Software security detection method and system for fingerprint browser

By adopting security detection methods that counterenant the environment and multi-hop dependency analysis in fingerprint browsers, the detection problems of complex camouflage behavior and internal security risks are solved, efficient camouflage detection, vulnerability mining and comprehensive risk assessment are achieved, and security protection capabilities are significantly improved.

CN119622727BActive Publication Date: 2025-06-24GUANGZHOU JEEKUP INFORMATION TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510147443.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-06-24
Estimated Expiration
2045-02-11

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect the complex disguise behavior and internal security risks of fingerprint browsers. Traditional methods lack adaptability to complex and dynamic disguise behaviors, and vulnerability detection is difficult to capture the vulnerability paths generated by multi-module interaction.

Method used

The fingerprint browser security detection method based on adversarial environment and multi-hop dependency analysis is adopted. By building an improved variational autoencoder model and adversarial generation network, the disguised detection probability matrix and module interaction log are obtained, the module dependency graph is built, the logical vulnerability and optimal utilization path are obtained, the comprehensive risk score is calculated, and the protection strategy is selected.

Benefits of technology

It realizes accurate detection and traceability of the complex camouflage behavior of fingerprint browsers, discovers potential vulnerabilities across modules, improves the comprehensiveness and accuracy of vulnerability discovery, and significantly improves the overall security protection capability through unified security detection and protection closed loop.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119622727B_ABST
    Figure CN119622727B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of information security, and discloses a software security detection method and system for a fingerprint browser. The method includes: first, obtaining a feature matrix and a module interaction log based on disguise features, behavior features, and module interaction features; second, obtaining a disguise detection probability matrix, disguise samples, and a disguise traceability report; third, constructing a module dependency graph, obtaining a disguise propagation path and a set of high-risk modules; fourth, obtaining logical vulnerabilities and an optimal exploitation path; fifth, calculating a comprehensive risk score and selecting a protection strategy based on the comprehensive risk score. The present invention can comprehensively address the challenges in disguise detection, attack traceability, and vulnerability mining of fingerprint browsers, overcome the shortcomings of existing technologies through innovative technical means, and provide an efficient and secure protection mechanism for fingerprint browsers for users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and particularly to a software security detection method and system for fingerprint browsers. Background Art

[0002] With the enhancement of privacy protection awareness, fingerprint browsers, as a tool with camouflage functions, have been widely used in recent years. By dynamically modifying key fingerprint characteristics such as users' hardware features, network attributes, and operating system information, it helps users achieve identity camouflage and privacy protection on the Internet. However, the popularization of such tools has also brought a series of security risks. On the one hand, the camouflage function of fingerprint browsers may be exploited by malicious users to evade tracking, perform batch malicious operations, or hide attack behaviors. Especially in attack scenarios such as malicious scripts and automated crawlers, fingerprint camouflage increases the difficulty of detection and traceability, making traditional behavior analysis and tracking technologies ineffective. On the other hand, the complexity of fingerprint browsers themselves also introduces new security risks. Since fingerprint camouflage involves the collaborative work of multiple modules, such as network communication modules, browser rendering engines, and camouflage parameter generation modules, the dependency relationships between modules are complex and dynamic, and traditional vulnerability detection methods (such as static code analysis or single-point dynamic analysis) are difficult to cover comprehensively. More seriously, the dependency relationships of these modules often hide potential logical vulnerabilities or design defects. Once exploited by attackers, the security of the entire fingerprint browser may be compromised, thereby threatening users' privacy and security.

[0003] Existing technologies have obvious deficiencies in solving these problems. For the problem of camouflage detection, traditional methods usually perform static analysis based on the characteristic rules of specific camouflage behaviors (such as certain fixed browser parameters), but this method lacks adaptability to complex and dynamic camouflage behaviors and is easily bypassed by opponents through advanced camouflage means. For vulnerability mining, most tools are based on the logical analysis of a single module (such as symbolic execution of a specific function), and it is difficult to capture the vulnerability paths generated by the interaction of multiple modules. In addition, existing camouflage detection and vulnerability mining technologies often run independently and fail to form a collaborative security protection strategy, resulting in the results of camouflage detection being unable to be directly used to repair vulnerabilities, and the discoveries of vulnerability mining being unable to help identify camouflage risks more efficiently. Therefore, existing technical means are unable to cope with the complex camouflage behaviors and internal security risks of fingerprint browsers. Summary of the Invention

[0004] The purpose of the present invention is to disclose a software security detection method and system for fingerprint browsers to solve the technical problems pointed out in the background art.

