AI-Based SDK Permission Invocation Method and Device
By building a reflection system to perform HOOK operations to generate log information, and combining AI technology to determine the results of SDK permission call, the high threshold and difficulty of SDK permission call monitoring are solved, and efficient monitoring and rectification are achieved.
Patent Information
- Application Number
- CN202411879146.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-19
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2044-12-19
AI Technical Summary
In the prior art, SDK permission call monitoring has problems such as high technical threshold, high operation difficulty, high rectification of third-party SDKs and low efficiency.
By building a reflection system of the target system, performing the HOOK operation of the target API to generate log information, determining the SDK permission call results based on the log information, and intercepting and encapsulation operations are realized through AI technology to reduce the difficulty of monitoring and rectification.
The SDK permission call monitoring process has been simplified, the technical threshold and operation difficulty have been reduced, the rectification efficiency has been improved, and the information security protection and compliance have been improved.
Smart Images

Figure CN119323045B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to the field of computer technology, and in particular, to an AI-based SDK permission invocation method and device. Background Art
[0002] Currently, with the rapid development of mobile Internet applications, the monitoring and management of permission invocations have become increasingly important.
[0003] In related technologies, mainly by creating virtual sandboxes and customizing read-only memories (ROMs), etc., to monitor the permission invocation process. The above methods have technical problems such as high monitoring technical thresholds, large operation difficulties, large SDK (Software Development Kit) rectification difficulties for third parties, and low efficiency.
[0004] Therefore, there is an urgent need for a new technical solution to solve the above technical problems. Summary of the Invention
[0005] According to the embodiments of the present application, an AI-based SDK permission invocation method and device are provided, which can simplify the SDK permission invocation monitoring process, reduce the SDK permission invocation monitoring technical threshold and operation difficulty, reduce the SDK rectification difficulty for third parties, and improve the SDK rectification efficiency for third parties.
[0006] In the first aspect of the present application, an AI-based SDK permission invocation method is proposed, including:
[0007] Construct a target reflection system corresponding to the target system;
[0008] When it is determined that the version of the target system is greater than the preset version, based on the target reflection system, perform a target HOOK operation on the target API to generate target log information, where the target API includes: the API corresponding to the sensitive operation, and / or, the API corresponding to the permission request operation, and the target log information includes: target interaction node feature data;
[0009] Determine the SDK permission invocation result according to the target log information.
[0010] In some feasible embodiments, before determining the SDK permission invocation result according to the target log information, the above method further includes:
[0011] When it is determined that the version of the target system is less than or equal to the preset version, based on the target system, perform a target HOOK operation on the target API to generate target log information.
[0012] In some feasible embodiments, when it is determined that the version of the target system is greater than the preset version, based on the target reflection system, performing a target HOOK operation on the target API to generate target log information includes:
[0013] Controlling the target APP to execute target code;
[0014] Injecting a target SDK permission call request into the target APP based on the target HOOK operation to generate target log information;
[0015] Wherein, the target SDK permission call request includes: a call request for phone status permission, a call request for file reading permission, a call request for camera permission, a call request for microphone permission, and / or a call request for location permission.
[0016] In some feasible embodiments, determining the SDK permission call result based on the target log information includes:
[0017] Triggering a target http request to obtain the packet capture result of the target log information;
[0018] Determining the SDK permission call result according to the packet capture result, wherein the SDK permission call result includes: the permission call result of the target APP and / or the permission call result of the third-party SDK.
[0019] In some feasible embodiments, the above method further includes:
[0020] Performing a target interception operation according to the SDK permission call result.
[0021] In some feasible embodiments, performing a target interception operation according to the SDK permission call result includes:
[0022] When it is determined according to the SDK permission call result that the SDK call permission executed by the target APP exceeds the minimum permission set corresponding to the target APP,
[0023] Performing a target filtering operation according to the target blacklist package name to make the target SDK return an error callback result.
[0024] In some feasible embodiments, performing a target interception operation according to the SDK permission call result further includes:
[0025] Generating a target model function according to the target interaction node feature data;
[0026] Determining a target interception operation probability parameter according to the target model function;
[0027] Performing a target interception operation according to the target interception operation probability parameter.
