to transmit the data to the device server through Application Two. The risk information and operation data of Application Two can be transmitted to Application One and then transmitted to the device server through Application One.
[0095] It should be noted that when transmitting the operation data, since it is known to have a risk, certain security measures can be taken to transmit the operation data to the device server while preventing the operation data from attacking Application One.
[0096] Optionally,Figure 7 is a flowchart of another data detection method shown according to an exemplary embodiment of the present disclosure. As Figure 7 shown, the method is applied to a device server and includes the following steps:
[0097] Step 701, obtaining operation data transmitted by a second type of application in an electronic device; the operation data is data generated when a first type of application in the electronic device performs a target operation.
[0098] Step 702, determining the reliability of the first type of application running on the electronic device based on the operation data.
[0099] The content involved in the above steps 701 - 702 has been described in the foregoing embodiments and will not be repeated here.
[0100] Optionally, performing step 702 to determine the reliability of the first type of application running on the electronic device based on the operation data includes three methods:
[0101] Method 1,
[0102] Performing: determining a risk value of the operation data based on a preset model, where the risk value is used to indicate whether there is a risk in the first type of application.
[0103] Figure 8 is an application framework diagram of a data detection method shown according to an exemplary embodiment of the present disclosure. As Figure 8 shown:
[0104] After the device server obtains the operation data of the first type of application forwarded by the second type of application, it determines the risk value of the operation data through a preset model.
[0105] Among them, the preset model can be a pre-trained risk control model that can determine whether there is a risk based on the operation data. Or, the preset model can also determine the risk value according to the following method:
[0106] The device server combines the information of the first type of application publicly available in the application store and conducts a risk analysis on the operations of the first type of application. An example of the analysis process is as follows:
[0107] The risk levels of application call operations range from 1 to 10 points from low to high. The specific scores are shown in Table 1:
[0108] Table 1:
[0109]
[0110]
[0111] Among them, under normal circumstances, when a first-type application enters the background running state, the operating system will end the background running of this first-type application after a specific period of time and restart it again when the user opens it again. Therefore, if a first-type application survives in the background for too long, it means that it has circumvented the operation of the operating system to close the background running, which can be regarded as a risky operation. At this time, within each cycle (for example, every day), each time the background running reaches 1 hour, 10 points will be recorded.
[0112] The first-type application obtains the Uri authorization of the system application (second-type application). Simply put: when an application in your mobile phone (such as the system photo album) wants to share a picture or file with another non-system third-party application (such as a social software), it will not directly give the third-party application the file itself, but give a special link (this link is called Uri). Due to concerns about user privacy and system security, not all applications can access these resources at will. Therefore, during the sharing process, the system photo album will first apply to the system for authorization to allow the third-party application to access specific pictures or files through this Uri. Only by obtaining this "Uri authorization" can the third-party application legally and safely obtain and use the resources selected by the user in the system application. It can be seen that Uri authorization will have relatively high permissions, and the first-type application can easily use these permissions to perform illegal operations (such as stealing user images). Therefore, each time 1 Uri permission is obtained, 8 points will be recorded.
[0113] Similarly, each time the first-type application controls the pop-up of an interface in the background, 5 points will be recorded; each time a payment application is launched, 3 points will be recorded; each time a desktop widget information is added, 3 points will be recorded; each time the duration of holding the WakeLock lock reaches 1 hour, 5 points will be recorded; if the size of the floating window exceeds a specific screen ratio (for example, three-quarters, and there is a suspicion of full-screen advertising at this time), 10 points will be recorded, and if the size of the floating window is smaller than a specific size (for example, 10 pixels * 10 pixels, which is relatively small and considered to pose little harm), 5 points will be recorded; interacting with three of the four major components (obtaining non-standard API interfaces of the Activity, Service, and Provider three services), 2 points will be recorded each time, and interacting with the component (non-standard API interface of Broadcast) will be recorded 1 point each time.