[0005] To achieve the above purpose, the present invention adopts the following technical solutions:

[0006] On the one hand, the present invention provides a software security detection method for a fingerprint browser, including:

[0007] In the first step, a feature matrix and a module interaction log are obtained based on disguise features, behavior features, and module interaction features;

[0008] In the second step, a disguise detection probability matrix, disguise samples, and a disguise traceability report are obtained;

[0009] In the third step, a module dependency graph is constructed to obtain a disguise propagation path and a set of high-risk modules;

[0010] In the fourth step, logical vulnerabilities and optimal exploitation paths are obtained;

[0011] In the fifth step, a comprehensive risk score is calculated and a protection strategy is selected based on the comprehensive risk score;

[0012] Obtaining the disguise detection probability matrix includes:

[0013] Construct an improved variational autoencoder model, and the variational autoencoder model is used to capture the distribution deviation of the feature matrix and detect disguise behaviors:

[0014] ;

[0015] Where:

[0016] is the input feature matrix;

[0017] is the feature matrix reconstructed by the encoder and decoder;

[0018] represents the Frobenius norm, which is used to measure the feature reconstruction error;

[0019] is the latent distribution generated by the encoder;

[0020] is the prior distribution;

[0021] is a regulation parameter for controlling the strength of the latent space constraint;

[0022] is the regularization term;

[0023] is the distribution deviation;

[0024] Optimize by the gradient descent method, and output the disguise detection probability matrix , the elements in Represents The probability of being a camouflage feature.

[0025] On the other hand, the present invention provides a software security detection system for a fingerprint browser, including a first acquisition module, a second acquisition module, a construction module, a fourth acquisition module, and a calculation module;

[0026] The first acquisition module is used to acquire a feature matrix and a module interaction log based on camouflage features, behavior features, and module interaction features;

[0027] The second acquisition module is used to acquire a camouflage detection probability matrix, camouflage samples, and a camouflage traceability report;

[0028] The construction is used to construct a module dependency graph, obtain a camouflage propagation path, and a set of high-risk modules;

[0029] The fourth acquisition module is used to acquire logical vulnerabilities and the optimal exploitation path;

[0030] The calculation module is used to calculate a comprehensive risk score and select a protection strategy based on the comprehensive risk score;

[0031] Obtaining the camouflage detection probability matrix includes:

[0032] Construct an improved variational autoencoder model, and the variational autoencoder model is used to capture the distribution deviation of the feature matrix and detect camouflage behavior:

[0033] ;

[0034] Where:

[0035] Is the input feature matrix;

[0036] Is the feature matrix reconstructed by the encoder and decoder;

[0037] Represents the Frobenius norm, which is used to measure the feature reconstruction error;

[0038] Is the latent distribution generated by the encoder;

[0039] Is the prior distribution;

[0040] Is a regulation parameter for controlling the strength of the latent space constraint;

[0041] Is the regularization term;

[0042] It is a distribution deviation;

[0043] Optimize through the gradient descent method , and output the camouflage detection probability matrix , The elements in represent is the probability of camouflage features.

[0044] Beneficial effects:

[0045] The present invention proposes a fingerprint browser security detection method and system based on an adversarial environment and multi-hop dependency analysis. The present invention can comprehensively address the challenges of fingerprint browsers in camouflage detection, attack traceability, and vulnerability mining, overcome the shortcomings of existing technologies through innovative technical means, and provide users with an efficient and secure fingerprint browser protection mechanism. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can also be obtained based on these drawings without creative efforts.

[0047] Figure 1 It is a schematic diagram of the software security detection method for the fingerprint browser of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Usually, the components of the embodiments of the present invention described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed present invention, but only represents the selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0049] As Figure 1 shown in an embodiment, the present invention provides a software security detection method for a fingerprint browser, including:

[0050] First step, obtain a feature matrix and module interaction logs based on camouflage features, behavior features, and module interaction features;

[0051] Second step, obtain a camouflage detection probability matrix, camouflage samples, and a camouflage traceability report;

[0052] In the third step, construct a module dependency graph to obtain the camouflage propagation path and the set of high-risk modules;

[0053] In the fourth step, obtain logical vulnerabilities and the optimal exploitation path;

[0054] In the fifth step, calculate the comprehensive risk score and select a protection strategy based on the comprehensive risk score;

[0055] Preferably, obtain a camouflage detection probability matrix, including:

[0056] Construct an improved variational autoencoder (VAE) model, and the variational autoencoder model is used to capture the distribution deviation of the feature matrix to detect camouflage behavior:

[0057] ;

[0058] where:

