Illegal Android application detection method and electronic device based on user interface transition graph
By performing dynamic and static analysis of Android applications, integrating user interface conversion graphs, and using GAE neural network and graph neural network for prediction, the coverage and accuracy problems of illegal application detection in the existing technology are solved, and efficient identification and classification of illegal application are achieved.
Patent Information
- Application Number
- CN202510134951.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2045-02-07
AI Technical Summary
When detecting illegal applications, the existing Android application classification methods have problems such as the large amount of redundant data of dynamic analysis, low coverage rate, poor accuracy of static analysis, and the inability to deal with dynamically loaded WebView content.
By performing dynamic and static analysis of the Android application to be detected, dynamic and static user interface conversion diagrams are obtained, mapping, alignment and fusion are established to obtain a hybrid user interface conversion diagram, and link prediction and edge addition and deletion are used to input the mixed feature map diagram neural network for label prediction.
有效改善了节点覆盖率低、转换边准确率低的问题,实现了对安卓应用的高效分析和违法应用的识别,具有较高的鲁棒性和广泛的应用价值。
Smart Images

Figure CN119577767B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of Android application detection, and in particular to a method and an electronic device for detecting illegal Android applications based on a user interface transition graph. Background Art
[0002] Android is a mobile operating system mainly used in mobile devices such as smartphones and tablets. In recent years, with the continuous development of the Internet and the increasing popularity of Android applications, a considerable part of illegal industries have started to rely on web pages and Android applications for dissemination and profit.
[0003] WebView is a special native user interface in Android that can quickly access local html resources or remote web pages and interact with them. It is a relatively special user interface management method compared to static layouts and dynamic generation. Due to the characteristics of WebView that it can reuse web pages and reduce development costs, some illegal Android applications use WebView to display illegal content in web pages. WebView will have a certain impact on the analysis of Android applications because the content displayed in it is not included in the code, and the loading process is also different from the conventional UI.
[0004] Most of the existing research on Android application classification focuses on whether the application is a "malicious application", and relatively few studies focus on whether its content is illegal.
[0005] At the same time, the existing Android application classification methods in the prior art usually only use dynamic or static analysis. Dynamic analysis requires running the program and simulating user behavior, and only the content triggered or jumped to will be collected into detailed data. The behaviors triggered multiple times will be recorded multiple times, and the user interfaces and transitions not triggered will not be in the user interface transition graph. Therefore, there are problems such as a large amount of redundant data and low coverage rate. Although the results of static analysis for obtaining the user interface transition graph are relatively comprehensive, its accuracy is not ideal, there are false positives and missed jump reports, and it is also unable to process the content in dynamically loaded WebView.
[0006] Therefore, there is an urgent need to propose a method for detecting illegal Android applications. Summary of the Invention
[0007] Aiming at the deficiencies of the prior art, the present invention provides a method and an electronic device for detecting illegal Android applications based on a user interface transition graph.
[0008] In a first aspect, an embodiment of the present invention provides a method for detecting illegal Android applications based on a user interface transition graph, the method comprising the following steps:
[0009] Perform dynamic analysis on the Android application to be detected to obtain a dynamic user interface transition graph;
[0010] Perform static analysis on the Android application to be detected, and obtain the static user interface transition graph and the metadata of the Android application to be detected;
[0011] Establish a mapping between the static user interface transition graph and the dynamic user interface transition graph, align and fuse the static user interface transition graph and the dynamic user interface transition graph to obtain a hybrid user interface transition graph;
[0012] Perform link prediction on the hybrid user interface transition graph to update the user interface transition graph;
[0013] Input the metadata of the Android application to be detected into an encoder for encoding, and splice the encoded metadata feature vector and the updated user interface transition graph to obtain a hybrid feature graph;
[0014] Input the hybrid feature graph into a graph neural network for label prediction to obtain the category corresponding to the Android application to be detected.
[0015] In a second aspect, an embodiment of the present invention provides an electronic device, including a memory and a processor, and the memory is coupled to the processor; wherein, the memory is used to store program data, and the processor is used to execute the program data to implement the above-mentioned method for detecting illegal Android applications based on the user interface transition graph.
[0016] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the above-mentioned method for detecting illegal Android applications based on the user interface transition graph.