[0028] In some feasible embodiments, the above method further includes:
[0029] Performing a target encapsulation operation on the target SDK dynamic interface.
[0030] In a second aspect of the present application, there is provided an AI-based SDK permission calling device for implementing the above-mentioned AI-based SDK permission calling method. The above device includes:
[0031] A construction unit for constructing a target reflection system corresponding to the target system;
[0032] An execution unit for, when it is determined that the version of the target system is greater than a preset version, performing a target HOOK operation on the target API based on the target reflection system to generate target log information, where the target API includes: APIs corresponding to sensitive operations, and / or, APIs corresponding to permission request operations, and the target log information includes: target interaction node feature data;
[0033] A determination unit for determining the SDK permission call result according to the target log information.
[0034] In a third aspect of the present application, there is provided an electronic device including a processor and a memory, where computer program instructions are stored in the memory, and when the computer program instructions are run by the processor, they are used to execute the above-mentioned AI-based SDK permission calling method.
[0035] The AI-based SDK permission calling method and device provided by the embodiments of the present application, where the method includes: constructing a target reflection system corresponding to the target system; when it is determined that the version of the target system is greater than a preset version, performing a target HOOK operation on the target API based on the target reflection system to generate target log information, where the target API includes: APIs corresponding to sensitive operations, and / or, APIs corresponding to permission request operations; determining the SDK permission call result according to the target log information. The present application can simplify the SDK permission call monitoring process, reduce the technical threshold and operation difficulty of SDK permission calls, reduce the rectification difficulty of third-party SDKs, and improve the rectification efficiency of third-party SDKs.
[0036] It should be understood that the content described in the Summary of the Invention section is not intended to limit the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In conjunction with the accompanying drawings and with reference to the following detailed description, the above and other features, advantages, and aspects of the embodiments of the present application will become more apparent. In the drawings, the same or similar reference numerals represent the same or similar elements, where:
[0038] Figure 1 It is a schematic flowchart of a method for invoking SDK permissions based on AI provided by an embodiment of the present application;
[0039] Figure 2 It is another schematic flowchart of a method for invoking SDK permissions based on AI provided by an embodiment of the present application;
[0040] Figure 3 It is yet another schematic flowchart of a method for invoking SDK permissions based on AI provided by an embodiment of the present application;
[0041] Figure 4 It is yet another schematic flowchart of a method for invoking SDK permissions based on AI provided by an embodiment of the present application;
[0042] Figure 5 It is a schematic structural diagram of a device for invoking SDK permissions based on AI provided by an embodiment of the present application;
[0043] Figure 6 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0044] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are some, but not all, of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.
[0045] In addition, the term "and / or" in this document is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after.
[0046] In the first aspect of the embodiments of the present application, a method for invoking SDK permissions based on AI is proposed. Figures 1 - 4 It is a schematic flowchart of a method 100 for invoking SDK permissions based on AI provided by an embodiment of the present application, as Figures 1 - 4 shown, the method 100 includes:
[0047] Step S1, construct a target reflection system corresponding to the target system.
[0048] Exemplarily, the above-mentioned target system may include: Android system, iOS system, Windows system, etc., which are not specifically limited herein.
[0049] Exemplarily, the above-mentioned target reflection system includes: a reflection framework corresponding to the above-mentioned target system. Specifically, the above-mentioned reflection framework includes: a HOOK framework.
[0050] It should be noted that during the process of performing the target HOOK operation on the target API, it is usually necessary to obtain the signature of the target system or add the whitelist permission to perform the corresponding reflection operation. Due to the above limitations, it is impossible to directly perform the HOOK operation on the target API. Based on this, the method 100 of this application proposes the following step S2:
[0051] Step S2, when it is determined that the version of the target system is greater than the preset version, based on the target reflection system, perform a target HOOK operation on the target API to generate target log information, where the target API includes: an API corresponding to a sensitive operation, and / or, an API corresponding to a permission request operation, and the target log information includes: target interaction node feature data.