[0114] Each time the accessibility service permission is obtained, 10 points are recorded; among them, the accessibility service permission is to eliminate the digital divide and ensure that all users can enjoy the convenient life brought by technology. Services include, but are not limited to: helping visually impaired users understand the content and operations on the screen through voice feedback, or operating electronic devices through voice; touch assistance: providing alternative input methods for users with inconvenient finger movements, such as supporting gesture control, switch control, or customizing button sizes, etc. Therefore, the accessibility service permission often requires the device to automatically control the electronic device (such as voice control, eye movement control, etc.) and requires relatively high system permissions.
[0115] For the front desk service duration per day, 10 points are recorded per hour. Among them, the front desk service duration refers to the situation where the first type of application is not displayed on the main interface, but runs, prompts, notifies, etc. in the status bar, system bar, etc.
[0116] Each time the contacts are read, 1 point is recorded; each time the text messages are read, 2 points are recorded; each time the call records are read, 1 point is recorded; each time a notification is displayed on the lock screen, 4 points are recorded; each time a user picture is deleted, 5 points are recorded.
[0117] It should be noted that the above methods are mainly used to determine the risk of the first type of application that does not require these permissions itself. For example, if the first type of application is itself a call application, then when reading information such as contacts and call records, points can be deducted or not deducted as appropriate.
[0118] Moreover, the above scoring is mainly for the usage situation of each first type of application on a single electronic device. In this way, when the first type of application has malicious behaviors that do not meet its own required scenarios, it can be quickly identified.
[0119] Method 2. Execution: Send the information of the first type of application and the operation data to the background server, and the background server is used to determine whether the first type of application has risks.
[0120] By sending the information of the first type of application and the operation data to the background server, the staff of the background server can directly determine whether the first type of application has risks manually.
[0121] Exemplarily, it can also be Method 3:
[0122] First, execute the step: Determine the risk value of the operation data based on a preset model, and the risk value is used to indicate whether the first type of application has risks; then execute the step: Send the information of the first type of application and the operation data to the background server, and the background server is used to determine whether the first type of application has risks.
[0123] At this time, the subsequent step can be further modified as follows: when the risk value of the operation data is determined to reach a preset value based on a preset model, the information of the first type of application and the operation data are sent to the background server; wherein, the risk value reaching the preset value includes at least one of the following:
[0124] The risk value when the first type of application runs on a single electronic device is greater than or equal to a first value; the average value of the risk values when the first type of application runs on multiple electronic devices is greater than or equal to a second value.
[0125] The first value and the second value can be the same or different.
[0126] Exemplarily, the second value can be set to be less than the first value. For example, the first value is 20 points and the second value is 10 points.
[0127] In this way, when the risk value of the first type of application on a single electronic device reaches 20 (greater than or equal to 20), it is determined that this first type of application has a risk; when the device server finds that the risk value of this first application on multiple electronic devices reaches 10, it is considered that this first type of application has a risk.
[0128] At this time, in order to more accurately determine whether the first type of application has a risk, or to determine how high the risk level is, it can be sent to the background server for the staff of the background server to verify, so as to obtain a more perfect protection measure as soon as possible.
[0129] For the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present disclosure is not limited by the described action sequence, because according to the present disclosure, certain steps can be performed in other sequences or simultaneously.
[0130] Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to the present disclosure.
[0131] Corresponding to the foregoing method embodiments for implementing application functions, the present disclosure also provides embodiments of a data transmission and data detection device and a corresponding terminal.
[0132] Figure 9 is a schematic structural diagram of a data detection device shown according to an exemplary embodiment of the present disclosure, as Figure 9 shown, the device includes:
[0133] An acquisition module 901, configured to acquire operation data of a first type of application in an electronic device.
[0134] A forwarding module 902, configured to forward the operation data to a device server through a second-type application in the electronic device, so that the device server determines the reliability of the first-type application based on the operation data; wherein, the first-type application is not connected to the device server.