[0059] is the input feature matrix;

[0060] is the feature matrix reconstructed by the encoder and decoder;

[0061] represents the Frobenius norm, which is used to measure the feature reconstruction error;

[0062] is the latent distribution generated by the encoder;

[0063] is the prior distribution (e.g., a standard normal distribution);

[0064] is a regulation parameter that controls the strength of the latent space constraint; generally, the value range of β is [0, 1]. The larger the value, the stronger the constraint on the latent space, and the smaller the value, the weaker the constraint on the latent space. A common initial value can be β = 0.5, but according to experiments, it may need to be adjusted. For example, if the model is overfitting, β can be increased to increase the constraint;

[0065] is the regularization term;

[0066] is the distribution deviation;

[0067] Optimize by the gradient descent method , use the backpropagation algorithm to calculate the gradient of the loss function with respect to the network parameters, and continuously update the parameters to minimize the loss function, and output the camouflage detection probability matrix , The elements in represent the probability of being a camouflage feature.

[0068] The innovation lies in introducing an additional regularization term , by enhancing the normal constraint of the latent space, improving the sensitivity to the distribution deviation of camouflage features.

[0069] Preferably, the camouflage features include hardware information and network information, the behavior features include API call frequency, page loading time, and file loading times, and the module interaction features include the call frequency and call order between modules, such as the interaction path of the camouflage module calling the network module. The definition of the module interaction feature dimension ensures coverage of the core camouflage functions and running behaviors of the fingerprint browser, providing comprehensive support for subsequent steps.

[0070] Preferably, the hardware information includes the CPU model of the device running the fingerprint browser; the network information includes the IP address of the device running the fingerprint browser.

[0071] Preferably, a feature matrix and module interaction logs are obtained based on the camouflage features, behavior features, and module interaction features, including:

[0072] Normalize the camouflage features;

[0073] The camouflage features (such as the IP address range) are processed by interval normalization to eliminate the scale differences between different camouflage schemes:

[0074] ;

[0075] where and are the upper and lower limits of the camouflage range, is the total IP interval size.

[0076] Perform time weighting on the behavior features;

[0077] To emphasize the importance of recent behaviors, introduce a time decay factor for the behavior features :

[0078] ;

[0079] is the behavior feature value, is the collection time, is the current time, is the time decay coefficient, used to control the importance of time.

[0080] Construct the module call feature matrix M:

[0081] ;

[0082] Among them, is the call weight of module to module ; represents the number of calls, is the weight of the k3rd type of call; N1 represents the total number of call types;

[0083] Call types include different API calls, different request types (GET, POST, etc.) or different operation methods (synchronous calls, asynchronous calls, etc.). Each type may have a different degree of impact on security, so it is necessary to assign a weight to each call type.

[0084] Combine the collected camouflage features , the standardized behavior features and the module call feature matrix into a unified feature matrix , in the form as follows:

[0085] ;

[0086] Among them, is the number of time windows, and each row represents the browser state within a time window, is the total number of modules;

[0087] Extract the call records between modules from the browser running logs to generate the module interaction log . Each call record contains the modules with call relationships, call frequencies, call types, and timestamp sequences. For example, the record format is as follows:

[0088] . The interaction log is directly used for subsequent module dependency analysis and vulnerability mining.

[0089] The feature matrix and the module interaction log are respectively used for camouflage detection and the construction of the module dependency graph. The feature matrix provides information on dynamic behavior and camouflage patterns, while the interaction log captures the complex dependency relationships between modules.

[0090] Preferably, obtain camouflage samples, including:

[0091] Use a generative adversarial network (GAN) to generate complex camouflage samples , to enhance the recognition ability of the camouflage detection model for complex camouflage behaviors; the optimization objective function of the generative adversarial network is:

[0092] ;

[0093] Wherein:

[0094] is random noise sampled from a latent distribution;

[0095] is a camouflage sample generated by the generator;

[0096] is a discriminator that determines whether a sample is a real feature;

[0097] represents the optimization objective function;

[0098] represents the expectation calculation for the random noise z sampled from the latent distribution p(z), represents the expectation calculation for the real data sample x from the data distribution X, where x represents the real data sample.

[0099] The generator of the GAN generates camouflage samples , and these samples are used for adversarial training of the camouflage detection model to further improve the generalization ability of camouflage behavior detection.