[0052] Exemplarily, the above-mentioned preset version can be defined according to the actual SDK permission monitoring requirements of the target user, which are not specifically limited herein.
[0053] Exemplarily, the above-mentioned target reflection system may include: multiple HOOK functions. Specifically, when it is necessary to perform a HOOK operation on different types of target APIs, the target HOOK function corresponding to the target API can be enabled correspondingly to generate the above-mentioned target log information. It should be noted that the above-mentioned target HOOK operation is used to record all permission call behaviors of the above-mentioned target API to generate the above-mentioned target log information.
[0054] It should be noted that the above-mentioned target log information is used to record the key feature information of sensitive operations, and / or, permission request operations. Among them, the above-mentioned key feature information may include: file operation-related information, network operation-related information, registry operation-related information, permission check-related information, and permission upgrade-related information, etc. The above-mentioned target interaction node feature data may include: collected target page control ID feature data, all text feature data of the target page, target application permission name feature data, API call frequency feature data, title feature data of the page before the target page, all text feature data of the page before the target page, control ID feature data of the page before the target page, device status feature data, and / or, application signature feature data.
[0055] Specifically, the above file operation-related information may include: operation path information of the file; operation type information of the file, such as: read, write, create, and delete, etc.; result information of the file operation, such as: operation failed or operation succeeded, etc.; operation time information of the file, such as: timestamp information of the file operation; calling object information of the file operation, such as: process name, process identifier (Process Identifier, PID), etc.
[0056] Specifically, the above network operation-related information may include: connection address information, such as: target IP address; port number information, such as: target port number; operation type information, such as: connection operation, send operation, receive operation, etc.; data volume information, such as: data volume sent or received; result information of the operation, such as: operation succeeded or operation failed, etc.; operation time information, such as: timestamp information when the operation occurred; calling object information of the network operation, such as: process name, process identifier (Process Identifier, PID), etc.
[0057] Specifically, the above registry operation-related information may include: registry key path information; operation type information, such as: read, write, delete, etc.; result information of the operation, such as: operation succeeded or operation failed; operation time information, such as: timestamp information when the operation occurred; calling object information of the registry operation, such as: process name, process identifier (Process Identifier, PID), etc.
[0058] Specifically, the above permission check-related information may include: Security Identifier information (SecurityIdentifier, SID); permission check result information; permission check operation time information, such as: timestamp information when the permission check operation occurred; calling object information of the permission check operation, such as: process name, process identifier (ProcessIdentifier, PID), etc.
[0059] Specifically, the above permission elevation-related information may include: information about the name of the elevated permission; result information of the permission elevation operation, such as: operation succeeded or operation failed; time information of the permission elevation operation, such as: timestamp information when the permission elevation operation occurred; calling object information of the permission elevation operation, such as: process name, process identifier (ProcessIdentifier, PID), etc.
[0060] Exemplarily, the above sensitive operations may include: file operations, network operations, and registry operations, etc. The above permission request operations may include: enabling request operations for the target hardware of the target electronic device and retrieval request operations for the target information, etc.
[0061] Specifically, taking the Android system as an example, when it is determined that the version of the Android system is greater than 8.0, the target HOOK operation can be performed on the target API based on the reflection class of the target reflection system to generate target log information.
[0062] In some feasible implementation manners, step S2, when it is determined that the version of the target system is greater than the preset version, performing the target HOOK operation on the target API based on the target reflection system to generate target log information includes:
[0063] Step S21, controlling the target APP to execute the target code.
[0064] Step S22, injecting the target SDK permission call request of the target APP based on the target HOOK operation to generate target log information; wherein, the target SDK permission call request includes: a call request for the phone status permission, a call request for the file reading permission, a call request for the camera permission, a call request for the microphone permission, and / or a call request for the location permission.
[0065] Exemplarily, the target APP can be controlled to execute its own target code so that all operations of the target APP pass through the SDK management class of the target HOOK framework.
