A network security pre-detection analysis method and system based on big data
By analyzing device registration information, building user portraits and dynamically generating security detection solutions, analyzing functional codes to identify network threats, solving the problem that traditional detection methods are difficult to identify new attacks, and achieving high-precision and intelligent network security detection.
Patent Information
- Application Number
- CN202411591144.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-08
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2044-11-08
AI Technical Summary
Traditional network security detection methods are difficult to identify new or variant network attacks, resulting in low detection accuracy and the inability to intelligently judge the real situation of the device user for effective security protection.
By obtaining and analyzing device registration information, building a user portrait, and dynamically generate a security detection scheme based on the user portrait, parsing each functional code to determine whether there is a cyber threat to be downloaded, and restricting download verification to prevent the spread of malware.
It improves detection accuracy, reduces false alarms and missed reports, can identify new, complex or variant malicious behaviors, and achieves higher intelligence and real-time response capabilities.
Smart Images

Figure CN119276609B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a network security pre-detection analysis method and system based on big data. Background Art
[0002] With the development of information technology and the popularization of the Internet, network security issues have become increasingly prominent. Especially with the advent of the big data era, the rapid increase in data volume and the complexity and variability of the network environment have made network security face greater challenges. Traditional network security detection methods are mostly based on feature matching or simple behavior analysis, which is difficult to cope with the diversity and complexity of modern network attacks.
[0003] With the widespread use of smart devices, traditional network security detection methods usually rely on predefined feature libraries to detect threats by matching known malicious features. The inability to identify new or variant network attacks in a timely manner leads to low detection accuracy, which has become a problem that needs to be solved urgently. Summary of the invention
[0004] The present application provides a network security pre-detection analysis method and system based on big data to solve the above-mentioned problems.
[0005] In a first aspect, the present application provides a network security pre-detection analysis method based on big data, the method comprising:
[0006] Obtaining device registration information; analyzing the device registration information, and determining a user profile of the device user based on the information analysis results;
[0007] Determine a security detection plan based on the user portrait;
[0008] According to the security detection scheme, the program source code is parsed to obtain several function codes of the software to be downloaded;
[0009] Each function code is parsed to determine whether the software to be downloaded has a network threat, and when it is determined that a network threat exists, the download verification of the device user is restricted.
[0010] Through this solution, by obtaining and analyzing the device registration information, a user profile of the device user can be constructed. This profile not only includes the basic information of the user, but also covers data such as device usage behavior. With the help of personalized user profiles, security detection solutions are tailored according to the user's specific usage, avoiding the false positives and missed negatives caused by traditional general detection solutions. Compared with traditional feature matching methods, parsing each function code and performing security detection based on the user profile can provide a deeper understanding of the potential threats of the software. In-depth analysis ensures that the system can not only detect known network threats, but also discover new, complex or variant malicious behaviors. It greatly improves the detection accuracy and reduces the possibility of false positives. Dynamically generate security detection solutions based on user profiles and device behaviors instead of relying on static rules. In order to solve the problem of being unable to intelligently judge the actual situation of the device user for effective security protection, the detection solution will also be adaptively adjusted as the user behavior and device status change, showing a higher level of intelligence. By quickly parsing each function code, the system can respond in time when potential threats are discovered, restrict download verification, and prevent the further spread of malware.
[0011] Optionally, parsing each function code to determine whether the software to be downloaded has a network threat includes:
[0012] According to the function code analysis results, determine the associated code of each function code;
[0013] Performing control parsing on the association code to determine the linkage triggering result between each function code and the corresponding association code;
[0014] Determine whether there is malicious conversion behavior according to the linkage trigger result;
[0015] If it is determined that there is malicious conversion behavior, it is determined that the software to be downloaded has a network threat.
[0016] Through this solution, by combining static and dynamic analysis, we can have a more comprehensive understanding of the behavior of function codes and their associated codes. Multi-dimensional analysis can capture new or variant attacks that traditional feature matching methods cannot identify, significantly improving detection accuracy. Monitoring the runtime behavior of function codes can timely detect potential threats such as abnormal network requests and sensitive resource access, making detection more real-time and accurate. Once an abnormal linkage between function codes and associated codes is found, early warnings or security measures can be quickly triggered, such as blocking software downloads, restricting access rights, etc., thereby reducing potential risks. Through behavioral pattern analysis combined with machine learning, malicious conversion behaviors can be quickly identified, and threats can be responded to in a timely manner to reduce losses. After confirming the existence of malicious conversion behaviors, the nature of the threat is comprehensively evaluated. Compared with traditional methods, the detection method based on behavioral analysis can reduce false alarms, reduce user troubles in the security protection process, and improve user trust. Once a potential threat is detected, it can promptly warn users and provide detailed security guidance to help users understand the risks and make correct responses.
[0017] Optionally, analyzing the device registration information and determining a user profile of the device user according to the information analysis result includes:
[0018] Analyze the device registration information to determine the age group and registration area of the device registrant;
[0019] Obtain the usage behavior of the device user and the IP location corresponding to each usage behavior;
[0020] Matching the registered region with the IP location corresponding to each usage behavior to determine the actual usage location;
[0021] Analyze the usage behavior, and determine whether the usage behavior matches the age group based on the behavior analysis result;
[0022] If there is a match, the user profile of the device user is determined based on the actual usage location and the age group.
[0023] Through this solution, by analyzing the device registration information (, a basic user profile can be constructed; this user profile not only includes the user's basic information, but also combines the device usage behavior to form a detailed user feature model. By obtaining the usage behavior of the device user and the corresponding IP location, common behavior patterns can be identified; this analysis helps to understand the user's normal usage habits, thereby providing a basis for subsequent security detection. When analyzing user behavior, the registration area is matched with the IP location of the usage behavior to determine the actual usage location. If it is found that the user behavior does not match the registration information (such as the user using the device in a different location), it may indicate a security risk. Based on the user profile, a reasonable behavior baseline can be set. When the user's behavior exceeds these baselines, an alarm can be issued immediately, thereby identifying potential network threats in a timely manner. Based on the user profile and usage behavior, the security policy can be dynamically adjusted. By continuously monitoring user behavior, the security policy can be adjusted in a timely manner to improve the overall security protection capability. By timely identifying abnormal activities (such as user behavior does not match the profile), the account can be effectively prevented from being stolen, and potential information abuse can be discovered and prevented at an early stage, thereby protecting the user's security.
[0024] Optionally, performing control parsing on the associated code to determine a linkage trigger result between each function code and a corresponding associated code includes:
[0025] Obtain and analyze device information, and determine the device model based on the device information analysis results;
[0026] Determine the anti-intrusion function of the device according to the device model;
[0027] Based on the anti-intrusion function of the device, the associated code is parsed to determine a triggerable operation;
[0028] According to the triggerable operation, a linkage trigger result between each function code and a corresponding association code is determined.
[0029] Through this solution, by deeply analyzing the functional code and its associated code of the software to be analyzed, it is possible to identify the complex relationship between the codes and understand their runtime behavior. It goes beyond the traditional feature matching method and can identify new or variant attacks; monitoring the triggering of associated codes when the functional code is executed can capture potential security threats in a timely manner.
[0030] Optionally, determining whether there is malicious conversion behavior based on the linkage trigger result includes: obtaining software update records of the software to be downloaded; analyzing the software update records to determine the update content of each update; analyzing the update content of each update to determine the update difference between the two closest updates; determining whether there is malicious conversion behavior based on the linkage trigger result and the update difference.