[0135] Optionally, when the forwarding module 902 is configured to forward the operation data to a device server through a second-type application in the electronic device, it is configured to:
[0136] Classify and store the obtained operation data.
[0137] Transmit the operation data stored after classification to the second-type application.
[0138] Control the second-type application to transmit the operation data stored after classification to the device server.
[0139] Optionally, when the forwarding module 902 is configured to classify and store the obtained operation data, it is configured to:
[0140] Mark a specific identifier for the operation data according to the type of the operation data.
[0141] Store the operation times and operation durations of each group of operation data respectively according to the mapping relationship between the operation data and the identifier.
[0142] Optionally, when the forwarding module 902 is configured to transmit the operation data stored after classification to the second-type application, it is configured to:
[0143] For each group of operation data, determine the risk level of the operation data.
[0144] Determine a target second-type application to obtain the operation data from multiple second-type applications; the higher the risk level of the operation data, the lower the system privilege of the target second-type application.
[0145] Transmit the operation data to the target second-type application.
[0146] Optionally, when the forwarding module 902 is configured to transmit the operation data stored after classification to the second-type application, it is further configured to:
[0147] In response to detecting that the target second-type application has a risk, transmit the operation data and the risk information of the target second-type application to other second-type applications; the multiple second-type applications include the target second-type application and the other second-type applications.
[0148] Optionally, when the obtaining module 901 is used to obtain operation data of a first type of application in an electronic device, it includes at least one of the following:
[0149] Obtain interface call information of the first type of application; obtain system permission information of the first type of application; obtain running information of the first type of application.
[0150] Figure 10 It is a schematic structural diagram of a data detection device shown by the present disclosure according to an exemplary embodiment, as Figure 10 shown, the device includes:
[0151] A response module 1001, configured to obtain operation data transmitted by a second type of application in the electronic device; the operation data is data generated when a first type of application in the electronic device executes a target operation.
[0152] A risk determination module 1002, configured to determine the reliability of the first type of application running on the electronic device based on the operation data.
[0153] Optionally, when the risk determination module 1002 is used to determine the reliability of the first type of application running on the electronic device based on the operation data, it is used for:
[0154] Determine a risk value of the operation data based on a preset model, and the risk value is used to indicate whether there is a risk in the first type of application.
[0155] Send information of the first type of application and the operation data to a background server, and the background server is used to determine whether there is a risk in the first type of application.
[0156] Optionally, when the risk determination module 1002 is used to send information of the first type of application and the operation data to the background server, it is used for:
[0157] When the risk value of the operation data determined based on the preset model reaches a preset value, send information of the first type of application and the operation data to the background server.
[0158] Wherein, the risk value reaching the preset value includes at least one of the following:
[0159] The risk value when the first type of application runs on a single electronic device is greater than or equal to a first value; the average value of the risk values when the first type of application runs on multiple electronic devices is greater than or equal to a second value.
[0160] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the descriptions in the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the present disclosure. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0161] Correspondingly, the embodiments of the present disclosure provide a computer program, and when the computer program is executed by a processor, the steps of any of the above methods are implemented.
[0162] Correspondingly, the embodiments of the present disclosure provide an electronic device, including: a processor; a memory for storing processor-executable instructions; wherein, the processor is configured to implement the steps of any of the above methods by running the executable instructions.
[0163] Figure 11 FIG. 10 is a schematic structural diagram of an electronic device according to an exemplary embodiment of the present disclosure. For example, the electronic device 1100 may be a user device, and may specifically be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, a wearable device such as a smart watch, smart glasses, a smart bracelet, a smart running shoe, etc.
[0164] Referring to Figure 11 , the electronic device 1100 may include one or more of the following components: a processing component 1102, a memory 1104, a power supply component 1106, a multimedia component 1108, an audio component 1110, an input / output (I / O) interface 1112, a sensor component 1114, and a communication component 1116.