[0066] Exemplarily, the entry point of the target APP can be determined. Among them, the entry point of a Windows application can be: the WinMain function or the main function. For an Android application, the entry point can be the onCreate of MainActivity.
[0067] Exemplarily, after determining the entry point of the target APP, the target code is automatically injected. Specifically, based on the dynamic link library injection technology, the SDK management class of the HOOK framework can be injected into the target APP. Alternatively, the source code of the target APP can also be modified to directly call the initialization program of the SDK management class at the entry point.
[0068] Exemplarily, after automatically injecting the target code, an initialization operation can be performed on the HOOK framework. Specifically, when the target APP is started, the initialization program of the SDK management class is called to ensure that all relevant APIs are HOOKed. It should be noted that all sensitive operations and permission request operations can be ensured to pass through the HOOK framework by HOOKing the key APIs.
[0069] Exemplarily, the above-mentioned target APIs may include: GetPhoneStatus for determining a phone status permission call request. The above-mentioned target APIs may also include: CreateFile for determining a file read permission call request. The above-mentioned target APIs may also include: OpenCamera for determining a camera call permission request. The above-mentioned target APIs may also include: OpenMicrophone for determining a microphone call permission request. The above-mentioned target APIs may also include: GetLocation for a location permission call request.
[0070] Based on this, when it is determined that the version of the target system is greater than the preset version, the above method can be implemented by controlling the target APP to execute the target code, so that the target APP can automatically perform a pre-self-check operation on its own SDK permission call process without waiting for the privacy detection report result from a third party. By injecting the target SDK permission call request of the target APP based on the target HOOK operation to generate the target log information, it can provide an accurate data basis for the subsequent control of the SDK permission call of the target APP, thereby saving development and testing time, simplifying the SDK permission call monitoring process, reducing the technical threshold and operation difficulty of the SDK permission call.
[0071] In some feasible implementation manners, in step S3 of determining the SDK permission call result according to the target log information, the above method 100 further includes:
[0072] Step S3, when it is determined that the version of the target system is less than or equal to the preset version, perform a target HOOK operation on the target API based on the target system to generate target log information.
[0073] Exemplarily, taking the Android system as an example, when it is determined that the version of the Android system is less than or equal to 8.0, directly perform a target HOOK operation on the target API to generate the above-mentioned target log information.
[0074] Based on this, the above method can implement hierarchical control of the SDK permission call of the target APP according to the version information of the target system. When it is determined that the version of the target system is less than or equal to the preset version, directly perform a target HOOK operation on the target API based on the target system to generate target log information, which is beneficial to reducing the resource occupation during the process of performing the target HOOK operation on the target API when the version of the target system is less than or equal to the preset version. While ensuring the operation efficiency of the target electronic device, it provides an accurate data basis for the subsequent control of the SDK permission call of the target APP and improves the monitoring efficiency of the SDK permission call.
[0075] Step S4, determine the SDK permission call result according to the target log information.
[0076] Exemplarily, the above target log information may include: non-compliant call behaviors, and / or, compliant call behaviors. Among them, the above non-compliant call behaviors include: call behaviors that the target APP executes on its own without the consent of the target user. The above compliant call behaviors include: call behaviors that the target APP executes with the consent of the target user.
[0077] Exemplarily, the target log information in the target log can be read, and based on the above target log information, target structured data is parsed and generated. Based on the above target structured data, the SDK permission call result is extracted.
[0078] Based on this, the AI-based SDK permission call method provided in this application includes: constructing a target reflection system corresponding to the target system; when it is determined that the version of the target system is greater than the preset version, based on the target reflection system, performing a target HOOK operation on the target API to generate target log information, where the target API includes: APIs corresponding to sensitive operations, and / or, APIs corresponding to permission request operations; determining the SDK permission call result according to the target log information. Based on the above target reflection system, this application can achieve getting rid of the high-version reflection restriction of the target system. Without obtaining the signature of the target system or adding whitelist permissions, the target API can be HOOKed, which is beneficial to accurately record the target API permission calling behavior through the above target log information, providing an accurate data basis for the subsequent control of the SDK permission call of the target APP, facilitating simplifying the SDK permission call monitoring process, reducing the technical threshold and operation difficulty of the SDK permission call monitoring, and improving the SDK permission call monitoring efficiency.