[0100] Preferably, obtain a camouflage traceability report, including:

[0101] Combine the camouflage detection probability matrix with the module interaction log to construct a camouflage propagation weight matrix :

[0102] ;

[0103] Wherein:

[0104] represents the camouflage propagation weight from module to module ;

[0105] represents the number of calls of module calling module ;

[0106] is the time correlation adjustment factor;

[0107] and are the latest timestamp and the earliest timestamp for the call between modules;

[0108] To prevent positive numbers with a zero denominator.

[0109] ϵ is a positive number to prevent a zero denominator, usually taking a very small positive number. Common values include:

[0110] ϵ = 1e-5: Commonly used to avoid division-by-zero errors in calculations;

[0111] ϵ = 1e-8: Used to ensure numerical stability when the time-stamp difference is very small.

[0112] Construct a camouflage propagation graph through the weight matrix and use the depth-first search algorithm to mark the propagation path of the camouflage behavior; finally, output a camouflage traceability report , the content includes:

[0113] The source module of the camouflage behavior;

[0114] The set of propagation paths and affected modules;

[0115] The camouflage propagation weight between modules.

[0116] γ is a time-correlation adjustment factor, which is used to balance the influence of time factors on the propagation weight. Usually, the value of γ is adjusted according to the application scenario, and the typical value range can be from 0.1 to 1. For example:

[0117] γ = 0.5: Indicates that the influence of time factors on the propagation weight is moderate;

[0118] γ = 1.0: Indicates that the influence of time factors on the propagation weight is very strong;

[0119] γ = 0.1: Indicates that the influence of time factors on the propagation weight is weak.

[0120] Provide the subsequent dependency analysis model with camouflage samples to enhance the robustness of subsequent model training, and the camouflage traceability report to support the construction of the module dependency graph.

[0121] This step realizes the detection of camouflage behaviors and the generation of complex camouflage samples by combining improved VAE and GAN models, and provides basic support for subsequent module dependency analysis and vulnerability mining through the traceability of the camouflage propagation path.

[0122] Preferably, construct a module dependency graph, obtain the camouflage propagation path and the set of high-risk modules, including:

[0123] Construction of the module dependency graph:

[0124] Module dependency graph Consisted of a set of modules and a set of directed edges The edge represents that module calls module ;

[0125] The calculation of the weight comprehensively considers the following three parts:

[0126] Influence of camouflage probability: Use the camouflage probability of the module to describe the propagation of camouflage on the call path;

[0127] Call frequency: Extract the number of calls from the module call feature matrix of module to module ;

[0128] Time decay factor: Through time series information, introduce time correlation to reduce the influence of historical calls;

[0129] The expression of the module propagation influence weight is:

[0130] ;

[0131] Where:

[0132] is the call time difference between module and module ;

[0133] is the time decay parameter used to adjust the influence of time factor on the propagation weight;

[0134] The value of τ can be set according to the actual scenario and data, which can be set to a specific time window, such as τ = 60 (indicating a time decay of 60 seconds), or set according to the average value of the time distribution in the data, such as τ = 1000 (indicating a decay of 1000 seconds).

[0135] Through the above calculation, a directed graph containing all module call relationships is generated

[0136] Analysis of camouflage propagation path:

[0137] In the constructed module dependency graph , perform an analysis of the camouflage propagation path for the high-weight edges with weights greater than the set weight threshold:

[0138] For each path , define the propagation influence score :

[0139] ;

[0140] Select paths with a propagation influence score higher than the threshold and mark them as high-disguise propagation paths, recording the set of modules on the paths;

[0141] High-weight edges refer to those edges with relatively large weight values and having a significant impact on the disguise propagation path, and usually a threshold (0.6) can be set for screening.

[0142] Marking of high-risk modules:

[0143] According to the high-weight edges in the propagation path, evaluate the risk level of each module:

[0144] For the module , calculate the disguise propagation score , defined as the sum of the weights of all associated edges:

[0145] ;

[0146] If exceeds the set threshold , then mark the module as a high-risk module, outputting its module number and risk score ; V represents the set of modules.

[0147] The setting rules of

[0148] include:

[0149] Or,

[0150] Rules based on percentage: Set the threshold as the highest disguise propagation score of the top 10% or 20% of all modules;

[0151] Or,

[0152] Rules based on historical data: Through the known high-risk modules in historical data, statistically analyze the distribution of their disguise propagation scores, and select the 90% or 95% percentile of the score distribution as the threshold.

[0153] This step constructs a module dependency graph by combining the disguise detection probability and module interaction logs, analyzes the propagation paths and influence scopes of disguise behaviors among modules, determines high-risk modules, and lays a data foundation for subsequent vulnerability mining and security protection.