[0165] The processing component 1102 generally controls the overall operation of the electronic device 1100, such as operations associated with display, telephone call, data communication, camera operation, and recording operation. The processing component 1102 may include one or more processors 1120 to execute instructions to complete all or part of the steps of the above methods. In addition, the processing component 1102 may include one or more modules to facilitate the interaction between the processing component 1102 and other components. For example, the processing component 1102 may include a multimedia module to facilitate the interaction between the multimedia component 1108 and the processing component 1102.
[0166] The memory 1104 is configured to store various types of data to support the operation of the device 1100. Examples of such data include instructions for any application or method operating on the electronic device 1100, contact data, phone book data, messages, pictures, videos, and the like. The memory 1104 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk.
[0167] The power supply component 1106 provides power to various components of the electronic device 1100. The power supply component 1106 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the electronic device 1100.
[0168] The multimedia component 1108 includes a screen that provides an output interface between the above-mentioned electronic device 1100 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The above-mentioned touch sensors can not only sense the boundaries of touch or swipe actions, but also detect the duration and pressure associated with the above-mentioned touch or swipe operations. In some embodiments, the multimedia component 1108 includes a front camera and / or a rear camera. When the electronic device 1100 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each of the front camera and the rear camera can be a fixed optical lens system or have a focal length and optical zoom capabilities.
[0169] The audio component 1110 is configured to output and / or input audio signals. For example, the audio component 1110 includes a microphone (MIC) that is configured to receive external audio signals when the electronic device 1100 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 1104 or transmitted via the communication component 1116. In some embodiments, the audio component 1110 further includes a speaker for outputting audio signals.
[0170] The I / O interface 1112 provides an interface between the processing component 1102 and a peripheral interface module, and the peripheral interface module can be a keyboard, a click wheel, buttons, etc. These buttons can include but are not limited to: a home button, a volume button, a start button, and a lock button.
[0171] The sensor assembly 1114 includes one or more sensors for providing status assessment of various aspects for the electronic device 1100. For example, the sensor assembly 1114 can detect the on / off state of the electronic device 1100, the relative positioning of components, such as the display and keypad of the electronic device 1100 as mentioned above. The sensor assembly 1114 can also detect a change in the position of the electronic device 1100 or a component of the electronic device 1100, the presence or absence of user contact with the electronic device 1100, the orientation or acceleration / deceleration of the electronic device 1100, and the temperature change of the electronic device 1100. The sensor assembly 1114 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor assembly 1114 can also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor assembly 1114 can also include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
[0172] The communication component 1116 is configured to facilitate communication between the electronic device 1100 and other devices in a wired or wireless manner. The electronic device 1100 can access a wireless network based on communication standards, such as WiFi, 4G or 5G, 4G LTE, 5G NR, or a combination thereof. In an exemplary embodiment, the communication component 1116 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 1116 further includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0173] In an exemplary embodiment, the electronic device 1100 can be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components for performing the above method.
[0174] In an exemplary embodiment, a non-transitory computer-readable storage medium is also provided, such as a memory 1104 including instructions, which when executed by a processor 1120 of the electronic device 1100, enables the electronic device 1100 to perform the steps of any of the above methods.
[0175] The non-transitory computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0176] Other embodiments of the present disclosure will be readily apparent to those skilled in the art after considering the specification and practicing the invention disclosed herein. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed herein. The specification and examples are only to be considered as exemplary, and the true scope and spirit of the present disclosure are pointed out by the following claims.
[0177] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.