[0017] In a fourth aspect, an embodiment of the present invention provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, it implements the above-mentioned method for detecting illegal Android applications based on the user interface transition graph.
[0018] Compared with the prior art, the beneficial effects of the present invention are:
[0019] The present invention provides a method for detecting illegal Android applications based on a user interface transition graph. By performing dynamic and static analysis on the Android application to be detected, a dynamic user interface transition graph and a static user interface transition graph are obtained; the dynamic and static user interface transition graphs are mapped, aligned, and spliced to obtain a hybrid user interface transition graph; the hybrid user interface transition graph is subjected to directed edge prediction and edge addition and deletion operations through a gravity-inspired GAE neural network, effectively improving the problems of low node coverage rate and low conversion edge accuracy rate. The present invention can efficiently analyze the Android application to be detected and has high robustness. When one or two parts of the dynamic user interface transition graph, the static user interface transition graph, and the statically extracted metadata fail to be extracted, other features can still be normally extracted and the final prediction can be completed, which has wide application value in tasks such as the governance of illegal Android applications and the review of the Android application platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0021] Figure 1 It is a flowchart of a method for detecting illegal Android applications based on a user interface transition graph provided by an embodiment of the present invention;
[0022] Figure 2 It is a schematic diagram of establishing a mapping between a static user interface transition graph and a dynamic user interface transition graph provided by an embodiment of the present invention;
[0023] Figure 3 It is a schematic diagram of link prediction provided by an embodiment of the present invention;
[0024] Figure 4 It is a schematic diagram of a hybrid feature graph provided by an embodiment of the present invention;
[0025] Figure 5 It is a schematic diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0027] It should be noted that, without conflict, the features in the following embodiments and implementation manners can be combined with each other.
[0028] To clearly illustrate the technical solutions provided by the embodiments of the present application, some concepts that may appear in the subsequent embodiments will be introduced first.
[0029] User Interface (UI): It is the medium for mobile applications to exchange and interact with users. Among them, Android UI includes all applications related to users' audio-visual and those that can interact with them, which consists of layouts and controls and can be controlled through XML static layouts or dynamically generated by code. In actual use, a combination of both can also be used to flexibly manage the UI.
[0030] User Interface Transition Graph (UI Transition Graph): It is a visualization method used to describe the transition relationships and processes between different user interfaces (UIs) in an application. It usually consists of a series of nodes and edges, where the nodes represent UIs and the edges represent the operations or events for users to transition from one UI to another.
[0031] As Figure 1 shown, an embodiment of the present invention provides an illegal Android application detection method based on a user interface transition graph, and the method includes:
[0032] Step S1: Perform dynamic analysis on the Android application to be detected to obtain a dynamic user interface transition graph.
[0033] Specifically, the step S1 includes the following sub-steps:
[0034] Step S101: Perform dynamic analysis on the Android application to be detected to obtain several user interfaces including WebView, the jump relationships between user interfaces, and the user interface tree and activity name corresponding to each user interface.
[0035] Specifically, in this example, a dynamic analysis method based on the breadth-first search strategy is adopted, and the DroidBot tool and the Talkback accessibility function plugin are used to test the Android application to be detected, obtaining several user interfaces including WebView, the jump relationships between user interfaces, and the user interface tree and activity name corresponding to each user interface.
[0036] Exemplarily, in this example, the Android application apk file to be detected is run in the simulator, and the DroidBot tool is automatically invoked through a configured Python script for dynamic analysis using a breadth-first search strategy. Information dynamically loaded on the web view WebView is obtained by acquiring the content of the rendering pipeline. The analysis results of the DroidBot tool include a large number of json files. Among them, there is a first json file and several second json files. The first json file contains the user interfaces and the jump relationships between the user interfaces, and the second json files include the user interface trees, activity names, controls, and the layouts of the controls of the user interfaces.
[0037] Step S102: Calculate the similarity between every two user interfaces based on the user interface trees, and consider the two user interfaces with a similarity greater than the threshold as different states of the same user interface; merge redundant user interfaces and update the jump relationships between the user interfaces.
[0038] Specifically, in this example, the similarity between every two user interfaces is calculated through the Levenstein distance based on the user interface trees. The two user interfaces with a similarity greater than the threshold are considered as different states of the same user interface. The user interfaces with high similarity are merged, and the jump relationships between the user interfaces are updated to alleviate the information explosion caused by the DroidBot tool distinguishing different user interfaces through the hash values of the user interface trees.