[0154] In the module dependency graph , define the multi-hop dependency strength between modules , For capturing dependencies from module to module :

[0155] ;

[0156] Wherein:

[0157] is the maximum weight path from module to ;

[0158] is the call weight of edge ;

[0159] is the probability of disguise propagation on edge ;

[0160] is the coefficient for adjusting the impact of disguise propagation;

[0161] This formula combines the call weight and the impact of disguise propagation, focuses on analyzing high-dependency strength paths, and screens potential high-risk chains. By controlling the weight of disguise propagation in dependency analysis, it ensures that the impact of disguise behavior is properly reflected in the dependency path.

[0162] Logical vulnerability mining:

[0163] On the paths where the multi-hop dependency strength of the filtered paths is greater than the set multi-hop dependency strength threshold , analyze logical vulnerabilities:

[0164] Construct a path constraint set , aggregating the logical constraint conditions of the modules on the path:

[0165] The constraint set of each module describes its logical conditions and input-output relationships; The constraint conditions of the constraint set include; logical relationships such as module input-output legality, data verification, permission control, and functional dependencies;

[0166] For example, the set multi-hop dependency strength threshold can be three-quarters of the number of edges on the maximum weight path.

[0167] Combined path constraints:

[0168] ;

[0169] ;

[0170] Use a constraint solver to check the path constraints Satisfiability. If satisfied, mark the path as a logical vulnerability;

[0171] Vulnerability exploitation path optimization:

[0172] For paths marked as logical vulnerabilities, optimize the vulnerability exploitation path:

[0173] Define the path cost as the sum of the costs of all dependencies on the path:

[0174] ;

[0175] The optimization goal is to minimize the path cost and find the optimal exploitation path , and the output is the potential vulnerability attack path.

[0176] Preferably, calculate the comprehensive risk score and select a protection strategy based on the comprehensive risk score, including:

[0177] Calculate the vulnerability impact score :

[0178] For the vulnerabilities related to the module in the vulnerability list, use the path cost to calculate its impact contribution:

[0179] ;

[0180] Among them:

[0181] is the number of vulnerabilities related to the module ;

[0182] is the path cost of the optimal exploitation path of the th vulnerability;

[0183] is the amplification factor used to enhance the impact of high-cost paths;

[0184] is a positive number to prevent the denominator from being zero;

[0185] Calculate the disguise propagation score :

[0186] Based on , introduce a time decay regularization term to reflect the dynamic impact of disguise propagation:

[0187] ;

[0188] Among them:

[0189] is the disguise propagation score for the module ;

[0190] is the interval between the most recent risk event of the module and the current time;

[0191] is the time decay parameter;

[0192] is the coefficient for adjusting the impact of disguise propagation;

[0193] Calculate the comprehensive risk score :

[0194] The comprehensive risk score of the module is composed of the vulnerability impact score and the disguise propagation score weighted:

[0195] ;

[0196] where and are the weight coefficients of the vulnerability impact score and the disguise propagation score respectively.

[0197] Furthermore, according to the level of the comprehensive risk score , a dynamic protection strategy can be selected for each module:

[0198] High-risk module processing ( ):

[0199] Isolate the module: Cut off the interaction between the module and other modules, and record abnormal behaviors;

[0200] Limit behavior: Reduce the call frequency of the high-risk module or lower its permissions;

[0201] Generate repair suggestions: Generate a module repair plan according to the vulnerability trigger conditions and the dependency chain.

[0202] Medium-risk module processing ( ):

[0203] Dynamic monitoring: Monitor the running status of the module in real time;

[0204] Abnormal capture: Record its call logs and mark the abnormal call paths.

[0205] Low-risk module processing ( ):

[0206] Keep running normally and update the risk assessment records regularly.

[0207] and They respectively represent the set first risk score threshold and the second risk score threshold.

[0208] Furthermore, the execution process of the protection measures is used as feedback to update the camouflage detection model and the dependency analysis model:

[0209] Model update mechanism:

[0210] Call behaviors and camouflage features of the newly added isolation module are added to update the parameters of the camouflage detection model;

[0211] Dynamically adjust the edge weights in the module dependency graph to reflect the latest risk distribution.

[0212] Adaptive adjustment: Recalculate the camouflage propagation impact score according to real-time monitoring data and the time decay coefficient , ensuring the dynamic adaptability of the model.

[0213] By introducing a time decay regularization term and a propagation impact weight for the patent scenario, calculating the comprehensive risk score of the module, and dynamically triggering real-time protection measures, this step realizes a closed-loop design from risk assessment to active protection, providing core guarantee for the security of the entire patent system.