Claims
1. A data detection method, characterized in that, The method includes: Obtaining operation data of a first type of application in an electronic device; Forwarding the operation data to a device server through a second type of application in the electronic device, so that the device server determines the reliability of the first type of application based on the operation data; wherein, the first type of application is not connected to the device server; The forwarding the operation data to the device server through the second type of application in the electronic device includes: Classifying and storing the obtained operation data; Transmitting the classified and stored operation data to the second type of application; Controlling the second type of application to transmit the classified and stored operation data to the device server; The transmitting the classified and stored operation data to the second type of application includes: For each group of operation data, determining the risk level of the operation data; Determining a target second type of application to obtain the operation data from multiple second type of applications; the higher the risk level of the operation data, the lower the system privilege of the target second type of application; Transmitting the operation data to the target second type of application.
2. The method according to claim 1, characterized in that, The classifying and storing the obtained operation data includes: Marking specific identifiers for the operation data according to the type of the operation data; Storing the operation times and operation durations of each group of operation data respectively according to the mapping relationship between the operation data and the identifiers.
3. The method according to claim 1, wherein The transmitting the classified and stored operation data to the second type of application further includes: In response to detecting a risk in the target second type of application, transmitting the operation data and the risk information of the target second type of application to other second type of applications; the multiple second type of applications include the target second type of application and the other second type of applications.
4. The method according to claim 1, characterized in that, The obtaining the operation data of the first type of application includes at least one of the following: Obtaining interface call information of the first type of application; Obtaining system privilege information of the first type of application; Obtaining running information of the first type of application.
5. A data detection method, characterized in that, The method includes: Obtaining operation data transmitted by a second type of application in an electronic device; the operation data is data generated when a first type of application in the electronic device performs a target operation; the operation data is data obtained by the electronic device by executing the method according to any one of claims 1 to 4; Determining the reliability of the first type of application running on the electronic device based on the operation data.
6. The method according to claim 5, wherein The determining the reliability of the first type of application running on the electronic device based on the operation data includes at least one of the following: Determining a risk value of the operation data based on a preset model, the risk value being used to indicate whether the first type of application has a risk; Sending information of the first type of application and the operation data to a background server, the background server being used to determine whether the first type of application has a risk.
7. The method according to claim 6, characterized in that, The sending the information of the first type of application and the operation data to the background server includes: When it is determined based on a preset model that the risk value of the operation data reaches a preset value, the information of the first type of application and the operation data are sent to the background server; Among them, the risk value reaching the preset value includes at least one of the following: The risk value when the first type of application runs on a single electronic device is greater than or equal to the first value; The average value of the risk values when the first type of application runs on multiple electronic devices is greater than or equal to the second value.
8. A data detection device, characterized in that, The device includes: An acquisition module, configured to acquire operation data of a first type of application in an electronic device; A forwarding module, configured to forward the operation data to a device server through a second type of application in the electronic device, so that the device server determines the reliability of the first type of application based on the operation data; wherein, the first type of application is not connected to the device server; When the forwarding module is used to forward the operation data to the device server through the second type of application in the electronic device, it is used for: Classify and store the acquired operation data; Transmit the classified and stored operation data to the second type of application; Control the second type of application to transmit the classified and stored operation data to the device server; When the forwarding module is used to transmit the classified and stored operation data to the second type of application, it is used for: For each group of operation data, determine the risk level of the operation data; Determine a target second type of application to obtain the operation data from multiple second types of applications; the higher the risk level of the operation data, the lower the system privilege of the target second type of application; Transmit the operation data to the target second type of application.
9. A data detection device, characterized in that, The device includes: A response module, configured to acquire operation data transmitted by a second type of application in an electronic device; the operation data is data generated when a first type of application in the electronic device executes a target operation; the operation data is data acquired by the electronic device by executing the method according to any one of claims 1 to 4; A risk determination module, configured to determine the reliability of the first type of application running on the electronic device based on the operation data.
10. An electronic device, characterized in that, Includes: A processor; A memory for storing instructions executable by the processor; Among them, the processor is configured to implement the steps of the method according to any one of claims 1 to 7 by running the executable instructions.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
ID verification method and system for third-party App
CN104052754A