[0039] Step S103: Construct a dynamic user interface transition graph with the merged user interfaces as nodes and the updated jump relationships between the user interfaces as edges.
[0040] Step S2: Perform static analysis on the Android application to be detected to obtain a static user interface transition graph and the metadata of the Android application to be detected.
[0041] Specifically, step S2 includes the following steps:
[0042] Perform static analysis on the Android application to be detected to obtain several user interfaces, the jump relationships between the user interfaces, and the user interface trees and activity names corresponding to each user interface.
[0043] Construct a static user interface transition graph with the user interfaces as nodes, the jump relationships between the user interfaces as edges, and the basic attributes and listener methods of the jump relationships between the user interfaces as edge features.
[0044] Among them, the process of performing static analysis on the Android application to be detected and obtaining several user interfaces includes: for each activity of the Android application to be detected, traverse the nodes in the call graph of the onCreate method corresponding to each activity, find the node corresponding to the setContentView method in the call graph, and determine the user interface associated with the activity by checking the parameters of the setContentView method.
[0045] Among them, obtaining the basic attributes of the jump relationship between user interfaces: obtaining the basic attributes including text, id, and clickable (whether it can be clicked) according to the user interface.
[0046] Among them, the process of obtaining the listener method corresponding to the jump relationship between user interfaces includes: performing reverse code on the Android application to be detected, traversing all instance functions in the reverse code for each activity of the Android application, using the FlowDroid tool to construct the call graph of the instance functions (the call graph uses function methods as nodes and call relationships as edges), and searching on the call graph to obtain the listener method corresponding to the jump relationship between user interfaces.
[0047] Exemplarily, perform static analysis on the Android application. First, obtain potential trigger controls and UI features through the PermDroid tool and code analysis, and construct a static UI transition graph by identifying functions involved in activity transitions; then use Androguard and Jadx to obtain static metadata.
[0048] Furthermore, the metadata of the Android application to be detected: text data, picture data; among them, the text data includes: application name, package name, certificate information; the picture data includes: application icon.
[0049] Step S3, establish a mapping between the static user interface transition graph and the dynamic user interface transition graph, align and fuse the static user interface transition graph and the dynamic user interface transition graph to obtain a hybrid user interface transition graph.
[0050] Specifically, the step S3 includes the following sub-steps:
[0051] Step S301, calculate the similarity of two nodes with the same activity name in the static user interface transition graph and the dynamic user interface transition graph. When the similarity is greater than the threshold (set to 0.87 in this instance), then consider the two nodes with the same activity name as the same user interface, thereby completing the mapping of nodes between the static user interface transition graph and the dynamic user interface transition graph.
[0052] Further, in this example, the Levenstein distance is used to calculate the node similarity of pairwise nodes with the same activity name in the static user interface conversion graph and the dynamic user interface conversion graph.
[0053] Step S302, when there is a node mapping relationship between two source nodes in the static user interface conversion graph and the dynamic user interface conversion graph, and there is a node mapping relationship between two destination nodes in the static user interface conversion graph and the dynamic user interface conversion graph, and the listener method corresponding to the edge between the source node and the destination node in the static user interface conversion graph is the same as the listener method corresponding to the edge between the source node and the destination node in the dynamic user interface conversion graph, there is an edge mapping relationship between the edge between the source node and the target node in the static user interface conversion graph and the edge between the source node and the target node in the dynamic user interface conversion graph; all the edges in the static user interface conversion graph and the dynamic user interface conversion graph are traversed pairwise, so as to complete the edge mapping between the static user interface conversion graph and the dynamic user interface conversion graph.
[0054] It should be noted that when the same reaches the UI node to trigger a conversion with the same characteristics, the target UI node is uniquely determined; therefore, in order to further match more conversion pairs, all the edges in the dynamic and static user interface conversion graphs are traversed pairwise to find those edges that have source nodes that have been regarded as the same user interface and have matching trigger controls and operation methods (the trigger controls in the static graph match the operation methods in the dynamic graph, such as setOnClickListener() and click operation are a pair of matching controls and methods), and these two edges are regarded as the same conversion, thereby completing the edge mapping, and the target nodes of these two edges are also marked as the same user interface.