[0031] Through this solution, by obtaining update records from the official website, application store or update server of the software, it is possible to ensure that the latest and most complete information is obtained. The comprehensiveness of the data lays a solid foundation for subsequent analysis. Comparing the contents of the two latest updates one by one can reveal the specific new, modified or deleted parts. Therefore, testers can more clearly identify which changes may bring security risks. New features and functions may cause security risks if they allow access to user sensitive data. By analyzing these features, potential security vulnerabilities can be discovered in a timely manner. Monitoring the execution results between software function codes and associated codes, and collecting linkage trigger data, can quickly identify behaviors that do not meet normal expectations.
[0032] Optionally, parsing each function code to determine whether the software to be downloaded has a network threat includes:
[0033] Obtaining and analyzing the user experience evaluation of the software to be downloaded, and determining whether the software to be downloaded is suspected of being inconsistent with the update content according to the evaluation analysis result;
[0034] If it exists, construct a reproduction model based on the program source code to reproduce the use of the software to be downloaded;
[0035] According to the functional code analysis result, adjusting the reproduction model to obtain a test model to achieve complete functional reproduction;
[0036] Running the test model, and determining the authenticity of the suspicion according to the running result;
[0037] Determine whether a network threat exists based on the authenticity of the suspicion.
[0038] Through this solution, through in-depth analysis of user reviews, the real performance of the software can be shown to users, helping them better understand the potential risks of the software. By analyzing user feedback and comparing it with update records, potential security risks can be quickly identified, such as data leakage or functional abnormalities. By continuously monitoring the operation status of the software and user feedback, new or variant network attack methods can be more effectively identified, thereby improving the sensitivity and accuracy of detection. Combined with the user's usage scenarios and device characteristics, the security detection strategy is optimized to improve the adaptability to potential threats. By combining user feedback, source code analysis and running model testing, a multi-level security detection framework is constructed, which can more comprehensively evaluate the security of the software.
[0039] Optionally, before analyzing the user experience evaluation of the software to be downloaded, the method further includes:
[0040] Analyze the usage experience evaluation and determine the identity of the evaluator;
[0041] Determining the evaluation record based on the identity of the evaluator;
[0042] Analyze the evaluation records to determine the evaluator's usage result score;
[0043] Determining whether the usage experience evaluation has the possibility of malicious evaluation according to the usage result score;
[0044] The analyzing the user experience evaluation of the software to be downloaded includes:
[0045] If there is no possibility of malicious evaluation in the usage experience evaluation, the usage experience evaluation of the software to be downloaded is analyzed.
[0046] Through this solution, by analyzing user reviews, the true performance of the software can be revealed, helping users better understand the potential risks of the software; by analyzing user ratings and comments, possible malicious behavior can be quickly identified. For example, a user rating that is significantly lower than the average level may mean that the user intentionally makes a malicious review. By detecting the repetitiveness and similarity of the review content, malicious reviews that are automatically generated or generated in batches by scripts can be found. Using sentiment analysis technology, users' attitudes and feedback on software functions can be identified. By continuously monitoring user feedback and behavior, signs of new network attacks can be identified in a timely manner, improving the ability to respond to potential threats. Combined with user usage scenarios and device characteristics, the software's security detection and protection strategies are optimized.
[0047] Optionally, before parsing each function code, the process further includes:
[0048] Obtaining the executable file of the software to be downloaded;
[0049] Based on a binary method, a hash value of the executable file is calculated using a hash algorithm;
[0050] Comparing the hash value of the executable file with a preset malware library to determine whether it is malware;
[0051] The parsing of each function code includes:
[0052] If it is not malware, each function code is parsed.
[0053] Through this solution, by comparing with the known malware hash value library, potential malware can be effectively identified, reducing the risk of users downloading and using malware. Identifying malware before users download software helps to build a stronger security protection system and promptly prevent the spread of potential security threats. Through the calculation of the hash algorithm, the uniqueness of the file can be verified quickly and efficiently. Compared with the traditional feature matching method, the hash value comparison speed is faster and the processing efficiency is higher. With the complexity and changeability of the network environment, regularly updating the malware library and comparing it with the newly released software can improve the ability to identify new or variant network attacks and enhance overall network security protection; by identifying the hash value of the software, the detection strategy can be dynamically adjusted according to historical detection data and newly discovered threats, and the ability to prevent new threats can be enhanced.
[0054] Optionally, after comparing the hash value of the executable file with a preset malware library, the method further includes:
[0055] If the hash value does not match any one of the preset malware libraries, decompile the executable software, and extract the internal logic and key functions of the executable file according to the decompilation result;
[0056] Analyzing the internal logic and the key function to determine the feature code of the executable file;
[0057] The feature code is compared with a preset feature library to determine whether the software to be downloaded is malicious software.
[0058] Through this solution, by decompiling and parsing the internal logic of executable files, deeper malicious behaviors can be identified, not limited to simple detection based on hash values. Identifying malware that has not been classified or is a new variant improves the ability to identify modern network attacks; by extracting signatures, malware features that do not rely on fixed hash values can be identified, which is especially important for dealing with new or variant network attacks that use multiple technologies to avoid detection. Compared with static hash value matching, dynamic parsing of executable file signatures can significantly reduce false positives and false negatives. By matching functional behaviors instead of relying solely on hash values, it is possible to more accurately determine whether the software has malicious characteristics; analyzing the logic of key functions can reveal the actual behavior of the software, helping security experts better understand the intent of the software. By extracting and analyzing signatures, the signature library can be dynamically updated and expanded to adapt to emerging malware. Flexibility is very important for rapidly changing network environments and can respond to new security threats in real time.
[0059] In a second aspect, the present application provides a network security pre-detection and analysis system based on big data, comprising:
[0060] A portrait analysis module is used to obtain device registration information; analyze the device registration information, and determine a user portrait of the device user based on the information analysis result;
[0061] A solution determination module, used to determine a security detection solution based on the user portrait;
[0062] A code analysis module, used to parse the program source code according to the security detection scheme to obtain several functional codes of the software to be downloaded;
[0063] The threat analysis module is used to parse each function code to determine whether the software to be downloaded has a network threat, and when it is determined that there is a network threat, restrict the download verification of the device user.
[0064] Optionally, when parsing each function code to determine whether the software to be downloaded has a network threat, the threat analysis module is used to: determine the associated code of each function code according to the function code parsing result; perform control parsing on the associated code to determine the linkage trigger result of each function code and the corresponding associated code; determine whether there is a malicious conversion behavior according to the linkage trigger result;
[0065] If it is determined that there is malicious conversion behavior, it is determined that the software to be downloaded has a network threat.
[0066] Optionally, when analyzing the device registration information and determining the user portrait of the device user based on the information analysis results, the portrait analysis module is used to: analyze the device registration information to determine the age group and registration region of the device registrant; obtain the usage behavior of the device user and the IP location corresponding to each usage behavior; match the registration region with the IP location corresponding to each usage behavior to determine the actual usage location; analyze the usage behavior and determine whether the usage behavior matches the age group based on the behavior analysis results; if matched, determine the user portrait of the device user based on the actual usage location and the age group.
[0067] Optionally, when the threat analysis module performs control parsing on the associated code to determine the linkage trigger result of each function code and the corresponding associated code, it is used to: obtain and analyze device information, and determine the device model based on the device information analysis result; determine the device anti-intrusion function based on the device model; based on the device anti-intrusion function, perform control parsing on the associated code to determine the triggerable operation; based on the triggerable operation, determine the linkage trigger result of each function code and the corresponding associated code.
[0068] Optionally, when the threat analysis module determines whether there is malicious conversion behavior based on the linkage trigger result, it is used to: obtain the software update record of the software to be downloaded; analyze the software update record to determine the update content of each update; analyze the update content of each update to determine the update difference between the two closest updates; determine whether there is malicious conversion behavior based on the linkage trigger result and the update difference.