[0079] In some feasible implementation manners, step S4 above, determining the SDK permission call result according to the target log information includes:
[0080] Step S41, triggering a target http request to obtain the packet capture result of the target log information.
[0081] It should be noted that, according to the format of the target log, a target http request can be correspondingly initiated for the above target log to obtain the packet capture result of the target log information.
[0082] Exemplarily, the packet capture result of the above log information can be obtained according to a network packet capture tool. Among them, the network packet capture tool can include: Wireshark, Fiddler, etc. Among them, the above packet capture result can be recorded in the captured_log.txt file.
[0083] Step S42: Determine the SDK permission call result according to the packet capture result, where the SDK permission call result includes: the permission call result of the target APP, and / or, the permission call result of the third-party SDK.
[0084] Exemplarily, the above packet capture result can be parsed to determine the permission call result of the target APP, and / or, the permission call result of the third-party SDK.
[0085] Based on this, the above method triggers a target http request to obtain the packet capture result of the target log information, and determines the SDK permission call result according to the packet capture result, which can realize requesting the SDK permission call result in the form of a network request, so that the target user can view the SDK permission call result in real time without waiting until the end of a round of testing, which is beneficial to improving the friendliness of the target user to view the SDK permission call result, and is beneficial to further improving the monitoring efficiency of the SDK permission call. Among them, the above SDK permission call result includes: the permission call result of the target APP, and / or, the permission call result of the third-party SDK, which is beneficial to realizing dual monitoring of the APP host and / or the third-party SDK, is beneficial to reducing the rectification difficulty of the third-party SDK, and improving the rectification efficiency of the third-party SDK.
[0086] In some feasible embodiments, the above method 100 further includes:
[0087] Step S5: Perform a target interception operation according to the SDK permission call result.
[0088] Exemplarily, the above SDK permission call result can be parsed. When it is determined that the actual permission calling scope of the target APP exceeds the preset permission corresponding to the target APP, the corresponding target interception operation is performed on the above exceeded target permission. Among them, the above preset permission can be defined by the target system or the target user.
[0089] Based on this, the above method can realize accurately triggering the target interception operation when the actual permission calling scope of the target APP exceeds the preset scope, so as to enhance the protection of the target user's information security.
[0090] In some feasible embodiments, the above step S5 of performing a target interception operation according to the SDK permission call result includes:
[0091] Step S51: When it is determined according to the SDK permission call result that the SDK call permission executed by the target APP exceeds the minimum permission set corresponding to the target APP, perform a target filtering operation according to the target blacklist package name to make the target SDK return an error callback result.
[0092] Exemplarily, the permission blacklist and package name blacklist of the target system can be read. Among them, the file name of the above-mentioned permission blacklist can be: blacklist.txt. The above-mentioned package name blacklist can be package_blacklist.txt. Among them, the permission blacklist and package name blacklist of the above-mentioned target system can be user-defined.
[0093] Exemplarily, the above SDK permission call results can be analyzed to determine the scope of permissions actually called by the target APP and the package name corresponding to the call object. Compare the actually called permission scope and package name with the minimum permission set and the package name corresponding to the minimum permission set to determine the exceeded target permissions and corresponding package names, and perform target filtering operations according to the above exceeded target permissions and corresponding package names, so that when the target APP requests SDK call permissions, the target SDK returns an error callback result.
[0094] Based on this, the above method can realize that when the SDK call permissions actually executed by the target APP exceed the minimum permission set corresponding to the target APP, directly intercept the permission call request of the target APP based on the above target blacklist package name, so that the target APP cannot call the API of the target system, thereby enhancing the protection of the target user information security and enhancing the compliance of the permissions actually called by the target APP with the privacy protocol.