[0055] Step S303, generate a hybrid user interface conversion graph according to the node mapping relationship and the edge mapping relationship between the static user interface conversion graph and the dynamic user interface conversion graph.
[0056] Exemplarily, such as Figure 2As shown, obtain the first activity name 'A' and the first user interface tree of the first node in the static user interface transition diagram, and obtain the second activity name 'A' and the second user interface tree of the second node in the static user interface transition diagram; obtain the activity name 'A' and the third user interface tree of the third node in the dynamic user interface transition diagram, and obtain the activity name 'A' and the fourth user interface tree of the fourth node in the dynamic user interface transition diagram. Calculate the similarity between the first node in the static user interface transition diagram and the third node in the dynamic user interface transition diagram using the Levenstein distance. If the similarity is greater than the threshold of 0.87, then these two nodes are regarded as the same user interface and node merging can be performed. Calculate the similarity between the second node in the static user interface transition diagram and the fourth node in the dynamic user interface transition diagram using the Levenstein distance. If the similarity is greater than the threshold of 0.87, then these two nodes are regarded as the same user interface and node merging can be performed. There is a node mapping relationship between the first node in the static user interface transition diagram and the third node in the dynamic user interface transition diagram, and there is a node mapping relationship between the second node in the static user interface transition diagram and the fourth node in the dynamic user interface transition diagram. The listener method corresponding to the edge between the first node and the second node in the static user interface transition diagram is setOnClickListener(), and the listener method corresponding to the edge between the third node and the fourth node in the dynamic user interface transition diagram is a click operation, that is, the listener method corresponding to the edge between the source node and the destination node in the static user interface transition diagram is the same as the listener method corresponding to the edge between the source node and the destination node in the dynamic user interface transition diagram. Then it is determined that there is an edge mapping relationship between the edge between the first node and the second node in the static user interface transition diagram and the edge between the third node and the fourth node in the dynamic user interface transition diagram.
[0057] Step S4, perform link prediction on the hybrid user interface transition diagram and update the user interface transition diagram.
[0058] Specifically, the step S4 includes the following steps:
[0059] Step S401, input the activity name of the user interface corresponding to each node in the hybrid user interface transition diagram and the text data in the user interface tree into the pre-trained BERT model to obtain node feature vectors.
[0060] Specifically, for the activity name of the user interface, set the processing token length to 64, the encoding length to 64, and use a BERT model dedicated to handling case-insensitive English; for the text data in the user interface tree, set the processing token length to 256, the encoding length to 64, and use a BERT model for Chinese. The loaded pre-trained BERT model is fine-tuned through the MLM task, that is, randomly masking the content of several tokens among them, and letting the BERT model predict the content that should be filled in this position.
[0061] Step S402: Input the node feature vector and the mixed user interface conversion graph into a pre-trained gravity-inspired GAE neural network (Gravity-Inspired Graph Autoencoders) to perform directed edge prediction on the mixed user interface conversion graph, and obtain the scores of the directed connections between each node in the mixed user interface conversion graph.
[0062] It should be noted that the gravity-inspired GAE neural network can output different results for directed edges by introducing gravity parameters, enabling the GAE that could not originally handle direction features to do so.
[0063] In this example, the gravity-inspired GAE neural network is used as the link prediction model. The training process of the link prediction model includes: using the mixed user interface conversion graph as the real graph to train the link prediction model to train the ability to predict the existence of edges, and then using the manually corrected user interface conversion graph for fine-tuning.
[0064] Step S403: Based on the scores of the directed connections between each node in the mixed user interface conversion graph and whether there are edges in the mixed user interface conversion graph, perform edge addition and deletion operations on the mixed user interface conversion graph, so as to update the user interface conversion graph.
[0065] Specifically, calculate the quartiles of the scores of the directed connections between each node in the mixed user interface conversion graph to determine the upper score threshold (in this example, the upper score threshold is 0.408) and the lower score threshold (in this example, the lower score threshold is 0.202);
[0066] Traverse the possible edges in the mixed user interface conversion graph: when the score of the directed connection between two nodes is greater than the upper score threshold, the directed connection between these two nodes is used as the edge to be added and added to the set of edges to be added; when the score of the directed connection between two nodes is less than the lower score threshold, the directed connection between these two nodes is used as the edge to be deleted and added to the set of edges to be deleted.