[0069] Optionally, when the threat analysis module parses each function code to determine whether the software to be downloaded poses a network threat, it is used to: obtain and analyze a user experience evaluation of the software to be downloaded, and determine, based on the evaluation analysis results, whether the software to be downloaded is suspected of being inconsistent with the update content; if so, construct a reproduction model based on the program source code to reproduce the use of the software to be downloaded; based on the function code parsing results, adjust the reproduction model to obtain a test model to achieve complete functional reproduction; run the test model, and determine the authenticity of the suspicion based on the running results; and determine whether a network threat exists based on the authenticity of the suspicion.
[0070] Optionally, the network security pre-detection and analysis system also includes an evaluation analysis module, which is used to: parse the usage experience evaluation to determine the identity of the evaluator; determine the evaluation record based on the identity of the evaluator; analyze the evaluation record to determine the evaluator's usage result score; determine whether the usage experience evaluation has the possibility of malicious evaluation based on the usage result score; the analysis of the usage experience evaluation of the software to be downloaded includes: if the usage experience evaluation does not have the possibility of malicious evaluation, then analyzing the usage experience evaluation of the software to be downloaded.
[0071] Optionally, the network security pre-detection and analysis system also includes a software comparison module, which is used to: obtain the executable file of the software to be downloaded; calculate the hash value of the executable file using a hash algorithm based on a binary method; compare the hash value of the executable file with a preset malware library to determine whether it is malware; and analyze each function code, including: if it is not malware, analyzing each function code.
[0072] Optionally, the network security pre-detection and analysis system also includes a feature comparison module, which is used to: if the hash value does not match any one in the preset malware library, decompile the executable software, and extract the internal logic and key functions of the executable file based on the decompilation result; parse the internal logic and the key functions to determine the feature code of the executable file; compare the feature code with the preset feature library to determine whether the software to be downloaded is malware. BRIEF DESCRIPTION OF THE DRAWINGS
[0073] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0074] Figure 1 A schematic diagram of an application scenario provided for an embodiment of the present application;
[0075] Figure 2 A flowchart of a network security pre-detection and analysis method based on big data provided in one embodiment of the present application;
[0076] Figure 3 A schematic diagram of the structure of a network security pre-detection and analysis system based on big data is provided for one embodiment of the present application. DETAILED DESCRIPTION
[0077] In order to make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0078] In addition, the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article, unless otherwise specified, generally means that the associated objects before and after are in an "or" relationship.
[0079] The embodiments of the present application are further described in detail below in conjunction with the drawings in the specification.
[0080] With the widespread use of smart devices, traditional network security detection methods usually rely on predefined feature libraries to detect threats by matching known malicious features. The inability to identify new or variant network attacks in a timely manner leads to low detection accuracy, which has become a problem that needs to be solved urgently.
[0081] Based on this, the present application provides a network security pre-detection analysis method and system based on big data, which obtains device registration information; analyzes device registration information, and determines the user portrait of the device user according to the information analysis results; determines the security detection scheme according to the user portrait; according to the security detection scheme, parses the program source code to obtain several function codes of the software to be downloaded; parses each function code to determine whether the software to be downloaded has a network threat, and when it is determined that there is a network threat, restricts the download verification of the device user. By obtaining and analyzing the device registration information, a user portrait of the device user can be constructed. This portrait not only contains the basic information of the user, but also covers data such as device usage behavior. With the help of personalized user portraits, security detection schemes are tailored according to the specific usage of the user, avoiding the false positives and false negatives caused by traditional general detection schemes. Compared with traditional feature matching methods, parsing each function code and performing security detection according to the user portrait can provide a deeper understanding of the potential threats of the software. In-depth analysis ensures that the system can not only detect known network threats, but also discover new, complex or variant malicious behaviors. The detection accuracy is greatly improved and the possibility of false positives is reduced. Dynamically generate security detection schemes based on user portraits and device behaviors instead of relying on static rules. In order to solve the problem of being unable to intelligently judge the actual situation of device users and provide effective security protection, the detection scheme will be adaptively adjusted as user behavior and device status change, showing a higher level of intelligence. By quickly parsing each function code, the system can respond in a timely manner when potential threats are discovered, restrict download verification, and prevent the further spread of malware. The real-time response mechanism avoids the risks brought by delayed detection, which is especially important when facing highly complex network attacks. Only when it is determined that there is a network threat will the download verification of the device user be restricted, reducing unnecessary security prompts and blocking operations, and ensuring the normal user experience. Compared with traditional security mechanisms that frequently prompt, this method is more accurate and efficient, allowing security and user experience to coexist in a balanced manner.
[0082] Figure 1A schematic diagram of an application scenario provided by the present application is provided. When a user downloads software, the method provided by the present application is applied. Specifically, the method provided by the present application is applied to any server, and the server interacts with the user device. By obtaining and analyzing the device registration information of the user device, a user profile of the device user can be constructed. This profile not only contains the basic information of the user, but also covers data such as device usage behavior. With the help of personalized user profiles, security detection schemes are tailored according to the specific usage of the user, avoiding the false positives and false negatives caused by traditional general detection schemes. Compared with traditional feature matching methods, parsing each function code and performing security detection according to the user profile can provide a deeper understanding of the potential threats of the software. In-depth analysis ensures that the system can not only detect known network threats, but also discover new, complex or variant malicious behaviors. The detection accuracy is greatly improved and the possibility of false positives is reduced. The security detection scheme is dynamically generated according to the user profile and device behavior, rather than relying on static rules. As the user behavior and device status change, the detection scheme will also be adaptively adjusted, showing a higher level of intelligence. By quickly parsing each function code, the system can respond in time when a potential threat is discovered, limit download verification, and prevent the further spread of malware.
[0083] For specific implementation methods, please refer to the following embodiments.
[0084] Figure 2 This is a flowchart of a network security pre-detection and analysis method based on big data provided by an embodiment of the present application. The method of this embodiment can be applied to the server in the above scenario. Figure 2 As shown, the method includes:
[0085] S201. Obtain device registration information; analyze the device registration information, and determine a user profile of the device user based on the information analysis results.
[0086] Device registration information can be information recorded by user devices (such as mobile phones, computers, etc.) through the registration process in a certain system or platform, such as the device's unique identifier (such as IMEI number, MAC address, etc.), device model, operating system version, geographic location and other information; as well as additional information such as the user's registration behavior, registration time, registration location, and the network used during registration.
[0087] User profiling can be a way of modeling user characteristics based on user behavior data, personal data, interest preferences and other information, including the user's geographic area, common device location, device usage frequency, common network environment operation habits (such as operation frequency), etc.
[0088] Specifically, traditional network security detection methods usually rely on predefined feature libraries to detect threats by matching known malicious features. The drawback of this traditional method is that it cannot identify new or variant network attacks in a timely manner, resulting in low detection accuracy; it cannot intelligently determine the actual situation of the device user for effective security protection. Through the information submitted by the user device during user registration, the device registration information is obtained with the permission of the law and the user, and all collected device registration information is stored in the database for subsequent analysis. Data analysis is performed based on the device registration information, the user's registration behavior is analyzed, and the user's operating habits are judged. The collection, storage and in-depth analysis of a large amount of user behavior data can identify the user's behavior characteristics, geographic location and other information; the user portrait is generated using an algorithm, and the user portrait information is combined with the device information to form a personalized usage model.
[0089] S202. Determine a security detection plan based on the user portrait.
[0090] A security detection solution can be a set of solutions designed to identify and prevent network security threats.