[0095] It should be noted that when it is determined that the third party cannot modify the target SDK, a separate control operation can be performed, so that without replacing the target SDK, the sensitive permissions of the target SDK can be controlled and intercepted. Based on this, it is beneficial to enhance the protection of the target user information privacy security during the operation of the target APP and enhance the compliance of the operation process of the target APP while ensuring the stable operation of the target APP.
[0096] In some feasible implementation manners, the above step S5, performing the target interception operation according to the SDK permission call result further includes:
[0097] Step S52, generating a target model function according to the target interaction node feature data.
[0098] Step S53, determining the target interception operation probability parameter according to the target model function.
[0099] Step S54, performing the target interception operation according to the target interception operation probability parameter.
[0100] Exemplarily, the target interaction node feature data may include: the collected target page control ID feature data, all the text feature data of the target page, the permission name feature data of the target application, the API call frequency feature data, the title feature data of the page before the target page, all the text feature data of the page before the target page, the control ID feature data of the page before the target page, the device status feature data, and / or the application signature feature data.
[0101] Exemplarily, preprocessing operations may be performed on the above target interaction node feature data to generate corresponding target encodings.
[0102] Specifically, based on label encoding, the above target page control ID feature data, the control ID feature data of the page before the target page, the device status feature data, and the application signature feature data, and / or the permission name feature data of the target application may be encoded respectively to generate target numerical data.
[0103] Specifically, based on the bag-of-words model in Word2Vec, according to all the text feature data of the above target page, all the text feature data of the page before the target page, and / or the title feature data of the page before the target page, target text data may be generated.
[0104] Specifically, based on the above target numerical data, target text data, and / or API call frequency feature data, combined target feature data may be generated. Among them, the above target feature data may include: ID feature combination data, and / or page text similarity score data.
[0105] It should be noted that among them, the above ID feature combination data is generated by combining the target page control ID feature data and the control ID feature data of the page before the target page. The above page text similarity score data is generated by combining all the text feature data of the target page and all the text feature data of the page before the target page.
[0106] It should be noted that in some feasible embodiments, the API call frequency feature data may be standardized to generate API call frequency standardized feature data.
[0107] Exemplarily, based on the above combined target feature data and the above API call frequency standardized feature data, a target model function may be trained based on the following formula to determine the target interception operation probability parameter:
[0108] ;
[0109] Among them, is used to represent the target interception operation probability parameter, For representing the preset activation function Sigmoid, For representing the feature data vector, For representing the preset offset, For representing the weight corresponding to the feature data vector.
[0110] It should be noted that the feature data vector contains vector elements corresponding to multiple feature data. Specifically, the feature data vector can be represented by the following formula:
[0111] ;
[0112] Among them, is the feature data vector, is the vector element corresponding to the first feature data, is the vector element corresponding to the second feature data, is the vector element corresponding to the third feature data, is the vector element corresponding to the fourth feature data.
[0113] It should be noted that the weight corresponding to the feature data vector can contain multiple weight elements corresponding to the vector elements corresponding to the above multiple feature data. Specifically, the weight corresponding to the above feature data vector can be represented by the following formula:
[0114] ;
[0115] Among them, is the weight corresponding to the feature data vector, is corresponding weight, is corresponding weight, is corresponding weight, is corresponding weight.
[0116] Exemplarily, based on the above formulas (1)-(3), when the determined target interception operation probability parameter is greater than or equal to the preset probability parameter, the target interception operation is executed; when the determined target interception operation probability parameter is less than the preset probability parameter, the target interception operation is not executed. Among them, the above preset probability parameter is set by itself according to actual needs.
[0117] Based on this, based on the above steps S52 - S53, it is possible to accurately generate a target model function based on the target interaction node feature data in log collection. Based on the target model function, accurately determine the target interception operation probability parameter, and according to the above target interception operation probability parameter, accurately execute the target interception operation, thereby further improving the accuracy of the target interception operation.
[0118] In some feasible embodiments, the above method 100 further includes:
[0119] Step S6, perform a target encapsulation operation on the target SDK dynamic interface.