[0214] The present invention also provides a software security detection system for a fingerprint browser, including a first acquisition module, a second acquisition module, a construction module, a fourth acquisition module, and a calculation module;

[0215] The first acquisition module is used to obtain a feature matrix and module interaction logs based on camouflage features, behavior features, and module interaction features;

[0216] The second acquisition module is used to obtain a camouflage detection probability matrix, camouflage samples, and a camouflage traceability report;

[0217] The construction module is used to construct a module dependency graph, obtain a camouflage propagation path, and a set of high-risk modules;

[0218] The fourth acquisition module is used to obtain logical vulnerabilities and the optimal exploitation path;

[0219] The calculation module is used to calculate the comprehensive risk score and select a protection strategy based on the comprehensive risk score;

[0220] Obtaining the camouflage detection probability matrix includes:

[0221] Construct an improved variational autoencoder model, and the variational autoencoder model is used to capture the distribution deviation of the feature matrix to detect camouflage behaviors:

[0222] ;

[0223] Wherein:

[0224] is the input feature matrix;

[0225] is the feature matrix reconstructed through the encoder and decoder;

[0226] represents the Frobenius norm, which is used to measure the feature reconstruction error;

[0227] is the latent distribution generated by the encoder;

[0228] is the prior distribution;

[0229] is the adjustment parameter for controlling the strength of the latent space constraint;

[0230] is the regularization term;

[0231] is the distribution deviation;

[0232] Optimized by the gradient descent method , output the camouflage detection probability matrix , The element in represents is the probability of the camouflage feature.

[0233] The progress of the present invention lies in:

[0234] 1. Camouflage detection and traceability mechanism in an adversarial environment:

[0235] To solve the problems of insufficient adaptability and weak traceability in camouflage detection in the prior art, the present invention introduces a camouflage detection mechanism in an adversarial environment. By constructing an adversarial camouflage behavior model (such as a variational autoencoder and a generative adversarial network), the present invention can accurately identify complex and dynamic camouflage behaviors and infer the true fingerprint features behind the camouflage. Combining the comparison and analysis of the malicious fingerprint database, this mechanism can efficiently trace the camouflage behavior and help quickly identify potential malicious users or attack sources.

[0236] 2. Vulnerability mining technology based on multi-hop dependency analysis:

[0237] In view of the problems of complex internal module interactions and high concealment of vulnerabilities in fingerprint browsers, the present invention proposes a vulnerability mining technology based on multi-hop dependency analysis. By constructing a module interaction dependency graph, dynamically analyzing the call relationships and logical dependency chains between modules, potential cross-module vulnerabilities are discovered. At the same time, symbolic execution technology is used to deeply explore complex logical branches, and reinforcement learning is combined to optimize the vulnerability exploitation path, thereby achieving efficient vulnerability mining and verification. This method overcomes the limitations of traditional single-module vulnerability mining methods and greatly improves the comprehensiveness and accuracy of vulnerability discovery.

[0238] 3. Unified security detection and protection closed-loop:

[0239] In view of the problem that disguise detection and vulnerability mining operate independently in the prior art, the present invention designs a unified security detection and protection closed-loop system. This system directly uses the disguise detection results to optimize the vulnerability mining process, such as preferentially exploring the dependency paths based on disguise behaviors. In addition, the system can generate a comprehensive risk report and automatically trigger protection measures (such as isolating malicious operations or prompting users to repair) based on real-time monitoring of disguise behaviors and vulnerability exploitation attempts. Through this closed-loop design, the present invention realizes the collaborative optimization of disguise detection and vulnerability mining and significantly improves the overall security protection ability.

[0240] Through the above innovative points, the present invention breaks through the limitations of the prior art, can comprehensively address the complex challenges in disguise detection, attack traceability, and vulnerability mining of fingerprint browsers, and provides users with efficient and reliable security protection.