[0091] Specifically, according to the key information in the user portrait, a security detection template suitable for the user is matched. The security detection template is dynamically adjusted according to the user's risk level. For high-risk users, the detection plan will be more stringent, while low-risk users may adopt a lighter detection method. In the detection plan, the detection steps are clearly defined, including which data to check, which algorithms to use for analysis, and setting the detection frequency. Configure the relevant rules for security detection in the background to ensure that the corresponding detection mechanism is automatically triggered when downloading software.
[0092] S203: According to the security detection scheme, parse the program source code to obtain several function codes of the software to be downloaded.
[0093] Program source code can be software code written by developers, which refers to computer programs written in a programming language.
[0094] Function code can be part of the code in the program used to implement a specific function. Function code usually refers to the implementation code of a specific function.
[0095] The software to be downloaded may be software that has not been downloaded by the current user but has been listed for download on the platform.
[0096] Specifically, when a user is ready to download a piece of software, the source code or executable file of the software is first downloaded. Static code analysis tools are used to parse the source code or decompile the binary file to extract the code of each functional module of the software. According to the functional division, the code segment of each functional module is extracted to ensure that each function can be analyzed independently later. The extracted functional code is stored in a temporary cache for further threat analysis.
[0097] S204, parsing each function code to determine whether the software to be downloaded poses a network threat, and restricting the download verification of the device user when it is determined that a network threat exists.
[0098] A cyber threat can be any activity or behavior that could cause damage, compromise, or misuse of a network, system, or data.
[0099] Download verification can be a detection mechanism to ensure that the software files or content downloaded by users have not been tampered with and are safe.
[0100] Specifically, each function code is subjected to in-depth static analysis to check whether it contains potential malicious behaviors (such as unauthorized data access, hidden network requests, unauthorized permission calls, etc.). Code analysis tools are used to detect abnormal patterns in function codes, such as malicious code features, vulnerability exploitation code, suspicious network communication behaviors, etc. If the function code contains external network requests, the system will further check whether these network connections are secure and whether they are associated with known malicious IP addresses or domain names. For each function code, based on the previous analysis, a security report is generated to indicate whether the function module has potential threats. If a threat is determined to exist during the above code parsing process, the download process is immediately interrupted and the user is prohibited from continuing to download the software. A security warning pops up to remind the user that the software may have security risks and provide a detailed risk description (such as potential malicious behavior types, threat levels, etc.). The security incident is recorded and added to the user's behavior analysis library as part of subsequent behavior analysis to further adjust the user's risk level and detection plan. If no threat is detected, the user is allowed to continue downloading and installing the software.
[0101] Through this solution, in order to detect and effectively identify malicious behaviors in applications, including the download of junk software, background traffic consumption, automatic downloads and background advertising. By obtaining and analyzing device registration information, a user profile of the device user can be constructed. The construction of user profiles based on big data can significantly improve the ability to identify abnormal behaviors in network security pre-detection; this profile not only contains basic information about the user, but also covers data such as device usage behavior. With the help of personalized user profiles, security detection schemes are tailored according to the user's specific usage, avoiding the false positives and false negatives caused by traditional general detection schemes. Compared with traditional feature matching methods, parsing each function code and performing security detection based on user profiles can provide a deeper understanding of the potential threats of the software. In-depth analysis ensures that the system can not only detect known network threats, but also discover new, complex or variant malicious behaviors. The detection accuracy is greatly improved and the possibility of false positives is reduced. The security detection scheme is dynamically generated based on user profiles and device behaviors, rather than relying on static rules. In order to solve the problem of being unable to intelligently judge the actual situation of the device user for effective security protection, the detection scheme will also be adaptively adjusted as the user behavior and device status change, showing a higher level of intelligence. By quickly parsing each function code, the system can respond promptly when potential threats are discovered, limit download verification, and prevent further spread of malware.
[0102] In some embodiments, based on the function code parsing results, the associated code of each function code is determined; the associated code is parsed for controls to determine the linkage triggering result of each function code and the corresponding associated code; based on the linkage triggering result, it is determined whether there is malicious conversion behavior; if it is determined that there is malicious conversion behavior, it is determined that the software to be downloaded has a network threat.
[0103] The associated code may be other code modules that are executed in conjunction with the functional code, such as library functions, system calls, or calls to other code segments.
[0104] Control parsing can be an operation to identify how function codes interact with the user interface and external resources (such as files and networks). Controls can include buttons, input boxes, file operation interfaces, and other user interaction and system function operation interfaces.
[0105] The linkage trigger results can include function calls, external requests, file operations, etc.
[0106] Malicious conversion behavior can manifest as unauthorized access, data leakage, privilege escalation and other abnormal operations.
[0107] Specifically, parse each function code, find out the associated code it depends on, use static code analysis technology to perform structured analysis on the controls in the function code and associated code, and confirm the code logic and calling relationship. By dynamically analyzing the trigger mechanism of the linkage between controls and codes, determine the linkage triggering results between the function code and its associated code, and observe the behavior of the function code at runtime to obtain the actual calling situation; once the execution of the associated code is triggered, monitor the interaction between these codes and external systems or resources, especially pay attention to network requests, file modifications, privilege escalation and other operations that may bring security risks, and judge whether these linkage behaviors meet normal expectations through behavioral pattern analysis. For example, after a function code is executed, whether an unexpected network request is initiated or sensitive resources are accessed to judge the normality of the behavior, and combined with the linkage trigger results, use machine learning algorithms or predefined malicious behavior pattern libraries to determine whether there is malicious conversion behavior. After confirming that the behavior of the function code and its associated code is abnormal or there is malicious conversion behavior, it is inferred that the software to be downloaded may have a network threat. At this time, it is necessary to comprehensively consider the execution environment of the associated code, the trigger conditions and the interaction of external resources to confirm the nature of the threat; according to the type of network threat (such as malware, data theft, Trojan horse program, etc.), different response measures are taken, such as blocking downloads, warning users or further analyzing the potential harm of the threat.
[0108] Through this solution, by using big data to analyze user behavior habits, we can establish a common APP usage model for the elderly (such as click frequency, commonly used applications, etc.) and identify associated jumps that are inconsistent with normal behavior. Through abnormal behavior detection algorithms (such as abnormal click frequency and the number of active background processes), we can identify potential threats of junk software and misleading advertisements. We can implement ad click behavior analysis and identify high-risk advertisements by analyzing ad click-through rate, jump path and ad style (such as theater ads, twist ads, etc.). By combining static and dynamic analysis, we can have a more comprehensive understanding of the behavior of function codes and their associated codes. Multi-dimensional analysis can capture new or variant attacks that traditional feature matching methods cannot identify, significantly improving detection accuracy. By analyzing the function code of the software, we can combine big data methods to detect network threats. For example, the control analysis of the associated code and the determination of the linkage trigger result require the extraction of features from a large amount of code behavior and analysis. Monitoring the runtime behavior of the function code can timely discover potential threats such as abnormal network requests and sensitive resource access, making detection more real-time and accurate. Once an abnormal linkage between a function code and an associated code is found, early warnings or security measures can be quickly triggered, such as blocking software downloads and restricting access rights, thereby reducing potential risks. Through behavioral pattern analysis combined with machine learning, malicious conversion behaviors can be quickly identified, and threats can be responded to in a timely manner to reduce losses. After confirming the existence of malicious conversion behaviors, a comprehensive assessment of the nature of the threat is conducted, such as identifying whether it is malware, data theft, or other types of network threats, to ensure that targeted countermeasures are taken; through real-time analysis and feedback, its detection and response strategies can be continuously optimized to form an adaptive security protection mechanism and enhance the ability to resist complex network attacks. Compared with traditional methods, detection methods based on behavioral analysis can reduce false alarms, reduce user troubles in the security protection process, and improve user trust. Once a potential threat is detected, it can issue a warning to the user in a timely manner and provide detailed security guidance to help users understand the risks and make the right response.