[0120] Exemplarily, a target intermediate layer class can be created. Among them, the above target intermediate layer class can be used to perform a target encapsulation operation on the target SDK dynamic interface. Specifically, authorized target users can be predefined in the above target intermediate layer class, so that the authorized target users can access the above target SDK dynamic interface, so that the above target users can expand the above interface by themselves according to different usage scenarios.
[0121] Based on this, by performing a target encapsulation operation on the target SDK dynamic interface, the above method can improve the applicability and expandability of the present method.
[0122] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0123] The above is the introduction of the method embodiments. The following further illustrates the solution of the present application through device embodiments.
[0124] In the second aspect of the embodiments of the present application, a device for AI - based SDK permission call is proposed, which is used to implement the above - mentioned AI - based SDK permission call method. Figure 5 This is a structural schematic diagram of a device 200 for AI - based SDK permission call provided by the embodiments of the present application, as Figure 5 shown, the device 200 includes: a construction unit 210, an execution unit 220, and a determination unit 230.
[0125] The construction unit 210 is used to construct a target reflection system corresponding to the target system;
[0126] An execution unit 220, configured to, when it is determined that the version of the target system is greater than a preset version, perform a target HOOK operation on a target API based on a target reflection system to generate target log information, where the target API includes: an API corresponding to a sensitive operation and / or an API corresponding to a permission request operation, and the target log information includes: target interaction node feature data;
[0127] A determination unit 230, configured to determine an SDK permission call result according to the target log information.
[0128] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the described modules can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0129] Figure 6 It is a structural schematic diagram of an electronic device provided in an embodiment of the present application.
[0130] As Figure 6 shown, the electronic device 300 includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage section 508 into a random access memory (RAM) 303. In the RAM 303, various programs and data required for the operation of the terminal device or the server are also stored. The CPU 301, the ROM 302, and the RAM 303 are connected to each other via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0131] The following components are connected to the I / O interface 305: an input section 306 including a keyboard, a mouse, etc.; an output section 307 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 308 including a hard disk, etc.; and a communication section 309 including a network interface card such as a LAN card, a modem, etc. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the I / O interface 305 as required. A removable medium 311, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 310 as required, so that a computer program read from it can be installed into the storage section 308 as required.
[0132] In particular, according to an embodiment of the present application, the above method flow steps can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product that includes a computer program carried on a machine-readable medium, and the computer program contains program code for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 309, and / or installed from the removable medium 311. When the computer program is executed by the central processing unit (CPU) 301, the above functions defined in the system of the present application are executed.
[0133] It should be noted that the computer-readable medium shown in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in conjunction with an instruction execution system, apparatus, or device. And in the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which the computer-readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0134] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that, in some alternative implementations, the functions denoted in the blocks may occur in a different order than that denoted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0135] The units or modules involved in the embodiments described in the present application may be implemented in software or in hardware. The described units or modules may also be provided in a processor. Among them, the names of these units or modules do not, in some cases, constitute a limitation on the units or modules themselves.
[0136] The above description is only a preferred embodiment of the present application and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the application involved in the present application is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the foregoing application concept. For example, the technical solutions formed by mutually replacing the above features with (but not limited to) technical features having similar functions in the present application.
Claims
1. An AI-based SDK permission calling method, characterized in that, including: constructing a target reflection system corresponding to the target system; when it is determined that the version of the target system is greater than a preset version, based on the target reflection system, performing a target HOOK operation on a target API to generate target log information, where the target API includes: an API corresponding to a sensitive operation, and / or, an API corresponding to a permission request operation, and the target log information includes: target interaction node feature data; wherein the target interaction node feature data includes: target page control ID feature data, all text feature data of the target page, target permission name feature data of the application, API call frequency feature data, title feature data of the page before the target page, all text feature data of the page before the target page, control ID feature data of the page before the target page, device status feature data, and / or, application signature feature data; determining an SDK permission call result according to the target log information; performing a target interception operation according to the SDK permission call result; the performing a target interception operation according to the SDK permission call result includes: generating a target model function according to the target interaction node feature data; determining a target interception operation probability parameter according to the target model function; wherein the target model function is trained and generated based on the following formula: ; Among them, is used to represent the target interception operation probability parameter, is used to represent the preset activation function Sigmoid, is used to represent the feature data vector, is used to represent the preset offset, is used to represent the weight corresponding to the feature data vector; performing a target interception operation according to the target interception operation probability parameter; the performing a target interception operation according to the target interception operation probability parameter includes: when it is determined that the target interception operation probability parameter is greater than or equal to a preset probability parameter, performing a target interception operation; including: when it is determined, according to the SDK permission call result, that the SDK call permission executed by the target APP exceeds the minimum permission set corresponding to the target APP, performing a target filtering operation according to a target blacklist package name, so that the target SDK returns an error callback result; when it is determined that the target interception operation probability parameter is less than the preset probability parameter, not performing a target interception operation; further including: creating a target intermediate layer class; performing a target encapsulation operation on a target SDK dynamic interface.