[0067] Traverse the set of edges to be added and the set of edges to be deleted: For the edges to be added, if such an edge does not exist in the current hybrid user interface conversion graph, add the corresponding connection relationship in the current hybrid user interface conversion graph; for the edges to be deleted, delete the corresponding connection relationship in the current hybrid user interface conversion graph.
[0068] It should be noted that for the edges to be deleted, since the edge information from dynamic analysis must be true, when there are only edges obtained from static analysis in the original UI conversion graph, delete this connection relationship.
[0069] According to the modified connection relationship, obtain the updated user interface conversion graph.
[0070] Step S5, input the metadata of the Android application to be detected into the encoder for encoding, and splice the encoded metadata feature vector and the updated user interface conversion graph to obtain a hybrid feature graph.
[0071] Specifically, step S5 includes the following sub-steps:
[0072] Step S501, encode the text data in the metadata of the Android application to be detected to obtain text features.
[0073] Specifically, for the text data in the metadata of the Android application to be detected, the text data includes the application name, package name, and certificate information. Convert all Chinese text data into pinyin, preprocess and delete the characters that cannot be parsed, and use the BiGRU model trained by the classification task to encode it into a 128-dimensional feature vector.
[0074] This classification task is to add a fully connected layer outside the BiGRU model, use the text data as the input, use the confidence scores under the first illegal category, the second illegal category,..., the Nth illegal category as the output, and use the cross-entropy as the loss function to train the BiGRU model.
[0075] Step S502, encode the image data in the metadata of the Android application to be detected to obtain image features.
[0076] Specifically, count the RGB values of the image pixels, count the R, G, and B channels respectively, divide the 256 values into 16 groups, calculate the proportion of the pixels in each group in the whole image, and obtain a total of 48-dimensional vector as the first vector.
[0077] Furthermore, perform a similar operation on the HSV channel. Since the value range of the V channel is 180 values, it is divided into 10 groups, and finally a 42-dimensional feature vector is obtained as the second vector.
[0078] Finally, the number of texts in the picture recognized by EasyOCR, whether there are keywords related to illegal content, and the result of whether there is a web link obtained by regular matching, a total of 6-dimensional features, are used as the third vector.
[0079] Perform standardization and splicing operations on the first vector, the second vector, and the third vector to obtain the picture features.
[0080] Step S503: Splice the text features and the picture features to obtain the metadata features of the Android application to be detected; splice the metadata features before each node feature of the updated user interface conversion graph to obtain the hybrid feature graph of the Android application to be detected, as Figure 4 shown.
[0081] Step S6: Input the hybrid feature graph into the graph neural network for label prediction to obtain the category corresponding to the Android application to be detected.
[0082] Specifically, input the hybrid feature graph into the graph neural network for label prediction to obtain the confidence scores of the Android application to be detected under the first illegal category, the second illegal category,..., the Nth illegal category; select the category with the highest confidence score as the category corresponding to the Android application to be detected.
[0083] In summary, the present invention provides a method for detecting illegal Android applications based on a user interface conversion graph. By performing dynamic and static analysis on the Android application to be detected, a dynamic user interface conversion graph and a static user interface conversion graph are obtained; mapping, alignment, and splicing are performed on the dynamic and static user interface conversion graphs to obtain a hybrid user interface conversion graph; the hybrid user interface conversion graph is used for directed edge prediction and edge addition and deletion operations through a gravity-inspired GAE neural network, effectively alleviating problems such as low accuracy of the static user interface conversion graph and low coverage of the dynamic user interface conversion graph. The present invention can efficiently analyze the Android application to be detected and has high robustness. When one or two parts of the dynamic user interface conversion graph, the static user interface conversion graph, and the statically extracted metadata fail to be extracted, other features can still be normally extracted and the final prediction can be completed, realizing the identification and category judgment of illegal Android applications, and having broad application value in tasks such as illegal Android application governance and Android application platform review.
[0084] According to an embodiment of the present invention, the present invention also provides an electronic device and a readable storage medium.