[0109] In some embodiments, the device registration information is analyzed to determine the age group and registration region of the device registrant; the usage behavior of the device user and the IP location corresponding to each usage behavior are obtained; the registration region is matched with the IP location corresponding to each usage behavior to determine the actual usage location; the usage behavior is analyzed, and based on the behavior analysis results, it is determined whether the usage behavior matches the age group; if it matches, the user profile of the device user is determined based on the actual usage location and age group.
[0110] The registration region can be the geographic location data provided by the user when registering a device or account, and can be automatically obtained through location services.
[0111] Usage behavior can be all activities of users when using devices or applications, including user operation habits, applications visited, operation frequency, web pages visited, etc.
[0112] The actual usage location may be the actual geographical location of the user when using the device.
[0113] The results of behavioral analysis can be conclusions drawn from analyzing the user's usage behavior, which generally involve whether the user behavior is normal, whether there are abnormal patterns, whether it meets the preset safety standards, etc.
[0114] Specifically, relevant fields are extracted from the device registration information, including the registrant's age, gender, region, and other information. Based on the extracted age information, the device registrants are divided into different age groups. The device usage behavior is monitored and recorded, including login time, application usage frequency, visited URLs, downloaded files, etc. Each time the usage behavior is recorded, the IP address at the time of use is obtained, and its location is determined through the IP geolocation service. The device registration area is compared with the IP location of each usage behavior to determine the actual usage location, such as when an elderly person is recommended by a stranger to download an unknown application when he is out. If there is a significant difference between the registration area and the location of the usage behavior, it is necessary to pay attention to potential security risks, analyze the usage behavior, and identify the user's common operation mode, such as commonly used applications, active time periods, access content types, etc. Based on the analysis results, it is determined whether the usage behavior matches the registrant's age group, for example, whether the usage frequency of certain applications or websites in a specific age group meets expectations. Based on the actual usage location, age group, and usage behavior, a user profile of the device user is constructed. Based on the user profile, possible security risks are identified. For example, if the age group does not match the usage behavior, such as older users frequently accessing youth-related content, there may be a risk of account theft. Combining device usage behavior with portraits to detect whether there are abnormal activities, such as frequent geographic location changes, unusual access patterns, etc., further assess security threats.
[0115] Through this solution, by analyzing the device registration information (, a basic user portrait can be constructed; this user portrait not only includes the user's basic information, but also combines the device usage behavior to form a detailed user feature model. By obtaining the usage behavior of the device user and the corresponding IP location, common behavior patterns can be identified; this analysis helps to understand the user's normal usage habits, thereby providing a basis for subsequent security testing. When analyzing user behavior, the registration area is matched with the IP location of the usage behavior to determine the actual usage location. If it is found that the user behavior does not match the registration information (such as the user using the device in a different location), it may indicate a security risk. Based on the user portrait, a reasonable behavior baseline can be set. When the user's behavior exceeds these When a baseline is reached, an alarm can be issued immediately, thereby identifying potential network threats in a timely manner. Security policies can be adjusted dynamically based on user profiles and usage behaviors. For example, for high-risk users, the frequency of security checks can be increased and more stringent detection measures can be used; while for low-risk users, the detection pressure can be appropriately reduced. In the current environment where network attacks are becoming increasingly complex, dynamic risk assessment based on user profiles can effectively respond to new or variant network attacks. By continuously monitoring user behavior, security policies can be adjusted in a timely manner to improve overall security protection capabilities. By promptly identifying abnormal activities (such as user behavior that does not match the profile), accounts can be effectively prevented from being stolen, and potential information abuse can be discovered and prevented at an early stage, thereby protecting user security.
[0116] In some embodiments, device information is acquired and analyzed, and the device model is determined based on the device information analysis results; the device anti-intrusion function is determined based on the device model; based on the device anti-intrusion function, the associated code is parsed to determine the triggerable operation; based on the triggerable operation, the linkage trigger result of each function code and the corresponding associated code is determined.
[0117] Device information can be various data and parameters about a specific device, including detailed information on hardware and software, including device model, operating system version, MAC address, IMEI number, etc.
[0118] A device model number can be a specific product model number assigned by the manufacturer, usually used to distinguish different types or versions of a device.
[0119] Intrusion prevention can be a security feature built into a device to detect, prevent and respond to potential cyber attacks and malicious behavior.
[0120] Triggerable actions are behaviors that users can take when interacting with a device or application that can trigger a specific action or event.
[0121] Specifically, hardware and software information is obtained from the device, and the model and other relevant parameters of the device are determined by parsing the device information. The device model is extracted based on the obtained device information. Based on the device model, the anti-intrusion function corresponding to the model is queried in the database to confirm whether the device has enabled these anti-intrusion functions and record their specific configurations; the software source code to be analyzed is parsed to find out the associated code on which each function code depends; the identified associated code is subjected to control parsing to check how these codes interact with the user interface and external resources (such as files, networks); the control type (such as buttons, input boxes, file operation interfaces, etc.) and its corresponding operations are identified; based on the results of control parsing, the triggerable operations associated with the function code and the associated code are determined; by analyzing the relationship between the function code and the associated code, it is determined whether the associated code is triggered when the function code is executed, and the specific triggering conditions are monitored and recorded, including external requests, file operations, function calls, etc.; the behavioral characteristics generated after the triggering are collected and analyzed, such as whether a network request is initiated, whether sensitive data is accessed, etc. Determine whether these behaviors are in line with normal expectations or whether there are anomalies (such as triggering unnecessary file modifications or network access). Abnormal behavior detection algorithms (such as abnormal click frequency and number of active background processes) can also be used to identify potential threats such as junk software and misleading advertisements.
[0122] When some malware is downloaded, these software will execute some functions in the background that are not initiated by user operations, such as background mining, multiple processes occupying the process and unable to be closed, background advertising, etc. The control can be parsed to determine the triggerable operations, thereby determining whether the function is caused by user operations.
[0123] Through this solution, by deeply analyzing the function code and its associated code of the software to be analyzed, it is possible to identify the complex relationship between the codes and understand their runtime behavior, which goes beyond the traditional feature matching method and can identify new or variant attacks; monitoring the triggering of the associated code when the function code is executed can timely capture potential security threats, such as unauthorized data access or abnormal network requests; through real-time monitoring and analysis, when behaviors that do not meet normal expectations are found, measures can be taken quickly to prevent the execution of suspicious operations and reduce potential security risks. Combining anti-intrusion functions with code behavior analysis, a multi-level security protection wall can be built to improve the overall security protection capabilities. By analyzing the behavioral characteristics generated after the trigger, operations that do not meet the normal user habits can be identified. For example, abnormal file modifications, frequent network requests, etc., these may be signs of malicious activities; when abnormal behaviors are detected, related functions or processes can be quickly isolated to prevent the spread of malicious behaviors and protect user data and system security. By analyzing the interaction between controls and codes, the user's behavior model can be continuously updated to understand the user's actual use of the device, which helps to improve the effectiveness and personalization of security detection.
[0124] In some embodiments, software update records of the software to be downloaded are obtained; the software update records are analyzed to determine the update content of each update; the update content of each update is analyzed to determine the update difference between the two closest updates; and based on the linkage trigger result and the update difference, it is determined whether there is malicious conversion behavior.
[0125] Software update records may be detailed information about software version updates, typically including the version number, update date, and related update description of each update.
[0126] Update content may be the specific changes and improvements included in each software update, including the addition of new features, modification of existing features, bug fixes, and performance optimization.
[0127] Update differences may be the specific changes and differences between two software version updates.