2. The method according to claim 1, wherein Before determining the SDK permission call result according to the target log information, the method further includes: when it is determined that the version of the target system is less than or equal to the preset version, based on the target system, performing the target HOOK operation on the target API to generate the target log information.
3. The method according to claim 1, characterized in that, the performing a target HOOK operation on a target API to generate target log information when it is determined that the version of the target system is greater than a preset version, based on the target reflection system, includes: controlling the target APP to execute target code; injecting a target SDK permission call request of the target APP based on the target HOOK operation to generate the target log information; wherein the target SDK permission call request includes: a call request for phone status permission, a call request for file reading permission, a call request for camera permission, a call request for microphone permission, and / or, a call request for location permission.
4. The method according to claim 3, characterized in that, Determining the SDK permission call result according to the target log information includes: Triggering a target HTTP request to obtain the packet capture result of the target log information; Determining the SDK permission call result according to the packet capture result, where the SDK permission call result includes: the permission call result of the target APP, and / or, the permission call result of a third-party SDK.
5. An AI-based SDK permission calling device, characterized in that, For implementing the method as described in claim 1, the device includes: A construction unit for constructing a target reflection system corresponding to the target system; An execution unit for, when determining that the version of the target system is greater than a preset version, performing a target HOOK operation on a target API based on the target reflection system to generate target log information, where the target API includes: an API corresponding to a sensitive operation, and / or, an API corresponding to a permission request operation, and the target log information includes: target interaction node feature data; Wherein, the target interaction node feature data includes: target page control ID feature data, all text feature data of the target page, target applied permission name feature data, API call frequency feature data, title feature data of the page before the target page, all text feature data of the page before the target page, control ID feature data of the page before the target page, device status feature data, and / or, application signature feature data; A determination unit for determining the SDK permission call result according to the target log information; Performing a target interception operation according to the SDK permission call result; Performing the target interception operation according to the SDK permission call result includes: Generating a target model function according to the target interaction node feature data; Determining a target interception operation probability parameter according to the target model function; Wherein, the target model function is trained and generated based on the following formula: ; Among them, is used to represent the target interception operation probability parameter, is used to represent the preset activation function Sigmoid, is used to represent the feature data vector, is used to represent the preset offset, is used to represent the weight corresponding to the feature data vector; Performing a target interception operation according to the target interception operation probability parameter; Performing the target interception operation according to the target interception operation probability parameter includes: Performing a target interception operation when determining that the target interception operation probability parameter is greater than or equal to a preset probability parameter; Includes: When determining that the SDK call permission executed by the target APP exceeds the minimum permission set corresponding to the target APP according to the SDK permission call result, Performing a target filtering operation according to the target blacklist package name to make the target SDK return an error callback result; Not performing a target interception operation when determining that the target interception operation probability parameter is less than the preset probability parameter; Also includes: Creating a target intermediate layer class; Performing a target encapsulation operation on the dynamic interface of the target SDK.
6. An electronic device, characterized in that, Includes a processor and a memory, wherein computer program instructions are stored in the memory, and when the computer program instructions are run by the processor, they are used to execute the method as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Permission calling monitoring method and device and electronic equipment
CN116956272A