[0085] Figure 5FIG. shows a schematic block diagram of an electronic device that can be used to implement embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, for example, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, personal digital processors, cellular telephones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely exemplary and are not intended to limit the implementation of the present invention described and / or claimed herein. The electronic device includes a computing unit 101 that can perform various appropriate actions and processes according to a computer program stored in the ROM 102 or a computer program loaded from the storage unit 108 into the RAM 103. In the RAM 103, various programs and data required for the operation of the electronic device can also be stored. The computing unit 101, the ROM 102, and the RAM 103 are connected to each other via a bus 104. The I / O interface 105 is also connected to the bus 104.
[0086] Multiple components in the electronic device are connected to the I / O interface 105, including: an input unit 106, such as a keyboard, a mouse, etc.; an output unit 107, such as various types of displays, speakers, etc.; a storage unit 108, such as a magnetic disk, an optical disk, etc.; and a communication unit 109, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 109 allows the electronic device to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0087] The computing unit 101 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 101 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 101 executes the various methods and processes described above. For example, in some embodiments, the method in the pressure injury multi-dimensional early warning system can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 108. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device via the ROM 102 and / or the communication unit 109. When the computer program is loaded into the RAM 103 and executed by the computing unit 101, one or more steps of the method in the pressure injury multi-dimensional early warning system described above can be executed. Alternatively, in other embodiments, the computing unit 101 can be configured to execute the method in the pressure injury multi-dimensional early warning system in any other suitable manner (e.g., by means of firmware).
[0088] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0089] The program code for implementing the methods of the present invention can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0090] In the context of the present invention, a readable storage medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A readable storage medium can be a machine-readable signal medium or a machine-readable storage medium. A readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0091] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0092] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.
[0093] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, can also be a server of a distributed system, or a server incorporating a blockchain.
[0094] Although embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
[0095] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A method for detecting illegal Android applications based on a user interface transition graph, characterized in that: The method comprises the following steps: Perform dynamic analysis on the Android application to be tested and obtain the dynamic user interface transition graph; Perform static analysis on the Android application to be tested, and obtain a static user interface transition graph and metadata of the Android application to be tested; Establishing a mapping between the static user interface transition graph and the dynamic user interface transition graph, aligning and fusing the static user interface transition graph and the dynamic user interface transition graph to obtain a hybrid user interface transition graph; Perform link prediction on the hybrid user interface transition graph, and update the user interface transition graph; Inputting metadata of the Android application to be detected into an encoder for encoding, and concatenating the metadata feature vector obtained by encoding with the updated user interface transition map to obtain a hybrid feature map; The mixed feature map is input into the graph neural network for label prediction to obtain the category corresponding to the Android application to be detected.
2. According to claim 1, a method for detecting illegal Android applications based on a user interface transition graph is characterized in that: The process of dynamically analyzing the Android application to be tested and obtaining the dynamic user interface transition graph includes: Dynamically analyze the Android application to be tested to obtain the user interface, the jump relationship between user interfaces, and the user interface tree corresponding to each user interface; Calculate the similarity between two user interfaces based on the user interface tree, and regard two user interfaces with a similarity greater than a threshold as different states of the same user interface; merge redundant user interfaces, and update the jump relationship between user interfaces; A dynamic user interface transition graph is constructed with the merged user interfaces as nodes and the jump relationships between the updated user interfaces as edges.
3. According to claim 1, a method for detecting illegal Android applications based on a user interface transition graph is characterized in that: The process of statically analyzing the Android application to be tested and obtaining the static user interface transition graph includes: Perform static analysis on the Android application to be tested to obtain several user interfaces, jump relationships between user interfaces, and user interface trees and activity names corresponding to each user interface; A static user interface transition graph is constructed with user interfaces as nodes, jump relationships between user interfaces as edges, and basic attributes and listener methods of jump relationships between user interfaces as edge features. Among them, the process of obtaining the listener method corresponding to the jump relationship between user interfaces includes: reversing the code of the Android application to be detected, traversing all instance functions in its reverse code for each activity of the Android application, building a call graph of the instance function, and searching on the call graph to obtain the listener method corresponding to the jump relationship between user interfaces.