[0128] Specifically, in some cases, some illegal software exploits the loopholes in the software platform's software audit when downloading. When the malware is downloaded, it does not ask the user for higher permissions, implants functions that steal user information or use user resources, but the content downloaded by the user is not updated in the background after the first installation, so as to implant the above functions to escape the audit of the software platform. Therefore, obtain the software update record from the official website, application store or update server of the software; extract key information from the update record of each version. From the sorted update records, select the two latest updates and extract their update content, compare the contents of these two updates one by one, and record the new, modified or deleted parts in the update; such as whether the newly added features and functions may bring security risks, monitor the execution results between the software function code and its associated code, collect relevant linkage trigger data, combine the linkage trigger results with the update differences, and analyze whether some new functions or modified contents are associated with abnormal behaviors. For example: the latest update introduces a new feature that allows access to user sensitive data, and then abnormal data transmission activities occur. Check whether the security patches in the update records are consistent with the potential vulnerabilities or abnormal behaviors found in the linkage trigger results. Based on the above analysis, determine whether there is malicious conversion behavior; such as unauthorized access, data leakage, and privilege escalation. If no update record is detected in the software platform, but updates and user privilege requests are still detected in the user terminal, the above-mentioned monitoring software function code and its associated code execution results process can still be entered.
[0129] Through this solution, by obtaining update records from the official website, application store or update server of the software, it is possible to ensure that the latest and most complete information is obtained. The comprehensiveness of this data lays a solid foundation for subsequent analysis. Comparing the latest two updates one by one can reveal the specific new, modified or deleted parts. Therefore, the tester can more clearly identify which changes may bring security risks. If the newly added features and functions allow access to user sensitive data, it may cause security risks. By analyzing these features, potential security vulnerabilities can be discovered in a timely manner. Monitoring the execution results between the software function code and the associated code and collecting linkage trigger data can quickly identify behaviors that do not meet normal expectations. For example, if the new function causes abnormal data transfer activities, it may indicate that the function has security risks. By integrating the changes in the update records with the linkage trigger results, malicious conversion behaviors such as unauthorized access, data leakage or privilege escalation can be quickly identified. This rapid response capability helps reduce potential losses. If suspicious behavior is detected, the corresponding security measures can be triggered immediately, such as limiting the software's functions or notifying the user to conduct a security check, improving the overall security protection capabilities.
[0130] In some embodiments, the user experience evaluation of the software to be downloaded is obtained and analyzed, and based on the evaluation and analysis results, it is determined whether the software to be downloaded is suspected of being inconsistent with the updated content; if so, a reproduction model is constructed based on the program source code to reproduce the use of the software to be downloaded; based on the function code analysis results, the reproduction model is adjusted to obtain a test model to achieve full functional reproduction; the test model is run, and the authenticity of the suspicion is determined based on the running results; based on the authenticity of the suspicion, it is determined whether there is a network threat.
[0131] The user experience evaluation can be the user's feelings and feedback on the software during use. The reproduction model can be a model built based on the functional modules and code logic when analyzing the software to be downloaded. The test model can be a model that is adjusted and optimized on the basis of the reproduction model, and then systematically tested to verify whether the software functions normally and whether the performance meets expectations, and to check whether there are any problems reported by users.
[0132] The authenticity of the suspicion can be determined by analyzing and reproducing the problem mentioned in the user feedback to determine whether it actually exists.
[0133] Specifically, by obtaining and analyzing the user's evaluation of the software experience, combined with the user evaluation records, determine whether there is a network threat. This requires processing a large amount of user evaluation data, involving big data technologies such as text analysis and sentiment analysis, to determine whether there are malicious or abnormal evaluations, and to analyze the suspicious behavior of the software. Obtain user experience evaluations of downloaded software from platforms such as app stores, official websites, and social media, such as user feedback, ratings, and comments. Classify the collected evaluations and filter out negative evaluations that are inconsistent with the updated content. For example, users may mention that a new feature cannot be used normally or there are security issues. Through natural language processing (NLP) technology, sentiment analysis is performed on user evaluations to identify users' positive and negative feedback on the software. Focus on the content of negative feedback, especially those related to the updated content; if users generally reflect that there are problems with a new feature, or mention frequent data leaks, there may be suspicion that it is inconsistent with the updated content. Compare user feedback with the software update record to confirm whether the problems mentioned by the user are related to the most recent update content; if user feedback shows that the software behavior is inconsistent with the functions described in the update record (for example, the new function is not implemented or a new problem is introduced), record the suspicion. If legal, obtain the source code of the software to be downloaded and ensure that there are sufficient permissions for analysis and reproduction. According to the functional modules of the software, build a reproduction model to ensure that the model includes all major functions and logic; run the adjusted test model in the test environment, simulate the user's operation process, monitor and record the results of the test model operation, including whether the function is normal, error messages, system response time and any abnormal behavior, collect logs and events generated during the test, pay special attention to behaviors related to network requests, file access, and user data processing, compare the test model operation results with user feedback, and check whether the problems or anomalies described by the user can be reproduced. Common behaviors, such as some malware that triggers certain functions only for special models or special groups of people. For example, ads often pop up when the elders at home use this software and cannot be closed normally, or the phone becomes stuck after opening the software. Therefore, it is necessary to set the user identity or use the corresponding model during the reproduction process. If the test model reproduces the negative experience or security issues mentioned by the user, it indicates that the suspicion is highly authentic. If the test model interacts with an external server, it monitors the sending and receiving of data to determine whether there are abnormal network requests. Based on the running results of the test model, it is evaluated whether there are network threats, especially those involving user data leakage, unauthorized access or malicious behavior.
[0134] Through this solution, through in-depth analysis of user reviews, the real performance of the software can be shown to users, helping them better understand the potential risks of the software. By analyzing user feedback and comparing it with update records, potential security risks can be quickly identified, such as data leakage or functional abnormalities. By continuously monitoring the operation status of the software and user feedback, new or variant network attack methods can be more effectively identified, thereby improving the sensitivity and accuracy of detection. Combined with the user's usage scenarios and device characteristics, the security detection strategy is optimized to improve the adaptability to potential threats. By combining user feedback, source code analysis and running model testing, a multi-level security detection framework is constructed, which can more comprehensively evaluate the security of the software.
[0135] In some embodiments, the usage experience evaluation is parsed to determine the identity of the evaluator; based on the identity of the evaluator, the evaluation record is determined; the evaluation record is analyzed to determine the evaluator's usage result score; based on the usage result score, it is determined whether the usage experience evaluation is likely to be malicious; if the usage experience evaluation is not likely to be malicious, the usage experience evaluation of the software to be downloaded is analyzed.
[0136] The evaluator identity may be relevant information of the user who provides the software usage experience evaluation, including the user's unique identifier, user name, historical behavior, and possible user characteristics.
[0137] Evaluation records can be specific evaluation information left by users after using the software, including ratings, comment content, timestamps, etc.
[0138] Specifically, collect user experience evaluation data about the software to be downloaded from major application stores, social media, forums and other platforms. According to the user ID, query all evaluation records of the user on different platforms, including time, rating, evaluation content, etc., pay attention to the user's evaluation of the software to be downloaded and the evaluation of other related applications to understand his evaluation style and preferences, and count the ratings of the evaluator on different software, especially pay attention to his rating of the downloaded software, calculate the difference between the user's rating on the software to be downloaded and his historical rating, such as whether it is significantly lower than his average rating, and perform sentiment analysis on the evaluation content to identify his true emotional tendency towards the software. Natural language processing (NLP) tools can be used to analyze the positive and negative emotions of the comments. Determine whether the user's rating is significantly different from his historical rating. If the rating is significantly lower than the average level, there may be malicious behavior. Analyze the user's comment content to see if there are repeated, automatically generated comments, or comments that are highly similar to other users. Check whether the user frequently evaluates the same software or publishes multiple negative reviews in a short period of time. Combine the rating, sentiment analysis and content detection results to comprehensively determine whether the user's evaluation is a malicious evaluation. If no malicious reviews are found, continue to analyze all user reviews of the software to be downloaded, use sentiment analysis to classify all user reviews, find out common problems and user attitudes towards new features. Summarize the strengths and weaknesses of the software based on user feedback, especially focusing on specific questions raised by users.