[0241] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A software security detection method for a fingerprint browser, characterized in that: include: The first step is to obtain the feature matrix and module interaction log based on the camouflage features, behavior features, and module interaction features; The second step is to obtain the camouflage detection probability matrix, including: Build an improved variational autoencoder model, which is used to capture the feature matrix Distribution deviation, detecting camouflage behavior: ; in: is the input feature matrix; is the feature matrix reconstructed by the encoder and decoder; Represents the Frobenius norm, which is used to measure the feature reconstruction error; The latent distribution generated for the encoder; is the prior distribution; A tuning parameter to control the strength of the latent space constraints; is the regularization term; is the distribution deviation; Optimization by gradient descent , output camouflage detection probability matrix , Elements in express is the probability of camouflaged features, i and j represent modules, is random noise sampled from the underlying distribution; Obtain disguised samples, which are used to perform adversarial training on the disguised detection model; Obtain a spoofing traceability report, including: Combine the camouflage detection probability matrix with the module interaction log to generate the camouflage propagation weight matrix; Construct a camouflage propagation graph based on the camouflage propagation weight matrix; Generate a camouflage traceability report based on the camouflage propagation graph; The third step is to build a module dependency graph to obtain the disguised propagation path and high-risk module set, including: Obtain the disguised propagation path based on the module dependency graph; obtain the high-risk module set based on the disguised propagation path; The fourth step is to obtain logical vulnerabilities and optimal exploit paths, including: Obtain the path belonging to the logic vulnerability based on the module dependency graph, and optimize the path belonging to the logic vulnerability to obtain the optimal exploitation path; Step 5: Calculate the comprehensive risk score and select a protection strategy based on the comprehensive risk score, including: The comprehensive risk score is calculated based on the path cost corresponding to the optimal exploitation path and the camouflage propagation score corresponding to the high-risk module.

2. The software security detection method for fingerprint browser according to claim 1, characterized in that: The camouflage features include hardware information and network information, the behavioral features include API call frequency, page loading time and file loading times, and the module interaction features include the calling frequency and calling sequence between modules; Hardware information includes the CPU model of the device running the fingerprint browser; network information includes the IP address of the device running the fingerprint browser.

3. The software security detection method for fingerprint browser according to claim 1, characterized in that: Obtain feature matrix and module interaction log based on camouflage features, behavior features, and module interaction features, including: Standardize camouflage features; Time-weighted processing of behavioral features; The building block calls the feature matrix M: ; in, It is a module For modules The call weight, Indicates the number of calls. is the weight of the k3th call type; N1 represents the total number of call types; The collected camouflage features , standardized behavioral characteristics and the module call feature matrix Combined into a unified feature matrix , The form is as follows: ; in, is the number of time windows, and each row represents the browser status within a time window. is the total number of modules; Extract the call records between modules from the browser running log and generate module interaction logs ,Each call record contains the module with the call relationship, the call frequency, the call type and the ,timestamp sequence.

4. The software security detection method for fingerprint browser according to claim 1, characterized in that: Get camouflage samples, including: Generate complex disguise samples using generative adversarial networks , enhance the recognition ability of the camouflage detection model for complex camouflage behaviors; the optimization objective function of the adversarial generation network is: ; in: is random noise sampled from the underlying distribution; is a disguised sample generated by the generator; It is a discriminator that determines whether the sample is a real feature; represents the optimization objective function; represents the expected calculation of random noise z sampled from the potential distribution p(z), It means to calculate the expectation from X for the real data sample x.

5. The software security detection method for fingerprint browser according to claim 4 is characterized in that: Obtain a spoofing traceability report, including: The camouflage detection probability matrix Interaction log with modules Combined, construct the camouflage propagation weight matrix : ; in: Representation Module To module The disguised propagation weight of Representation Module Calling Modules The number of calls; is the time-dependency adjustment factor; and The latest and earliest timestamps for inter-module calls; To prevent positive numbers with zero denominators; Through the weight matrix Construct a camouflage propagation graph and use a depth-first search algorithm to mark the propagation path of the camouflage behavior; finally output a camouflage traceability report , including: The source module of the disguised behavior; The set of propagation paths and affected modules; Pretend propagation weights between modules.

6. The software security detection method for fingerprint browser according to claim 5, characterized in that: Build a module dependency graph to obtain the disguised propagation path and high-risk module set, including: Construction of module dependency graph: Module dependency graph By module collection and the set of directed edges Composition, edge Representation Module Calling Modules ; The calculation of weights takes into account the following three parts: Camouflage Probability Impact: Exploitation Module The probability of camouflage Describe the propagation of masquerades on the call path; Call frequency: feature matrix of calls from the module Extract the module To module Number of calls ; Time decay factor: introduces time correlation through time series information to reduce the impact of historical calls; The expression of module propagation influence weight is: ; in: It is a module and modules The call time difference; is the time decay parameter, which is used to adjust the influence of time factors on the propagation weight; Through the above calculations, a directed graph containing all module call relationships is generated , and record the weights of all edges; Analysis of camouflage propagation paths: Module dependency graph being built In the example, the high-weight edges whose weights are greater than the set weight threshold are analyzed for disguised propagation paths: For each path , defining the propagation impact score : ; Select the communication impact score above the threshold The path is marked as a high-camouflage propagation path, and the module set on the path is recorded; High-risk module flags: Based on the high-weight edges in the propagation path, the risk level of each module is assessed: For modules , calculate the camouflage propagation score , defined as the sum of the weights of all incident edges: ; like Exceeding the set threshold , then the module Mark as a high-risk module and output its module number and risk score ; V represents a collection of modules.