4. The method for detecting illegal Android applications based on a user interface transition graph according to claim 1, characterized in that: The process of establishing a mapping between the static user interface transition graph and the dynamic user interface transition graph, aligning and fusing the static user interface transition graph and the dynamic user interface transition graph to obtain a hybrid user interface transition graph includes: Calculate the similarity between two nodes with the same activity name in the static user interface transition graph and the dynamic user interface transition graph. When the similarity is greater than a threshold, the two nodes with the same activity name are regarded as using one user interface, thereby completing the mapping of nodes between the static user interface transition graph and the dynamic user interface transition graph. When there is a node mapping relationship between two source nodes in the static user interface conversion graph and the dynamic user interface conversion graph, and there is a node mapping relationship between two destination nodes in the static user interface conversion graph and the dynamic user interface conversion graph, and the listener method corresponding to the edge between the source node and the destination node in the static user interface conversion graph is the same as the listener method corresponding to the edge between the source node and the destination node in the dynamic user interface conversion graph, there is an edge mapping relationship between the edge between the source node and the destination node in the static user interface conversion graph and the edge between the source node and the destination node in the dynamic user interface conversion graph; all edges in the static user interface conversion graph and the dynamic user interface conversion graph are traversed pairwise, thereby completing the mapping of edges between the static user interface conversion graph and the dynamic user interface conversion graph; A hybrid user interface transition graph is generated according to the mapping relationship between nodes and the mapping relationship between edges in the static user interface transition graph and the dynamic user interface transition graph.
5. The method for detecting illegal Android applications based on user interface transition graph according to claim 1, characterized in that: The process of performing link prediction on the hybrid user interface transition graph and updating the user interface transition graph includes: Input the activity name of the user interface corresponding to each node in the hybrid user interface transition graph and the text data in the user interface tree into the pre-trained BERT model to obtain the node feature vector; Input the node feature vector and the hybrid UI transition graph into the pre-trained gravity-inspired GAE neural network to perform directed edge prediction on the hybrid UI transition graph, and obtain the scores of directed connections between nodes in the hybrid UI transition graph; Based on the scores of directed connections between nodes in the hybrid user interface transition graph and whether there are edges in the hybrid user interface transition graph, edge addition and deletion operations are performed on the hybrid user interface transition graph, thereby updating the user interface transition graph.
6. The method for detecting illegal Android applications based on user interface transition graph according to claim 5, characterized in that: Based on the scores of directed connections between nodes in the hybrid user interface transition graph and whether there are edges in the hybrid user interface transition graph, adding and deleting edges in the hybrid user interface transition graph, thereby updating the user interface transition graph includes: Based on the scores of directed connections between nodes in the hybrid user interface transition graph, quartiles thereof are calculated to determine an upper score threshold and a lower score threshold; The edges that may exist in the hybrid user interface transition graph are traversed: when the score of the directed connection between two nodes is greater than the upper score threshold, the directed connection between the two nodes is taken as an edge to be added and added to the set of edges to be added; when the score of the directed connection between two nodes is less than the lower score threshold, the directed connection between the two nodes is taken as an edge to be deleted and added to the set of edges to be deleted; Traverse the edge set to be added and the edge set to be deleted: for the edge to be added, if the edge does not exist in the current hybrid user interface conversion graph, add the corresponding connection relationship in the current hybrid user interface conversion graph; for the edge to be deleted, delete the corresponding connection relationship in the current hybrid user interface conversion graph; According to the modified connection relationship, an updated user interface conversion diagram is obtained.
7. The method for detecting illegal Android applications based on user interface transition graph according to claim 1, characterized in that: The process of inputting the mixed feature map into the graph neural network for label prediction and obtaining the category corresponding to the Android application to be detected includes: Input the mixed feature map into the graph neural network for label prediction, and obtain the confidence scores of the Android application to be detected in the first illegal category, the second illegal category, ..., the Nth illegal category respectively; The category with the highest confidence score is selected as the category corresponding to the Android application to be detected.
8. An electronic device, comprising a memory and a processor, characterized in that: The memory is coupled to the processor; wherein the memory is used to store program data, and the processor is used to execute the program data to implement the illegal Android application detection method based on the user interface conversion diagram as described in any one of claims 1-7 above.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by the processor, it implements the illegal Android application detection method based on the user interface conversion diagram as described in any one of claims 1-7.
10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the illegal Android application detection method based on the user interface conversion diagram described in any one of claims 1-7 is implemented.
Citation Information
Patent Citations
Application processing method and device, and computer storage medium
WO2019149150A1
KR20200039912A