[0139] Through this solution, by analyzing user reviews, the true performance of the software can be revealed, helping users better understand the potential risks of the software; by analyzing user ratings and comments, possible malicious behavior can be quickly identified. For example, a user rating that is significantly lower than the average level may mean that the user intentionally makes a malicious review. By detecting the repetitiveness and similarity of the review content, malicious reviews that are automatically generated or generated in batches by scripts can be found. Using sentiment analysis technology, users' attitudes and feedback on software functions can be identified. By continuously monitoring user feedback and behavior, signs of new network attacks can be identified in a timely manner, improving the ability to respond to potential threats. Combined with user usage scenarios and device characteristics, the software's security detection and protection strategies are optimized.
[0140] In some embodiments, an executable file of the software to be downloaded is obtained; a hash value of the executable file is calculated using a hash algorithm based on a binary method; the hash value of the executable file is compared with a preset malware library to determine whether it is malware; if it is not malware, each function code is parsed.
[0141] An executable file may be a file containing computer program codes that can be directly executed by an operating system to perform specific functions or tasks.
[0142] The preset malware library may be a preset database containing known malware hash values (such as MD5, SHA-256, etc.) for quickly identifying known malware to improve detection efficiency and accuracy.
[0143] Malware can be programs or code that damages, interferes with, steals, or otherwise harms computer users and computer operations.
[0144] Specifically, obtain the executable file of the software to be downloaded from a trusted app store or official website; select a suitable hash algorithm (such as SHA-256, MD5, etc.); use a programming language (such as Python, Java, etc.) or a command line tool (such as sha256sum, md5sum, etc.) to hash the executable file; preset a database containing known malware hash values; compare the calculated executable file hash value with the entries in the malware library; if a match is found, it is determined to be malware; if not found, it is determined to continue the subsequent steps to parse each function code;
[0145] Through this solution, by comparing with the known malware hash value library, potential malware can be effectively identified, reducing the risk of users downloading and using malware. Identifying malware before users download software helps to build a stronger security protection system and promptly prevent the spread of potential security threats. Through the calculation of the hash algorithm, the uniqueness of the file can be verified quickly and efficiently. Compared with the traditional feature matching method, the hash value comparison speed is faster and the processing efficiency is higher. With the complexity and changeability of the network environment, regularly updating the malware library and comparing it with the newly released software can improve the ability to identify new or variant network attacks and enhance overall network security protection; by identifying the hash value of the software, the detection strategy can be dynamically adjusted according to historical detection data and newly discovered threats, and the ability to prevent new threats can be enhanced.
[0146] In some embodiments, if the hash value does not match any of the preset malware libraries, the executable software is decompiled, and based on the decompilation results, the internal logic and key functions of the executable file are extracted; the internal logic and key functions are parsed to determine the feature code of the executable file; the feature code is compared with the preset feature library to determine whether the software to be downloaded is malware.
[0147] Critical functions can be functions in executable files that play an important role in the core logic or specific functions of the program, such as user input, data processing, network requests, file access and other sensitive operations.
[0148] Signatures can be patterns extracted from executable files to identify software characteristics or behaviors.
[0149] The preset feature library may be a database containing known malware feature codes that is preset for quickly identifying and detecting known malware.
[0150] Specifically, choose a suitable decompilation tool, such as Ghidra, IDA Pro, Radare2, dotPeek (for .NET applications), etc., depending on the type and platform of the application to be analyzed; load the executable file to be downloaded into the decompilation tool, and the tool will automatically analyze the file structure and code; manually check the decompiled code to identify key control flows, such as conditional judgments, loops, and function call relationships. Use the graphical interface functions of the tool, such as control flow graphs (CFG), to visualize the operation logic of the program; determine the key functions of the program based on the function name and call relationship, such as user input processing, data transmission, file access, etc.; pay attention to functions related to network requests, file operations, and permission requests, because these are usually potential behaviors of malware; analyze the implementation of each key function line by line to understand its logic and potential security risks. For example, the sendData() function may send user data to an unknown external server; study the parameter types and return values of the function, understand its input and output behaviors, so as to better identify possible malicious behaviors; extract feature codes based on internal logic and key functions. These signatures can be specific function calls, API usage, specific strings, keywords or data patterns; the extracted signatures are formatted into a form suitable for comparison so that they can be matched with the signature library; a database containing known malware signatures is preset; the extracted signatures are compared with the entries in the malicious signature library to determine whether there is a match; if a match is found, the software is determined to be malware; if there is no match, further analysis is continued.
[0151] Through this solution, by decompiling and parsing the internal logic of executable files, deeper malicious behaviors can be identified, not limited to simple detection based on hash values. Identifying malware that has not been classified or is a new variant improves the ability to identify modern network attacks; by extracting signatures, malware features that do not rely on fixed hash values can be identified, which is especially important for dealing with new or variant network attacks that use multiple technologies to avoid detection. Compared with static hash value matching, dynamic parsing of executable file signatures can significantly reduce false positives and false negatives. By matching functional behaviors instead of relying solely on hash values, it is possible to more accurately determine whether the software has malicious characteristics; analyzing the logic of key functions can reveal the actual behavior of the software, helping security experts better understand the intent of the software. By extracting and analyzing signatures, the signature library can be dynamically updated and expanded to adapt to emerging malware. Flexibility is very important for rapidly changing network environments and can respond to new security threats in real time.
[0152] Figure 3 A schematic diagram of a network security pre-detection and analysis system based on big data is provided in accordance with an embodiment of the present application. Figure 3 As shown, the big data-based network security pre-detection and analysis system 300 of this embodiment includes: a portrait analysis module 301, a solution determination module 302, a code analysis module 303, and a threat analysis module 304.
[0153] The portrait analysis module 301 is used to obtain device registration information; analyze the device registration information, and determine the user portrait of the device user based on the information analysis result;
[0154] A solution determination module 302 is used to determine a security detection solution based on the user portrait;
[0155] The code analysis module 303 is used to parse the program source code according to the security detection scheme to obtain several function codes of the software to be downloaded;
[0156] The threat analysis module 304 is used to parse each function code to determine whether the software to be downloaded has a network threat, and when it is determined that there is a network threat, restrict the download verification of the device user.
[0157] Optionally, when parsing each function code to determine whether the software to be downloaded poses a network threat, the threat analysis module 304 is used to: determine the associated code of each function code based on the function code parsing result; perform control parsing on the associated code to determine the linkage trigger result between each function code and the corresponding associated code; determine whether there is malicious conversion behavior based on the linkage trigger result; if it is determined that there is malicious conversion behavior, then it is determined that the software to be downloaded poses a network threat.
[0158] Optionally, when analyzing the device registration information and determining the user portrait of the device user based on the information analysis results, the portrait analysis module 301 is used to: analyze the device registration information to determine the age group and registration region of the device registrant; obtain the usage behavior of the device user and the IP location corresponding to each usage behavior; match the registration region with the IP location corresponding to each usage behavior to determine the actual usage location; analyze the usage behavior and determine whether the usage behavior matches the age group based on the behavior analysis results; if matched, determine the user portrait of the device user based on the actual usage location and the age group.