7. The software security detection method for fingerprint browser according to claim 6, characterized in that: Obtain logical vulnerabilities and optimal exploit paths, including: Module multi-hop dependency analysis: In the module dependency graph In the definition of multi-hop dependency strength between modules , For capturing slave modules To module Dependencies: ; in: It is a module arrive The maximum weight path of It is on the path The call weight of It is the edge The probability of camouflage propagation on ; is the coefficient that adjusts the effect of camouflage propagation; Logical vulnerability mining: The paths whose multi-hop dependency strength is greater than the set multi-hop dependency strength threshold are selected. Above, analyze the logical loopholes: Constructing a set of path constraints , logical constraints of modules on the aggregation path: Each module The set of constraints Describe its logical conditions and input-output relationships; Combined with path constraints: ; Checking path constraints using the constraint solver If satisfied, the path is marked as a logic loophole; Vulnerability Exploitation Path Optimization: For the paths marked as logical vulnerabilities, optimize the vulnerability exploitation path: Defining path costs is the sum of the costs of all dependencies on the path: ; The optimization goal is to minimize the path cost and find the best utilization path , the output is the potential vulnerability attack path.

8. The software security detection method for fingerprint browser according to claim 1, characterized in that: Calculate the comprehensive risk score and select a protection strategy based on the comprehensive risk score, including: Calculating Vulnerability Impact Score : For the vulnerability list and module Related vulnerabilities, exploiting path cost Calculate its impact contribution: ; in: For modules The number of associated vulnerabilities; is the path cost of the optimal exploit path for the dth vulnerability; is the amplification factor, used to enhance the impact of high-cost paths; is a positive number that prevents the denominator from being zero; Calculating the camouflage propagation score : based on , a time-attenuated regularization term is introduced to reflect the dynamic impact of camouflage propagation: ; in: For modules 's camouflage propagation score; It is a module The interval between the most recent risk event and the current time; is the time decay parameter; is the coefficient that adjusts the effect of camouflage propagation; Calculating a composite risk score : The comprehensive risk score of a module is composed of the weighted vulnerability impact score and the camouflage propagation score: ; in, and They are the weight coefficients of vulnerability impact score and camouflage propagation score respectively.

9. A software security detection system for a fingerprint browser, characterized in that: It includes a first acquisition module, a second acquisition module, a construction module, a fourth acquisition module and a calculation module; The first acquisition module is used to acquire a feature matrix and a module interaction log based on camouflage features, behavior features, and module interaction features; The second acquisition module is used to: Get the camouflage detection probability matrix, including: Build an improved variational autoencoder model, which is used to capture the feature matrix Distribution deviation, detecting camouflage behavior: ; in: is the input feature matrix; is the feature matrix reconstructed by the encoder and decoder; Represents the Frobenius norm, which is used to measure the feature reconstruction error; The latent distribution generated for the encoder; is the prior distribution; A tuning parameter to control the strength of the latent space constraints; is the regularization term; is the distribution deviation; Optimization by gradient descent , output camouflage detection probability matrix , Elements in express is the probability of camouflaged features, i and j represent modules, is random noise sampled from the underlying distribution; Obtain disguised samples, which are used to perform adversarial training on the disguised detection model; Obtain a spoofing traceability report, including: Combine the camouflage detection probability matrix with the module interaction log to generate the camouflage propagation weight matrix; Construct a camouflage propagation graph based on the camouflage propagation weight matrix; Generate a camouflage traceability report based on the camouflage propagation graph; The construction module is used to build a module dependency graph, obtain the disguised propagation path and high-risk module set, including: Obtain the disguised propagation path based on the module dependency graph; obtain the high-risk module set based on the disguised propagation path; The fourth acquisition module is used to obtain logical vulnerabilities and optimal exploitation paths, including: Obtain the path belonging to the logic vulnerability based on the module dependency graph, and optimize the path belonging to the logic vulnerability to obtain the optimal exploitation path; The calculation module is used to calculate the comprehensive risk score and select a protection strategy based on the comprehensive risk score, including: The comprehensive risk score is calculated based on the path cost corresponding to the optimal exploitation path and the camouflage propagation score corresponding to the high-risk module.

Citation Information

Patent Citations

  • Homologous vulnerability security response method and system based on propagation influence analysis

    CN117556432A