[0159] Optionally, when the threat analysis module 304 performs control parsing on the associated code to determine the linkage trigger result of each function code and the corresponding associated code, it is used to: obtain and analyze device information, and determine the device model based on the device information analysis result; determine the device anti-intrusion function based on the device model; based on the device anti-intrusion function, perform control parsing on the associated code to determine the triggerable operation; based on the triggerable operation, determine the linkage trigger result of each function code and the corresponding associated code.
[0160] Optionally, when the threat analysis module 304 determines whether there is malicious conversion behavior based on the linkage trigger result, it is used to: obtain the software update record of the software to be downloaded; analyze the software update record to determine the update content of each update; analyze the update content of each update to determine the update difference between the two closest updates; determine whether there is malicious conversion behavior based on the linkage trigger result and the update difference.
[0161] Optionally, when the threat analysis module 304 parses each function code to determine whether the software to be downloaded has a network threat, it is used to:
[0162] Obtain and analyze the user experience evaluation of the software to be downloaded, and determine whether the software to be downloaded is suspected of being inconsistent with the update content based on the evaluation and analysis results; if so, construct a reproduction model based on the program source code to reproduce the use of the software to be downloaded; based on the function code analysis results, adjust the reproduction model to obtain a test model to achieve complete function reproduction; run the test model, and determine the authenticity of the suspicion based on the running results; based on the authenticity of the suspicion, determine whether there is a network threat.
[0163] Optionally, the network security pre-detection analysis system 300 further includes an evaluation analysis module 305, which is used to:
[0164] Parse the usage experience evaluation to determine the identity of the evaluator; determine the evaluation record based on the identity of the evaluator; analyze the evaluation record to determine the evaluator's usage result score; determine whether the usage experience evaluation has the possibility of malicious evaluation based on the usage result score; the analyzing the usage experience evaluation of the software to be downloaded includes: if the usage experience evaluation has no possibility of malicious evaluation, then analyze the usage experience evaluation of the software to be downloaded.
[0165] Optionally, the network security pre-detection and analysis system 300 further includes a software comparison module 306, which is used to:
[0166] Obtain the executable file of the software to be downloaded; calculate the hash value of the executable file using a hash algorithm based on a binary method; compare the hash value of the executable file with a preset malware library to determine whether it is malware; and parse each function code, including: if it is not malware, parse each function code.
[0167] Optionally, the network security pre-detection and analysis system 300 further includes a feature comparison module 307, which is used to:
[0168] If the hash value does not match any one of the preset malware libraries, the executable software is decompiled, and based on the decompilation result, the internal logic and key functions of the executable file are extracted; the internal logic and the key functions are parsed to determine the feature code of the executable file; the feature code is compared with the preset feature library to determine whether the software to be downloaded is malware.
[0169] The system of this embodiment can be used to execute the method of any of the above embodiments. The implementation principles and technical effects are similar and will not be described in detail here.
Claims
1. A network security pre-detection and analysis method based on big data, characterized in that: include: Get device registration information; Analyze the device registration information, and determine a user profile of the device user based on the information analysis result; Determine a security detection plan based on the user portrait; According to the security detection scheme, the program source code is parsed to obtain several function codes of the software to be downloaded; Parsing each function code to determine whether the software to be downloaded has a network threat, and if it is determined that there is a network threat, restricting the download verification of the device user; The step of parsing each function code to determine whether the software to be downloaded has a network threat includes: According to the function code analysis results, determine the associated code of each function code; Performing control parsing on the association code to determine the linkage triggering result between each function code and the corresponding association code; Determine whether there is malicious conversion behavior according to the linkage trigger result; If it is determined that there is malicious conversion behavior, then it is determined that the software to be downloaded has a network threat; The performing control parsing on the associated code to determine the linkage trigger result between each function code and the corresponding associated code includes: Obtain and analyze device information, and determine the device model based on the device information analysis results; Determine the anti-intrusion function of the device according to the device model; Based on the anti-intrusion function of the device, the associated code is parsed to determine a triggerable operation; According to the triggerable operation, a linkage trigger result between each function code and a corresponding association code is determined.
2. The method according to claim 1, characterized in that The analyzing the device registration information and determining a user profile of the device user according to the information analysis result includes: Analyze the device registration information to determine the age group and registration area of the device registrant; Obtain the usage behavior of the device user and the IP location corresponding to each usage behavior; Matching the registered region with the IP location corresponding to each usage behavior to determine the actual usage location; Analyze the usage behavior, and determine whether the usage behavior matches the age group based on the behavior analysis result; If there is a match, the user profile of the device user is determined based on the actual usage location and the age group.
3. The method according to claim 1, characterized in that Determining whether there is malicious conversion behavior according to the linkage trigger result includes: Obtaining a software update record of the software to be downloaded; Analyze the software update records to determine the update content of each update; Analyze the updated content of each update and determine the update difference between the two most recent updates; It is determined whether there is malicious conversion behavior according to the linkage trigger result and the update difference.
4. The method according to claim 3, characterized in that: The step of parsing each function code to determine whether the software to be downloaded has a network threat includes: Obtaining and analyzing the user experience evaluation of the software to be downloaded, and determining whether the software to be downloaded is suspected of being inconsistent with the update content according to the evaluation analysis result; If it exists, construct a reproduction model based on the program source code to reproduce the use of the software to be downloaded; According to the functional code analysis result, adjusting the reproduction model to obtain a test model to achieve complete functional reproduction; Running the test model, and determining the authenticity of the suspicion according to the running result; Determine whether a network threat exists based on the authenticity of the suspicion.
5. The method according to claim 3, characterized in that: Before analyzing the user experience evaluation of the software to be downloaded, the method further includes: Analyze the usage experience evaluation and determine the identity of the evaluator; Determining the evaluation record based on the identity of the evaluator; Analyze the evaluation records to determine the evaluator's usage result score; Determining whether the usage experience evaluation has the possibility of malicious evaluation according to the usage result score; The analyzing the user experience evaluation of the software to be downloaded includes: If there is no possibility of malicious evaluation in the usage experience evaluation, the usage experience evaluation of the software to be downloaded is analyzed.
6. The method according to claim 1, characterized in that Before parsing each function code, the following steps are also included: Obtaining the executable file of the software to be downloaded; Based on a binary method, a hash value of the executable file is calculated using a hash algorithm; Comparing the hash value of the executable file with a preset malware library to determine whether it is malware; The parsing of each function code includes: If it is not malware, each function code is parsed.
7. The method according to claim 6, characterized in that After comparing the hash value of the executable file with the preset malware library, the method further includes: If the hash value does not match any one of the preset malware libraries, decompile the executable file, and extract the internal logic and key functions of the executable file according to the decompilation result; Analyzing the internal logic and the key function to determine the feature code of the executable file; The feature code is compared with a preset feature library to determine whether the software to be downloaded is malicious software.
8. A network security pre-detection and analysis system based on big data, characterized in that: The method as claimed in any one of claims 1 to 7 comprises: A portrait analysis module is used to obtain device registration information; analyze the device registration information, and determine a user portrait of the device user based on the information analysis result; A solution determination module, used to determine a security detection solution based on the user portrait; A code analysis module, used to parse the program source code according to the security detection scheme to obtain several functional codes of the software to be downloaded; The threat analysis module is used to parse each function code to determine whether the software to be downloaded has a network threat, and when it is determined that there is a network threat, restrict the download verification of the device user.
Citation Information
Patent Citations
Proxy server having mobile terminal malicious software behavior detection capability and method
CN105187394A
Flow analysis-based IOS malicious software early warning and detection system and method
CN107092830A
Software gene and script detection method and device for generating script file and medium
CN111324892A